Most safety software logs incidents. Few close them. The single biggest gap in legacy EHS is the violation that gets reported, sits in a queue, and reappears at the next audit because no one owned the corrective action and no one issued a closure certificate. SiteGuard was architected around the closed-loop incident lifecycle — the seven-stage workflow that takes an incident from field observation to closure with a named reviewer, a defined corrective action, a tracked responsible user, and an issued certificate. This guide walks HSE managers and safety officers through each stage of the workflow, the SiteGuard feature that powers it, and the audit-trail evidence each stage produces. The goal is not to log incidents; it is to close them, demonstrably, with a certificate the auditor and the client can verify in seconds.
Why most incident workflows break at the closure step #
Three failure modes recur in legacy EHS. First, the incident record has no owner — the HSE manager logs it, but no one is assigned to close it, so it sits indefinitely. Second, the corrective action has no reviewer — even if someone completes the correction, there is no second pair of eyes to verify the closure, so the audit trail is incomplete. Third, there is no certificate — the closure is a status field on a record, not an issued artifact, so the auditor cannot verify what was corrected, by whom, and when. SiteGuard's seven-stage workflow eliminates all three failure modes by making closure a workflowed object with a defined lifecycle, a named reviewer, and an issued certificate. The certificate is the artifact that converts a logged incident into a closed incident, and it is exactly what ISO 45001:2018 clause 10.2 requires.
Stage 1 — Violation Reporting captures the incident #
The incident lifecycle begins in the field, with the inspector observing a nonconformity and tapping Report Violation in SiteGuard Field. The Violation Reporting form captures five elements: the violation type (from a configured list — fall-protection, electrical, housekeeping, PPE, etc.), the priority (low, medium, high, critical), a textual description, one or more Photo Evidence attachments, and the forfeit amount if the organisation applies financial penalties. Each photo is automatically stamped with the device GPS coordinates and the capture timestamp, so the evidence is regulator-grade from the moment it is captured. Submitting the violation pushes it to Recent Violations on the inspector's device and to the manager's Violation Closure queue in SiteGuard Manager — the same record, in two views, with no reformatting.
Stage 2 — Recent Violations surfaces it for review #
Recent Violations is the inspector-side view of violations logged in the current month. It serves two purposes: it gives the inspector a personal closure ledger (so they can see which of their findings are still open), and it gives the HSE manager a quick-look queue for triage. The HSE manager reviews the violation, assigns or reassigns priority, and decides whether it warrants a Corrective Action Program or a simple acknowledgement closure. For high-priority violations — a missing harness on a leading edge, a malfunctioning gas detector, an untrained worker in a confined space — the manager escalates immediately to Corrective Action Programs. For low-priority violations — a mislabeled fire extinguisher, a missing exit sign — the manager may close directly with a documented acknowledgement. The triage decision is recorded against the violation, so the audit trail shows why a given finding did or did not trigger a CAP.
Stage 3 — Violation Closure drives the lifecycle #
Violation Closure is the manager-side queue that drives the violation through its status lifecycle. The statuses are: Open (just submitted), In Review (manager is evaluating), Corrective Action Assigned (a CAP has been created and assigned), and Closed (the corrective action is complete, the certificate has been issued, and the reviewer has signed off). The status model is enforced — a violation cannot jump from Open to Closed without passing through Corrective Action Assigned, which means every closed violation has a documented corrective action behind it. This is what ISO 45001:2018 clause 10.2 means by reacting to nonconformity and taking action to control and correct it — the workflow operationalises the clause, rather than treating it as a memo. The status transitions are timestamped and attributed, so the audit trail shows who moved the violation from one status to the next, and when.
Stage 4 — Corrective Action Programs defines the correction #
Corrective Action Programs is the SiteGuard module that defines what the correction actually is. A CAP record includes: the correction type (immediate fix, training, procedure change, equipment replacement, etc.), the description of the required correction, the certificate requirement (whether closure requires a certificate of completion), and the reviewer. The CAP is linked back to the originating violation, so the audit trail from violation to corrective action is bidirectional — the violation record shows which CAP closed it, and the CAP record shows which violation triggered it. This bidirectional linking is what auditors look for under clause 10.2, because it proves the organisation can trace every corrective action back to its originating nonconformity, and every nonconformity forward to its corrective action. For high-hazard sites on NEOM, Red Sea, or Diriyah, the bidirectional link is exactly what the mega-project PMO audits during its quarterly HSE review.
Stage 5 — Assigned Actions tracks the responsible user #
Assigned Actions is the SiteGuard feature that turns a CAP into assignable work, not just paperwork. Once a CAP is created, an Assigned Action is created and assigned to a specific user — a site supervisor, a training manager, an equipment technician — with a due date and a status. The responsible user receives the action on SiteGuard Field, completes the required work, attaches Photo Evidence if applicable, and submits it for closure. The HSE manager reviews the submitted action, approves it (or rejects it back for rework), and the closure certificate is issued. This is the stage that eliminates the no-owner failure mode — every corrective action has a named, tracked responsible user, with the date the action was assigned and the date it was completed. For a tier-1 contractor managing 30 open CAPs across multiple NEOM sites, the Assigned Actions view is the worklist that drives daily HSE operations.
Stage 6 — Certificates and Worker Compliance close the loop #
The closure certificate is the artifact that converts a logged incident into a closed incident. When the assigned action is approved, SiteGuard issues a certificate that records: the corrective action taken, the responsible user, the reviewer, the closure date, and the originating violation. The certificate is stored against the Worker Compliance record of the responsible user, so the worker's safety profile reflects the corrective actions they have completed. For training-type CAPs (e.g., re-training a worker on confined-space entry after a nonconformity), the certificate is also the training record, satisfying ISO 45001 clause 7.2 (competence). The next time an auditor asks what you did about violation 1042, the HSE manager pulls up the violation, the CAP, the assigned action, the certificate, and the Worker Compliance record — all in one view, all bidirectionally linked. That is what closed-loop incident management looks like in practice.