The single most common scaling problem in EHS is not site count — it is entity count. A Saudi holding with five subsidiaries bidding on Aramco, SABIC, NEOM, and Red Sea contracts in parallel needs to run each subsidiary's safety operations within the right legal entity boundary, while the holding-level safety director needs cross-entity visibility to govern the group as a whole. Mainstream EHS suites handle this through business hierarchy configuration, user groups, and custom reporting — which works but is a configuration project that adds weeks to deployment and produces reports that are entity-aware only because someone built them that way. SiteGuard takes a different approach: Company Scope is a first-class feature that scopes safety operations across companies and entities by default, and Compliance Reporting rolls the per-entity evidence into a single regulator-ready audit export. This article walks through both features and the operational realities they resolve for a GCC multi-entity operator — the holding that needs group-level visibility, the contractor that needs per-client evidence, and the safety director who needs to defend an audit across all subsidiaries at once.
Company Scope: multi-entity safety as a default #
Company Scope is the manager-side feature that scopes safety operations across companies and entities. When the safety officer creates a site, a plan, a checklist template, a worker, a vehicle, or an equipment record in SiteGuard Manager, that record belongs to a specific company or entity within the holding. Users & Roles manages the role boundaries: a site manager sees only the sites and workers within their entity; a company admin sees the full entity; a holding-level safety director with cross-entity visibility can filter across subsidiaries. The scoping is not a configuration layer added on top — it is a property of every record, set at creation time and enforced by the platform thereafter. This is the architectural decision that makes multi-entity safety a deployment choice rather than a customization project. For a Saudi holding with five subsidiaries — say, a construction subsidiary bidding on a NEOM contract, a logistics subsidiary bidding on an Aramco contract, a facilities management subsidiary bidding on a Red Sea contract, an industrial subsidiary bidding on a SABIC contract, and a corporate services subsidiary running shared services — each subsidiary's safety operations run within their own entity boundary, while the holding-level safety director can see the entire group's safety posture on a single dashboard. The same SiteGuard tenant handles all five entities without duplicating users, sites, or plans across subsidiaries.
Why this matters for holdings and contractors #
For a Saudi holding, the operational reality is that each subsidiary bids on different clients with different compliance regimes — Aramco HSE Code, SABIC safety standards, NEOM sustainability and safety framework, Red Sea Global sustainability standards, Civil Defense inspection cycles. Each subsidiary needs its safety records isolated within its own legal entity for audit defense, but the holding needs cross-entity visibility to govern group safety posture and to defend a group-level audit. Company Scope delivers both: per-entity isolation for subsidiary audit defense and cross-entity visibility for holding-level governance. For a contractor, the operational reality is different: the contractor may run safety operations for multiple clients on multiple sites, and each client expects evidence that is scoped to their contract. Company Scope lets the contractor run all client operations within a single SiteGuard tenant while producing per-client evidence exports through Compliance Reporting — without mixing client data across contracts. This is the difference between a platform that scales with the contractor's growth and one that forces the contractor to provision a new tenant per client, which is operationally unworkable for a contractor running 20 concurrent client engagements. The economic implication is significant: a single SiteGuard tenant handles the multi-entity reality, rather than N tenants each with their own configuration cost.
Compliance Reporting: regulator-ready evidence export #
Compliance Reporting is the manager-side feature that aggregates evidence from Daily Plan visits, violations, and certificates into a regulator-ready export. The safety officer filters by entity, by site, by date range, by certificate type, by violation type, or by inspector — and SiteGuard Manager produces an export that carries the GPS-stamped visit records, the violation history with closure status, the certificate inventory with active versus expired status, and the photo evidence attached to each. The export is shaped by what the regulator expects to see, not by what is easy for the platform to produce — which is the inverse of how most EHS reporting works. For an ISO 45001:2018 stage-2 audit, the safety officer produces the monitoring evidence clause 9.1.1 requires (visit history with GPS stamps), the nonconformity evidence clause 10.2 requires (violation history with corrective actions), and the competence evidence clause 7.2 requires (certificate inventory) — all from the same Compliance Reporting surface. For a Saudi Civil Defense inspection, the safety officer produces the visit evidence the inspector expects (which safety officer visited which site when), the violation evidence (which violations were raised and closed), and the certificate evidence (which workers hold which certificates) — again from the same surface. The export is the single artifact the auditor accepts; the safety officer does not assemble it from five systems.
ISO 45001:2018 clauses 7.2, 9.1.1, 9.2, and 10.2 #
Compliance Reporting is shaped by the specific ISO 45001:2018 clauses a stage-2 auditor samples. Clause 7.2 requires documented evidence of worker competence — the certificate inventory, filtered by entity, by site, by worker, or by certificate type. Clause 9.1.1 requires documented evidence of monitoring and measurement — the GPS-stamped visit history that proves inspections actually happened at the planned frequency. Clause 9.2 requires the internal audit programme — which the safety officer assembles from the visit history, the violation history, and the corrective action closure record. Clause 10.2 requires documented evidence of incident and nonconformity handling — the violation history with closure status and the corrective actions that resolved each. SiteGuard Compliance Reporting produces all four from the same surface, filtered by entity for multi-subsidiary holdings or by client for multi-client contractors. For a Saudi holding defending a stage-2 audit across five subsidiaries, the safety director produces five entity-scoped exports plus one cross-entity view that demonstrates group-level governance — and every record carries the GPS stamp, the reviewer approval, and the template version that makes it audit-grade. This is the difference between an audit that takes a day and one that takes a week of document assembly.
Saudi Civil Defense and Aramco/SABIC contractor qualification #
For a Saudi contractor, the regulator-facing side of Compliance Reporting is what matters most. The Saudi Civil Defense inspection cycle expects safety records that carry verifiable presence evidence, violation history with closure, and worker certificate inventory — all of which SiteGuard Compliance Reporting produces by default. The Aramco Contractor Safety Code expects documented evidence of safety officer site visits at a specified frequency, GPS-stamped where required, with violation closure and corrective action records attached. The SABIC safety standards expect equipment inspection records per asset, with inspector identity and inspection results tracked over time — which SiteGuard produces through the Equipment Inspections module feeding into Compliance Reporting. For a contractor bidding on multiple clients in parallel, the ability to produce per-client evidence exports from a single tenant is the difference between a compliance posture that scales with the contractor's growth and one that breaks under the weight of multiple concurrent audits. Mainstream EHS suites can produce this evidence by stitching together multiple modules and custom reports per client, which works but takes days per audit cycle and is exactly the friction that drives contractors to maintain parallel spreadsheet ledgers outside the EHS system — which is where the audit failures actually happen.
How Company Scope and Compliance Reporting fit the rest of SiteGuard #
Company Scope and Compliance Reporting are the two features that make SiteGuard viable for multi-entity operators, but they do not run in isolation. Company Scope is set at the top of the deployment — every Site, every Daily Plan, every Checklist Template, every Worker Compliance record, every Vehicle, every Equipment Registry record carries its entity. Site Import bulk-loads the site master from spreadsheets including the entity scoping. Users & Roles manages the role boundaries — site manager, company admin, holding-level safety director, auditor — within the entity scope. Platform Settings configures the plan, action, and checklist item types that govern the inspection vocabulary within each entity. Compliance Reporting pulls from Daily Plan visits (Visit History with GPS stamps), Violation Reporting and Violation Closure (violation history with closure status), Corrective Action Programs and Assigned Actions (corrective action closure record), Worker Compliance and Certificates and Certificate Types (competence evidence), Equipment Inspections (equipment inspection record), and Fleet Management and Fleet Expiry Alerts (fleet compliance evidence). Notifications push audit-relevant events to the safety officer in real time, so the manager knows the moment a violation is closed or a certificate expires — events that affect the compliance posture the Compliance Reporting export will eventually reflect. The two features are the convergence point of the entire SiteGuard feature set for a multi-entity operator; without them, the platform is a site safety tool, with them, it is a group safety governance platform.