Witnessed events · oil, gas & industrial
The isolation gets verified at the wellhead. The paperwork gets written after the incident.
Energy isolation, confined-space entry and hot work all turn on a second person confirming something before anyone goes to work. That confirmation happens at a tank battery or a compressor station with no coverage, and it lands on a paper permit.
The failure mode is not a citation. It is a fatality, and then an investigation in which the only evidence is a document produced by the people being investigated.
Why the permit fails exactly when it matters.
Nobody is being careless. The control was designed around a clipboard, and the clipboard has no way to prove any of this.
A signature is not a walkdown
The line accepts whatever is written on it. It cannot distinguish a second person who physically verified every isolation point from one who signed at the truck because the crew was already waiting.
Paper has no honest sense of time
A permit completed at the end of the job looks identical to one completed at the panel before the work started. After an incident, that ambiguity is the whole argument.
The document is held by the party being examined
When OSHA, an insurer or opposing counsel arrives, the evidence lives with the operator or the contractor whose conduct is in question. That is the worst possible position to defend from.
What a verification would have to do to survive the investigation.
This is the same primitive we built for witnessed clinical events. The site is different; the requirement is not.
Two people, provably two people
Both parties sign one record rather than initialling separate boxes, each bound to their own credential. If both signatures resolve to the same key the record refuses to seal — the check lives in the cryptography, not in a policy nobody reads at 5 a.m.
Operator and contractor, no shared login
The two signers usually work for different companies. Records are self-contained and carry each signer’s full public key, so a third party verifies without an account at either firm. Building this per-company would mean re-issuing every credential later.
Sealed on the device, no coverage required
The record completes on the phone in someone’s pocket and queues until the crew is back in signal. The seal time governs, so the sync delay is a fact about the radio, not a question about the crew.
Nobody can quietly revise it, including us
Change the equipment, the isolation points, the time or either name and the record stops verifying. An investigator confirms that independently, in a browser, without trusting the operator or Authyr.
Who this actually protects.
The authorized employee who did it right
After a serious incident, the person who actually walked the isolation and the person who did not have exactly the same evidence: a signature and a recollection. The one who did the job properly is currently protected by nothing.
The HSE manager
A permit programme running across sites you cannot personally see, where gaps surface as broken chains rather than as something an auditor has to happen to notice during a spot check.
The contractor being blamed
When responsibility is contested between operator and service company, a record neither party could have altered is worth considerably more than two sets of paperwork that disagree.
Where this actually stands.
We’d rather tell you this plainly than let you find out on a call.
What exists today
- The two-person seal is built, tested, and proven on live infrastructure — a two-signer record sealed by two real passkeys, synced, and independently verified
- Per-signer keys — each signer’s own passkey signs, so neither party (nor Authyr) could produce a sealed record alone
- Cross-organisation verification from day one — operator and contractor need no shared enrollment authority
- Offline-first sealing with a local queue; the seal timestamp governs, not the upload time
- Selective disclosure — prove the isolation was verified while commercially sensitive fields stay withheld, mathematically bound to the same seal
- A published
lockout_tagoutrecord schema, riding the same envelope as every other witnessed event with no structural changes
What does not exist yet
- A field capture flow for permits — the record type is a schema draft, not a product you can hand a crew
- Integration with any permit-to-work, CMMS or contractor-management system
- Any deployment on a live site
- Measured physical proximity beyond same-device — designed into the schema, not implemented, and labeled as the weak claim it is
Two boundaries we state up front. This proves that two credentialed people co-signed one record and that nothing has changed since — it does not prove either of them walked the isolation points. And we are not selling you compliance: OSHA’s energy-control standard requires periodic inspection by someone other than the person using the procedure, and group lockout has its own rules, but no regulation obliges you to buy a system like this. Any vendor who tells you otherwise is hoping you will not check.
Talk to us about a pilot.
We are Houston-based and looking for one operator or service company willing to tell us what actually happens on a permit today. The founder reads every message.