Industry guide · Internal Tools

Electronic Permit to Work Software: How Do You Stop Two Crews Working the Same Isolation?

Permit to Work software visual showing file signature, lock, and shield alert.
The short answer

Budget $70,000 to $150,000 for a first release in 12 to 18 weeks covering permit issue and close, the electronic isolation register, gas test capture and area based conflict checks. A full control of work platform adding contractor competency, turnaround surge handling, offline field devices and a work order link into SAP PM or Maximo runs $180,000 to $450,000 phased over 6 to 12 months, in our delivery experience. Build when you issue more than roughly 40 live permits a day, run several area authorities, or bring 300 plus contractors on site for a turnaround. Do not build if you are a single small plant issuing under ten permits a day with one permit issuer: Damstra or Enablon Control of Work will serve you better than anything we could write.

Why control of work breaks the moment the permit office gets busy

It is 05:40 in the permit office of a mid size refinery. Twenty two contractor supervisors are queued at the window. The isolation register is a red binder that one person controls. The area authority for the north units is signing his fourth hot work permit while a pipefitter waits to ask whether a spade off the debutaniser is still in or was pulled last Thursday. Somewhere in that queue sit two jobs that must not run together: a crew hydroblasting an exchanger bundle and a crew about to break a flange on a line draining into the same sump. Nothing in that room can see the pair.

The stack around this is familiar. Work orders live in SAP PM or IBM Maximo. Permits are paper, or a PDF form printed, signed, scanned and filed. The isolation register is the binder plus a spreadsheet that only agrees with it some of the time. Gas readings are handwritten by whoever held the detector. Some sites have bought Enablon Control of Work, Sphera Control of Work or Damstra, and use maybe half of it.

Here is the uncomfortable part. Incident investigations at plants like yours rarely find a missing rule. OSHA 1910.147 covers energy isolation, 1910.146 covers confined space entry, 1910.119 covers process safety management, and your site procedure already says the right things. What investigations find is two permits that were each individually correct, issued by different area authorities, for two jobs that shared one drain header. Paper cannot represent that relationship, so the only defence is a supervisor who happens to remember.

Problem 1: conflicts are spatial and system based, and a permit list cannot see them

A permit references an equipment tag. That is where most electronic systems stop. Real simultaneous operations conflicts are not tag against tag, they are relationship against relationship. The jobs that hurt people share a common drain, a common flare header, a vent stack, a scaffold platform above another live job, a crane radius over an operating unit, or a firewater ring main that one of the permits has depressurised.

The commercial packages model a permit to asset link and then a manual SIMOPS review meeting. That review meeting is a human reading a printed list at 06:00, which is exactly the control that failed. What you need is a site model: equipment tags grouped into systems, systems grouped into areas, areas carrying elevation and access relationships, and a rules layer that says which combinations require an additional authority or a hard stop.

What a custom build does: when the issuer opens a new permit against tag E-1204, the system already knows every other live or planned permit that touches E-1204, anything on its isolation boundary, anything on the same sump or flare sub header, and anything physically above or below it in the same structure. It shows the clash before the signature, not in a review meeting after. The rules are yours, written from your SIMOPS matrix, and editable by your HSE lead without a vendor change request. That single capability is normally why the project gets approved.

Problem 2: the isolation register is your safety spine and it is still a binder

Ask a plant manager what the highest consequence data set on site is and the honest answer is the isolation register. Which valves are shut, which spades are in, which breakers are racked out, which of those are long term isolations carried over from the last turnaround, and who is hung on each one. In a lot of plants that lives in a book, a spreadsheet and a set of numbered tags in a cabinet.

What breaks it is time. A long term isolation applied in March is still in place in September, the original applicant has left the contractor, the tag number has been reused, and the de isolation instruction references a drawing revision nobody can find. Then a second job wants a partial de isolation of the same boundary to test a pump, and the register has no concept of partial.

What a custom build does: isolation points are objects, not lines in a book. Each carries its energy source, method, applied by, verified by, tag number, drawing reference and photo. An isolation certificate groups points into a boundary. Permits hang on the boundary, and the system will not allow de isolation while any permit is hung. Long term isolations get review dates and escalate when they pass. Partial de isolation is a first class operation with its own approval, because it happens and pretending it does not is how people get hurt. The register becomes queryable, so the question of what is isolated in unit 4 right now takes two seconds instead of a walk to the permit office.

Problem 3: your approval matrix is not the vendor approval matrix

Every site has grown its own control of work standard, usually after an incident. Hot work in a classified area needs the area authority plus the fire watch nomination plus a gas test within the last 30 minutes. Confined space entry needs a rescue plan and a standby person named on the permit. Night shift permit extension is allowed for cold work only, and only by the shift superintendent. Contractor supervisors can request but never issue. Some permits need the process engineer when the job touches a relief path.

Configurable workflow engines in the big packages will get you close, then force a compromise on the last 20 percent, and the compromise is always in the direction of the vendor model. Sites then run a shadow paper process for the exceptions, which means the electronic record is incomplete, which is the worst of both worlds during an investigation.

What a custom build does: your permit types, your fields, your signature stages and your escalation rules, expressed as data rather than code so HSE can change a rule without a release. Validity windows and shift handover behave the way your standard says, not the way a Norwegian offshore operator negotiated with a vendor in 2014.

Problem 4: turnaround multiplies volume by ten and the field has no signal

Normal operation might be 40 permits a day. A major turnaround takes that to 400 or 600, with contractor crews who have never been on your site, a temporary permit office in a portacabin and three shifts. Any system that is merely acceptable at 40 falls over at 600, usually at the queue rather than in the software.

Two hard constraints shape the build. First, mobile devices inside a process unit need to be rated for the hazardous area classification, so field issue and field gas testing run on intrinsically safe tablets or handhelds, and that hardware is slower and has a smaller screen than the developer laptop the demo was built on. Second, there is often no reliable wifi at the far end of a unit, so the field app must work fully offline and reconcile later, with clear rules about what a field user is allowed to do while offline. Signing a hot work permit offline is not one of them. Recording a gas test result is.

What a custom build does: pre approval of routine permit packs before the turnaround starts, so the 06:00 queue is a collection point rather than a drafting session. Group issue for repeat jobs. Kiosk mode at the gate. A dashboard that shows the shift superintendent live permit count by area, which is the number that tells you whether you have too many people in one unit.

What this costs and how long it takes

Across the 2,000 plus projects Digital Heroes has delivered, the honest shape here is a first release at $70,000 to $150,000 shipping in 12 to 18 weeks. That covers permit types and workflow, the electronic isolation register, gas test capture, area and system based conflict detection and a field view. It is a system the permit office runs on from day one, not a pilot. The full platform, adding contractor competency and induction checks, turnaround surge features, offline intrinsically safe devices, work order integration and analytics, runs $180,000 to $450,000 phased over 6 to 12 months.

What pushes the number up on control of work projects specifically:

  • The number of permit types and how different their rule sets are, since each is effectively its own form and workflow.
  • Building the site model, meaning the tag to system to area hierarchy and the drain, flare and firewater relationships that drive conflict rules. If your P and IDs and equipment register are messy, this is discovery work and it is not optional.
  • SAP PM or Maximo integration, which is a real project on its own if the work order and functional location data is inconsistent.
  • Hazardous area rated hardware and offline sync, which roughly doubles the field app effort compared with a normal tablet app.
  • Multi site rollout where each site insists its standard is different, which it is, so the rules layer has to be genuinely site scoped.

What keeps the number down: start with one unit, two permit types and the isolation register. That is where the risk concentrates and where the learning is.

Build versus buy, and when buying is the right answer

Buy if you are a single plant issuing under ten permits a day with one permit issuer and no turnaround larger than a few dozen contractors. Damstra and the entry tiers of the big platforms will digitise your form, and a custom build would be an expensive way to get a PDF replacement. Buy also if you are a group site being told to standardise on the corporate Enablon or Sphera instance, because fighting that is a political project and not a software one.

Build when two or more of these are true. Your SIMOPS control depends on a person remembering relationships between systems. Your isolation register is paper or a spreadsheet and you have long term isolations older than a year. You have implemented a commercial package and run a shadow paper process for the permit types it could not express. Your turnaround permit office is the bottleneck that delays the 07:00 start every morning. You operate multiple sites with genuinely different standards and one vendor configuration is being forced on all of them.

The threshold is not permit volume alone. It is whether the coordination logic between permits, isolations and areas has become the actual safety control on your site. Once it has, that logic belongs in a system you own and can change the week after an incident, not in a vendor backlog.

How to choose a developer for control of work software

Ask them to whiteboard the data model before you sign anything. A developer who has done this draws permit, isolation point, isolation certificate, tag, system, area, gas test and event log, and can explain why a permit hangs on a boundary rather than on a tag. A developer who draws forms and approvals has built an expense tool and is about to learn process safety on your budget.

Ask specifically how conflict detection works. If the answer is a report the issuer can run, they have not understood the failure mode. It must be evaluated at issue and it must consider relationships between equipment, not just matching tag numbers.

Ask what they have integrated. SAP PM functional locations and Maximo asset hierarchies are different problems. Gas detector data capture, badge and access control systems at the gate, and intrinsically safe device management are each specific. Ask for the named system and version, not a claim about integrations in general.

Ask who owns the code and get it in writing before kickoff. You should own the repository, the infrastructure accounts and the right to hire anyone else. At Digital Heroes the code is yours from the first commit, and on a safety critical system you should walk away from any developer who hedges on that.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. McKinsey's Developer Velocity research finds best-in-class tools are the top contributor to software business success, yet only about 5% of executives ranked tools among their top-three software enablers, signaling underinvestment in developer tools (this finding originates in McKinsey's Developer Velocity study rather than the linked generative-AI article). Source: McKinsey & Company (2023) →
  2. Almost half of all the activities people are paid almost $16 trillion in wages to do in the global economy have the potential to be automated by adapting currently demonstrated technologies. Source: McKinsey Global Institute (2017) →
  3. IBM frames first-time fix rate as a core field service KPI, noting the industry average sits around 80% (roughly one in five jobs needs a return visit). Correction: IBM cites best-in-class providers at 89-98%, not '85%+'. Source: IBM (2024) →
  4. The 2015 CHAOS data (based on the modern definition of success) reports that only about 29% of software projects succeed, 52% are challenged, and 19% fail, with the three most important success skills being executive sponsorship, emotional maturity, and user involvement. Source: The Standish Group (reported via InfoQ Q&A with Jennifer Lynch) (2015) →
Omir Pal Singh · Finance & Accounts Manager · Delhi

Omir handles finance and accounts at Digital Heroes, which puts him close to how software projects are actually billed: milestones, change requests, retainers and the cost of scope that moves. His perspective helps buyers read a proposal properly before signing it.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does a custom electronic permit to work system cost for a refinery?
A first release covering permit issue and close, the isolation register, gas test capture and area based conflict checks typically runs $70,000 to $150,000 and ships in 12 to 18 weeks, based on Digital Heroes delivery experience. A full control of work platform with contractor competency, offline field devices and SAP PM or Maximo integration runs $180,000 to $450,000 over 6 to 12 months. The largest cost drivers are the number of distinct permit types and the quality of your equipment register. Hazardous area rated hardware roughly doubles field app effort.
Is Enablon or Sphera Control of Work good enough, or should we build?
They are credible platforms and if your site is happy inside their permit model, use them. The common failure is the last 20 percent of your standard: a permit type, a signature stage or an isolation practice the configuration cannot express, which forces a shadow paper process and leaves your electronic record incomplete. They also model permits against equipment tags rather than against systems, so conflicts across a shared drain or flare header still depend on a human review meeting. If either of those describes your site, building is the honest answer.
Can permit to work software detect simultaneous operations conflicts automatically?
Yes, but only if the system holds a site model rather than a permit list. Tags need to roll up into systems and areas, and the relationships that actually cause harm, such as a shared sump, a common flare sub header, work directly above another live job or a depressurised firewater section, need to be represented as data. Then the clash is shown to the issuer at the moment of issue instead of surfacing in a morning review. Building that model from your P and IDs is usually the biggest discovery task in the project.
How do we handle long term isolations that carry over between turnarounds?
Treat every isolation point as an object with an owner, a method, a verification record and a review date, not a line in a register. The system then escalates when a review date passes, keeps the drawing reference and photo attached, and blocks de isolation while any permit is still hung on the boundary. Partial de isolation needs to be a first class operation with its own approval, because crews do it whether or not your software supports it. This is the single feature that most improves audit outcomes.
Will a permit system work in the field with no wifi and hazardous area restrictions?
It has to. Devices taken inside a process unit must suit the area classification, which usually means intrinsically safe tablets or handhelds with smaller screens and slower processors than a normal device. The app must run fully offline and reconcile on reconnection, with explicit rules on what is permitted offline. Recording a gas test result offline is reasonable. Collecting an authorising signature for hot work offline is not, and any developer who offers it has misunderstood the risk.
How long does it take to roll out electronic permit to work across several sites?
Plan a first site in 12 to 18 weeks, then 4 to 8 weeks per additional site, most of which is site model building and standard reconciliation rather than engineering. Sites will insist their permit standard differs, and they are usually right, so the rules layer needs to be genuinely site scoped from the start rather than retrofitted. Attempting a single corporate configuration across genuinely different plants is the most common way these programmes stall.
Does the system need to integrate with SAP PM or Maximo?
It should, because a permit without its work order is half a record and duplicate data entry kills adoption in the permit office. The realistic integration is work order and functional location reference in, permit status out, so the maintenance planner can see whether a job is permit ready. Treat this as its own workstream if your functional location data is inconsistent, since cleaning that is often the hidden work. Do not attempt to run permits inside the maintenance system itself, since the approval and isolation logic does not fit there.
What happens to our permit records during an incident investigation?
That is exactly why the build should use an append only event log. Every issue, extension, suspension, gas test, isolation application and close is stored as an immutable timestamped event, and corrections are new events rather than edits. An investigator can then reconstruct what was live on a given piece of equipment at a given hour in minutes, including concurrent work, which is the question paper systems answer with a guess. It also proves the record has not been tidied after the fact.
We only issue about a dozen permits a day. Do we need custom software?
Probably not, and we would say so. At that volume with one issuer and no large turnarounds, a commercial control of work product or even a well disciplined paper system with a proper isolation register is proportionate. The build case begins when several area authorities issue in parallel, when conflicts depend on someone remembering how systems connect, or when a turnaround takes you to several hundred permits a day. Spend the money on competency and supervision until then.
What should I prepare before contacting a software development agency?
A one-page brief beats a 40-page requirements document: the business problem in plain words, who will use the system, the 5 to 10 workflows it must handle, the tools it must connect to, and your budget range and deadline driver. You do not need wireframes, a specification, or technical vocabulary; producing those is the agency's job during discovery. Stating a budget range up front is the single best move, because it gets you honest scoping instead of a quote engineered to win the meeting.
How do I calculate whether custom software will pay for itself?
Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.
What are the most common mistakes companies make when building internal tools?
The three failures Digital Heroes sees most: building for every department at once instead of nailing one workflow, designing without the end users so staff quietly go back to their spreadsheets, and leaving no named owner after launch so small bugs pile up until the tool dies. A subtler fourth is faithfully recreating the old spreadsheet, including its workarounds, instead of fixing the process first. Start with one team's most painful workflow and put the actual users in the room from week one.
At what point does Retool cost more than building a custom tool?
The crossover usually lands between 25 and 50 daily users. At Retool's published Business rates of $50 per standard user and $15 per end user monthly, a 40-person deployment with a typical seat mix runs roughly $9,000 to $15,000 per year, every year, while a comparable custom tool built once for $20,000 to $30,000 carries no per-seat fees and costs about 15 to 20 percent of the build price annually to maintain. On a three-year horizon, custom comes out ahead for most growing teams in Digital Heroes engagements.
Should we build the whole internal tool at once or start with an MVP?
Start with a version that fully replaces one workflow, ship it in 4 to 6 weeks, and let real usage set the roadmap. Internal tools have a captive audience, so you learn within days which features matter, and across Digital Heroes projects roughly a third of initially requested features never get built once staff work with version one. Phasing also spreads the spend: a $40,000 vision becomes a $15,000 phase one that starts paying for itself while phase two is scoped.
How many SaaS seats do we need before building custom becomes cheaper?
The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
Who owns the code when an agency builds my software?
You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.
What are the biggest mistakes first-time software buyers make?
Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.
Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?