Y4.05.2Identifiable lockout/tag ownershipdesign

A lockout tag needs to name who applied it, why, and when it's expected to come off

Aliases: identifiable lockout/tag ownership · hazardous energy control

What it is

A proper tag should identify who authorized and applied the lock, the specific scope of the work, how to reach that person or the corresponding team, the time the lock was applied, and the planned review or release condition — so that anyone encountering the lock in the field knows who controls this isolation and who to coordinate with. A planned release time is a cue for management and communication, not an unlock instruction that should fire automatically once reached — reaching that time means "this needs review," not "this should now be restored."

Why it happens

Binding a lock to a specific, identifiable person — rather than an abstract "team" or "department" — is what actually deters someone uninformed from removing it; a lock anyone can open is a lock in name only. The time information on a tag solves a different problem: for a shift handover or a long-standing isolation, someone arriving later cannot tell whether this lock was applied minutes ago or weeks ago without a timestamp, and the two situations call for completely different handling. But however complete a tag's information is, genuinely safe release still requires independently confirming four things: whether the work itself is actually finished, whether everyone involved has cleared the hazard area, whether removed guards and safeguards have been restored, and whether anyone else who could be affected has been notified. Tag information only makes verifying these four things traceable — it does not substitute for actually checking each one.

Where it stops holding

For privacy reasons, some settings may be unsuited to printing a personal phone number directly on a tag, and a team contact or a dispatch channel can substitute — as long as a path back to the specific responsible person remains traceable. An estimated completion time naturally shifts as work progresses and should not be treated as a process failure just because it was extended once. Common practice generally reserves lock removal to the person who applied it; an exception (the applier has left site and cannot be reached) requires a stricter, predefined alternative removal procedure rather than anyone present acting on their own judgment — the specific requirements for that exception procedure can vary by jurisdiction and must be checked against local rules.

Applying it

Use durable, standardized, clearly legible tags that fully record the responsible person, the equipment involved, the scope of work, the time the lock was applied, the planned review point, and the condition required for release; whenever work is extended, explicitly update the time on the tag rather than leaving stale information hanging that can mislead.

  • How to check: at every shift handover and every non-routine (exception) removal, require verifying each responsible person's identity against who is actually present, complete every step of the applicable exception procedure before allowing removal, and audit for cases where tag information does not match who actually applied the lock.

Related

  • Same group: Y4.05.1 Lockout/tagout for hazardous energy control · Y4.05.3 Permit-to-work field verification · Y4.05.4 Expired permit and residual work state
  • Nearby: Y1.07 Shift handover · Y4.04 Inadvertent-operation prevention devices
  • Search terms: Identifiable lockout/tag ownership · hazardous energy control · safety-critical work

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Y4.05.2