
The chair sets the pace
Recording keeps up with the discussion. Nobody waits for the scribe, and nothing is reconstructed from memory afterwards.
Hazard study environment
Process Hazard Analysis Software
Sit in on a study demonstration
We chair studies and we build the software, so it records the way a study actually runs
We chair hazard studies and we write the recording model, so what the software asks for is what a facilitator needs to capture at the moment it is said. The model follows the discussion rather than routing it into a fixed set of fields, which keeps the study file current with the room and legible when it is reopened years later.
The record stays continuous from drawing revision through to closed action. Revalidation therefore works from the delta instead of repeating the original sweep.
Carries forwardnode set bound to a drawing revision
Study boundary bound to a named P&ID revision with the line list and stream data attached. Nodes segmented by design intent and hydraulic continuity, not by drawing sheet. Sheet based nodes are how studies end up oversized.
Carries forwarddeviation matrix, fully swept
Systematic guide word to parameter sweep under IEC 61882, extensible to batch, transient and startup modes where a steady state matrix would leave the operating envelope unexamined.
Carries forwardseverity ranked against a stated worst case
Causes and consequences captured as discrete linked records, not narrative. Credible worst case is separated from maximum conceivable, so a severity rank states which of the two it was assigned against.
Carries forwardcredited layers, unqualified ones struck
Each claimed safeguard tested for independence, specificity, dependability and auditability before it is admitted as a protection layer, so only protection that genuinely qualifies is credited.
Carries forwardrequired risk reduction factor
Initiating event frequency, enabling conditions and conditional modifiers resolve to residual risk. The required risk reduction factor carries forward into the safety requirements specification.
Carries forwardaction on the corporate register
Actions raised against the originating deviation, classified by hierarchy of control, and exported to the corporate register with ownership and traceability to the scenario preserved.
We keep a study searchable and revalidatable years after it closes. Each deviation is held as discrete linked fields rather than prose, so a reviewer can reach the cause, the safeguard or the action without rereading the study to find them.
| Field | Recorded as | Why it is a field and not prose |
|---|---|---|
| Study basis | P&ID A 214 rev 6, line list rev 3 | Bound to the revision the team actually worked from, so the basis can be established years later. |
| Node | Feed surge drum and downstream pump suction | Segmented by design intent and hydraulic continuity, not by drawing sheet. |
| Guide word and parameter | No / Flow | Systematic sweep to IEC 61882, so coverage can be reported rather than assumed. |
| Deviation | No flow to pump suction during normal running | Stated as a plant condition, not as a component failure. |
| Cause | Suction strainer blinding by upstream fouling | Discrete linked record, so the same cause is searchable across every node. |
| Consequence | Pump runs dry, seal failure, hydrocarbon release at grade | Credible worst case, kept separate from maximum conceivable. |
| Safeguard | Low suction pressure alarm, operator response, low low trip | Each tested for independence before it is credited as a layer. |
| Risk rank | Severity major, likelihood possible, before layers | Ranked on the same record, so the LOPA argument never drifts from the deviation. |
| Action | Confirm trip test interval supports the claimed integrity | Raised against the cause and exported with owner and date intact. |
Every guide word against every parameter, with the cells nobody reached still showing. A visible gap can be justified as out of scope or closed in a further session. An unreported gap leaves the study claiming coverage it does not have.
| Flow | Pressure | Temp | Level | Compo | Reaction | |
|---|---|---|---|---|---|---|
| No | ||||||
| More | ||||||
| Less | ||||||
| Reverse | ||||||
| Part of | ||||||
| As well as | ||||||
| Other than |
Risk ranking and layer credit sit on the same record as the deviation, not in a separate file. The number that leaves the study is the one the safety requirements specification needs.



Recording keeps up with the discussion. Nobody waits for the scribe, and nothing is reconstructed from memory afterwards.

Rows fill as the team talks. Causes and safeguards attach to the deviation they belong to, not to a note at the end.

The next cycle opens on what changed since the last one, so a five year revalidation costs a fraction of a repeat sweep.
Every awkwardness in the recording model was found by our own leaders and scribes in live sessions, not in a specification workshop. When a field slows a study down it gets changed, because we are the ones sitting in the room when it does.
A study is bound to the drawing revision it was actually worked from. If that revision is superseded the study does not silently follow it, so the basis it was worked from can always be established.
The environment reports which parameter and guide word combinations were assessed and which were not. A gap that is visible can be justified or closed. A gap that is invisible becomes a finding for somebody else to make.
PHAx records and structures a hazard study. It does not chair one. The quality of a study still rests on an independent competent leader, accurate drawings and a team willing to disagree with the design, and no software changes that.
We will come back with the study duration, the facilitator and scribe it needs and what the licence and support would cost. Tell us the unit and the P&ID revision it sits at.