Operational assurance
Operational assurance. Not digital checklists.
Your plant is already covered in software. Maintenance systems. Permit systems. Inspection sheets. Shift logs. SCADA. A historian. And yet, after every incident, the same questions get asked — and answering them takes a fortnight of archaeology.
Every regime ends up asking the same six questions.
COMAH, PSM, PSSR, COSHH, HSG65, ISO 45001, your insurer, your own internal audit. Strip away the vocabulary and the schedule detail and what remains is remarkably consistent. It is also, almost word for word, what gets asked after something goes wrong.
01
Did you know what needed doing?
The definition — versioned, published as a governed act.
02
Was it actually done?
The observation, appended, with the time it was taken on the plant.
03
By the correct person?
The operator, named on the entry and attributable for ever.
04
On the correct equipment?
The equipment, frozen onto the reading at capture — with its full place path.
05
At the correct time?
The window it was due in, and whether it landed inside it.
06
Can you prove it today?
Append-only by construction: corrections add entries, never replace them.
Operational assurance is the discipline of being able to answer them on an ordinary Tuesday, without warning. It sits between procedure and evidence — the procedure says what should happen; the evidence shows what did. Most sites are strong on the first and thin on the second, and the thinness is rarely because the work wasn't done.
The actual difference
Most systems record inspections. Amberhold records relationships.
A site typically holds hundreds of records about the same pump — a maintenance history, an inspection sheet, a permit, a line in last Tuesday's shift log, a note on a whiteboard, a tag someone laminated. None of those systems know they are describing the same machine. Joining them up is a person's afternoon, every time.
A reading on its own is nearly worthless as evidence. Pressure = 4.2 barg answers none of the six questions. What makes it evidence is everything it is attached to — and whether those attachments still say the same thing in two years' time.
So Amberhold freezes them at capture. The equipment the reading was taken on, its full path through the plant, the point definition it was judged against, the window it was due in, who took it and when they took it on the plant— all copied onto the entry as it is written, never re-resolved later. Rename the pump, move it under the unit it's fitted to, retire it: last winter's reading still says exactly what it said last winter.
One reading, and what it carries
4.2 barg
└ 03:14, night shift — taken on the plant,
not when the phone found signal
└ operator, named, attributable for ever
└ point "discharge pressure"
unit + expected band as they read
that night, not as edited since
└ round "PPL night walk"
due window 02:00–06:00
└ equipment P2403
with its whole place path,
frozen at capture
└ the tag on the machine —
where the point asked
for a scanIllustrative, not a screenshot. Where a point observes an area or a process rather than one machine, the equipment link is simply absent — an honest blank, never a placeholder.
The operational memory of your plant.
Engineers don't think in folders. They think in relationships: boilers contain burners, burners have checks, checks produce observations, observations belong to equipment, equipment sits somewhere real. Amberhold is built the same way, which is why nothing has to be filed twice — every record already belongs to the thing it is about.
Pump P2403 ├── rounds that cover it live today ├── observations anchored to it live today ├── temporary controls declared live today ├── verification events (scans) live today ├── identity tag bound to it live today ├── interventions — top-ups, doses live today │ (their own lane: never a reading, │ never range-checked, never │ completes a point) └── one equipment-history screen on the road
Honest as at 2 August 2026. The plant tree answers what Amberhold holds about an item now; the single life-of-the-equipment timeline is not built yet.
This is an evidence model before it is a screen, and the distinction is worth being straight about. What exists today is the anchoring: every observation carried its equipment and its place with it at the moment of capture, rather than being joined up afterwards by a query that has to guess.
What that buys you is retrievability that doesn't depend on anybody having predicted the question. A record that was filed correctly can be found. A record that was anchored correctly can be found by questions nobody designed a form for.
It is also why the equipment-history screen is a matter of building the view rather than repairing the data — and why we won't claim it until it's in front of an operator.
Regulatory expectations
How Amberhold supports industrial assurance.
Almost no industrial regulation prescribes software. What they require is that an organisation demonstrates operational control, monitoring and evidence. Amberhold provides evidence that supports those duties — it never claims compliance on the organisation's behalf. The fourth column is the one that matters most: it is what stays yours, and it is not a small column.
| Regulation or guidance | What it expects | What Amberhold evidences | Still the duty holder's |
|---|---|---|---|
| COMAH 2015 | A safety management system that demonstrably operates — operational control, monitoring, audit and review. | Operator evidence, verification events, temporary controls with bound monitoring, all attributable and append-only. | The safety report, the major-accident prevention policy, competence, procedures. |
| PSSR 2000 | A written scheme, examinations against it, operation within safe operating limits. | Routine surveillance between examinations — pressures, weeps, relief paths, recorded against the equipment. | The written scheme, the competent person, the statutory examinations. |
| COSHH 2002 | Exposure controlled, and precautions kept effective in use. | That the operational checks you defined were done — extraction running, stores inspected, spill kit present. | The assessment, exposure control, health surveillance, LEV thorough examination. |
| HSWA 1974 · MHSWR 1999 | Arrangements for effective planning, organisation, control, monitoring and review. | The monitoring half — what was defined, what was due, what was done, what was found. | The arrangements themselves, and every duty the Act places on the employer. |
| HSG65 | Plan · Do · Check · Act. | Check — active monitoring you can inspect, and the record that feeds review. | Plan, Do and Act. The management system is the site's, not the software's. |
| ISO 45001 | Monitoring, measurement, documented information protected against loss of integrity. | Auditable operational records, append-only by construction rather than by policy. | The whole OH&S management system, and the certification itself. |
| Permit to work | Work authorised against known plant status. | Operational context beside the permit — declared temporary controls, what is being watched, verification status. | Authorising work. Amberhold issues no permits and holds no permit authority. |
| Shift handover | Safety-critical information communicated, prepared and cross-checked. | Not yet a handover feature. Records that would feed one exist today; a handover pack is on the road. | The handover process, its discipline, and the conversation itself. |
Amberhold is regulation-informed and site-controlled: recognised duties shape what the platform can express, and your site decides applicability, limits, frequency and authorised roles. The platform never decides legal applicability. The full mapping, regime by regime →
Where the line is.
A category page is exactly where software companies start overclaiming. So here is the boundary, drawn from our side of it — including the three places this argument is most tempting to stretch.
Straight talk
Permits. Amberhold issues no permits and authorises no work. Your permit system keeps that authority. What Amberhold can put beside it is operational context: what temporary controls are declared on that equipment, what monitoring is bound to them, whether the last check was verified at the machine.
Shift handover.There is no handover feature today, and we won't imply otherwise. The records a good handover pack would draw on — live temporary controls, missed and overdue rounds, abnormal findings, verification failures — exist now. Assembling them into a handover is on the road, not shipped.
Equipment history. The evidence is anchored to equipment today; the single life-of-the-machine screen is not built. We describe that as an evidence model, because that is what it currently is.
And the constant one. Amberhold never decides whether a reading is acceptable, whether a pump sounds wrong, or whether your site is compliant. Competent people do that. Software that graded plant condition would be selling you a judgement it is in no position to make.
Amberhold doesn't make a site compliant.
It makes operational evidence trustworthy.
Every operator action, inspection, verification, temporary control and observation stays permanently connected to the equipment it belongs to — so what you hand an inspector is evidence, not assumption.
Questions we actually get asked
- What is operational assurance?
- The discipline of demonstrating that a plant is being operated the way its management system says it should be. It sits between procedure and evidence: the procedure says what should happen, the evidence shows what did. Most sites are well served on the procedure side and thin on the evidence side — not because people aren't doing the work, but because the record of it is scattered across systems that don't know they're describing the same pump.
- How is this different from inspection or EHS software?
- Inspection software records inspections. Amberhold records relationships: every observation, verification and temporary control is anchored to the equipment it belongs to, at the moment it was captured, and that anchor is frozen so a later re-parent or relink can't quietly restate what a reading said months ago. The difference shows up the day someone asks a question nobody designed a form for.
- Does Amberhold make my site compliant?
- No, and no software can. Compliance comes from people, procedures, maintenance, competence and management systems. What Amberhold does is make the operational evidence behind those things trustworthy: attributable, append-only, and anchored to the right equipment. Applicability, limits and judgement stay with your site and your competent persons.
- Does it replace our CMMS, permit system or DCS?
- No. Your maintenance system owns work orders, your permit system authorises work, your control system runs the plant. Amberhold sits alongside them and holds the operational assurance record — the structured human look at the plant, and what it found. It is deliberately not a CMMS with a different badge.
- Can it tell me everything that happened to one pump?
- Partly, today. The plant tree already answers what Amberhold holds about a given item right now: the temporary controls declared on it, the rounds that cover it, the identity tag bound to it. The full life-of-the-equipment timeline is on the road — but the evidence is already anchored for it, because every observation carried its equipment and place with it at capture rather than being joined up afterwards.
Keep reading
How Amberhold supports industrial safety management
The canonical mapping: every regime, what it requires, what the record evidences, and what Amberhold doesn't do.
Temporary controls register
The clearest case of assurance as a product: declared controls with monitoring bound to each one.
The Complete Guide to Digital Operator Rounds
Where the evidence comes from in the first place — and the questions to ask any vendor, including us.