Incident Management & EHS

Every incident — safety, environmental, security, IT, quality — on one record that knows what report it owes.

Eight category kinds on one dynamic-field schema. A track-aware state machine with a regulatory clock that blocks closure until you’ve filed. OSHA 300/300A/301 and RIDDOR F2508 generated from live data. TRIR and DART trended for the board.

Book a demo

Used by EHS teams in manufacturing, energy, healthcare, and construction

EHS teams running on ForgeSOP

Your incident data lives in five systems. None of them talk.

OSHA 300 is reconstructed every December

Three weeks of cross-referencing incident emails, HR records, and a paper logbook to produce a form that should have been generated automatically.

Near misses, deviations, and incidents all live in different places

Quality runs deviations in one tool, safety runs incidents in another, and the lessons learned never cross-pollinate.

Regulatory notification windows are a stopwatch

RIDDOR requires reporting within 10 days. OSHA Severe Injury within 24 hours. If your incident system doesn’t surface notification clocks, you find out you missed one when the inspector calls.

One EHS platform. Every record. Every report.

One dynamic-field schema, eight category kinds

Safety, Environmental, Security, IT, Quality, Customer-Complaint, Operational, and Custom — one schema, each kind with its own required fields and routing. A track-aware state machine runs NEW → TRIAGE → INVESTIGATING → AWAITING_REPORT → CLOSED, and closure is blocked until the reports the incident owes are filed.

Regulatory report generators (not templates)

OSHA 300, 300A, 301 — generated from live data. RIDDOR F2508 — generated from live data. EPA Toxic Release Inventory — exportable. GDPR Article 33 — when an incident involves personal data.

TRIR / DART trended for the board

Real-time TRIR and DART calculations with industry benchmarks. Trend the last 12 months, drill into the contributing incidents, share the dashboard with leadership in one click.

INCIDENT CLASSIFICATION

Eight category kinds. One dynamic-field schema.

Safety, Environmental, Security, IT, Quality, Customer-Complaint, Operational, and Custom. Each kind has its own intake fields, classification rules, regulatory clock, and report-generation logic — on one record type that rolls up together.

Bodily injury, illness, near-miss, or fatality. Triggers OSHA 300/301 in the US and RIDDOR F2508 in the UK based on classification. Severity drives the regulatory clock — OSHA Severe Injury is 24 hours, RIDDOR specified injuries are 10 days.

Safety regulatory report preview

Regulatory clock: 24h OSHA Severe Injury · 10d RIDDOR

Bodily injury, illness, near-miss, or fatality. Triggers OSHA 300/301 in the US and RIDDOR F2508 in the UK based on classification. Severity drives the regulatory clock — OSHA Severe Injury is 24 hours, RIDDOR specified injuries are 10 days.

Safety regulatory report preview

Regulatory clock: 24h OSHA Severe Injury · 10d RIDDOR

Spill, emission, or discharge exceeding reporting thresholds. Triggers EPA Toxic Release Inventory plus applicable state-level notifications, each with their own clocks. Per-substance reportable-quantity logic determines which jurisdictions fire and on what window.

Environmental regulatory report preview

Regulatory clock: Per-substance reportable quantity

Data breach, threat, weapons event, or physical-security incident. When personal data is involved, a 72-hour GDPR Article 33 clock starts and the workflow elevates to a confidentiality-restricted track for security and compliance roles.

Security regulatory report preview

Regulatory clock: 72h GDPR Art. 33 where personal data is involved

System outage, data loss, or access-control incident. Captures impacted services and affected records on the dynamic-field schema; escalates to a GDPR Article 33 path when personal data is in scope, otherwise tracks against an internal SLA.

IT regulatory report preview

Regulatory clock: Internal SLA · GDPR Art. 33 if personal data

A quality deviation, nonconformity, or escape raised as an incident. Routes straight into the Quality workflow — RCA, CAPA, and effectiveness check — and can generate an ISO 9001 nonconformity report.

Quality regulatory report preview

Regulatory clock: ISO 9001 §10.2 corrective-action SLA

A complaint about a product, service, or safety condition. Complaint-handling fields capture the customer, channel, and severity; a complaint that indicates a defect escalates into a CAPA and, where relevant, a recall assessment.

Customer-Complaint regulatory report preview

Regulatory clock: Complaint-handling SLA · escalates to CAPA

A process upset, unplanned downtime, or logistics failure that isn’t itself a safety or quality event. Captured for trend analysis and to spawn corrective actions; ties back to the asset and SOP involved.

Operational regulatory report preview

Regulatory clock: Internal SLA

Define your own category kind with its own required fields, routing, and severity rules — without a schema migration. Custom kinds inherit the same state machine, regulatory-clock, anonymity, and audit-trail behavior as the seeded ones.

Custom regulatory report preview

Regulatory clock: Workspace-defined

Two things most incident tools miss.

The regulatory clock that blocks closure

When an incident owes a report, it enters AWAITING_REPORT — and it cannot be closed until the required filings exist. Time-zone-aware deadlines surface the right form (OSHA, RIDDOR, EPA, GDPR Article 33) before the clock runs out, so a missed window stops being something you discover when the inspector calls.

Anonymous reporting with break-the-glass

Anonymous intake is a workspace policy: report without attaching an identity, keep the record fully auditable. Unmasking requires a dual-approval break-the-glass — two authorized roles must approve, and the unmasking is itself written to the audit trail. The reporter is protected; the exception is controlled.

REGULATORY REPORTS

Auto-generated, audit-defensible, signed.

OSHA 300 log, 300A annual summary, 301 incident report, and RIDDOR F2508 — all generated from live incident records with full data lineage.

  • OSHA 300 — Log of Work-Related Injuries and Illnesses previewHash-chain verified

    OSHA 300 — Log of Work-Related Injuries and Illnesses

  • OSHA 300A — Summary of Work-Related Injuries previewHash-chain verified

    OSHA 300A — Summary of Work-Related Injuries

  • OSHA 301 — Injury and Illness Incident Report previewHash-chain verified

    OSHA 301 — Injury and Illness Incident Report

  • RIDDOR F2508 — UK reportable injury form previewHash-chain verified

    RIDDOR F2508 — UK reportable injury form

METRICS

TRIR and DART that the CFO will believe.

Real-time TRIR (Total Recordable Incident Rate) and DART (Days Away, Restricted, or Transferred) trending. Drill into any month, any site, any chapter kind. Benchmark against your industry’s BLS rate.

  • Per-site, per-region, per-BU rollups
  • Industry benchmarks via BLS data
  • Board-ready PDF and PNG exports
TRIR/DART dashboard with monthly trend and industry benchmark

INVESTIGATIONS

Every incident gets to root cause and stays there.

5-Whys, Fishbone, Bowtie, or ICAM — pick per incident. Findings auto-spawn CAPAs (Corrective and Preventive Actions). CAPA closure runs an effectiveness check tied back to the incident — so "we did the training" doesn’t count as closed unless training records confirm it.

  • Multi-method RCA per chapter kind
  • Bi-directional CAPA wiring with e-signed closure
  • Effectiveness verification: training records, inspection passes, no recurrence in N days
Investigation panel with 5-Whys and bidirectional CAPA linkage

Incident reported on Monday. OSHA 300 line on Tuesday.

  1. 1

    Capture

    Worker reports from phone, or supervisor opens an incident from the desktop. Eight chapter kinds; the form adapts.

  2. 2

    Investigate + classify

    Triage, RCA, regulatory classification. Notification clocks run in the background.

  3. 3

    Close + report

    CAPAs close with evidence. OSHA / RIDDOR lines generated automatically. Audit packet exported on demand.

Built to satisfy

  • OSHA 1904
  • RIDDOR 2013
  • EPA TRI
  • ISO 45001
  • ISO 14001
  • ANSI Z10
  • GDPR
  • SOC 2 Type II
  • HIPAA-ready

Integrates with

  • SAP
  • Oracle EBS
  • Workday
  • ADP
  • Okta
  • MS Teams
  • Slack
  • Power BI

Outcomes EHS leaders actually report.

0 hrs

to generate OSHA 300/300A (was: 80 hrs)

100%

of regulatory clocks tracked in real time

47%

drop in CAPA cycle time

1.8 → 0.9

average TRIR after Y1 (manufacturing customers)

“We used to spend the first two weeks of January reconstructing the OSHA 300 from a paper logbook. This year it took eleven minutes. The auditor asked who built the report. I said: the data did.”
Priya N.EHS Manager, multi-site manufacturer, 2,800 employees, 6 plants

Enterprise pricing, transparent.

Per-site + per-employee tiers. Volume pricing for multi-site organizations. Free 14-day pilot for a single site.

Get pricing

Frequently asked

EHS software (Environmental, Health & Safety software) is a platform for managing the regulated lifecycle of workplace safety, occupational health, and environmental incidents — from incident reporting and root-cause analysis through to corrective actions and regulatory reporting. Modern EHS platforms generate OSHA 300/300A/301 in the US, RIDDOR F2508 in the UK, EPA TRI environmental reports, and ISO 45001 / 14001 audit artifacts from live operational data, replacing the spreadsheet-and-binder world that most EHS teams still live in.

ForgeSOP handles eight incident category kinds on one dynamic-field schema: Safety, Environmental, Security, IT, Quality, Customer-Complaint, Operational, and a Custom kind you define yourself. Each kind has its own required fields, routing, and regulatory clock, but they all share one state machine, one anonymity model, and one hash-chained audit trail — so a safety injury, a data breach, and a customer complaint all live on the same record type and roll up together.

Yes. Anonymous reporting is a workspace policy: a reporter can file an incident without attaching their identity, and the record is still fully auditable. If the identity ever needs to be revealed — for a legal or safety reason — ForgeSOP uses a dual-approval "break-the-glass" workflow: two authorized roles must both approve the unmasking, and the unmasking itself is written to the audit trail. The reporter is protected by default; the exception is controlled and recorded.

Intelex and Cority are mature enterprise EHS suites — extremely deep, slow to deploy, and priced for global enterprises. VelocityEHS is broader and easier to adopt but lighter on audit-grade signature chains. ForgeSOP offers the regulatory report-generator depth of the enterprise suites (OSHA 300/300A/301, RIDDOR F2508), the deployment speed of modern SaaS (live in weeks, not quarters), and a hash-chained audit trail that holds up to FDA-grade inspection. Per-site pricing makes mid-market adoption realistic.

Yes. The OSHA 300 log is generated continuously from live incident records — every incident that meets recordability criteria becomes a row, with the column classification (Death / Days Away / Job Transfer / Other Recordable) determined by the incident’s data. The 300A annual summary aggregates from the same source. Electronic submission compatibility is built in. The audit trail proves every line back to its source incident.

Yes. Incidents classified under RIDDOR 2013 categories (specified injuries, dangerous occurrences, occupational diseases, gas incidents) generate the F2508 form with HSE-aligned categorization. The 10-day regulatory clock runs in the background; missed-deadline alerts escalate to the workspace admin and safety lead.

TRIR (Total Recordable Incident Rate) = (recordable injuries × 200,000) / total hours worked. DART (Days Away, Restricted, or Transferred) is the subset of TRIR that involved lost or restricted time. ForgeSOP calculates both in real time using incident classification + payroll-imported hours (or manually entered hours), and benchmarks them against the relevant BLS industry rate. Drill from the dashboard into the contributing incidents.

Every investigation produces findings; findings auto-spawn CAPAs (Corrective and Preventive Actions) with owners, due dates, and evidence requirements. CAPA closure requires an effectiveness check — for a training-based CAPA, that means training records exist; for an engineering control, an inspection has passed within a freshness window. CAPAs that close without effective evidence are flagged red on the dashboard.

Yes. Native integrations with Workday, ADP, SAP, Oracle EBS for employee + hours-worked data; Power BI, Tableau, and Looker for dashboard exports; Slack, MS Teams, ServiceNow for notification routing. REST API and webhooks for everything else.

Typical mid-market deployment: 2–4 weeks for a single-site pilot, 8–12 weeks for a multi-site rollout. Enterprise-suite competitors typically take 6–18 months. We deploy fast because we ship a real product, not a configurator.

Forge better processes

One platform. Always audit-ready.

Bring SOPs, checklists, audits, incidents, and CAPAs into one connected system for safer, clearer, and more consistent operations.

No credit card required · Built for teams that run on process