Replicus SAFU — Control of Work
Safe workpermittingwithout thechange request.
Permit to Work, isolation certificates, temporary defeats and non-permitted work — one configuration-driven platform for oil, gas and process facilities. Your safety team changes the workflow. Not a vendor ticket.
Status — August 2026
SAFU is in pilot. It is not yet a live production product. We are running a first deployment with an offshore operator and taking a small number of additional pilot partners before general availability.
This page describes the platform as specified and being delivered. Capabilities still in delivery are marked. If you are evaluating for a near-term rollout, tell us your timeline on the call and we will be straight with you about what is ready and when.
What SAFU covers
Four safety-critical document types, one state engine, one signature model, one audit trail. Adding a fifth is configuration — not a release.
Permit to Work
Full lifecycle from request through authorisation, issue, live work, suspension and closure. Hazard assessment, gas testing with configurable retest intervals, work-order linkage and discipline sign-off — enforced by the state engine, not by convention.
Isolation Confirmation Certificate
Mechanical, electrical, process and instrument isolations. Isolation points are placed directly on the P&ID inside the platform — markup is a separate layer, the source drawing is never modified, and multiple certificates can mark up the same drawing independently.
Temporary Defeat of Isolation
Tiered authorisation that matches real operational risk — from a control room operator inhibiting a nuisance alarm for a shift, through to multi-signature sign-off on a safety system defeat. The system type determines the authorisation path automatically.
Non-Permitted Work
Low-risk and routine tasks with a proportionate hazard assessment and configurable validity period — so routine work stops competing with permit throughput, and still leaves a record.
Where SAFU is different
01
CompletedConfiguration, not code
Rename a role, reorder a signature step, add a permit type, change terminology to match your site's language. Self-service, three-tier governance (tenant, region, site). No professional services engagement, no change request, no invoice.
02
CompletedIsolations designed on the drawing
An embedded drawing canvas for P&IDs, single line diagrams, schematics and plot plans. Isolation points go where they belong — on the diagram — instead of round-tripping through a separate markup tool and arriving as a flat PDF attachment.
03
CompletedBuilt for the field, offline
A native iOS and Android field app. Read your permit, confirm isolation points, record a gas test and sign with no connectivity. Work queues locally in encrypted, per-user storage and syncs in order when the device is back in range.
04
CompletedSIMOPS that re-checks itself
Conflict detection runs at creation and again at every transition to Live — not once at request time. The Facility Overview gives the control room and the oncoming shift a live picture of what is live, where, and what conflicts were acknowledged.
05
CompletedDeficiencies stay in the record
When a verifier finds a problem, the fix is an in-app assignment to a named person — timestamped, traceable, clearable. Not a phone call, not a corridor conversation, not an email thread outside the audit trail.
06
CompletedWritten for this domain
Instrument isolation as a first-class type. Short-term defeats for control room operators. Long-term isolation review separated from field audit. Dual signature on expired permit closure. Details that only come from working the actual process.
Enterprise from day one
| Authentication | SAML 2.0, OpenID Connect and OAuth 2.0. SSO is the default deployment pattern for enterprise tenants — your identity provider stays the source of truth. |
|---|---|
| Audit trail | Every state change and field edit recorded. Immutable and tamper-evident — no user, including an administrator, can alter or delete an audit entry. |
| Tenancy & access | Three-tier tenancy — tenant, region, site — with role-based access control and row-level data isolation enforced in the database, not only in the application. |
| Signatures | Electronic signature with PIN. PINs are never stored, transmitted in cleartext, or recoverable by any user or administrator. Offline signing keys are generated inside the device's hardware security module and are non-exportable. |
| Integration | Work order integration with SAP PM, including a manual entry fallback for sites without it. REST API and webhooks through the platform integration gateway. |
| Your drawings | P&IDs and schematics are uploaded to your tenant's drawing library and stay under your control. No third-party markup tool in the loop. |
Is it a fit?
Built for
- Offshore platforms and FPSOs
- Refineries, terminals and processing plants
- Thermal, SAGD and upgrader facilities
- Any high-hazard site running PTW, isolations and simultaneous operations
- Sites moving off paper, spreadsheets, or a system that bills for every change
Not this
- SAFU is a Control of Work platform — not a full EHS suite
- Incident management, ESG reporting and environmental compliance come from the wider Replicus platform or an integrated partner
- SAFU is in pilot, not general availability — if you need a production system deployed this quarter, we are probably not your answer yet
- We would rather tell you all of that now than after signature
Request a demo
A working walkthrough of the platform against your own permitting process — not a slide deck. Tell us how you run permits today and we will show you the equivalent in SAFU.