Safe Behavior

How to Design a Stop-Work Authority Drill for a Multi-Shift Plant in 14 Days

A stop-work drill becomes credible when it tests the complete decision path across shifts. This fourteen-day guide helps safety and operations leaders rehearse authority, evidence, handover, and restart decisions without turning the exercise into blame theater.

By 9 min read
workplace setting representing how to design a stop work authority drill for a multi shift plant in 14 days — How to Design a

Key takeaways

  1. 01A stop-work drill should test the complete path from noticing a changed condition to verifying a safe restart.
  2. 02The authority to pause work must be clear before the scenario begins, while restart authority may belong to another role.
  3. 03A calm response protects the voice that raises a concern without removing the need for technical assessment and control.
  4. 04Evidence for restart should include a physical or operational verification, not only a new signature.
  5. 05Multi-shift and contractor participation reveal whether the routine works beyond the usual supervisor relationship.
  6. 06The drill creates value when leadership repairs a barrier and keeps the tested routine visible at the point of work.

A stop-work drill becomes credible when it tests the complete decision path, from noticing a changing condition to restoring work with evidence. A multi-shift plant should rehearse who can stop the task, who receives the escalation, what temporary controls are allowed, and how the restart decision is verified.

Many organizations teach stop-work authority as a sentence on a slide. That is not enough for a night-shift operator who sees a missing guard or a supervisor facing production pressure. The routine has to work across shifts without requiring the person who raised the concern to argue for permission.

James Reason's work on latent failures helps explain why a weak response is rarely only an individual problem. The local behavior is shaped by the reporting channel, the supervisor's first reaction, the clarity of authority, and the controls that remain available after work stops. The following fourteen-day plan turns those conditions into a practical rehearsal.

What you need before starting

Choose one routine task with a credible change point, such as a temporary bypass, line-of-fire exposure, contractor interface, or failed pre-use check. Do not stage a dramatic emergency. The purpose is to test decision quality.

Before the first drill, name the operations owner, EHS facilitator, shift representatives, and evidence recorder. Review the stop-work procedure, the relevant permit or isolation process, and the escalation rules for the selected task. ISO 45001:2018 expects participation and consultation mechanisms, but the drill must show whether they operate at the point of work.

Step 1: Define the decision the drill must test

Write one sentence that describes the decision without revealing the scenario. For example, the drill may test whether a supervisor pauses a routine transfer when the exclusion zone changes. Identify the work, the changing condition, and the decision that must be made.

Verify the sentence with the operations owner and remove any language that already contains the answer. A useful drill asks whether the team recognizes the condition and uses its authority. A weak drill tests whether people can repeat the procedure's preferred wording.

The common error is choosing a hazard too obvious to test judgment.

Step 2: Map the authority path

Draw the shortest path from the first observation to the restart decision. Include the worker, supervisor, area owner, control-room contact, EHS support, and any contractor representative who affects the work. Separate stop authority from restart authority, because the decisions often belong to different roles.

Verify the map during a short shift meeting by asking each role what it can do without approval. If a person says, "I would call my manager first," ask whether the procedure requires a call before the task is paused. The answer should be visible in the local rule, not dependent on confidence or hierarchy.

The common error is making a protective pause depend on too many approvals.

Step 3: Set the no-blame opening response

Agree on the first three responses supervisors will use when work stops. They should acknowledge the concern, stabilize the task, and ask for the observable condition. Avoid questions that sound accusatory.

Verify the response through a short role-play with a supervisor and an operator. The supervisor should be able to say, "Thank you for stopping the task. Let us make the area safe and understand what changed," without turning the moment into a speech about vigilance.

The common error is confusing a calm response with unrestricted acceptance.

Step 4: Choose the evidence standard

Define what must be seen, checked, or recorded before the task can resume. Evidence may include a physical inspection, isolation test, updated permit, revised exclusion zone, or confirmation that the crew understands the change. Use evidence available in the selected operation.

Verify the standard with the person who owns the control. If the owner cannot explain how the control is tested, the drill has identified a control-design gap before the scenario begins.

The common error is treating a new signature as proof that a barrier works.

Step 5: Brief the observers without briefing the participants

Give observers a small evidence sheet with four fields: what changed, who acted, what control was verified, and how restart was decided. Do not give them a scorecard that rewards speed alone. The aim is to test the system, not form completion.

Verify observer consistency by showing two sample descriptions and asking what would count as evidence in each case. Agree on the difference between an observed action and an interpretation. "The operator placed both hands on the radio and called the supervisor" is evidence. "The operator was confident" is an interpretation.

The common error is allowing observers to coach the team.

Step 6: Run the first drill on day three

Run the first rehearsal during a normal operating period, with the smallest group that can expose the decision path. Keep it controlled and stop immediately if the exercise creates a real exposure. The facilitator should announce the drill after the team reaches the pause point or intervention is required.

Verify four timestamps: when the condition became observable, when the task paused, when the escalation reached the right owner, and when the restart decision was issued. The time sequence matters because a team can have a good procedure and still delay the protective action.

The common error is treating the first run as pass or fail.

Step 7: Debrief the decision, not the personality

Hold the debrief within the same shift. Ask what the team saw, what it believed the condition meant, which authority it used, and what evidence was missing. Keep the questions attached to the work system. Do not ask who was brave, who hesitated, or who should have known better.

Verify that the person who raised the concern can describe what happened without being interrupted by the most senior participant. That detail reveals whether the organization is learning from the signal or simply collecting a manager's version of events.

The common error is ending the debrief with a reminder to pay attention.

Step 8: Repair one barrier before the second drill

Choose one barrier exposed by the first drill and repair it before repeating the exercise. The repair may change a handover field, move a radio, clarify the permit owner, add a control-room prompt, or revise the restart checklist. Keep it small enough to complete within the plan.

Verify the repair at the point of work rather than only in a meeting. If a new field is added to a form, ask the next shift to use it during the actual task. If authority is clarified, ask the supervisor to explain the decision without reading from the procedure.

The common error is opening a corrective-action program that delays rehearsal.

Step 9: Repeat the drill across shifts

Run the same decision test with day, evening, and night representatives. Keep the core condition stable so comparisons remain useful, but allow each shift to explain its local constraints. A night team may have different access to maintenance support, a different contractor mix, or a different escalation route.

Verify whether the authority path and evidence standard remain intact when the usual manager is absent. Compare the decisions, not the personalities. If one shift pauses immediately and another waits for approval, the organization has found a design inconsistency that needs attention.

The common error is assuming shared training guarantees shared action.

Step 10: Test the handover after a stop

Introduce a shift change after the task has paused but before the restart decision is complete. Require the outgoing team to transfer the condition, controls, unresolved questions, and restart authority to the incoming team. The incoming supervisor should be able to reconstruct the decision without relying on memory or a private conversation.

Verify the handover by removing one participant from the conversation and asking the incoming supervisor to state what remains unsafe, what has been tested, and who can authorize resumption. If those answers are unclear, the task has not been handed over safely.

The common error is handing over paperwork status instead of exposure status.

Step 11: Add the contractor interface

Repeat the exercise with the contractor role included when contractors perform or control the task. Clarify that the contractor can pause work, the host will receive the concern, and commercial pressure does not replace technical verification.

Verify the contractor's understanding by asking the representative to identify the first person they would contact and the condition that would prevent restart. Use the same evidence standard for employees and contractors unless a documented technical reason requires a different rule.

The common error is assigning a host procedure that contractors never practiced.

Step 12: Measure decision quality with a short review

Use a small review set after each drill. Record whether the pause occurred before exposure increased, the right owner was reached, the critical control was verified, the concern was documented, and the restart decision was understood. These are process signals, not a worker quota.

Verify each observation against a source, such as the observer sheet, a permit revision, a physical check, or a debrief record. Avoid converting the result into a single performance score that can be improved by changing the recording habit.

The common error is rewarding stop-work counts without resolving their causes.

Step 13: Run the leadership review on day twelve

Ask the operations leader to review the evidence and make three decisions. First, which barrier must become standard practice? Second, which authority rule needs clarification? Third, what resource or production decision would make the safe action difficult next month?

Verify that the review ends with named owners and dates. The leader should also state what will happen when the control is unavailable, because a stop-work routine is tested most seriously when the preferred solution cannot be installed immediately.

The common error is praising participation while leaving the system unchanged.

Step 14: Publish the local routine on day fourteen

Convert the tested path into a one-page local routine. Include the right to pause, the immediate response, the escalation route, the evidence needed for restart, the handover requirement, and the rule for documenting unresolved exposure. Place it where the task begins, not only in the training portal.

Verify the routine with a new worker, a supervisor, and a contractor representative. Each person should be able to explain the first action and the restart boundary in their own words. Schedule a short repeat drill after a significant process change, serious near miss, or shift-structure change.

The common error is treating publication as completion.

Final checklist for a credible stop-work drill

  • The scenario tests a realistic change point in routine work.
  • Every role knows who can pause the task and who can authorize restart.
  • The first response protects the reporter from blame while the condition is assessed.
  • Restart depends on verified evidence, not only a new signature.
  • Observers record actions and evidence rather than personality judgments.
  • Day, evening, and night shifts complete the same decision path.
  • Contractors receive the same practical authority and evidence standard.
  • The organization repairs at least one barrier before repeating the test.
  • Leadership assigns owners and resources for unresolved exposure.
  • The final routine is visible at the point of work and scheduled for rehearsal.

Conclusion: authority becomes real when the system rehearses it

Stop-work authority is not established by a policy sentence or a training completion rate. It becomes credible when a worker can pause changing work, a supervisor can respond without defensiveness, and the organization can verify the conditions required for restart across every shift.

Andreza Araujo's safety work consistently connects culture with the decisions an organization makes visible. Her book Safety Culture: From Theory to Practice provides a useful anchor for that distinction, because a declared value matters only when the operating system supports it under pressure.

For more practical safety resources, explore Andreza Araujo's books and field guides or read the site's safe-behavior articles.

FAQ

What is the purpose of a stop-work drill?

A stop-work drill tests whether a team can recognize a changing condition, pause the task, escalate the concern, verify controls, and make a safe restart decision without relying on personal confidence or informal permission.

Should a stop-work drill use a real emergency?

No. A controlled scenario is safer and usually produces better evidence about authority, communication, control verification, and handover. Stop the exercise immediately if it creates a real exposure.

How often should a plant repeat the drill?

Repeat it after significant process, staffing, contractor, or shift changes, and use a planned cadence that fits the site's risk profile. The fourteen-day setup is a launch plan, not a substitute for continued rehearsal.

How can leaders avoid blaming the person who stopped work?

Leaders should begin by acknowledging the pause, stabilize the task, and ask what changed. The review should examine the decision path and available controls before judging individual behavior.

What evidence is needed before work restarts?

The evidence depends on the task, but it should show that the changed condition has been understood, the relevant control is available and working, the affected crew knows the new boundary, and the authorized person has made the restart decision.

Topics safe-behavior stop-work-authority behavioral-safety multi-shift-operations safety-drill control-verification safety-leadership

Frequently asked questions

What is the purpose of a stop-work drill?
A stop-work drill tests whether a team can recognize a changing condition, pause the task, escalate the concern, verify controls, and make a safe restart decision without relying on personal confidence or informal permission.
Should a stop-work drill use a real emergency?
No. A controlled scenario is safer and usually produces better evidence about authority, communication, control verification, and handover. Stop the exercise immediately if it creates a real exposure.
How often should a plant repeat the drill?
Repeat it after significant process, staffing, contractor, or shift changes, and use a planned cadence that fits the site risk profile. The fourteen-day setup is a launch plan, not a substitute for continued rehearsal.
How can leaders avoid blaming the person who stopped work?
Leaders should begin by acknowledging the pause, stabilize the task, and ask what changed. The review should examine the decision path and available controls before judging individual behavior.
What evidence is needed before work restarts?
The evidence depends on the task, but it should show that the changed condition has been understood, the relevant control is available and working, the affected crew knows the new boundary, and the authorized person has made the restart decision.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI