The riskiest ten minutes of the day.
A shift handover is the controlled transfer of both the operating picture and the responsibility for it from an outgoing crew to an incoming one. Guidance from major-hazard regulators has converged on the same principles for decades: it should happen face to face, be two-way with both parties accountable for a shared understanding, be supported by a written record rather than replaced by one, and be given the time it needs. Handover failures are a recurring theme in process-safety investigations — the Piper Alpha inquiry found that the status of a permit was not communicated across a shift change — because the information that gets lost is exactly the information that was still unresolved.
Seven things the incoming crew cannot work without.
Why verbal alone loses information
Recall favours the last hour of a twelve-hour shift, so the middle of the shift quietly disappears. Numbers quoted from memory drift. The conversation happens on a running plant with interruptions. Nothing survives for the shift after next, or for the investigation three weeks later that needs to know what was already abnormal on Tuesday.
What a written handover gets right
Fixed structure so a reader knows where to look; exceptions before narrative; numbers pulled from the system so they match every other report; every open item carrying an owner and a condition for closing it; a clear line between what was observed and what was inferred; acknowledged by both parties and retained where it can be searched.
Written supports, never replaces
The document is the agenda for the conversation, not a substitute for it. The incoming crew asks; the outgoing crew answers; critical items are repeated back in the receiver's own words. A signed report handed over in silence has transferred paper, not understanding.
Where handovers go wrong.
- Squeezed into the last three minutes of the shift. Fifteen to thirty minutes of paid overlap is a design decision, not a generosity, and it is the cheapest control on this list.
- A free-text narrative with no structure: unreadable at speed, unsearchable later, and it quietly buries the one open permit in paragraph four.
- Yesterday's report copied forward with the numbers changed. Once a crew reads a template that is always the same, they stop reading it.
- Written by the outgoing supervisor alone, so what the operators actually saw never enters the record.
- Numbers in the handover that disagree with the numbers in the reporting system. After the second time, neither source is trusted.
- Speculation recorded as fact. “Bearing is failing” and “bearing sounds rough at low speed, not investigated” are different statements, and only one of them is honest.
- No retention. When a problem is finally investigated, the shift record is the only evidence of what was already known and when — if it exists.
What makes a handover writable.
A handover is only as fast to produce as the plant data behind it. When states, counts, alarms and work orders already carry asset and product context, the report is assembled rather than composed — that is what contextualization adds and what a Unified Namespace makes available to every consumer at once, with ISA-95 providing the equipment names both crews already use. In practice the handover is where several other threads surface: the shift's OEE losses and their reasons, which alarms are currently shelved after rationalization, deferred work that feeds maintenance, and the observations that later become the timeline in a root cause analysis.
Crews should be editing a handover, not composing one.
Shift Report takes a data bundle you supply — states, counts, alarm events, work orders, quality flags — and drafts the structured written handover in the crew's language, with the exceptions first and the open items listed. The people on shift correct and sign it; the conversation still happens. The agent reasons over the export you give it and does not connect to your plant systems. Five free runs, then it is part of the agents plan.
See Shift Report