Draft machine-specific lockout procedures, job hazard analyses and permit packs, keep safety data sheets and records aligned, and flag what a change made stale — a safety professional verifies and authorises.
Take the equipment record, energy sources, isolation points and drawings for one machine from your asset data.
02
Load the procedures, analyses, permits and safety data sheets on file, and the change log that says what moved.
Reason
03
Draft a machine-specific procedure — each energy source, its isolation point, the verification step and the order.
04
Re-read the analyses, permits and records that name the machine, the task or the chemical that changed.
05
Check each safety data sheet against the supplier's current issue and the chemical inventory the plant holds.
Decide
06
Flag a document where the drawing, the walk-down note and the energy-source list do not agree with each other.
07
Hold anything drafted from a general template rather than that machine's own data, and say which it was.
Out
08
Assemble the pack — draft, sources read, what changed, open questions and the documents naming that machine.
09
Present it for verification. Nothing is live until a safety professional has walked it down and authorised it.
→Product statement
The agent drafts, cross-references and flags. A competent safety professional verifies the document against the machine as it stands today and authorises it — no document is live until they do.
Example workflow
One change, end to end
AgentHuman
1Change loggedA machine rebuild, a new guard, a modified task, a chemical substitution or a safety data sheet reissued by the supplier
2Affected documents foundThe procedures, analyses, permit templates, inspection records and training records that name that machine, task or chemical
3Machine data readEquipment record, energy sources, isolation points, drawings, prior walk-down notes and the date the document was last verified
4Draft preparedThe revised procedure or analysis, with every energy source, isolation point and verification step traced to where it came from
No human action required
Stages 1 to 4 run without a person in the loop — finding, reading and drafting all happen against records. A machine with no current walk-down ends that stretch on the spot.
5DecisionSplits on confidence and on whether the machine data supports the draft
Machine data supports the draft
Reaches the safety professional to verify.
Thin, conflicting or stale data
Stops with the gap named and drafts no further.
Safety professional
Walks the machine down against the draft, corrects what the record got wrong, then authorises and issues it.
Verify on the machine · Correct · Send back
Authorised — handed back▼
6Pack filed for verificationDraft, sources, diff, open questions and the walk-down checklist — written to the document system as unapproved
7Outcome evaluatedWhat the walk-down corrected, what the reviewer rewrote, and which documents were still stale at the next audit
Corrections
What the walk-down changes is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Authorising or issuing a permit to work.
Certifying a lockout procedure as verified.
Signing off a job hazard analysis or risk assessment.
Closing an incident, investigation or corrective action.
Automation boundaryAgent acts unaided
✓Draft machine-specific procedures from equipment and energy-source data.
✓Search the documents you hold for what names that machine, task or chemical.
✓Compare safety data sheets against supplier issue dates and the inventory.
✓Assemble the pack, flag stale documents and name what it could not verify.
The agent writes drafts and flags into the document system, always unapproved. Authorising them is not its to write.
Deciding a machine may be worked on.
Declaring a document current without a walk-down.
Changing an isolation point or an energy-control method.
Approving a chemical substitution or a new chemical.
Example output
One procedure revision, annotated
Everything the agent drafts is attached to the change that triggered it and the machine record it was read from.
Draft output · single procedure revisionIllustrative example
Change logged
Machine
Document
Drafted
Confidence
Status
Guard and clamp rebuild
Trim press 4, rebuilt
Lockout procedure, rev 6
Energy sources, one added
86%
Unverified — not live
As receivedThe change as logged and the machine it names, with the revision of the document it affects.
Why this is flaggedThe rebuild added an accumulator that the energy-source list does not carry.
ActionVerify on the machineCorrectSend back
What the score decidesConfidence decides how hard the walk-down looks, never that a document is live.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every logged changeRebuild, new chemical, modified task or a reissued sheet
03Draft & cross-reference
Work from that machine's own data
Use the equipment record, the energy-source list, the drawings and the walk-down notes for that machine, not a general template.
01Approved path
List the documents a change touches
One rebuild usually lands in a procedure, an analysis, a permit template and a training record. The list arrives for the safety officer to confirm, not one search at a time.
02Human review
Send the safety lead to the machine
Time goes to the walk-down and the signature instead of to working out which documents named the machine in the first place.
04Build an evidence trail
Retain the change that triggered it, the sources read, the draft, the flag, the walk-down result and the authorising signature — on both paths.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Integration availability depends on the client's existing systems and API access.
Agent controls
Six layers between the model and a live procedure
Each control wraps the one inside it. A draft clears every layer before a safety professional reads it, and the walk-down sits outside all six.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to finding and flagging if evaluation signals degrade.Roll back
L5TraceabilityRecord the trigger, sources read, draft, flag, walk-down result and signature.Record
L4Competent-person gateVerification, authorisation and issue stay with the person your procedure names.Gate
L3Draft confidenceThin or conflicting machine data is marked for the walk-down to settle.Flag
L2Source agreementDrawings, energy list and walk-down notes that disagree stop the draft and name the conflict.Stop
L1Machine-data scopeDrafts are built from that machine's own record, never from a general template.Constrain
Model coreDraft produced — energy sources, isolation points, verification steps, sources read and confidence
L1 – L2Keep the draft tied to that machine
L3Decides how hard the walk-down looks
L4 – L5Keep authorisation with a person, trail intact
L6Pulls automation back when signals degrade
How Nestack evaluates it
Evaluate the whole document set — not only the procedure at the end.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the draft the safety lead opens
Depth of coverage ▼
E1Final-output evaluationWas every hazardous energy source on the machine named, against a walk-down?
E2Step-level evaluationDid it read the right machine record, drawing revision and walk-down note?
E3Isolation-point accuracyWas each isolation point the one that actually isolates that source?
E4Staleness detectionAfter a logged change, was every affected document found and flagged?
E5Slice evaluationHow does draft quality change across equipment types and ages?
E6Business outcomeWhat did the walk-down correct, and what was still stale at audit?
Floor — the procedure a fitter locks out to
Failure modes
Where each failure originates in the agent
Seven failure modes plotted against the five stages of the agent lifecycle. A wrong lockout procedure can get someone killed, so none of these becomes a live document by itself — verification against the actual machine, by a competent person who then signs it, is the control that stops them. If one gets through anyway, the machine is stood down, the document is withdrawn, everyone trained to it is re-briefed, and the record shows what was issued and who authorised it.
Agent lifecycleDirection of processing →
01 · Retrieval2 modes
SD-01
Stored energy missed
Residual pressure, a spring, a raised ram or a charged capacitor.
SD-02
Isolation point wrong
The disconnect named no longer isolates that source.
Stage readsThe equipment record, energy list, drawings and notes
02 · Reasoning2 modes
SD-03
Template, not machine
A general procedure drafted as though it were specific.
SD-04
Simultaneous work missed
A permit pack that lets two conflicting jobs run at once.
Stage draftsThe procedure, the analysis and the assumptions made
03 · Cross-reference1 mode
SD-05
Change does not propagate
The procedure is revised; the analysis and permit are not.
Stage linksEvery other document that names the same machine
04 · Output1 mode
SD-06
Current but never verified
In date, correctly formatted, never checked against the machine.
Stage returnsThe draft and the flags the safety lead reads
05 · Currency / Version1 mode
SD-07
Superseded sheet kept
The supplier reissued and the old sheet stays on file.
Stage tracksSheet issue dates, template and content versions
Sev-1 · a person could be hurt by the documentSev-2 · the draft rests on the wrong machineSev-3 · records go stale, rework rises
A document is only as good as the machine record behind it
Two machines in one plant are not the same drafting problem. A machine with as-built drawings and a current energy-source list drafts cleanly; a press rebuilt twice, with drawings nobody updated, does not. Reported by slice, not in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Rebuilt or modified machines
6.5%
3.8×
Review
Legacy machines, poor drawings
4.8%
2.8×
Review
Reissued supplier sheets
3.3%
1.9×
Watch
Current standard-build machines
1.3%
0.8×
Normal
Bar: walk-down correction-rate lift vs. plant baseline · scale 0–4.0× · tick marks 2.0×2 of 4 slices over threshold
Evidence-linked improvement
A missed energy source becomes a check on the next draft
What a walk-down corrected, and what an audit found stale, come back as machines the agent is re-tested on before the next pack is drafted.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Walk-down corrections and stale-document findings cluster on one class of machine.
02Diagnose
Traced to the equipment record, a drawing never updated, a missed reference, or a change nobody logged.
03Improve
The retrieval rule, the drafting constraint or the document-link map changes under your document control, with a named approver.
04Verify
Re-run against held-out machines of that type, including the ones the walk-down corrected.
05Learn
That machine becomes a permanent case, and the reason it failed enters the checklist your verifiers work to.
Learn → DetectThe return edge. A change to a safety document is a controlled change — verified, authorised and re-issued before anyone works to it, not after.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, machine and document data, drafting, evaluation, SDS currency, then verification workflow and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Workflow discovery and boundary definition.
02Equipment register and energy-source audit.
03Document inventory and machine-reference map.
04Drawing and walk-down source access.
05Lockout-procedure drafting to your format.
06Hazard-analysis and risk-assessment drafting.
07Change triggers and staleness detection.
08Permit pack assembly and conflict checks.
09Evaluation suite and held-out machine records.
10Chemical inventory and SDS-currency checks.
11Verification workflow and authorisation gate.
12Observability, deployment and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne machine familyProductionProduction document stackAdvancedMulti-site / multi-plant
Introduced at Pilot
Machine-specific procedure drafting✓✓✓
Document-to-machine traceability✓✓✓
Stale-document flagging after a change✓✓✓
Authorisation by your safety professional✓✓✓
Baseline evaluation✓✓✓
Introduced at Production
Hazard-analysis and risk-assessment drafting—✓✓
Permit pack assembly and conflict checks—✓✓
Observability and evaluation—✓✓
Introduced at Advanced
Chemical inventory and SDS currency——✓
Incident and inspection record assembly——✓
Multi-site and enterprise controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on machines and document types in scope, the state of your equipment and energy-source data, chemical inventory size, verification workflow and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your equipment register and energy-source lists→Equipment register and energy-source auditWeek 1
02The procedures, analyses and permit templates you hold today→Document inventory and machine-reference mapWeek 1
03Drawings, as-built records and walk-down notes→Drawing and walk-down source accessWeek 2
04How a change is logged, and who has to hear about it→Change triggers and staleness detectionWeek 3
05Procedures that were wrong before, including the near misses→Evaluation suite, regression cases and failure-mode testingWeek 4
06Your chemical inventory and safety data sheet library→Chemical inventory and SDS-currency checksWeek 5
07Named safety professionals to verify and authorise→Verification workflow, then packs issued under your document controlWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Phases are drawn over the weeks they actually occupy. Week 5 carries both the SDS-currency checks and the first packs your reviewers verify.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Workflow discovery, boundary definition and the document inventoryW2Equipment register, energy-source data, drawings and walk-down notesW3Procedure and hazard-analysis drafting, and the change triggersW4Evaluation suite, held-out machines and permit-conflict testingW5SDS-currency checks, first packs and the verification workflowW6Your safety team walks down, verifies and authorises under your document control
Reading the bandEnergy-source completeness is tested against a walk-down in week 4, before any pack reaches a reviewer in week 5.
At the end of W6Drafts have been walked down, verified and authorised by your own safety professionals, then Agent Care takes over monitoring.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Manufacturing AI agent
Build a safety-documentation helper around your document control.
Show us one machine, the energy-source data you hold for it, and every document that names it today. We'll draft one lockout procedure from your own records, list the analyses, permits and records that machine appears in, and mark what we could not verify without walking it down.