Safety Indicators and Metrics

Safety Signal Explained: 4 States from Observation to Operating Decision

Safety signals are early evidence that exposure, control quality, or decision conditions may be changing. This F7 explainer defines four states that help leaders move from observation to interpretation, ownership, and an operating decision.

By 3 min read
Safety leader converting an early warning signal into an operating decision

Key takeaways

  1. 01A safety signal is early evidence that exposure, control quality, or decision conditions may be changing.
  2. 02The four states are observation, interpretation, ownership, and operating decision.
  3. 03A signal should be described close to the evidence before anyone assigns a cause.
  4. 04EHS may coordinate the review, but the owner should be able to change the relevant control.
  5. 05A closed action is not proof that the exposure changed until the field arrangement is verified.

A safety signal is easy to notice and easy to waste. A repeated workaround, a delayed escalation, or a worker's hesitation may enter a log, receive a label, and disappear without changing the work.

A safety signal is an observable indication that exposure, control quality, or decision conditions may be changing. It becomes useful only when someone interprets its meaning, assigns ownership, and changes the operating decision before harm occurs.

Definition

A signal is not the same as an incident, a metric, or proof that a control has failed. It is an early piece of evidence that deserves a response proportionate to the possible consequence. The evidence can come from a near miss, a field conversation, a maintenance delay, a repeated exception, or a change in workload.

James Reason's work on latent conditions helps explain why signals matter. The visible event is often the last expression of weaknesses that formed earlier in design, supervision, information, or resource decisions. A signal gives leaders an opportunity to examine those conditions while the organization still has room to change them.

Andreza Araujo's work on the gap between declared compliance and operating reality adds a practical test. If a signal is collected but cannot influence a decision, the reporting process is producing data without protection.

4 states of a safety signal

1. Observation

The first state is something seen, heard, measured, or reported. The description should stay close to the evidence. “The isolation point was not accessible during the planned maintenance window” is more useful than “the team was careless,” because the first sentence preserves a condition that can be checked.

At this stage, capture the task, location, time, people exposed, intended control, and immediate change in conditions. Avoid turning an observation into a conclusion before the evidence has been tested.

2. Interpretation

Interpretation asks what the observation may indicate. One inaccessible isolation point could be a local defect, while the same condition across several jobs may indicate a design, planning, or maintenance problem. The question is not whether the signal sounds serious. It is which exposure or control weakness it represents.

Use the consequence as a filter. A small deviation connected to a high-consequence hazard deserves faster attention than a frequent nuisance with no credible path to serious harm, even though the nuisance may still require correction.

3. Ownership

A signal becomes actionable when a person with authority accepts responsibility for the next decision. EHS may coordinate the review, but the owner should be the leader who can change the equipment, schedule, staffing, design, contractor arrangement, or operating rule that shaped the exposure.

Unowned signals often create the appearance of control. They accumulate in dashboards, while the people closest to the work learn that reporting changes nothing. A named owner, a decision date, and an escalation route make the signal part of governance rather than an archive.

4. Operating decision

The final state is a visible change in how work will proceed. The decision may be to continue with a strengthened control, pause the task, redesign the sequence, provide technical support, or escalate the exposure to a higher authority. Recording the signal without recording this decision leaves the risk unresolved.

Verification should happen in the field. The question is whether the changed arrangement is available and usable under the conditions that generated the signal. A closed action in software is not evidence that the exposure has changed.

How to differentiate a signal from a routine data point

InputWhat it providesWhat leaders still need
Near missEvidence of an unwanted event that stopped short of harmThe conditions and controls that made recurrence possible
Metric movementA change in recorded frequency or severityA check that reporting, exposure, and definitions remained stable
Worker concernFirsthand information about task difficulty or uncertaintyA response that protects the person from carrying the risk alone
Repeated exceptionEvidence that the planned method does not fit the workA decision about redesign, authorization, or stopping the task

The difference is not the source of the information. It is the decision value of the information. A routine data point describes what happened. A safety signal asks what may happen next if the conditions remain unchanged.

When should leaders escalate a safety signal?

Escalate when the signal connects to a serious potential consequence, repeats after correction, crosses organizational boundaries, or reveals that the current owner cannot change the relevant control. Escalation should also occur when a metric improves while field evidence becomes less credible, because apparent progress can hide weaker reporting or a changed exposure.

A useful review can take one signal and write the four states in sequence. Name the observation, state the interpretation, identify the owner, and record the operating decision. If the sequence stops at the first or second state, the organization is collecting warning evidence without converting it into prevention.

Final takeaway

A safety signal is not valuable because it was entered into a system. It is valuable when evidence moves through interpretation and ownership until the work, the control, or the decision changes. Leaders who review that chain can find weak conditions early, before a near miss becomes the event that finally attracts attention.

Explore more practical conversations on safety leadership and operating decisions at Headline Podcast.

Topics safety signals safety indicators leading indicators risk ownership operating decisions

Frequently asked questions

What is a safety signal?
A safety signal is an observable indication that exposure, control quality, or decision conditions may be changing. It becomes useful when someone interprets its meaning, assigns ownership, and changes the operating decision before harm occurs.
What are the four states of a safety signal?
The four states are observation, interpretation, ownership, and operating decision. Together they move early evidence from a description of conditions to a visible change in how work will proceed.
Is a safety signal the same as a near miss?
No. A near miss is one possible source of a safety signal. Other sources include worker concerns, repeated exceptions, maintenance delays, field conversations, and changes in workload or task conditions.
Who should own a safety signal?
The owner should be the leader with authority to change the equipment, schedule, staffing, design, contractor arrangement, or operating rule connected to the exposure. EHS can coordinate without owning every operational correction.
When should a safety signal be escalated?
Escalate when it connects to a serious potential consequence, repeats after correction, crosses organizational boundaries, or reveals that the current owner cannot change the relevant control.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI