Safety Signal Explained: 4 States from Observation to Operating Decision
Safety signals are early evidence that exposure, control quality, or decision conditions may be changing. This F7 explainer defines four states that help leaders move from observation to interpretation, ownership, and an operating decision.
Key takeaways
- 01A safety signal is early evidence that exposure, control quality, or decision conditions may be changing.
- 02The four states are observation, interpretation, ownership, and operating decision.
- 03A signal should be described close to the evidence before anyone assigns a cause.
- 04EHS may coordinate the review, but the owner should be able to change the relevant control.
- 05A closed action is not proof that the exposure changed until the field arrangement is verified.
A safety signal is easy to notice and easy to waste. A repeated workaround, a delayed escalation, or a worker's hesitation may enter a log, receive a label, and disappear without changing the work.
A safety signal is an observable indication that exposure, control quality, or decision conditions may be changing. It becomes useful only when someone interprets its meaning, assigns ownership, and changes the operating decision before harm occurs.
Definition
A signal is not the same as an incident, a metric, or proof that a control has failed. It is an early piece of evidence that deserves a response proportionate to the possible consequence. The evidence can come from a near miss, a field conversation, a maintenance delay, a repeated exception, or a change in workload.
James Reason's work on latent conditions helps explain why signals matter. The visible event is often the last expression of weaknesses that formed earlier in design, supervision, information, or resource decisions. A signal gives leaders an opportunity to examine those conditions while the organization still has room to change them.
Andreza Araujo's work on the gap between declared compliance and operating reality adds a practical test. If a signal is collected but cannot influence a decision, the reporting process is producing data without protection.
4 states of a safety signal
1. Observation
The first state is something seen, heard, measured, or reported. The description should stay close to the evidence. “The isolation point was not accessible during the planned maintenance window” is more useful than “the team was careless,” because the first sentence preserves a condition that can be checked.
At this stage, capture the task, location, time, people exposed, intended control, and immediate change in conditions. Avoid turning an observation into a conclusion before the evidence has been tested.
2. Interpretation
Interpretation asks what the observation may indicate. One inaccessible isolation point could be a local defect, while the same condition across several jobs may indicate a design, planning, or maintenance problem. The question is not whether the signal sounds serious. It is which exposure or control weakness it represents.
Use the consequence as a filter. A small deviation connected to a high-consequence hazard deserves faster attention than a frequent nuisance with no credible path to serious harm, even though the nuisance may still require correction.
3. Ownership
A signal becomes actionable when a person with authority accepts responsibility for the next decision. EHS may coordinate the review, but the owner should be the leader who can change the equipment, schedule, staffing, design, contractor arrangement, or operating rule that shaped the exposure.
Unowned signals often create the appearance of control. They accumulate in dashboards, while the people closest to the work learn that reporting changes nothing. A named owner, a decision date, and an escalation route make the signal part of governance rather than an archive.
4. Operating decision
The final state is a visible change in how work will proceed. The decision may be to continue with a strengthened control, pause the task, redesign the sequence, provide technical support, or escalate the exposure to a higher authority. Recording the signal without recording this decision leaves the risk unresolved.
Verification should happen in the field. The question is whether the changed arrangement is available and usable under the conditions that generated the signal. A closed action in software is not evidence that the exposure has changed.
How to differentiate a signal from a routine data point
| Input | What it provides | What leaders still need |
|---|---|---|
| Near miss | Evidence of an unwanted event that stopped short of harm | The conditions and controls that made recurrence possible |
| Metric movement | A change in recorded frequency or severity | A check that reporting, exposure, and definitions remained stable |
| Worker concern | Firsthand information about task difficulty or uncertainty | A response that protects the person from carrying the risk alone |
| Repeated exception | Evidence that the planned method does not fit the work | A decision about redesign, authorization, or stopping the task |
The difference is not the source of the information. It is the decision value of the information. A routine data point describes what happened. A safety signal asks what may happen next if the conditions remain unchanged.
When should leaders escalate a safety signal?
Escalate when the signal connects to a serious potential consequence, repeats after correction, crosses organizational boundaries, or reveals that the current owner cannot change the relevant control. Escalation should also occur when a metric improves while field evidence becomes less credible, because apparent progress can hide weaker reporting or a changed exposure.
A useful review can take one signal and write the four states in sequence. Name the observation, state the interpretation, identify the owner, and record the operating decision. If the sequence stops at the first or second state, the organization is collecting warning evidence without converting it into prevention.
Final takeaway
A safety signal is not valuable because it was entered into a system. It is valuable when evidence moves through interpretation and ownership until the work, the control, or the decision changes. Leaders who review that chain can find weak conditions early, before a near miss becomes the event that finally attracts attention.
Frequently asked questions
What is a safety signal?
What are the four states of a safety signal?
Is a safety signal the same as a near miss?
Who should own a safety signal?
When should a safety signal be escalated?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.