Skip to content
Before Anybody Knows

All notes  /  The programme

Who Owns the Arrangement

The recurring work a lone worker programme generates, and what decays first when nobody has it.

The programme · Analysis

A lone worker programme is not a project with an end. It is a set of lists that go out of date and a chain that has to be tested.

When who owns the arrangement also depends on reliable work records, the original guide can support time, attendance and workload review without being treated as the emergency response itself. Compare any workflow with HSE lone-working guidance and keep alarm ownership, escalation and dispatch responsibilities explicit.

The recurring work

Escalation tree review, quarterly and after every departure.

Testing, quarterly, at realistic hours.

Alert review: false alarm rate, missed check-ins, what happened to each.

Device estate: batteries, replacements, who has what.

Address flags: added, reviewed, retired.

Risk assessments, reviewed after incidents and rota changes.

And the supplier relationship, including what they hold about your people.

A part-time role, usually absorbed by somebody in health and safety or operations who was not asked.

What decays first

The escalation tree, which is the most consequential and the least visible.

Then the device estate: units unaccounted for, batteries flat, people who left still holding one.

Then the address flags, which accumulate and are never retired, so a flag from four years ago drives a two-worker visit that nobody questions and nobody needs.

And finally the testing, which stops quietly because it is the only item with no deadline attached.

Naming the owner

One person, named, with allocated time.

With authority to change intervals, flags and the tree without a committee.

And a deputy, because alarms do not pause for annual leave.

In small organisations this is a fraction of a role, and the fraction is what stands between a system and a shelf of devices.

The runbook

How the tree is maintained and tested.

How an address flag is added, what it must say, and when it is reviewed.

How a device is issued, checked and recovered.

What happens after an alarm, and after an incident.

Written so the deputy can run a quarter unaided, which is the test.

What to report

Monthly: alerts by type, false alarm rate, missed check-ins.

Quarterly: test results with timings, tree review, device audit.

Annually: incidents and near misses, withdrawals, flags added and retired, and whether response times improved.

The measure of whether the role exists

Ask when the escalation tree was last tested.

If nobody knows, the programme is a set of devices — and that is the honest state of a large share of them.

The first ninety days for a new owner

Test the escalation tree, unannounced, at night. It will find something.

Audit the device estate: who has what, is it charged, is it reporting.

Read the last year of alerts and classify them, which produces the false alarm rate nobody has.

Check the risk assessments against the current rota, which will find situations nobody assessed.

And ask ten workers what happens after they press the button, which is the fastest measure of whether the arrangement is understood.

Five tasks, three months, and they produce a complete picture of where the programme actually is.

What to escalate upward

Any task identified as one that should not be done alone, with what it would cost to change.

Response times that cannot be improved without a monitoring contract.

A two-worker requirement that scheduling cannot meet.

These are decisions above the owner's authority, and presenting them with numbers is the role's main contribution beyond the routine work.

Handover

The runbook, tested by having the deputy run a quarter.

The current tree, the device register, the flag list, the test log.

And a note of what is known to be wrong and not yet fixed, which is the most useful document in the set and the one nobody writes.

What the role should not become

The person who answers every alarm, which makes them unavailable to run the programme and creates a single point of failure.

A device administrator, which is a task rather than a role.

Or the person who is blamed when an incident happens, which is where these roles go when the organisation has not decided what it is actually accountable for.

The measure of the role

Time from event to somebody knowing, tested quarterly and trending down.

Findings closed rather than logged.

And whether the workers can describe the arrangement when asked, which is the outcome the whole role exists to produce.

Where the role should sit

Close enough to operations to change a rota, and independent enough to say that a task should not be done alone.

Health and safety with operational authority, or operations with a safety remit — either works and the combination matters more than the department.

Not solely in procurement, which optimises the contract rather than the outcome.

And not in a central function so remote from the work that it cannot get a site briefing, which produces accurate reports about an arrangement nobody follows.