Skip to content
Before Anybody Knows

All notes  /  The programme

Scheduling as a Safety Control

The rota decides who is alone, where, at what hour and under what pressure. It is the most powerful control in this subject and is rarely treated as one.

The programme · Analysis

Almost every lone working risk is created or removed by a scheduling decision taken days earlier by somebody who was not thinking about safety.

When scheduling as a safety control also depends on reliable work records, the reporting resource can support time, attendance and workload review without being treated as the emergency response itself. Compare any workflow with HSE lone-working guidance and keep alarm ownership, escalation and dispatch responsibilities explicit.

What the rota decides

Who is alone, and for how long.

Whether a flagged visit gets two workers or one.

What time of day somebody attends a difficult address.

Whether there is enough time to do the work properly, or whether the person arrives rushed and leaves late.

Whether shifts overlap at opening and closing, or whether there is a gap.

And whether the same person attends the same client, which builds the relationship that prevents most aggression.

The pressure that produces the risk

A round with no slack means a worker who is already late at the third visit.

Which means arriving rushed, skipping the arrival assessment, and being less willing to withdraw — because withdrawal costs a visit and the visit has to be made up.

The schedule creates the conditions under which the dynamic risk assessment is made, and a tight one predetermines the answer.

Building safety into the schedule

Flagged addresses cannot be assigned to one person. This should be a system rule rather than a policy, because a policy is overridden by whoever is covering absence at seven in the morning.

Difficult visits in daylight, which is a constraint the scheduler can apply if they are told which ones.

Travel time counted as work time and scheduled realistically, because compressed travel is where the driving risk enters.

Overlap at opening and closing in retail and security.

And a slack allowance, which is the difference between a schedule that survives a single delay and one that does not.

When staffing is short

The predictable moment when all of the above is abandoned.

Which is why the rules have to state what happens: which visits are deferred, which are converted to phone contact, and who decides.

Decided in advance, by somebody senior, and written down.

Because the alternative is a scheduler at seven in the morning making a safety decision under pressure with no authority to defer anything, and the decision will be to send one person.

The escalation route for a schedule that cannot be staffed safely

Somebody above the scheduler has to be able to say a visit does not happen today.

Named, reachable, and with the authority to disappoint a client.

A service where nobody can make that call will always fill the gap with a lone worker, and every individual decision will look reasonable.

Lone working created by absence

The largest source of unassessed lone working.

Two people rostered, one calls in sick, and the arrangement silently becomes a lone working situation that no assessment covers.

Which should trigger a check rather than a shrug: is this task on the not-alone list, is this address flagged, is there cover?

A single prompt in the absence process handles it, and it is absent from most.

Schedulers as part of the safety system

They need to know what a flag means and that it cannot be overridden.

They need to know which tasks require two people.

They need permission to leave a gap rather than fill it unsafely.

And they need to be told when their schedule produced an incident, which almost never happens and is the feedback that would change the next one.

Training the lone workers and not the schedulers leaves the decision-maker untrained.

Fatigue in the rota

Consecutive nights, short turnarounds, long shifts alone.

Which affect judgement precisely when judgement is the control, and which are entirely scheduling decisions.

Set limits and apply them mechanically, because the decision taken in the moment always favours coverage.

The measures

Flagged visits attended by one person, which should be zero.

Lone working created by same-day absence, counted.

Schedule adherence against planned times, where a persistent gap means the round is not achievable.

Consecutive nights and turnaround times.

And incidents mapped against the schedule that produced them, which is the analysis that connects the rota to the outcome and which almost nobody runs.

The client conversation

Some of this requires telling a client they cannot have what they asked for: not that hour, not that day, not with one person.

Which is a commercial conversation the organisation has to be willing to have, and the willingness is what determines whether the scheduling controls survive contact with a contract.

Where a contract was priced without the pairing requirement, that is the point at which it has to be reopened rather than absorbed by whoever is on the round.

Making the connection visible

Report incidents alongside the schedule that produced them: the round, the time, the staffing, and whether the visit was running late.

Two datasets, one join, and it is the analysis that turns scheduling from an administrative function into a safety control.

Most services hold both and have never put them together.