Technical Safety Management System
Demonstrate tolerability and retain the evidence behind the demonstration.
The engineering system of record for demonstrating that a major-hazard facility design reduces risk to an approved tolerability basis. It governs the hazard register, major-accident hazards, barriers and safety-critical elements, performance standards, verification schemes and the safety-case evidence that connects claims to supporting records.
A claim is worth the evidence beneath it.
A safety case is a structured argument supported by evidence. TSM maintains the claims, arguments, evidence and conditions that could invalidate them as governed records rather than as a one-time assembled document.
Passing tests is not certification.
Numerical methods are prevented from production use until the required technical review, benchmark reproduction and technical-authority approval have been completed. Passing software tests alone does not constitute engineering certification, so unapproved engines do not produce production safety-integrity or quantitative-risk results.
Each engine states its chain position, its version, the standards it references, how many equations it carries and how many reference cases it has been checked against.
- Methods and deterministic calculation engines are governed through registration, version control, benchmarking and formal admission to production use.A method that has not completed that assurance path remains unavailable for production execution.
- A reference case is namedWhere a result is derived rather than validated, the engine says so and names the reference case it was checked against.
- Refused at the gateA prototype cannot be run in production. The refusal is enforced by the runtime rather than by a policy somebody could waive.
An approved record is superseded, never edited.
Approved technical-safety records are superseded rather than edited. Where a superseded record has downstream dependencies, those dependent records are identified so the need for reassessment remains visible.
Basis, identify, analyse, safeguard, demonstrate, verify.
The application's own navigation, arranged as the demonstration is built rather than as a feature list. Every chip is a page.
The safety basis
The technical safety basis, risk acceptance criteria, the values used in cost-of-averting-a-fatality judgements, governance documents and the regulatory frameworks the demonstration answers to.
- Technical Safety Basis
- Risk Acceptance Criteria
- ICAF / VPF Values
- Governance Documents
- Regulatory Frameworks
Identify
The hazard register, major accident hazard designation, technical safety studies, workshops and the design intent that each hazard is assessed against.
- Hazard Register
- Major Accident Hazards
- Technical Safety Studies
- Workshops
- Design Intent
Analyse
Barrier models, layer-of-protection analysis with an independent-protection-layer library, consequence, quantitative risk assessment, escalation and risk analysis; each held as a governed engineering record.
- Bowties
- LOPA
- IPL Library
- Consequence
- QRA
- Escalation Analysis
- Risk Analysis
Safeguard
Safety-critical elements and their performance standards, fire and gas, fire protection, hazardous area classification, escape, evacuation and rescue, and the temporary refuge assessment.
- SCE & Performance Standards
- Fire & Gas
- Fire Protection
- Hazardous Area Classification
- EER & Temporary Refuge
- OBRA
Demonstrate and verify
The safety case as claims, arguments, evidence and defeaters; tolerability demonstration; verification schemes and independent verification body findings.
- Safety Case
- ALARP
- Verification Schemes
- IVB Findings
Engineering governance
Calculation governance, engines and methods with their executions, controlled references, engineering knowledge and mappings, and the technical safety actions, assumptions and decisions behind them.
- Calculation Governance
- Engines & Calculations
- Engineering Methods
- Method Executions
- Controlled References
- Technical Safety Actions
- Engineering Assumptions
- Engineering Decisions

TSM defines the safeguard. PSM keeps it credible.
TSM governs the design definitions for barriers, safety-critical elements, safety instrumented functions, integrity targets, safety requirements specifications, performance standards and proof-test intervals, and publishes the approved definitions for operational use.
- Offshore and onshore major-hazard regimes in one application
- Occupational safety, incidents and permits are deliberately out of scope
- The enterprise risk register lives in the enterprise risk system, not here

A refused row comes back with the reason it was refused.
Rows refused in recent batches are reported as their own figure, and the guidance is explicit: correct the file and load it again rather than editing the record afterwards. Controlled workbooks carry the organisation's own allowed values, so an import is validated against what the organisation actually recognises.
- Comprehensive extract packages of everything the organisation holds
- A dataset browser stating what each dataset supports and why
- Every load and every extract recorded with what it did
Passing tests is not certification
Every calculation engine in the platform is a prototype. Each has passing software tests; none has been through independent technical review, published-benchmark reproduction and technical authority approval, so production execution is refused by the runtime gate.
No inferred compliance
The application does not infer that a facility is compliant, and it does not produce a safety integrity level or a quantitative risk figure without an admitted engine. Where nothing can be shown, it says so.
Not visible to you, not zero
Where a reader is not permitted to see records, the application says they are not visible rather than reporting a count of zero; because those are different statements to put in front of a technical authority.
Approved records are superseded
An approved engineering record is never edited. Supersession is non-cascading and requires the dependent records to be reassessed, so the demonstration cannot quietly drift.
More of what the application covers.
- Safety case with claims, arguments, evidence and defeaters
- Major accident hazard designation against the hazard register
- Independent protection layer library behind layer-of-protection analysis
- Performance standards held with the element they govern
- Verification schemes and independent verification body findings
- Escape, evacuation and rescue with temporary refuge assessment
- A read-only versioned interface over the governed registers
- Identity-based segregation of duties and an immutable audit trail
The design demonstration, beside the operation it is handed to.
- PSMPSM: Process Safety Management SystemProcess safety in operation. TSM owns the design definitions and publishes them; PSM is the system of record once the plant runs.
- RMSRMS: Risk Management SystemThe enterprise risk register sits in RMS; TSM holds the technical safety demonstration.
- AIRMSAIRMS: Asset Integrity & Reliability Management SystemInspection and mechanical integrity of the equipment the safeguards depend on.
- HSEHSE: Health, Safety & Environment Management SystemOccupational safety, incidents and permits; deliberately outside the technical safety scope.
See TSM with one of your safety cases.
Bring one major accident hazard and the safeguards claimed against it. We will show the registers it produces, the verification scheme it needs and exactly what the application will and will not compute.

