Confined space entry process map
A swimlane map of entering a tank, void or cofferdam, from risk assessment to closeout, across the technician, HSE/safety, the gas-free engineer and standby/rescue. It is the one map in this cluster with a genuine dead end: a risk assessment can prohibit entry outright, with no path back into the process.
Opens a copy in the editor and saves it in this browser. No account, nothing sent anywhere.
What is in this map
19 steps across 4 swimlanes and 5 phases, with 4 decision points.
- Swimlanes (who does the work)
- Technician, HSE / Safety, Gas-Free Engineer and Standby / Rescue
- Phases (left to right)
- Identification, Preparation, Testing and permit, Entry and Closure
Why map this process
Most process maps assume every request eventually gets fulfilled one way or another. This one does not, deliberately: the risk assessment can conclude the space is not entry-safe at all, and that outcome is a real terminus — entry prohibited, alternative method required — not a loop back to try again. That is the correct shape for a control that exists specifically to stop unsafe entries, and flattening it into a retry loop would misrepresent what a prohibited entry actually means.
Standby and rescue readiness sits after the permit is issued and before anyone enters, which is a sequencing choice worth preserving. It would be simpler to fold rescue readiness into permit issuance, but keeping it as its own gate means a valid permit with unready rescue equipment still cannot let anyone into the space — two different failure conditions, checked separately, exactly as they should be.
Every step in the map
This is the spreadsheet behind the diagram. The numbers in “Goes to” are row numbers, which is exactly what the editor’s “Line to” column holds — so you can read the flow here and retype any part of it.
| # | Step | Shape | Swimlane | Phase | Goes to |
|---|---|---|---|---|---|
| 1 | Confined space work identified (tank, void, cofferdam) | Start | Technician | Identification | 2 |
| 2 | Conduct confined space *risk assessment* | Process | HSE / Safety | Identification | 3 |
| 3 | Risk assessment finds the space **entry-safe** with controls? | Decision | HSE / Safety | Identification | 5 (Yes, with controls), 4 (No, prohibited) |
| 4 | Entry prohibited, alternative method required | Reject | HSE / Safety | Identification | End |
| 5 | Isolate, **lock out** and tag electrical, mechanical and piping systems | Process | Technician | Preparation | 6 |
| 6 | Ventilate space and stage rescue equipment | Process | HSE / Safety | Preparation | 7 |
| 7 | Test atmosphere for *oxygen*, *flammable gas* and toxins | Process | Gas-Free Engineer | Testing and permit | 8 |
| 8 | Atmosphere **safe for entry** without breathing apparatus? | Decision | Gas-Free Engineer | Testing and permit | 10 (Safe), 9 (Marginal, monitor) |
| 9 | Set up continuous atmosphere monitoring for the entry | Process | Gas-Free Engineer | Testing and permit | 10 |
| 10 | Issue confined space entry permit | Approval | HSE / Safety | Testing and permit | 11 |
| 11 | Assign standby person and confirm rescue plan | Process | Standby / Rescue | Entry | 12 |
| 12 | Standby, rescue equipment and communications **all in place**? | Decision | Standby / Rescue | Entry | 14 (Ready), 13 (Not ready) |
| 13 | Delay entry until standby and rescue readiness are confirmed | Delay | Standby / Rescue | Entry | 12 |
| 14 | Personnel enter and carry out the work | Process | Technician | Entry | 15 |
| 15 | Periodic atmosphere re-check and communication with standby | Process | Gas-Free Engineer | Entry | 16 |
| 16 | Work complete and **all personnel accounted for** on exit? | Decision | Technician | Closure | 18 (Complete), 17 (Not complete) |
| 17 | Continue work, repeat periodic checks | Process | Technician | Closure | 15 |
| 18 | De-isolate systems, remove tags and close the entry permit | Process | HSE / Safety | Closure | 19 |
| 19 | Confined space entry closed out | End | HSE / Safety | Closure | End |
The decision points
Every branch in the map, with the label on each outgoing line. These are the questions the process has to be able to answer.
-
3. Risk assessment finds the space **entry-safe** with controls?
Owned by HSE / Safety · Identification
- Yes, with controls → step 5
- No, prohibited → step 4
-
8. Atmosphere **safe for entry** without breathing apparatus?
Owned by Gas-Free Engineer · Testing and permit
- Safe → step 10
- Marginal, monitor → step 9
-
12. Standby, rescue equipment and communications **all in place**?
Owned by Standby / Rescue · Entry
- Ready → step 14
- Not ready → step 13
-
16. Work complete and **all personnel accounted for** on exit?
Owned by Technician · Closure
- Complete → step 18
- Not complete → step 17
Making it yours
The prohibited-entry step is not a normal box — it uses Engine3's terminal Reject shape, and it should stay that way rather than becoming a Process box with no outgoing line, because the shape itself is what tells a reader glancing at the diagram that this branch is a stop, not an unfinished step. When adapting the atmosphere-testing decision, keep both of its branches (safe without breathing apparatus, marginal requiring continuous monitoring) — deleting the marginal branch would force every borderline atmosphere reading into a binary safe/unsafe call the chart's own testing step does not actually support.
What to watch out for
- Do not merge lockout with atmosphere testing. Isolating electrical, mechanical and piping systems is a physical control that has to be complete before testing the atmosphere means anything — testing an unisolated space and calling the result valid is exactly the mistake this ordering prevents.
- The standby-readiness loop delays entry, and that delay is the point. If your adaptation routes straight from permit issuance to entry without the readiness gate, a permit becomes sufficient to enter a space with no rescue plan in place — which is the condition that turns a routine entry into a fatality when something goes wrong.
- Periodic re-checks during entry are not the same event as the initial atmosphere test. An atmosphere that was safe at entry can change while someone is inside — treating the pre-entry test as sufficient for the whole duration removes the only control that catches a changing atmosphere before it becomes an emergency.
Frequently asked questions
Why does a prohibited entry end the process instead of looping back to try again?
Because 'try again' implies the same conditions might pass on a second attempt, and a risk assessment that finds a space unsafe for entry is not describing a condition that changes by retesting — it is describing the space itself. The map's terminal branch is honest about that: the next step is a different method of doing the work, not another attempt at this one.
What is the difference between the initial atmosphere test and the periodic re-check during entry?
The first clears the space for entry; the second confirms it is still clear once people are inside and conditions may have changed — off-gassing, a nearby hot work operation, a ventilation failure. Treating them as one check assumes the atmosphere cannot change during the work, which is exactly the assumption confined-space fatalities disprove.
Our site requires two standby persons for certain spaces — how do I show that?
Add it as a Notes entry on the standby-assignment row rather than a new row: 'two standby persons required for spaces over X depth' is a condition on the existing step, not a different action. Reserve a new row for an actual different step, like a formal handover between two standby shifts on a long entry.
Open the map and start editing
The editor loads this chart with the spreadsheet underneath it. Change a cell and the diagram redraws — no drawing, no signup.