Most organisations investigate incidents. Rather fewer learn anything. The gap is not effort, paperwork or software. It is purpose. An investigation that knows what it is for behaves differently from the first hour: it protects people, protects evidence, establishes what happened before arguing about why, and follows the conditions upward into the decisions that shaped the work. One that does not produces a tidy document, a named individual, a retraining action, and the same event again eighteen months later.
A note on scope: this is a general explanation of the discipline for managers and engineers who need to understand how investigation works. Serious incidents need competent, trained investigators, and statutory duties to report incidents to an authority vary entirely by jurisdiction, so you must establish your own from your own regulator rather than from an article.
The message up front: an investigation exists to understand how the work produced this outcome so that the conditions can be changed. It is not a disciplinary process and it is not an exercise in establishing liability. Where those purposes get mixed in, the information dries up, the accounts harden, and the investigation fails while still producing a report.
1. Purpose first, because it determines everything else
Every later decision inherits from this one. The purpose of an incident investigation is to understand how the work, as it was actually being done, produced the outcome that occurred, in enough detail that the organisation can change the conditions which made that outcome possible.
Note what that excludes: establishing who was at fault, determining whether the company is liable, confirming the procedure was breached. Those are legitimate activities with different rules and consequences. What they cannot do is share a process with learning, for a reason that is practical rather than moral. The raw material of an investigation is what people tell you about how work really happens, including the shortcuts, workarounds and pressures they never reported. Nobody volunteers that into a process that may be used to sanction them. They give you the version that matches the procedure, and the investigation studies a fiction.
This is not a soft position. The international standard for root cause analysis, IEC 62740:2015, covers after-the-event analysis and explicitly excludes assigning responsibility or liability from its scope. It is voluntary, paywalled and law nowhere by itself, so read it as what the technical community considers the activity to be rather than a rule imposed on you. But the people who codified causal analysis drew the same line, because mixing the two purposes degrades the analysis.
The practical test
If the people closest to the work cannot describe how the job is genuinely done, including the parts that do not match the written method, without calculating the consequences of saying so, you do not have an investigation. You have a hearing with an investigation's paperwork.
None of this means nobody is accountable. It means accountability is a separate process, on its own evidence, once the learning is out, and that the investigation treats an action as something to be explained rather than judged. That is section 8.
"Accident investigation" and "incident investigation" are used interchangeably in most workplaces. The substantive distinction is between events that caused harm and events that could have, and the second is the cheaper teacher: identical causes, nobody hurt. A process that only engages after an injury declines most of the available learning. That category is covered in near miss meaning, examples and reporting.
2. The immediate phase: people, then a second event
Make safe and care for people. Casualty care, evacuation, isolation of energy sources, containment, muster and headcount. No investigative consideration justifies delaying this. If preserving the scene conflicts with treating someone, the scene loses.
Then prevent a second event. This is the step organisations skip. The conditions that produced the first are usually still present: the same defective tool in the same rack, the same isolation practice on the identical adjacent unit, the same scaffold method on the other three elevations, the same control logic on the sister pump. Meanwhile the instinct to restore production is at its strongest in exactly that window, because the disruption is visible and expensive and someone senior is asking when it will be back.
So ask, before resuming anything: what else is exposed to the condition that produced this, and what are we doing about it now? The answer may be a temporary stop on a class of task, a check of identical equipment, or a revised control until the investigation reports. Interim measures are allowed to be crude and to be replaced later. What they must not be is skipped because the proper fix is not yet known. The hierarchy that should shape both interim and permanent measures is required by ISO 45001:2018 (as amended by Amd 1:2024) at clause 8.1.2, and in the United States by ANSI/ASSP Z10.0-2019 at section 8.4; it is also described by NIOSH, the US research agency, which has no regulatory power. Both are voluntary standards and neither is law in any jurisdiction by itself. See the hierarchy of controls complete guide.
On reporting: many jurisdictions place a legal duty on employers to notify an authority of certain categories of incident, and some place duties on preserving the scene until permitted to disturb it. The reportable categories, thresholds, notification routes and deadlines are set entirely by the law where you operate, and differ between countries and often between regions of one country. Your organisation must establish its own, from its own regulator, before it needs them. None is stated here.
3. Securing the scene and preserving evidence
Evidence is the one thing an investigation cannot obtain later. Analysis, interviews, report and actions can all be done a week late at some cost in quality. Evidence that was swept up, reset, overwritten or driven away is gone permanently, and what follows is confined to arguing about what probably happened.
Securing the scene means a boundary, control of who enters, and a record of the state of things before anything moves. A camera and fifteen methodical minutes, wide shots then detail, is the highest-value quarter hour in the whole investigation: position of valves, switches, breakers, guards and interlocks, what was on the screen, where tools were lying, what the access looked like. "Before anything is touched" includes before the well-meaning restoration a supervisor will otherwise order within the hour. Think in categories, because each is lost differently and on a different timescale.
| Evidence type | Why it matters | How it is lost | What to do first |
|---|---|---|---|
| Physical failed components, tools, guards, fixings |
The part carries the failure mechanism in its fracture surface, wear pattern or deposits | Binned during clean-up, sent for repair, cannibalised, or cleaned before examination | Tag, bag, label, log who holds it, do not clean it. Store it with a named custodian |
| Positional valve and switch states, isolations, settings |
Shows the configuration the work was actually done in, not the one the procedure assumes | Reset within minutes by anyone restoring the plant to a safe or working state | Photograph and write down every setting before recovery begins. The fastest-decaying evidence there is |
| Transient lighting, noise, weather, visibility, screen content |
Explains what the person could see, hear and perceive at the moment | Stops existing. Gone within hours, often minutes, and unrecoverable | Record conditions on site, at the time, in writing. Return at the same hour if you can |
| Electronic alarm and event histories, trends, logs, footage |
An objective, timestamped sequence to anchor accounts against | Buffer overwrite on a rolling window, automatic purge, retention expiry | Issue a preservation request the same day to a named system owner, naming systems and time window |
| Documentary permits, work orders, method statements, handovers |
Shows what was authorised, planned, communicated and assumed, and by whom | Filed, superseded, quietly corrected, or never captured at all | Collect the copies in use at the scene, not the masters. The difference is often the finding |
| People's accounts what those present saw, did and expected |
The only source for intent, understanding, perceived pressure and how work is really done | Converges as people discuss it, and hardens once blame is anticipated | Take initial accounts early and separately, as soon as people are fit to give them |
Two categories deserve a further word. The failed component is frequently the most informative object in the event, and it is routinely thrown away. If a part failed and the mechanism matters, preserve it unopened, uncleaned and unrepaired for someone competent to interpret; that examination is a distinct discipline, covered in failure analysis methods, process and examples.
And memories begin to change from the moment those involved start talking to each other. That is not dishonesty. Recall is reconstructive: gaps get filled with what must have happened, details migrate between witnesses, and a group that has discussed an event for two days produces a shared narrative less accurate than four separate accounts taken on day one. Hence early separate accounts, and hence a delayed investigation is weaker however skilled the investigator.
4. Who investigates, and why it is not automatic
Resourcing should be proportionate to actual consequence and to potential consequence, which is the harder judgement. A dropped object that hit nobody had the potential to kill somebody, and if the potential is what you are preventing, the potential should size the response. Scaling only by actual harm under-investigates exactly the events that were cheapest to learn from.
Two qualities decide whether the person leading can do it, and they pull in opposite directions. One is enough knowledge of the work to understand the answers: to know the isolation described is not the isolation the drawing shows, to recognise a technically impossible explanation. Without it, an investigator is transcribing. The other is enough independence to ask uncomfortable questions and publish unwelcome answers. Without it, an investigator cannot follow the causes into decisions their own management made.
So a serious investigation led solely by the line manager responsible for the work is structurally compromised, whatever that individual's integrity. They are being asked to examine whether their own resourcing, planning, supervision and tolerance of shortcuts contributed, and to write it down. Some manage it; a process should not depend on people being exceptional. The usual resolution is a small team: someone independent leading, someone with the technical knowledge supporting, and where a workforce safety representation arrangement exists, their involvement. The line manager's legitimate roles are the immediate phase and owning the actions afterwards, and keeping those separate from leading the analysis is most of what a good policy has to say about resourcing. Wider context sits in what HSE means in practice.
5. Establishing what happened, before asking why
This is the section most processes compress and most investigations regret compressing. Before any question about causes can be answered usefully, the investigation has to establish what occurred, in sequence: not a summary, but specific events and the conditions surrounding them.
The core instrument is a timeline of discrete factual statements, each with a time if you have one, each attributed to its supporting evidence, covering actions, communications, equipment states and changes, alarms and prevailing conditions. Build it forward from well before the event, because the causes are rarely in the final minute. They are in the shift handover, the planning two days earlier, the decision three months before that to run the unit differently. What makes a timeline valuable is the annotation. Every entry is marked as one of three things:
- Known: supported by evidence you can point to. A log entry, a photograph, a reading, a document, a consistent account from someone who was there.
- Assumed: believed reasonably but not evidenced, usually because it follows from something known or because it is normal practice. Mark it and keep it marked, because assumptions accumulate invisibly and by the report stage read exactly like facts.
- Unknown: a gap, stated as a gap. "Between 09:12 and 09:26 there is no record of what was done and no account covering the period" is a legitimate and useful finding.
The single most common investigative failure is a story that fits the available facts being mistaken for what happened. Say it that plainly, because the mechanism is so comfortable. A coherent narrative feels like knowledge: it satisfies the reader, closes the report, lets everyone move on. But many stories fit the same facts, and the one that arrives first usually matches what the investigator already expected. The defence is procedural: keep the gaps visible, test the narrative against each piece of evidence individually, and actively look for the alternative that also fits. If only one explanation was ever considered, nothing has been tested.
6. Interviewing: a skill, not a form to fill
Interviewing supplies most of the information in an investigation and is where most investigations are weakest, because it is treated as a collection chore rather than a skill. What follows is not a protocol but the principles, with the reason each exists.
As soon as practical, because recall decays and converges, and an account given before the person has heard everyone else's is worth several taken afterwards. Balanced against whether they are fit to be interviewed: someone who has just watched a colleague injured is not.
Separately, because two people interviewed together produce one account. The more confident or senior person sets the narrative and the other agrees, often sincerely. Separation is not suspicion; it is the only way to get independent data points.
Privately, with the purpose explained, because people manage their answers according to what they think is being done with them. If your organisation genuinely separates investigation from discipline, say so. If it does not, do not claim it does; the claim gets tested once, and then the process is known to lie.
Open questions and free recall before specific questions, because the order matters more than people expect. Ask the person to describe, uninterrupted and in their own words, what happened from whatever starting point they choose, and let the silences run. Only when free recall is exhausted go back to specifics. Asking specifics first replaces their memory with your framework, and you never get the free account back.
No leading and no cross-feeding. "You didn't check the isolation, did you?" gets an answer about isolation-checking regardless of what happened. "Ahmed says the alarm was already active" hands the person a memory they will adopt in good faith and repeat as their own. Both contaminate the only independent evidence you have, irreversibly. And record what was said, not what it meant: a summary captures the investigator's conclusion rather than the account, and cannot be re-examined when later evidence changes the interpretation.
Underneath all of it: people will not tell you what really happens if they expect to be blamed for it. Every technique above is second-order compared with that. An investigator with poor technique where telling the truth is safe gets closer to what happened than a skilled interviewer where it is not.
The limit of interviewing
No method recovers a memory that was never formed. A witness who says "I do not know, it happened too quickly" may be giving the most accurate answer available. Pressing until they produce detail does not retrieve information; it manufactures it.
7. From what happened to why: separating the levels
Once the sequence is established, the investigation turns to causes. The methods belong to their own articles; what belongs here is the framing that makes any of them work, the separation of levels. There are at least three, and conflating them is how investigations end up recommending a toolbox talk in response to a design problem.
| Level | Question it answers | Illustrative hypothetical carried through | What a fix here looks like |
|---|---|---|---|
| Immediate circumstances | What happened at the sharp end, in the last minutes | A technician opened a pump casing that was still pressurised and was sprayed with hot condensate | Nothing durable. A fix only here means telling one person to be careful next time |
| Conditions that made it possible | What made that action likely, easy or apparently correct | The vent discharged out of sight of the work position, the gauge on that unit had been unreliable for months, and the sister unit isolated the other way round | Add local indication in view, repair the gauge, standardise the isolation arrangement across units |
| Organisational and systemic factors | Which prior decisions on design, procedure, resourcing and workload created those conditions | The gauge defect sat in a deferred backlog with no safety-critical review, the two units were modified in different years with no consistency requirement, and the task was planned for one person against a method written for two | Change how the backlog is triaged, require consistency across modifications, correct the resourcing assumption in planning |
| Cause of the escape (cuts across the above) | Why the existing controls, checks or detection did not catch it before harm | The permit check relied on a gauge reading with no independent confirmation, and the pre-task check had no step that would detect residual pressure | Add an independent means of proving depressurisation, so absence of pressure is positively verified rather than assumed |
That hypothetical is invented to illustrate the levels and is not drawn from any actual event. The same incident yields different fixes depending on which level you stop at, and the stopping point is usually determined by cost rather than evidence.
The fourth row is the one most often missing. The cause of the event and the cause of the escape are different questions with different fixes. Why residual pressure remained in the casing is one investigation. Why a permit system, a pre-task check and a gauge all failed to reveal it is another, and frequently the more valuable one, because the control that failed to catch this event is also failing to catch everything else. An investigation that explains the event perfectly and never asks why the safety net was absent has fixed one hazard and left the net torn.
Two notes before handing off. The distinction between an unsafe act and an unsafe condition is useful as a sorting aid and dangerous as a conclusion, for reasons in unsafe act vs unsafe condition. And the choice of method should follow from the shape of the event: a simple linear sequence suits a different tool from a complex event with interacting conditions and redundant controls that all failed. The process end to end is in root cause analysis methods and step by step guide; choosing between techniques is in RCA tools: 8 methods explained, the most common of them in the 5 Whys method, and a structured team route in the 8D guide.
On the standards landscape, since it is routinely misstated: IEC 62740:2015 is the international standard for root cause analysis, describing principles, process steps and recognised techniques including the Why method and the cause-and-effect diagram, so do not let anyone tell you RCA has no standard. IEC 61025:2006 covers fault tree analysis, IEC 60812:2018 (Edition 3) covers failure modes and effects analysis, and risk assessment techniques are catalogued in IEC 31010:2019, which is IEC and not ISO. ISO 31000:2018 is risk management guidance and is not certifiable, whatever certificate you have been shown. Bowtie analysis comes from a 2018 CCPS and Energy Institute concept book and is not a standard. All are voluntary and none is law by itself anywhere.
8. Human error, treated properly
"Human error" is a legitimate starting point for an investigation and is never a conclusion. It names what happened without explaining any part of it. Saying an operator made an error is about as informative as saying a pump failed: true, sometimes, and the beginning of the work rather than the end. Nobody accepts "the pump failed" as a root cause, and the same standard should apply to people.
An investigation that ends at human error has stopped one step before the useful part, and it is seductive because it is cheap: it explains everything, costs nothing, locates the problem in an individual who can be retrained or replaced, and leaves the organisation's arrangements unexamined. That is the conclusion that costs least, dressed as a finding. The productive questions start where it stops:
- Why did the action make sense to the person at the time? The central question. People generally do what appears reasonable given what they know and what they are under, and almost nobody chooses the option they believe will hurt them. If the action looks incomprehensible, you are missing information about the situation, not looking at an incomprehensible person.
- What information did they actually have? Not what existed somewhere in the organisation, but what was visible, legible and present at the work position at that moment. Hindsight makes the relevant signal obvious; at the time it was one indication among many, possibly out of sight.
- What were the conditions and pressures? Time, heat, noise, fatigue, shift position, access, the other three jobs waiting, the unspoken expectation about how long this should take. These excuse nothing. They explain the probability.
- Did the system make the error likely, or easy? Two similar controls adjacent and unlabelled. Two units isolated in opposite directions. A step omittable with no feedback. A form signable before the check is done. Where an error is easy to make and hard to detect, the design produced it and will produce it again with a different person.
- Was the practice normal? If the same deviation is common, widely known and tacitly tolerated because the official method does not work or does not fit the time allowed, the finding is the gap between the written and the real method. That is organisational, and usually the important one.
The test worth applying to any report: if the recommendations would only have prevented this event had that specific person behaved differently, the analysis is not finished. Ask whether a competent, motivated, averagely tired colleague could have done the same thing on a different day. Where the answer is yes, and it usually is, the condition is the finding.
An honest limit
Treating error as something to explain rather than punish is not the same as treating every action as blameless. Deliberate, knowing violation of a control the person understood and had no pressure to bypass exists, and an organisation has to deal with it. The reason to keep that out of the investigation is not that it never applies. It is that an investigation which starts by looking for it will find it where it is not there, and stop looking for anything else.
9. Findings, recommendations and the report
A finding states what was the case, supported by identified evidence. An opinion states what the investigator believes. Both belong in a report and must be visibly distinguishable, because a reader who cannot weigh them discounts the whole document. Where evidence is thin, say so in the finding: "the gauge is believed to have been reading low, on the basis of two accounts and no record" tells the reader how much to lean on it.
Recommendations are where reports collapse into uselessness. The test is whether a recommendation changes the conditions under which work is done, or merely exhorts people to be more careful within unchanged conditions. "Retrain the technician" and "remind staff of the importance of isolation" are among the most common recommendations in workplace investigation and among the weakest, because they leave every condition as it was and transfer the whole burden onto vigilance that was already being applied. Their quiet appeal is that they are cheap, fast to close and produce a signed record.
| Weak recommendation | Why it fails | Stronger version |
|---|---|---|
| Remind all staff to follow the isolation procedure | Assumes the cause was forgetting. Changes nothing about why it was not followed | Standardise the arrangement so both units isolate the same way, and add positive proof of depressurisation to the task |
| Retrain the individual involved | Fixes one person in one role. The next person inherits the same conditions | Change the step so the unsafe state is detectable, then reflect it in the task instruction for everyone |
| Issue a toolbox talk on the incident | Communication is not a control. Useful alongside a fix, worthless instead of one | Make the physical or procedural change, then communicate what changed and why |
| Review the procedure | No owner, no scope, no definition of done. Closes on evidence a review occurred | Revise the named procedure to require two-person verification at the pressure-proving step, owner named, date set |
| Emphasise the importance of reporting defects | Treats an organisational triage failure as a workforce motivation problem | Change triage so safety-critical items cannot sit in the deferred backlog without periodic review at a named level |
| Increase supervision | Adds monitoring without removing the hazard, and degrades as attention moves on | Eliminate or engineer out the exposure where reasonably practicable, and use supervision only for what remains |
Every recommendation needs a named owner, a date, and a description specific enough that two people would agree whether it has been done. "Improve communication" fails that test, and so does committee ownership: a recommendation owned by a department is owned by nobody. Then hand over. Actions have their own lifecycle of definition, implementation, verification of effectiveness and closure, which is not the investigation's to run; investigations that try to carry it either never close or close the day the last action was assigned. That lifecycle belongs to the corrective and preventive action process in CAPA explained, and for the distinction that trips up most registers, corrective action vs preventive action. Fixing this occurrence is corrective; changing the conditions so the class of event cannot recur is preventive. A register full of the first with none of the second is a register of repairs.
10. What to do with the learning
An investigation produces two outputs: a set of actions, handed off above, and understanding, which has to travel or it does not exist beyond the people who did the work. Most organisations do the second badly in a recognisable way: they circulate a summary nobody reads. A one-page alert with a photograph, a sequence and three bullets of lessons learned, emailed to a distribution list and filed by most recipients in under fifteen seconds. It satisfies the requirement to share and transfers nothing, because it is written in the register of compliance rather than the register of work.
What travels is learning delivered in the form the recipient already uses. If the finding changes how a task is done, it belongs in the task instruction, the permit conditions, the pre-task check or the planning template, not only a bulletin. If it concerns a class of equipment, it belongs with the people who maintain that class, discussed rather than distributed. If it concerns a decision-making pattern, the audience is the people who make those decisions, and a workforce bulletin is the wrong recipient. Coding the event consistently in whatever system holds maintenance and defect history also matters, because that is what makes the pattern visible in aggregate later; the structure is in failure codes: problem, cause, action.
Then the part almost nobody does: come back later and check whether the actions worked, rather than whether they were closed. A high closure rate tells you about administrative diligence. What you need to know is whether the condition is gone: whether the standardised isolation arrangement is on all the units and not just the two that were convenient, whether the revised check has drifted back, whether the triage change survived the first busy month. Verification of effectiveness is a visit, a sample and a conversation, not a status field, and it is worth setting a date for someone other than the action owner to do it. If your process cannot conclude "this was closed but it did not work", it cannot tell learning from paperwork.
11. How investigations fail
The failure patterns are consistent enough to list plainly, and recognisable enough to use as a self-assessment.
- Started late. Days pass while it is decided who owns it. By the time anyone arrives the positional and transient evidence is gone and the accounts have converged.
- Scene disturbed, evidence lost. Area tidied, plant reset, component binned or sent for repair, footage aged off its buffer. Nothing recovers this.
- Conducted to satisfy a form. The fields get filled, and the shape of the template becomes the shape of the analysis. A form records an investigation; it is not a method for doing one.
- Blame arrives early and the truth leaves with it. Once the workforce concludes the process is looking for someone, accounts turn defensive and the investigation studies the official version of the work.
- A single cause declared because the form has one field. Real events have multiple contributing conditions. A system that forces one root cause gets one, selected on convenience, and discards the rest.
- Recommendations aimed at the last person in the chain. The nearest human absorbs the entire finding, and every upstream condition survives intact.
- Systemic factors identified, then quietly dropped. The most damaging pattern, because the analysis was correct. The resourcing assumption, the design inconsistency, the backlog policy are found, drafted, then softened or removed because the fix is expensive or implicates someone senior. What remains is the cheap subset.
- Actions closed without verification. The register looks healthy, the conditions are unchanged, and the next occurrence surprises everyone reading the dashboard.
- No aggregate view. Each event is investigated alone, so the fifth instance of the same condition on different equipment is investigated from scratch. A competent backlog and downtime record makes the pattern visible if anyone looks, as covered in maintenance backlog and downtime tracking.
Systems attract more attention than they deserve here: most maintenance or HSE systems hold records, actions and verification adequately, and the choice does not determine whether investigation works. Control-of-work records are the exception worth integration effort, because permits and isolations are so often central to the sequence, as discussed in permit to work integration with CMMS.
And the tell, if you want one indicator of whether investigation is functioning: unwelcome findings survive to the final report. Not that they are acted on immediately, which depends on money and time. That they are still in the document, named, owned and dated, after review. If every final report in your archive is comfortable for management to read, the analysis is being edited somewhere between the evidence and the conclusion, and no amount of investigator training fixes that.
The idea to walk away with
An investigation exists to understand how the work produced this outcome so the conditions can be changed. Everything practical follows from holding that purpose steady: people first, then prevent the second event, then preserve the evidence that will otherwise be gone by tomorrow, then establish what happened with the gaps left visible, then ask why across all the levels including why the controls did not catch it, then recommend changes to conditions rather than exhortations to care more, then verify the conditions actually changed. The two things that most reliably break it are mixing in blame and stopping at human error: the same failure in different clothes, both locating the problem in an individual, both cheaper than the alternative, both leaving an unchanged system and a completed file.
Final thoughts
Investigation quality is not a function of template design, software or training budget. It is a function of whether the organisation can tolerate what a good investigation produces. A genuine investigation will regularly conclude that a decision about resourcing, design, procedure or workload contributed, and will say so where someone senior has to read it. An organisation that can absorb that gets better; one that cannot will produce competent-looking reports about individuals for years and keep being surprised.
The two cheapest improvements are unglamorous. Get to the scene faster and take separate accounts on day one, because that is where evidence is lost permanently. And check later whether the actions worked rather than whether they were closed, because that is where learning is lost silently. Neither needs a budget. Both need someone to decide they matter.
Disclosure
Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.
Reviewing how your organisation investigates?
Independent advisory on incident and defect workflows, how investigation findings connect to the action register, and whether verification is actually happening. 22+ years across utilities, oil and gas, manufacturing, government and facility operations.
Book a conversationRelated reading: Root cause analysis: methods and step by step guide, Near miss meaning, examples and reporting, RCA tools: 8 methods explained, CAPA explained, Failure analysis methods, Hierarchy of controls. Primary sources: IEC , ISO , UK HSE (Great Britain) , US OSHA .
Muhammad Abbas
CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.
Work with me