"Do we need a permit or do we need LOTO?" is one of the most common questions I hear when a maintenance organisation is tightening up its safe-system-of-work documentation, and it is usually the wrong question. It treats two things that operate at different layers as competing options. The honest answer, in a great many real maintenance jobs, is "both, and the permit is where you record that the isolation was done and verified". Understanding why that is the answer, rather than memorising either procedure, is what stops people building a control system with a hole in the middle of it.
The message up front: these are not alternatives and you do not choose between them. A permit to work controls the decision to allow work and the coordination around it. Lockout/tagout controls the energy. A permit on its own physically prevents nothing. An isolation on its own coordinates nothing. Most of the value in this topic sits at the joint between them, which is also where most real-world failures happen.
What this article is
This is a general explanation of how two safety systems relate to each other, written for planners and managers who have to design or audit the paperwork. It is not a procedure to adopt. Both a permit-to-work system and an energy-control programme must be defined by a competent person for the specific site, plant and hazards, against the law that actually applies in that jurisdiction.
1. Why this is not a choice
The confusion has a simple root: both systems exist to stop people being hurt while working on plant, both generate paperwork, and in many organisations both are owned by the same HSE function. From a distance they look like two brands of the same thing. They are not.
A permit to work is an administrative control. It is a document and, more importantly, a process: somebody with authority examines a proposed job, decides what conditions must hold before it can start, records those conditions, and formally hands the work area over to a named person for a defined period. The permit is the authorisation. Its power is in who signs it and what they were required to check before signing.
Lockout/tagout is a physical state. Energy sources are identified, disconnected or blocked, the isolating devices are secured with locks so they cannot be operated, the stored energy is released or restrained, and the absence of energy is verified by test. The lock is not a record of anything. It is a piece of hardware preventing a switch being thrown.
Once you see the difference between an authorisation and a physical state, the "either/or" framing collapses. You can authorise a job perfectly and still have a live machine. You can isolate a machine perfectly and still have two crews working against each other because nobody coordinated the job. The two systems answer different questions, so the interesting question is how they fit together. For the systems themselves, see the complete guide to lockout/tagout and the complete guide to permit to work. This article deliberately does not re-teach either one.
2. What each one actually is
It is worth being precise, because a lot of argument at site level comes from two people using the same word for different objects.
A permit to work is a formal written authorisation issued by a person appointed to do so, covering a defined task, in a defined location, for a defined period, subject to stated conditions and precautions. The document is the visible part. The system around it is the substance: who may issue, who may receive, what has to be checked, what has to be on the permit, how it is displayed, how it is suspended, how it is handed back and cancelled. A permit is fundamentally a communication and control instrument. It exists so that everyone who could affect the job, or be affected by it, is working from the same agreed picture.
Lockout/tagout, or more accurately the control of hazardous energy, is the set of physical actions and hardware that put plant into a safe, de-energised, verified state and keep it there while people work on it. The tag communicates. The lock prevents. The verification test proves. The devices and their information content are a topic in themselves, covered in the guide to LOTO tags, and the sequence in which the steps are performed is covered in the LOTO procedure guide.
One useful test: if you removed the paper and left everything else in place, what would you still have? Remove the permit and you still have a locked-off machine, but nobody has agreed that this job may proceed, in this area, at this time, alongside those other activities. Remove the locks and you still have a signed agreement that the job may proceed, on a machine that anybody can start.
3. What each one actually protects against
This is the dimension most comparisons skip, and it is the one that matters.
A permit to work protects against bad decisions and bad coordination. It catches the job that should not have been approved at all, the job approved without the operations team knowing, the job that clashes with a simultaneous activity nearby, the job whose hazards were never properly thought through, the job handed to a crew who did not understand the conditions. Those are real causes of real harm, and no physical device addresses any of them.
Lockout/tagout protects against the energy itself. Unexpected start-up, residual pressure, stored mechanical energy in a spring or a raised load, gravity, capacitance, thermal energy, trapped process fluid. It is the only one of the two that stands between a person's hands and a machine that could move.
State this one plainly
A permit to work does not physically prevent the release of hazardous energy. It cannot. It is paper and signatures. If the permit says the machine is isolated and the machine is not isolated, the permit will not stop the machine starting. That single sentence resolves most of the confusion in this topic, and it is why an energy-control requirement written into a permit has to be physically executed and verified, not merely asserted on the form.
The reverse limitation is just as real, and less often admitted. An isolation is silent. It does not tell the shift team that a pump is out of service, it does not tell a second contractor that the line they are about to cut is the one being worked on, and it does not schedule anything. Isolation protects the isolator. Permits protect the operation.
4. Who issues, who applies, and the asymmetry that follows
There is a structural difference here that has practical consequences, and it is worth dwelling on.
A permit is issued by an authorising person to a recipient. The authority flows downward. The issuer is typically someone with control of the plant or area, competent to assess the hazards and empowered to grant access. The recipient accepts the permit on behalf of the working party and takes responsibility for working within its conditions. Because this is a transfer of authority between roles, it can legitimately be done on behalf of others: a supervisor can accept a permit for a crew of six, and a permit can be handed over between shifts through a defined re-issue or transfer step.
A personal lock is different. It is applied by the individual whose safety depends on it, and in most well-run energy-control programmes it is removed by that same individual. The lock is not a delegation of authority. It is a person asserting, physically, that they are inside the machine. That is why you cannot meaningfully apply a personal lock on somebody else's behalf, and why a group lock box exists as a mechanism for letting each member of a crew retain their own physical assurance rather than trusting a supervisor's signature to stand in for it.
This asymmetry is where a lot of interface failures originate. Permits are designed to be transferable. Personal locks are designed not to be. When an organisation treats the permit as the master record and the isolation as an attachment to it, it tends to start transferring both, and that is the moment the physical protection quietly becomes a paperwork entry.
5. The comparison across the dimensions that matter
Laid out side by side, with each row explained rather than reduced to a tick:
| Dimension | Permit to work | Lockout/tagout |
|---|---|---|
| What it is | A document and the authorisation process behind it. An agreement that a defined job may proceed under stated conditions. | A physical state of plant, achieved with isolating devices, locks and verification. Hardware, not agreement. |
| What it physically prevents | Nothing. It prevents work being authorised without the right checks, which is a different thing from preventing motion or energy. | Operation of the isolating device, and therefore the re-energisation of the plant while the lock is in place. |
| Primary risk it addresses | Uncontrolled or uncoordinated work: clashing activities, unaware operators, unassessed hazards, unauthorised access. | Unexpected start-up and release of stored energy while a person is exposed to it. |
| Who originates it | An appointed authorising or issuing person with control of the plant or area. | The person doing the work, or an authorised isolator acting within the programme, with each exposed person adding their own lock. |
| Can it be done on your behalf | Yes. A permit can be accepted by a supervisor for a working party and transferred through a defined step. | No, not the personal lock. Somebody else's signature is not a substitute for your own lock on the device. |
| Scope it covers | A whole job: multiple hazards, area access, other trades, simultaneous operations, a time window, and the conditions across all of them. | Specific energy sources at specific isolation points on specific equipment. Narrow and precise by design. |
| Duration and handover | Time-bounded and formally handed over, suspended or re-issued through defined steps, usually with a hand-back and cancellation. | Persists as a state for as long as the locks remain fitted. Continuity across a shift change depends on people, not paperwork. |
| Evidence it leaves | A signed, auditable record of who authorised what, when, under which conditions, and who accepted it. | Little on its own. A lock in place proves a present state, not a history. Evidence comes from the register, tag or permit that references it. |
| Its main blind spot | It can be complete, correct and signed while the physical plant is not in the state it describes. | It says nothing about coordination, other hazards, other trades, or whether this job should be happening at all. |
Read down the "what it physically prevents" row and the "can it be done on your behalf" row together and you have the whole argument. One system is transferable and non-physical. The other is physical and non-transferable. They are complements.
6. The four combinations
Because they are independent layers, all four states are possible, and three of them are legitimate in the right circumstances. The examples below are my own illustrations, not references to any actual site.
| Combination | Illustrative example | What makes it appropriate |
|---|---|---|
| Permit only | Hot work on a structural steel member in an occupied plant area, with no energised equipment involved in the task. | There is no hazardous energy on the work item to isolate. The hazard is the process the work introduces, plus its interaction with the surroundings. Control is about authorisation, fire watch, area conditions and coordination. |
| LOTO only | A technician replacing a drive belt on a single non-critical conveyor in a workshop, under the site's standing energy-control procedure. | The hazard is entirely the machine's own energy, the work is routine and well understood, and the site's rules do not classify it as permit work. This is common and entirely legitimate, not a shortcut. |
| Both | Internal inspection of a process vessel requiring drain-down, electrical and mechanical isolation of the agitator, and entry by two people. | Several hazards, several trades, an access element, a time window and a required physical state. The permit wraps the job and names the isolations. The isolations make the permit's conditions real. |
| Neither | A visual external inspection of a running pump from a safe walkway, recording readings from a local gauge. | No exposure to hazardous energy and no interaction with other activities. Ordinary risk assessment and standing instructions cover it. Requiring paperwork here devalues the paperwork everywhere else. |
That last row deserves emphasis, because organisations under audit pressure tend to extend permits to everything. A permit system that covers trivial work trains people to sign without reading, which degrades the system exactly where it is needed. Deciding which work genuinely needs a permit is one of the harder judgements in designing the system, and it belongs to the site, not to a template. The categories in use are covered in the guide to permit types.
7. How they nest when both are needed
When both apply, the relationship is not parallel, it is nested. The permit is the outer wrapper and the isolation is one of the conditions inside it. The logical order is straightforward:
- The job is assessed and the permit is raised, specifying the isolations required, named at the level of specific points rather than as a general instruction.
- The isolations are applied by the authorised person, stored energy is dealt with, and absence of energy is verified by test.
- The verification is confirmed back to the permit, and the exposed workers apply their own personal locks.
- Only then is the permit valid and the work area formally handed over.
- At the end, the sequence reverses: work complete, personal locks removed by their owners, permit handed back, isolations removed under control, plant returned to service.
A worked hypothetical, clearly my own, to show the nesting concretely. A chilled water pump in a central plant room needs its mechanical seal replaced. The permit covers the whole job: access to the plant room, the mechanical work, the water spillage risk, a four hour window, and the fact that a second crew is working on the adjacent chiller the same morning. Inside that permit, three isolations are named: the pump's electrical supply at a specified local isolator, the suction valve at a specified tag number, and the discharge valve at another. The isolator is locked, both valves are locked in the closed position, the line section is drained and vented, and the electrical isolation is proved dead at the motor terminals. The fitter and the mate each fit a personal lock to the lock box holding the isolation keys. The permit is not valid until the isolation section is signed as verified. When they finish, both personal locks come off individually, the permit is handed back, and only then are the valve and electrical locks removed and the pump returned to the operations team.
Notice what each layer contributed. Without the permit, nobody would have accounted for the second crew or the four hour window. Without the isolations, the permit's assurance that the pump was safe to open would have been words. The hierarchy of controls is the reason the two are not interchangeable: isolation is an engineering-level control acting on the hazard, while a permit is an administrative control acting on people's behaviour, and the hierarchy is explicit that the two sit at different levels of reliability.
8. The failure modes at the interface
This is the section I would most want a maintenance manager to read, because almost all the useful material on this topic treats each system in isolation and then stops. The joint between them is where things actually go wrong.
- "Isolate as necessary." A permit that carries a vague instruction instead of named isolation points has delegated the most important technical decision on the job to whoever happens to be holding the paper. Naming the points is what makes the requirement checkable and what makes an incomplete isolation visible.
- Permit signed before the isolation was verified. The signature and the physical act drift apart, usually under time pressure, and the permit then becomes a record of an intention rather than a state. Every permit system needs the isolation confirmation to be a gate, not a box.
- Isolation removed while the permit is still live. Often innocent: a valve is reopened to help another job, or an isolator is reset during a fault investigation. The permit is still displayed, the working party still believes the plant is dead, and nothing in the paperwork has changed.
- Shift-change handover with absent lock owners. The permit is transferred to the incoming shift, which permits are designed to allow. The personal locks belong to people who have gone home, which personal locks are designed to prevent. Unless the programme defines exactly how continuity of isolation is maintained across a change of personnel, this gap opens every single night shift.
- Multiple permits against one isolation. Three jobs on the same isolated system, three permits, three working parties, and no single view of who is still inside. The first crew to finish hands back, someone removes the isolation, and the other two are still working. Coordination of a shared isolation has to be explicit, and it is a function the individual permits do not perform by themselves.
- Return-to-service without checking the permits are closed. The mirror image of the above, at the end of the job rather than during it.
Paperwork is not protection
A thorough permit system can produce a feeling of safety the physical state does not support. The more comprehensive and well-audited the paperwork becomes, the more confidently people rely on it, and the less likely anyone is to walk to the switch room and look. I would state this firmly: the quality of a permit tells you about the quality of the decision, not about the condition of the plant. If your assurance activity only ever samples documents, you are measuring one layer and assuming the other.
9. Which sectors lean on which
The balance between the two systems varies by sector, and it is worth knowing so that you can read another organisation's practice without assuming it is wrong.
Process, energy, marine and construction environments typically run formal permit systems as the primary control, sometimes covering the majority of non-routine work. The reason is structural: many hazards, many simultaneous activities, large numbers of contractors, and plant where one system interacts with another. In those settings coordination is the dominant risk, so the coordinating instrument dominates.
Manufacturing and facilities environments more often run energy control as the everyday primary discipline, with permits reserved for higher-hazard categories such as hot work, confined space entry, work at height, excavation and high-voltage work. Most maintenance tasks are single-asset, single-trade, well understood and repeated, so the physical control carries the load and the permit is brought in when the job stops looking like that.
Neither pattern is more mature than the other. They are responses to different risk profiles. What causes trouble is importing one wholesale into the other, most commonly a heavy process-industry permit template dropped into a facilities operation, where it collapses under its own volume within a year.
A related caution: the vocabulary differs by employer. What one organisation calls an isolation certificate, another calls an electrical permit, and another treats as a section of the general work permit. Some sites use "permit" for the document and "certificate" for the isolation record; others use both words interchangeably. The words matter far less than the two functions. When you review an unfamiliar system, ignore the labels and ask the two questions: where is the authorisation decision recorded, and where is the physical state established and verified? If one of those has no clear home, you have found the gap. The broader vocabulary problem across the discipline is covered in what HSE actually means.
10. Contractors and multi-employer sites
Multi-employer working is where the division of labour between the two systems becomes most visible, because it is the situation an isolation cannot address at all.
When a client's operations team, a mechanical contractor, an electrical contractor and a specialist inspection body are all present on the same plant in the same week, the coordination problem is not technical, it is organisational. Who knows what everyone else is doing? Who can stop a job? Whose rules apply where they differ? These are exactly the questions a permit system answers, and there is no physical device that answers them. The permit does the coordination work that no isolation can do.
At the same time, the principle from section four holds without exception: each worker's personal protection cannot be delegated to a document. A contractor's fitter who is told "the client has isolated it, the permit says so" and who does not have a personal lock on that isolation is relying on somebody else's paperwork to keep the machine still. That is precisely the arrangement personal locks exist to replace. This is one of the most common weaknesses in contractor-heavy environments, and it is usually not deliberate: the client's isolation programme was written for its own staff and never extended to cover how a third party's people attach their own physical assurance.
Two specific permit categories concentrate these problems and are worth reading separately: confined space permits and hot work permits.
11. Where standards and law sit, by jurisdiction
This is where the asymmetry between the two systems becomes formal, and it is important not to universalise any one country's position.
Energy control is codified in some jurisdictions. In the United States, energy control for general industry is regulated federally as 29 CFR 1910.147, "The control of hazardous energy (lockout/tagout)". That scope qualifier matters: construction and certain other sectors are covered by different provisions, and many US states operate their own approved plans which may impose different or additional requirements, for example California's energy-control rule at 8 CCR 3314. A US general-industry requirement is not a global one.
Great Britain has no single dedicated LOTO regulation. Isolation and permit duties there arise from general legislation and from sector guidance rather than from one named energy-control rule. The general duties sit under the Health and Safety at Work etc. Act 1974, and machinery and work-equipment duties including isolation from sources of energy sit under the Provision and Use of Work Equipment Regulations 1998 (SI 1998/2306). Sector and activity-specific instruments add to that picture, for example the Confined Spaces Regulations 1997 (SI 1997/1713), whose Approved Code of Practice L101 ("Safe work in confined spaces", 3rd edition, December 2014) carries special evidential status in Great Britain. Northern Ireland has separate instruments with different years, so do not read Great Britain citations across to it.
Permit to work is not established by a single international standard. This is the honest and slightly awkward point. It is a widely used industry practice, shaped by sector convention and regulator guidance, rather than a single global legal or standards scheme. The best known reference is UK HSE guidance HSG250, "Guidance on permit-to-work systems: A guide for the petroleum, chemical and allied industries" (2005), which is freely available, is guidance rather than law, creates no duties in itself, and was written for the petroleum, chemical and allied industries largely around paper systems. Anyone telling you that a specific international standard mandates a permit-to-work system is overstating the position.
That said, some permit categories are attached to specific legal requirements in specific places. In the United States, permit-required confined spaces in general industry are regulated as 29 CFR 1910.146, whose scope excludes construction, agriculture and shipyards; construction confined spaces are covered separately by 29 CFR 1926 Subpart AA, sections 1926.1201 to 1926.1213, introduced by a 2015 final rule. For hot work, there is no US federal standard actually titled "hot work permit"; the widely used private-sector reference is NFPA 51B, "Standard for Fire Prevention During Welding, Cutting, and Other Hot Work", 2024 edition, which is a private standard and not law by itself, and which applies to you only in the edition your authority having jurisdiction has adopted.
On the management-system side, ISO 45001:2018, "Occupational health and safety management systems", as amended by Amd 1:2024, is certifiable and requires the hierarchy of controls at clause 8.1.2. In the United States, ANSI/ASSP Z10.0-2019 requires it at section 8.4. That hierarchy is the formal basis for treating isolation and permits as controls of different reliability rather than as equivalents. Both documents are voluntary and are not law anywhere by themselves.
The jurisdiction trap
A great deal of the safety material circulating online quietly assumes US federal general-industry rules apply everywhere. They do not. US OSHA regulations have no legal force outside the United States, and British regulations have none outside Great Britain. If you operate in the Gulf, in Asia or anywhere else, these are useful benchmarks and often contractually required, but the binding requirements are your own national and local ones, and only a competent person working from those can tell you what your permit and isolation systems must contain.
12. Where both meet maintenance management
Briefly, because this is not the point of the article. Both systems eventually have to connect to the way work is planned and recorded. In practice that means permit requirements and isolation requirements attached to the asset record and carried onto the work order, so that a planner raising a job on a particular pump can see that it is permit-controlled and which isolation points apply, rather than discovering it at the plant.
Maintenance management software of any kind can hold that association, and most modern systems do. It is a genuinely useful thing to have, because it moves the knowledge out of individual heads and into the planning step. It is also worth being clear-eyed about what it does not do: a permit workflow in a system is still administrative control, and putting it on a screen does not make it a physical one. For how permit workflow behaves inside a maintenance system specifically, see permit to work integration with a CMMS, and for how the work classification itself is structured, work order types.
The idea to walk away with
A permit to work and lockout/tagout are not two options on a menu. One controls the decision to allow work and the coordination around it. The other controls the energy. A permit alone leaves a live machine. An isolation alone leaves an uncoordinated site. On most non-trivial maintenance jobs the permit is the wrapper and the isolation is one of the conditions inside it, and the permit's real function in that arrangement is to record that the isolation was specified, executed and verified before the job was allowed to start.
If you take one operational habit from this, make it the gap at the interface. Look at your permits and ask whether they name isolation points or wave at them. Ask whether the isolation confirmation is a gate or a box. Ask what happens to personal locks at shift change, and what happens when three jobs share one isolation. Those four questions find more real risk than another round of document auditing ever will.
Final thoughts
The reason "LOTO or permit?" persists as a question is that both systems produce paperwork, and paperwork is what most organisations can see. The physical state is harder to see, easier to assume, and the only one of the two that stops a machine moving. Any assurance regime that samples only the documents will eventually be surprised by the plant.
The vocabulary will keep differing between employers and sectors, and that is manageable. What is not manageable is a system where nobody can point to where the authorisation decision is recorded, or where the physical state is established and proved. Get those two homes clearly defined, defined by someone competent to do it for your plant and your law, and keep the joint between them honest. The rest is detail.
Disclosure
Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.
Reviewing how your permit and isolation systems fit together?
Independent advisory on how safe-system-of-work requirements are carried through asset records, work orders and planning, and where the interface between authorisation and physical control tends to leak. 22+ years across utilities, oil and gas, manufacturing, government and facility operations.
Book a conversationRelated reading: Lockout/tagout: the complete guide, Permit to work: the complete guide, The LOTO procedure step by step, Types of permit to work, Hierarchy of controls, Confined space permits, Hot work permits.
Primary sources: US OSHA , UK HSE , ISO .
Muhammad Abbas
CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.
Work with me