In short: Digital permit to work systems are the single biggest process improvement available to a refinery or terminal turnaround, and most rollouts stall for a mundane reason: the tablets lose signal the moment a supervisor walks into the plant. The permit system is only as good as the network that carries it.
Key Takeaways
- The permit office is the bottleneck — A major turnaround issues hundreds of permits a day through a process still anchored to paper, queues and a cabin by the gate, and every queued hour is contractor time the operator is paying for.
- Digital permits fail at the plant boundary — Permit-to-work software works in the demo and dies in the pipe rack, because public mobile coverage inside a steel-dense process unit is close to zero and WiFi cannot economically reach it.
- Coverage is a turnaround deliverable — Treating connectivity like scaffolding, namely temporary infrastructure planned and costed per event, is what makes a digital permit system usable where the work actually happens.
In a nutshell

Why do turnarounds still run on paper permits?
A turnaround compresses years of maintenance into a few weeks. The workforce on a UK refinery or gas terminal turnaround routinely triples, with a thousand or more additional contractors on site for the peak fortnight; the event is planned for two years and costs tens of millions of pounds; and every job on the schedule, from a flange break to a vessel entry, needs a permit to work before anyone touches a spanner.
The permit process itself is not bureaucratic decoration. The HSE's guidance in HSG250 sets out why formal control of work exists in process industries, and the industry learned the lesson in the hardest way available: the Cullen Inquiry into Piper Alpha found that failures in the permit-to-work system, a night-shift crew unaware that a relief valve had been removed on the day shift, sat at the centre of the chain that killed 167 people in 1988. Nobody in the sector argues for less rigour.
What operators do argue about is the mechanics. On many UK sites a permit still means paper: a form drafted the day before, signed at a permit office in the morning, carried to the job in a plastic wallet, and walked back for closure at shift end. During normal operations that is workable. During a turnaround, when the site issues several hundred permits a day instead of a few dozen, the permit office becomes the plant's narrowest pipe. Contractors queue from before six; supervisors spend the first working hour of every shift standing in line; a clash discovered at the counter, two crews permitted into the same pipe rack, sends one crew back to the cabin to wait. Multiply an hour of lost time by a thousand contractors at turnaround day rates and the queue is costing more per week than most sites spend on connectivity in a decade.
What does a digital permit to work actually change?
A digital permit to work system moves the permit from paper to a controlled electronic workflow: permits are drafted, risk-assessed, approved, issued, suspended and closed on screens, with the state of every permit visible to everyone entitled to see it, in real time.
The gains are specific rather than general. Firstly, clash detection happens at planning time rather than at the counter; the system knows that isolation X and permit Y touch the same line before either crew is mobilised. Secondly, the morning queue largely disappears, because permits are approved electronically and collected at the job front rather than the cabin. Thirdly, the audit trail writes itself; when the HSE or the site's own process safety team asks who authorised what and when, the answer is a query rather than a fortnight of box files. Fourthly, and this is the one supervisors mention first, a permit can be suspended plant-wide in minutes when conditions change, a gas alarm, a weather hold, an adjacent lift, rather than by sending runners.
UK operators are not debating the principle; digital control of work platforms are established products, and most majors have deployed one somewhere in their portfolio. The debate, in our experience, is why the deployments so often disappoint on the sites that need them most.
Why do rollouts stall at the plant boundary?
Because the software assumes a connected device, and a process plant is one of the most hostile radio environments in industry. The same steel that makes a refinery strong makes it opaque: dense pipe racks, vessels, structures and cable trays attenuate and reflect signal so thoroughly that public 4G, patchy at the fence line of many rural coastal sites to begin with, is effectively absent at grade inside a process unit. WiFi can be engineered into a plant, but covering hundreds of acres of outdoor steel with access points is slow and expensive, every device in a hazardous area needs ATEX or IECEx certification, and turnaround work happens in exactly the corners, inside bunds, under structures, at the tops of columns, that a fixed WiFi design never quite reaches.
So a familiar failure pattern repeats. The digital permit system is piloted in the office and the permit cabin, where it works. It is rolled out to the field, where supervisors discover that the tablet updates in the car park and freezes at the job front. Crews revert to printing the permit anyway, "just in case", and within a fortnight the site is running the paper system and the digital system in parallel, which is worse than either alone: double the administration, and nobody entirely sure which copy is authoritative. The software takes the blame. The network was the problem.
It is worth saying that connectivity is not the only failure mode; digital permit projects also stall on training, on contractor onboarding and on over-complicated workflow design. But coverage is the failure mode that no amount of change management can talk around, because a supervisor who cannot load the permit at the job front is right to distrust the system.
How does private 5G carry a permit system into the plant?
By being engineered for the plant rather than for the public. A private 5G network is designed around the site's own geometry: radios placed to cover the process units, tank farms and turnaround laydown areas specifically, licensed spectrum (in the UK, typically Ofcom's shared access licences in band n77) that the site controls, and capacity reserved for the site's own devices rather than shared with the nearest town. 5G's propagation and uplink behaviour do not repeal physics; dense steel still needs deliberate radio planning. The difference is that deliberate planning is possible, because the operator of the network and the operator of the plant are on the same side of the fence.
Two deployment patterns matter for turnarounds. The first is permanent coverage, built once and used daily for operations, inspection rounds and condition monitoring, with the turnaround as the peak load. The second is worth more attention than it gets: temporary coverage as a turnaround deliverable, deployed for the event the way scaffolding, cabins and welfare units are, and demobilised afterwards. A trailer-mounted or skid-mounted small cell with satellite or leased-line backhaul can put dependable coverage over a turnaround worksite and its contractor village for the duration; we have written previously about portable cell-on-wheels deployments in other sectors, and the economics transfer. For a site not yet ready to commit to permanent infrastructure, hiring coverage for the event is the honest middle option, and it converts the business case from an abstraction into a measured result.
Hazardous areas need one further honest caveat: handsets and tablets used in ATEX zones must themselves be Ex-rated, and Ex-rated 5G devices, whilst available from the specialist manufacturers, remain a shorter menu at a higher price than their safe-area equivalents. Device selection belongs in the turnaround plan alongside the network, not after it.
What should a turnaround team do first?
Treat connectivity as a line item in the turnaround scope, eighteen months out, alongside scaffolding and cranage. The sequence we would argue for is short: (i) survey the worksites on the schedule for existing coverage, honestly, at grade and inside the structures, not from the road; (ii) decide the permit workflow first and the network second, so the coverage design follows the work fronts rather than a site map; (iii) price temporary coverage for the event against the permanent build, and let the turnaround pay for the trial.
The measure of success is equally short. If the last permit of the shift closes from the job front, on the tablet, without anyone walking to a cabin, the system has done its job. Sites that get there do not go back to paper.
