'We Alerted Someone' Is Not an OSHA Defense

Blog · Vision AI

'We Sent an Alert' Won't Hold Up When OSHA Asks Who Stopped the Line.

By Rohit Gupta7 min read

Short answer

Edge safety-vision platforms detect PPE gaps, falls, and restricted-zone entry, then fire an alert or a vague 'pre-programmed response' — and their 'visual audit trail' records what the camera saw, not what was done about it.

A camera on your plant floor sees a worker cross under a suspended load with no hard hat. Two hundred milliseconds later the model is certain, and a notification is already on its way to someone's phone. What happens in the next ninety seconds is the only thing an inspector or a plaintiff's counsel will care about — and it is the exact thing an edge safety-vision platform hands off to a second system it does not govern. The detection was never the safeguard. The enforced response is. 'We alerted someone' describes a notification. It does not describe a control.

Start by giving the cameras their due, because they earn it. Real-time detection of PPE gaps, falls, and restricted-zone entry, running on-device at the edge, means a hazard is seen the instant it appears — across far more of the floor than any human watch-stander could cover, and often without a single frame leaving the plant. That last point is an honest answer to the privacy objection, and it is backed by real security posture: on-edge inference, zero-retention options, recognized certifications. Confidence scores paired with human review are a pragmatic middle path, not a gimmick — they keep a person in the decision precisely where the model is unsure. This is a genuine democratization of a capability that used to demand a dedicated safety officer per line. None of what follows disputes any of it.

But notice exactly what all of that governs. It governs the read — did the model see the hazard, how sure was it, where in the frame, has its accuracy drifted since deployment. Every certification, every confidence threshold, every grounded bounding box is an assurance about perception. And perception is where these platforms stop.

What comes after the detection is, architecturally, a signal thrown over a wall. The strongest version in the category is a 'pre-programmed response' — fire a relay, sound a horn, flash a strobe, POST a webhook — and the more common version is a notification to an operator, a dashboard, or a supervisor's phone. Both share a defining property: they are open-loop. The signal leaves the vision system, and nothing downstream is obliged to confirm that the hazard was abated, that the right person received it, or that anyone acted at all.

That leaves you with three failure modes — and they are the very ones 'proactive safety' was sold to eliminate:

  • Missed. The alert lands in a queue, at a shift change, in a noisy control room where it competes with fifty others.
  • Muted. After enough marginal positives, the horn gets silenced, the channel muted, the relay bypassed — the classic alarm-fatigue endgame.
  • Ignored. The notification is acknowledged and nothing else happens, because acknowledgment is not abatement.

Here is the part that should worry counsel most. The 'visual audit trail' these platforms tout — the clip, the timestamp, the bounding box — records what the camera saw. It does not record what was done about it. You end up with immaculate evidence that a hazard was detected and no evidence that it was corrected. In an enforcement context that is the worst of both worlds: proof of awareness, silence on the response.

DETECT & NOTIFY · response ungoverned safety vision edge detection alert the wall operator phone / dashboard — may be muted horn · strobe · relay — open-loop, no confirm PLC / MES signal — second system acts, or doesn't visual audit trail records the DETECTION — not the response an alert is missable · mutable · ignorable DETECT → REMEDIATE · one runtime vision Function inline policy gate confidence-gated versioned · approver-set governed remediation lockout · escalate SLA below threshold HITL — high-stakes pause before commit Connector → line control / EHS immutable per-action audit detection → policy → action → actor → outcome the ENFORCED response — proven, not surfaced

Walk it forward to the day it matters. After an incident, an inspector or a plaintiff's counsel does not ask whether your cameras were good. They ask a chain of questions about the response: was the hazard identified, what specific corrective action followed, on what timeline, who was accountable for it, and can you prove that action was enforced rather than merely suggested. A muted alert with a beautiful clip answers the first question and indicts you on the rest.

That is the uncomfortable inversion at the center of detect-and-notify. Detection without a provable, enforced response does not just fail to help — it can raise your exposure, because you now hold a durable record establishing that the condition was known. The liability was never in the seeing. It lives entirely in the doing — on a timeline, under accountability — and the doing is exactly the part the vision platform leaves in a system it neither governs nor records.

The architectural fix is to stop treating the detection as the end of the loop and make it the first step of one. On a composable process fabric, the vision model runs as a governed Function inside a Deterministic Workflow. The detection is not thrown anywhere; it is consumed, on the same runtime, by a remediation process whose controls are enforced inline. That single move reframes every weak point of detect-and-notify:

  • The response is a governed workflow, not a signal. A restricted-zone entry doesn't merely trip a relay; it triggers a defined remediation with the corrective action as an enforced step — a governed lockout or line-stop issued through a Connector, the only primitive that touches your external estate.
  • Non-acknowledgment escalates by construction. If the accountable person doesn't acknowledge within the SLA window, the workflow escalates — to the shift manager, then higher — because the timeline is a property of the process, not a hope pinned on a busy human. An alert has no such spine.
  • High-stakes actions are HITL by design. Halting a line or dispatching a responder is a pause-before-commit checkpoint the workflow enforces, not a courtesy the operator may skip. And where the model is unsure, confidence-gated policy routes the case to a person before anything physical happens — the confidence score becomes a versioned, approver-set control, not a magic number buried in downstream code.
  • The audit records the enforced response. Every action emits an immutable per-action record binding detection → confidence → policy → action → actor → outcome. That is not a clip of what the camera saw. It is the receipt of what was done — by whom, under which policy, and whether it was verified.

Make it concrete, and keep it explicitly hypothetical. Picture a worker stepping into an energized-equipment exclusion zone. On this design the detection routes into a remediation workflow that issues a governed stop to that zone's control system through a Connector, opens an acknowledgment task to the area supervisor with an SLA, escalates to the shift manager if it goes unacknowledged, and writes each step to the per-action audit as it happens. If the model's confidence sits below the policy threshold, nothing physical fires — the case goes to a human reviewer first. This is an architectural property of where the control sits, not a demonstrated result or a live demo: the enforced response is reachable, and provable, because it executes as governed steps on one runtime.

Be precise about two things, because expert readers will test both. First, this is not a claim that the fabric needs no integration — it runs over the estate you already operate (line controllers, access control, the EHS system of record) through governed Connectors; what changes is where the decision about the response lives. Second, the strongest version of the category does more than alert: it writes the detection into a PLC tag or pipes it to an MES, and that is genuinely more end-to-end than a bare detector — concede it plainly. But the decision-and-action logic there is authored separately, in a different tool, by different people; no policy travels across the wire with the signal; and the audit is split-brain — what the camera saw lives in one system, what the PLC did in another, with nothing binding them into a single provable record that the required response was enforced on time. On the fabric, detect → decide → act → audit is one accountable transaction, not a signal lobbed over a wall into a system that acts without oversight.

In the inquiry that follows an incident, no one asks what your cameras saw. They ask what you did about it — and whether you can prove it was enforced.

See what this looks like for your enterprise.

Not a demo. A strategic conversation about how your enterprise could operate
when every process runs on one governed fabric.

Start the Conversation