Files
ims/docs/BRD_HSE_IMS.md
T

339 lines
17 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Business Requirement Document
## Centralized AI-Powered HSE Incident Management & Reporting System
**Client:** Setia Corporation — 3PL Warehouse Operations
**Prepared by:** Wee Ihan Yap
**Version:** 1.0
**Date:** 12 July 2026
**Status:** Final
---
## 1. Executive Summary
Setia Corporation currently manages Health, Safety and Environment (HSE) incident reporting through a combination of WhatsApp messages, Excel spreadsheets, and paper-based forms. This process creates significant gaps: delayed notifications, incomplete evidence, inconsistent classification, and manual workload for statutory DOSH reporting.
This document defines the business requirements for a centralized, AI-powered HSE Incident Management System (IMS) that replaces these manual processes. The system captures every incident digitally, runs a structured workflow from report through closure, tracks corrective actions, and generates statutory JKKP reports automatically — eliminating the administrative burden on HSE staff and ensuring zero missed regulatory deadlines.
---
## 2. Business Objectives
1. Replace WhatsApp/Excel/paper incident reporting with a single digital system capturing all incident types.
2. Enforce a structured, auditable workflow: report → triage → investigation → CAPA → verification → closure.
3. Track all Corrective and Preventive Actions (CAPAs) to completion with automated escalation for overdue items.
4. Provide management with a live dashboard replacing monthly manual report compilation.
5. Ensure full compliance with Malaysian DOSH reporting obligations (NADOPOD 2004) without manual form-filling.
6. Use AI (Claude API) to reduce HSE admin burden: drafting summaries, suggesting root causes, flagging incomplete reports, and detecting risk patterns.
---
## 3. Stakeholders
| Role | Representative(s) | Responsibility |
|---|---|---|
| Sponsor / Business Owner | Ms. Agnes, Mr. Terence | Approve requirements, budget, go-live sign-off |
| HSE Lead | Mr. Yap | Primary system user; investigation, CAPA, DOSH filing |
| Operations | Mr. Jensen | Supervisor workflow, CAPA ownership |
| Floor Staff / Reporters | All employees, guards | Incident submission via QR scan |
| System Developer | Wee Ihan Yap | Design, build, deployment |
---
## 4. User Roles & Access
| Role | Who | Access Level | Primary Responsibility |
|---|---|---|---|
| Reporter | Any employee, supervisor, witness, security guard | Submit reports via QR/app; view own reports only | Report incidents and hazards immediately |
| Operation Supervisor | Warehouse/shift supervisor | Full access to incidents in their site/zone | Secure area, first response, initial classification |
| HSE Officer | Safety Assistant / HSE team | Full access across all sites | Investigation, RCA, CAPA assignment, verification, closure, DOSH filing |
| CAPA Owner | Department head (Ops, Maintenance, HR, etc.) | CAPA items assigned to their department only | Complete corrective actions, upload proof |
| Management | Ms. Agnes, Mr. Terence, Mr. Yap, Mr. Jensen | Read-only dashboard across all sites | Review trends, approve budgets, audit readiness |
| System Admin | IT / appointed super-user | Full configuration access | User management, site/zone setup, form configuration |
Every action must be attributable to a logged-in user — no anonymous edits.
---
## 5. Scope
### 5.1 In Scope
- Digital incident capture for all seven incident types (see §6)
- Full incident lifecycle: report → triage → investigation → CAPA → verification → closure
- Evidence management: photos, videos, documents at every lifecycle stage
- CAPA board with auto-escalation and effectiveness re-check
- Email and WhatsApp Business notifications
- In-app notification bell and badge
- DOSH compliance: automated JKKP 6, JKKP 7, JKKP 8 PDF and CSV generation
- AI-assisted features: quality check, severity suggestion, similar incident retrieval, RCA/CAPA drafting, risk heatmap
- Multi-site, multi-zone QR-based reporting
- Multi-language UI (English, Bahasa Malaysia, Mandarin)
- Mobile-first, offline capture with auto-sync on reconnect
- Dashboard: leading/lagging indicators, site/zone heatmap, CAPA on-time rate, trend charts
- Admin panel: user management, site/zone CRUD, role assignment
- Full audit trail (every action logged with user + timestamp)
- 5-year data retention per DOSH requirements
### 5.2 Out of Scope
- WMS (Warehouse Management System) integration (optional future phase)
- Tamil language support (deferred unless workforce requires it)
- Third-party EHS platform integration
- External audit portal access
---
## 6. Incident Types
The system must support all seven incident types, each with a type-specific intake form:
1. **Injury / Medical Treatment Case** — LTI and non-LTI
2. **Near Miss** — fast, low-friction form (near-miss volume is the primary leading safety indicator)
3. **Unsafe Condition / Hazard Observation** — proactive, not tied to an event
4. **Property / Asset / MHE Damage** — forklift, racking, dock equipment
5. **Environmental Incident** — spill, leak, chemical release, waste
6. **Security Incident** — theft, unauthorized access
7. **Fire / Emergency Incident**
---
## 7. Incident Reference Format
Every incident auto-generates a unique reference number:
```
SITE-YYYYMM-####
```
Example: `KL01-202607-0042`
---
## 8. Functional Requirements
### 8.1 Incident Reporting
- Reporter scans a site/zone-specific QR code or opens the app
- System pre-fills site and zone from QR token (no manual entry)
- Reporter selects incident type and completes type-specific intake form
- Minimum one photo required for injury reports; video and documents optional
- System auto-generates incident reference number and timestamps report
- Automatic notification fires immediately to the relevant Supervisor and HSE Officer
- Offline capture supported: form data queued in browser (IndexedDB) and synced on reconnect
### 8.2 Triage & Initial Response
- Supervisor or HSE Officer confirms or reclassifies incident type
- Assigns severity level (15); AI may suggest a level but a human always confirms
- Workflow branches by type:
- Injury: medical/first-aid path, LTI/non-LTI classification, lost-day tracking
- Asset/MHE: emergency shutdown/LOTO, operator-error check, HR/discipline path if applicable
- Environmental: containment steps, spill-kit deployment, environmental authority check
- Near miss / hazard: skip to root-cause and CAPA directly
- System automatically evaluates incident data against NADOPOD 2004 rules and presents the applicable obligation (immediate DOSH notification / JKKP 6 / JKKP 7 / JKKP 8) as a checklist for the HSE Officer
### 8.3 Investigation & CAPA
- HSE enters witness statements, alcohol/urine test result (if applicable), evidence
- Structured root-cause analysis via selectable template: 5-Why or Fishbone (not free text only)
- Every CAPA item must record: description, responsible department/owner, due date, priority, and root-cause linkage
- Auto-escalation ladder:
- 3 days before due date: reminder to owner
- On due date: notify owner
- 3 days overdue: notify owner's manager
- 7 days overdue: notify HSE Officer, flag red on dashboard
### 8.4 Verification & Closure
- CAPA owner uploads completion evidence (photo/document proof) before marking CAPA as done
- HSE verifies effectiveness; if not effective, CAPA **reopens** (not closed with open gap)
- Once all CAPAs verified, HSE closes incident
- On closure: record locks against further edits; only addenda can be appended
- Closed incident automatically enters JKKP 8 annual register
### 8.5 Evidence Management
Evidence must be attachable at every lifecycle stage, not only at initial report:
| Stage | Expected Evidence |
|---|---|
| Report | Scene photo/video, hazard photo |
| Response | LOTO tag photo, first-aid record, medical referral letter |
| Investigation | Witness statement scans, CCTV export, equipment inspection report, alcohol/urine test result |
| CAPA | Before/after photos, purchase receipts, training attendance sheets, updated SOP |
| Verification | Final confirmation photo/video that corrective action is in place and effective |
Requirements:
- Accepted formats: JPG, PNG, HEIC, MP4, MOV, PDF, DOCX, XLSX
- Max file size: configurable (recommended 200 MB for video; compress on upload)
- Every file records: uploader, timestamp, incident ID, stage, immutable SHA-256 file hash
- Files retained minimum 5 years; never auto-deleted
- Thumbnail/preview generation so HSE can review without downloading
### 8.6 Notifications
| Channel | Use |
|---|---|
| Email | Formal records: investigation assignment, CAPA assignment, closure notifications |
| WhatsApp Business API | Time-critical alerts: new serious incident, CAPA overdue escalation |
| In-app notification bell | All events for all users; unread badge count; dropdown list |
### 8.7 Dashboard & Analytics
- Total incidents, near misses, severity rate, open vs. closed counts
- **Leading vs. lagging indicator split** (near miss/hazard = leading; injury/LTI = lagging)
- Site/zone/shift heatmap — critical for multi-warehouse operations
- CAPA on-time completion rate (%)
- Top incident category and top root cause, trended over 12 months
- DOSH-reportable incident count and filing status (filed / pending / overdue)
- AI rising-risk zone flags: zones with statistically increasing incident frequency
- Export to PDF/Excel for board reporting
### 8.8 AI-Assisted Capabilities
All AI outputs are suggestions that a human reviews and approves — never auto-submitted to DOSH and never auto-closed without human sign-off.
| Capability | Description | Business Value |
|---|---|---|
| Report quality check | Flags incomplete reports before submission (missing photo on injury report, vague description) | Fixes delayed/incomplete information problem |
| Severity/category suggestion | Suggests severity level (15) and incident category from free-text description | Speeds triage, reduces classification inconsistency |
| Similar incident retrieval | Surfaces top-5 past incidents with similar description/location/equipment via vector similarity | Reveals recurring hazards; supports trend detection |
| RCA/CAPA drafting assistant | Suggests likely root causes and draft corrective actions from investigation notes | Cuts write-up time, improves CAPA consistency |
| JKKP form auto-fill | Generates JKKP 6/7 PDF drafts and JKKP 8 annual register from stored data | Removes single biggest admin burden |
| Risk heatmap / prediction | Combines near-miss, incident, and hazard data by site/zone/shift to flag rising-risk areas | Predictive safety capability tuned to Setia's own warehouses |
All AI suggestions logged to audit trail: what was suggested and what the human ultimately chose.
### 8.9 DOSH Compliance (NADOPOD 2004)
The system encodes Malaysia-specific statutory reporting rules and automatically determines the applicable obligation:
| Situation | Obligation |
|---|---|
| Fatality or serious bodily injury (NADOPOD First Schedule: fracture, amputation, loss of sight) | Notify nearest DOSH office immediately; submit JKKP 6 within 7 days |
| Dangerous occurrence (Second Schedule: boiler explosion, structural collapse) regardless of injury | Notify DOSH immediately; submit JKKP 6 within 7 days |
| Other injury causing incapacity for more than 4 consecutive days | Submit JKKP 6 within 7 days |
| Occupational poisoning or disease (Third Schedule) | Submit JKKP 7 within 7 days |
| Any of the above | Also logged in JKKP 8 annual register; retained on-site 5 years; submitted to DOSH before 31 January each year |
### 8.10 Admin Management
- User management: invite by email, assign role and site, activate/deactivate
- Site CRUD: name, address, region, active flag
- Zone CRUD: name per site, QR code generation and download per zone
- All admin actions logged to audit trail
---
## 9. Non-Functional Requirements
| Category | Requirement |
|---|---|
| Mobile-first | Must work on low-end Android phones common on warehouse floors |
| Offline | Incident form submittable offline; data queues locally (IndexedDB) and auto-syncs on reconnect |
| Multi-language | English, Bahasa Malaysia, Mandarin (all three available at all times via language switcher) |
| Multi-site | Site and zone are first-class fields on every record from day one |
| Access control | Role-based access enforced at the database level (Supabase RLS), not only in UI |
| Audit trail | Every create/edit/status-change/file-upload logged with user and timestamp; immutable |
| Data retention | Minimum 5 years per DOSH JKKP 8 requirement; evidence files never hard-deleted |
| Performance | Incident list uses server-side pagination; no unbounded queries |
| Security | API keys server-side only; never exposed to client; RLS on all tables |
---
## 10. System Architecture Summary
**Stack:**
| Layer | Technology |
|---|---|
| Frontend + API routes | Next.js 15 (App Router) |
| Database + Auth + Storage | Supabase (Postgres + RLS + pgvector) |
| Hosting | Vercel (frontend) + Supabase cloud |
| AI | Claude API (Anthropic) — server-side only |
| Email | Resend |
| WhatsApp | Meta WhatsApp Business Cloud API |
| PDF generation | pdf-lib (JKKP 6/7 form fill) |
| QR codes | qrcode npm package |
**Deployment:** Vercel (frontend) + Supabase cloud. Custom domain `hse.setiacorp.com` once MVP validated. All secrets stored as environment variables — never committed to code.
---
## 11. Key Database Entities
| Entity | Purpose |
|---|---|
| sites | Warehouse locations |
| zones | Named areas within a site, each with a unique QR token |
| users | All system users with role, department, site assignment |
| incidents | Core record: type, site, zone, severity, status, lifecycle timestamps |
| evidence_files | Files attached at each lifecycle stage with immutable hash |
| investigations | RCA method, findings, root cause summary, test results |
| capa_actions | CAPA items with owner, due date, priority, status, effectiveness recheck date |
| dosh_reports | JKKP 6/7/8 records with filing status and generated PDF link |
| notifications_log | All notifications sent across all channels |
| audit_log | Immutable record of every system action |
---
## 12. Development Phases
| Phase | Scope | Status |
|---|---|---|
| 0 | Foundation: scaffold, auth, DB migrations, QR codes | Complete |
| 1 | Core reporting: incident form, inbox, evidence upload, email notification | Complete |
| 2 | Investigation + CAPA: triage, 5-Why/fishbone, CAPA board, verification, JKKP 6/7 PDF | Complete |
| 3 | AI features + dashboards: Claude integration, pgvector similar incidents, role dashboards, CSV export | Complete |
| 4 | Scale & polish: WhatsApp notifications, i18n EN/MS/ZH, PWA offline capture, CAPA effectiveness recheck | Complete |
| 5 | Usability & compliance: notification bell, closure lock, pagination, type-specific intake, witness/alcohol UI, JKKP 8, admin management, evidence thumbnails | Complete |
| 6 | Analytics & predictive: 12-month trend chart, top root causes trended, AI rising-risk zone flags | Complete |
---
## 13. Success Metrics
| Metric | Target |
|---|---|
| Digital incident capture rate | 100% within 30 days of launch (zero WhatsApp-only reports) |
| CAPA on-time closure rate | Above 85% within 3 months |
| Incident-to-HSE notification time | Under 2 minutes (vs. current WhatsApp-dependent manual forwarding) |
| Monthly HSE report preparation time | Reduced from days to minutes (auto-generated from dashboard) |
| Missed DOSH statutory reporting deadlines | Zero |
---
## 14. Assumptions & Constraints
- All warehouse sites have internet access sufficient for mobile web browsing; offline mode covers low-signal periods only.
- Users are expected to have a smartphone (Android minimum); desktop access available for HSE Officers and management.
- Supabase free/starter tier sufficient for initial rollout; video-heavy storage may require upgrade to Supabase Pro or Cloudflare R2 migration at scale.
- `SUPABASE_SERVICE_ROLE_KEY` must be set in production environment for admin user-invite functionality.
- WhatsApp Business API requires approved Meta Business account and message templates before production use.
- VPS cron jobs must be registered for CAPA escalation and effectiveness recheck automation post-deployment.
- Evidence files must never be deleted; storage cost is a known ongoing operational expense.
---
## 15. Glossary
| Term | Definition |
|---|---|
| CAPA | Corrective and Preventive Action |
| DOSH | Department of Occupational Safety and Health (Malaysia) |
| HSE | Health, Safety and Environment |
| JKKP 6 | Malaysia statutory form — notification of accident/dangerous occurrence |
| JKKP 7 | Malaysia statutory form — notification of occupational poisoning/disease |
| JKKP 8 | Malaysia statutory form — annual register of accidents/occupational diseases |
| LTI | Lost Time Injury (injury resulting in at least one day away from work) |
| LOTO | Lockout/Tagout (energy isolation safety procedure) |
| MHE | Material Handling Equipment (forklifts, pallet jacks, etc.) |
| NADOPOD 2004 | Notification of Accident, Dangerous Occurrence, Occupational Poisoning and Occupational Disease Regulations 2004 |
| pgvector | Postgres extension for vector similarity search (used for similar incident retrieval) |
| QR | Quick Response code (used for site/zone identification on incident report form) |
| RCA | Root Cause Analysis |
| RLS | Row-Level Security (Supabase/Postgres feature enforcing data access at DB level) |
| 3PL | Third-Party Logistics |