Hold your written emergency procedures, send each person the few lines meant for their role when an alert goes out, brief people ahead of time, and keep a record of who confirmed they had read which version.
A procedure is your organisation's own written answer to "what do we do when…": your evacuation, your invacuation, your lockdown, how you communicate while it is happening. In whoot. a procedure has two parts. Action cards are the few lines each person is sent with an alert, according to the role they hold: a marshal is told what marshals do, a visitor is told where to go. The checklist is the list of steps worked by whoever is running the incident. You will find them under Security Ops → Scenarios → Procedures.
security_ops.manage. whoot. holds your wording, puts it in front of the right people and keeps the record. The wording is yours: holding a procedure here supports the work the Terrorism (Protection of Premises) Act asks of you, and does not by itself meet a duty. A procedure has to fit your premises and be known to your people.A response role is a named audience: Marshals, Door and security team, All staff, Visitors and public. Each role says who holds it, and a card is written for a role rather than for a person, so the cards keep working as people join and leave. Set roles up on the Response roles tab. A role can be held by any mix of:
The order of the list matters. Somebody who holds more than one role is sent one card, never two: the card for the first of their roles, reading down the list. Put the specific roles at the top and the catch-alls at the bottom, and drag to reorder. Who holds a role, and the order of the roles, take effect on the next alert without publishing anything.
An action card is up to five short lines, each of 120 characters or fewer, for one role. The limit is deliberate: a card longer than that is one nobody finishes reading on a phone during an emergency. Open a procedure, choose Action cards, and write a card for each role that needs one. A role you leave empty is skipped, and a person in it is sent the card for the next role they hold.
{assembly_point} or {safe_area} in a card and the place is filled in when the alert goes out. Set the places once under Site details. When an assembly point moves, change it there and the next alert carries the new one, with nothing to publish.Only a published version reaches people. Editing a card changes your working copy and nothing else; alerts keep sending the last version you published until you publish again. A procedure that has never been published is a draft and sends no cards at all, and one you have edited since publishing is marked unpublished changes. Publish shows what is about to change in terms of the alert — which roles get a card, which languages, what the text gains, when the next review falls — and each publish becomes a numbered version, kept with your name, the date and an optional note on what changed.
Starter procedures adds four procedures to work from — Evacuation, Invacuation, Lockdown and Communication — with the five roles their cards are written for: Incident lead, Door and security team, Marshals, All staff and Visitors and public. They arrive as drafts and send nothing until you publish them. The wording was written to fit any premises, which means it fits none exactly: read each card against your exits, where your people gather and who does what. The first time you publish a starter procedure you are asked to confirm that you have. A new workspace starts with all four as drafts.
An alert follows the procedure of the incident it belongs to, or of the scenario it was declared from, or failing both the procedure written for that kind of alert. When the alert goes out, each person is matched to their role and sent that role's card:
The wording is fixed to the alert at the moment it is sent. Publishing a new version half-way through an incident changes what the next alert says, never what somebody is already reading. A practice alert carries the cards in the same way, so a drill shows people what a real alert would tell them.
Under each role's card, Add a language opens a second copy of the card to write in that language, with the original beside it. A person is shown a translation when there is one for their language and the card as you wrote it otherwise — always one whole card, never a mixture. The response page uses the language the person has chosen on the page; the app uses the phone's language. Site details are filled into a translation as they are into the original.
A procedure nobody has read is only a document. A briefing asks the people who hold a role to read their action card, outside any incident, and confirm that they have. Open a published procedure, choose Briefings and New briefing. Pick the roles to brief, add a message if you want one shown above the card, and set a confirm by date if there is one. People reach a briefing in three ways, and each sees the same page: their card, and a button to confirm.
Open a briefing to see how it is going: how many have confirmed in the app, by text and from the shared link; each person with their role, how they were reached, when they confirmed and in which language; who has opened it without confirming; and who on the roles' recipient lists has still to confirm. Export CSV takes the list away for your records, and Close briefing stops further confirmations. A briefing always shows the version that was published when it was created, so when you publish a new version the earlier briefings are marked Superseded — brief people again on the new one.
On an incident's Checklist tab, What people were told answers the question an incident lead is asked on the radio: what did the stewards get? It shows the procedure and version the alert carried, the text message line, each role's card with the languages it was sent in, and how many people were matched to each card in the app and by text — including how many were sent no card. It shows what was actually sent, not what the procedure says today, and the same panel is on the incident's dossier in History afterwards.
A procedure's Record holds who owns it, how often it is reviewed and when the next review is due. Mark as reviewed is for the read-through that finds nothing to change: it moves the review date on without creating a version. Every published version is listed with who published it, when, and their note, and each downloads as a PDF — the cards by role with their translations, the text message line and the checklist — to pin up, talk through or hand to an inspector.
The venue evidence pack draws on the same record. It counts only published procedures as written procedures, and for each one gives the version, who published it, the review date and the latest briefing on that version with how many confirmed. It flags a review that is overdue, edits made since the published version, and a current version nobody has been briefed on.