A ship-to-shore crane is down for a hoist gearbox change. Three trades converge on it inside an hour: the terminal's own mechanical fitters, an OEM technician flown in for the drive, and an electrical contractor pulling motor cabling. The crane sits on 6,600-volt shore supply, holds a suspended headblock, carries hydraulic accumulators charged to hundreds of bar, and has a boom that will drop under its own weight the moment a brake is released. Every one of those energies can kill a person who assumes the machine is "off" because it is not moving. Lockout/tagout is the discipline that turns "off" into "proven safe," and at a terminal it is rarely one person locking one switch. It is several crews, on several energy sources, on one massive machine, across a shift change.
What lockout/tagout is and why terminals need it
Lockout/tagout, almost always shortened to LOTO, is the set of practices that isolates a machine or system from every source of hazardous energy before anyone services it, and keeps it isolated until the work is finished and people are clear. A lock physically holds an isolation device in the safe position. A tag identifies who applied it and why. Together they are the visible, enforceable promise that the equipment cannot start, move, or release energy while a body is inside the line of fire.
The reason terminals need it more than most industrial sites is the sheer variety of stored energy on their equipment. Hazardous energy is not just electrical. On terminal assets it appears in at least five forms, and a competent energy control procedure has to account for each:
- Electrical, from the high-voltage supply to STS and RTG cranes, reefer racks, conveyor drives, and pump motors at a liquid-bulk berth.
- Mechanical, in the rotating shafts and drums of a hoist, the moving belt of a ship-loader, or the momentum of a coasting conveyor that keeps turning long after the drive is cut.
- Hydraulic, in the accumulators and rams that raise spreaders, tilt hatch covers, level RoRo ramps, and drive grabs on a bulk crane.
- Pneumatic, in the compressed-air systems on brakes, clamps, and pneumatic conveying lines.
- Gravitational and stored, in a suspended headblock, a loaded boom, a raised ramp, a charged spring, or a column of product standing in a pipe above a valve.
A single conveyor at a dry-bulk terminal can hold four of those at once: an electrical drive, mechanical inertia in the belt and pulleys, a hydraulic take-up, and gravity feeding material from a hopper above. Isolating only the motor starter leaves three ways for the machine to hurt the person who cleared a chute. That is why loto safety is treated as a distinct control and not folded into general electrical work. International practice reflects this. The energy-control model is written into US OSHA 29 CFR 1910.147, into the European Union framework under Directive 89/391/EEC and the use-of-work-equipment and machinery directives that flow from it, and into the UK's Provision and Use of Work Equipment Regulations 1998 (PUWER). Above all of them, ISO 45001 sets the management-system expectation, and for a port facility the ISPS Code governs who is even allowed near the asset in the first place.
The energy-control procedure, step by step
A lockout tagout procedure is not a philosophy, it is a sequence, and the order is not negotiable. Skipping or reordering a step is how people get caught. A defensible LOTO procedure runs through six stages.
1. Prepare and notify
Identify the machine and every energy source feeding it, using the equipment-specific isolation procedure rather than memory. Notify all affected workers that the asset is going down for service. On a terminal this notification is operational as much as safety-critical: a crane about to be locked out has to come out of the vessel plan, and the berth has to know.
2. Shut down
Bring the equipment to a normal, controlled stop using its own controls. Do not isolate a machine that is still running under load. Let the conveyor empty, let the hoist land its load, let the pump come off line in sequence.
3. Isolate
Operate every isolation device that separates the machine from its energy: open the main disconnect, close and chock the block valves on a hydraulic or product line, close the air-supply valve, and physically restrain any part that can move under gravity. One machine can have half a dozen isolation points, and all of them are in scope.
4. Apply locks and tags
Each isolation device gets a lock. Each worker exposed to the hazard applies their own personal lock, so the equipment cannot be re-energised while any one of them is still on it. The tag names the person, the date, and the reason. This is the point where "isolated" becomes "locked out," and it is the step that must never be delegated to someone else on your behalf.
5. Release stored energy
This is the step untrained crews skip. After isolation, discharge or restrain everything the machine is still holding: bleed hydraulic accumulators to zero, vent air receivers, lower or block a suspended boom or ramp, drain a section of pipe, discharge capacitors, and relieve spring tension. An isolated accumulator is still a loaded gun until it is bled.
6. Verify zero energy
Prove it. Try to start the machine from its normal controls and confirm nothing happens, then return the control to off. Test electrically with a meter, confirm hydraulic and pneumatic gauges read zero, and physically check that gravity-loaded parts are down or blocked. Only a verified zero-energy state authorises hands-on work. When the job is done, the sequence reverses in a controlled way: clear tools and people, remove locks each by their own owner, and re-energise only after a final all-clear.
Group LOTO and contractor LOTO: the highest-risk gap
The six steps are the easy part. They describe one competent person isolating one machine. A terminal almost never works that way, and the real exposure lives in the gap between crews.
Take the crane gearbox job again. The terminal fitters, the OEM technician, and the electrical contractor are all on the same asset, on different energy sources, on their own timelines. If the electrical contractor finishes first and pulls their lock, nothing tells them the OEM technician is still inside the hoist housing relying on that same isolation. This is precisely what group lockout exists to prevent. The isolations go on once, a group lockbox holds the keys, and every worker hangs a personal lock on that box. The equipment cannot be released until the last personal lock is removed, so no crew can re-energise a machine another crew is still inside.
Two things make this uniquely hard at a terminal. The first is third-party maintenance. OEM technicians and specialist contractors rotate through, often do not know the site's isolation points, and are not on the terminal's own systems. They need to be inducted, verified as competent, and folded into the same group lockout as the direct-hire crews, not run as a parallel process. The way a facility governs those crews sits inside its control-of-contractors process, and a contractor who has not been through it should not be holding a lock at all.
The second is the shift handover. Terminal maintenance runs around the clock. A long isolation started on days can still be live at 20:00, and the crew coming on has to inherit it with total confidence about what is locked out, why, who owns each lock, and what is still energised. A handover that loses one lock, or lets an off-going worker's personal lock walk out of the gate in a pocket, breaks the entire chain. Group and contractor LOTO across a shift change is the single highest-risk gap in terminal energy control, and it is almost always a communication failure rather than a technical one.
Where paper LOTO fails
Most terminals still run this on paper and coloured tags, and paper degrades exactly where the risk concentrates.
- Lost and orphaned tags. A tag hung at 03:00 in wind and salt spray fades, tears, or blows off. A worker leaves at end of shift with a personal lock still in their locker. Nobody can now say with certainty whether the machine is safe, and the safe assumption, that it is not, stalls the operation.
- No audit trail. When the tag comes off, the record of that isolation effectively ceases to exist. Six months later, after an incident or during an ISO 45001 audit, there is no reliable way to reconstruct who isolated what, when energy was verified as zero, and who authorised re-energisation.
- No link to the permit. High-risk work at a terminal runs under a permit to work, and the isolation is the safety condition the permit depends on. On paper the permit lives in one folder and the LOTO tags live on the machine, connected only by a signature and human memory. Nothing structurally prevents a permit being signed off, or extended, while an isolation it relied on has quietly been removed. The isolation, the risk assessment that called for it, and the permit that authorises the work are three documents that have to agree, and on paper they routinely do not.
None of these are exotic failures. They are the ordinary friction of running LOTO with cardboard and biros across a 24-hour operation, and every one of them puts a person between a machine and its stored energy.
Digital LOTO inside a permit-to-work system
The fix is not a better tag. It is to stop treating the isolation as a loose artifact and bind it to the work it protects. Digital lockout/tagout inside a permit-to-work platform ties every isolation to three things at once: the equipment being worked on, the permit that authorises the work, and the worker who applied and owns each lock.
That single link closes the gaps paper leaves open. Isolations are declared against the specific asset and its known energy sources, so no source gets missed and no crew improvises the isolation points. Every personal lock is recorded against a named, inducted, and competency-verified worker, which makes group lockout and contractor lockout auditable in real time: the system knows exactly who is still on the machine and will not let it be released while anyone is. The zero-energy verification is captured as a step that has to be completed, not a box someone remembers to tick. And because the isolation is a condition of the permit, the permit cannot be closed or extended while a lock is still live, and a live isolation cannot be quietly abandoned while its permit is still open. The two enforce each other.
The audit trail comes for free, because it is the record itself and not a reconstruction. Every isolation, every lock applied and removed, every verification, and every handover carries a name and a timestamp, which is precisely what ISO 45001 expects a facility to be able to produce, and precisely what an investigation into a near miss or an incident needs when the question is whether the machine was actually safe. Handover stops depending on a whiteboard: the oncoming shift inherits the live isolations, their owners, and their status as data, not as folklore.
This is the model Stowlog is built around. Isolation is governed as part of Stowlog's permit-to-work module, so the lockout that protects a maintenance crew is the same record that authorises their work, references the assessment behind it, and stands up in an audit, the way permit-controlled high-risk work at a port terminal is meant to run. LOTO does not fail because operators do not know the six steps. It fails in the space between crews, shifts, and paperwork, and that space is exactly where an energy-control procedure tied to the permit stops being a promise on a tag and starts being something you can prove.



