Skip to main content

Reporting an incident

Incidents capture events that have happened, including reports your workers submit through My ReFresh. As an admin you can log incidents directly, triage what comes in, and drive each one through to resolution.

Written by Taylor Laing
  • Incidents live under /app/identification/* (incidents, triage, investigations).

  • Workers can report through My ReFresh; admins can log incidents on their behalf.

  • A shareable reporting link supports both identified and anonymous worker reports.

  • Each incident has a code (for example, INC-2026-0004), a type, a severity, and a lifecycle status.

The three ways an incident arrives

Path

Who uses it

Notes

Worker report

Any worker, via /portal/incidents/report

Identified or anonymous

Admin on behalf

An admin logging an incident directly

Includes a Restrict Access option to limit who can see sensitive reports

Public anonymous intake

Anyone, via a shareable link (/report/[slug])

CAPTCHA and consent; the reporter gets a key (RPT-XXXXXXXX) and optional password to check status at /report/status

See Setting up anonymous incident reporting (admin) for producing and sharing the public link, Investigating an incident for what happens once an incident is substantiated, and the My ReFresh collection for the worker side.

Logging an incident as an admin

From the incidents list, start a new report. The form captures:

  • A short summary and a description of what happened.

  • Type: Complaint, Injury or Illness, Near Miss, or Something Else.

  • Severity: Insignificant, Minor, Moderate, Major, or Catastrophic.

  • Date, time, and location.

  • The people involved.

  • Whether a regulatory notification is required.

  • A Restrict Access option for sensitive reports.

Save the incident; it appears in the list in Reported status.

Sharing the reporting link

The Share Reporting Link button on the incidents page produces your organisation's public reporting link, which supports both identified and anonymous reporting. Share it in onboarding materials, posters in shared spaces, internal communications, and manager email signatures. For the full setup, including how the public form and Report Key work, see Setting up anonymous incident reporting (admin).

Triaging incidents

New incidents wait in the triage queue until an admin classifies and routes them. Triage runs as a three-step wizard: Review and Classify, then Route and Assign, then Flag Actions and Complete. Only groups set up for incident handling can be assigned an incident, and the lead you pick is scoped to the assigned group, so choose the group first. See Triaging an incident for the full walkthrough.

Resolving an incident

When corrective work is done, the resolution flow runs as a six-step wizard: What Happened, Actions Taken, Link Resources, Risk Assessment(s), Controls, and Resolve. Linking risk assessments and controls is what lets their ratings and effectiveness be revisited off the back of the incident. See Resolving an incident for the full walkthrough.

Incident lifecycle

Status

Meaning

Reported

Logged, not yet under active review

Under Review

Being triaged and assessed

Investigating

An investigation has started

Resolved

Corrective actions complete; ready to close

Closed

Formally closed; record retained for the audit trail

Did this answer your question?