Incidents live under
/app/identification/*(incidents, triage, investigations).Workers can report through My ReFresh; admins can log incidents on their behalf.
A shareable reporting link supports both identified and anonymous worker reports.
Each incident has a code (for example,
INC-2026-0004), a type, a severity, and a lifecycle status.
The three ways an incident arrives
Path | Who uses it | Notes |
Worker report | Any worker, via | Identified or anonymous |
Admin on behalf | An admin logging an incident directly | Includes a Restrict Access option to limit who can see sensitive reports |
Public anonymous intake | Anyone, via a shareable link ( | CAPTCHA and consent; the reporter gets a key ( |
See Setting up anonymous incident reporting (admin) for producing and sharing the public link, Investigating an incident for what happens once an incident is substantiated, and the My ReFresh collection for the worker side.
Logging an incident as an admin
From the incidents list, start a new report. The form captures:
A short summary and a description of what happened.
Type: Complaint, Injury or Illness, Near Miss, or Something Else.
Severity: Insignificant, Minor, Moderate, Major, or Catastrophic.
Date, time, and location.
The people involved.
Whether a regulatory notification is required.
A Restrict Access option for sensitive reports.
Save the incident; it appears in the list in Reported status.
Sharing the reporting link
The Share Reporting Link button on the incidents page produces your organisation's public reporting link, which supports both identified and anonymous reporting. Share it in onboarding materials, posters in shared spaces, internal communications, and manager email signatures. For the full setup, including how the public form and Report Key work, see Setting up anonymous incident reporting (admin).
Triaging incidents
New incidents wait in the triage queue until an admin classifies and routes them. Triage runs as a three-step wizard: Review and Classify, then Route and Assign, then Flag Actions and Complete. Only groups set up for incident handling can be assigned an incident, and the lead you pick is scoped to the assigned group, so choose the group first. See Triaging an incident for the full walkthrough.
Resolving an incident
When corrective work is done, the resolution flow runs as a six-step wizard: What Happened, Actions Taken, Link Resources, Risk Assessment(s), Controls, and Resolve. Linking risk assessments and controls is what lets their ratings and effectiveness be revisited off the back of the incident. See Resolving an incident for the full walkthrough.
Incident lifecycle
Status | Meaning |
Reported | Logged, not yet under active review |
Under Review | Being triaged and assessed |
Investigating | An investigation has started |
Resolved | Corrective actions complete; ready to close |
Closed | Formally closed; record retained for the audit trail |
