SiliciumHex FieldKit

Problem Solving & Quality · Contain

First-Hour Incident Protocol

A fixed sequence for the first hour: make safe, stop the spread, preserve evidence, inform, appoint a leader. Thinking comes after.

  • Time1 h
  • FormatTeam
  • StageContain

First-Hour Incident Protocol: what it is and why it works

The First-Hour Incident Protocol is a fixed, pre-agreed sequence for the opening minutes of an incident: make safe, stop the spread, preserve evidence, inform, and appoint one incident leader who opens a log. It applies to quality escapes, process upsets, equipment failures and spills. The order matters: people and the environment come first, then limiting the damage, then protecting the information the investigation will need, then bringing in the right people, all under a single point of command.

It works because stress degrades judgment. Without a protocol, the first hour tends to produce conflicting instructions, a cleaned-up scene and a customer who hears about the problem from someone else. A short, rehearsed sequence frees attention for the few decisions that actually require thought. The protocol does not replace the site emergency response plan, lockout/tagout or permit rules; it sits alongside them and always defers to them. After the first hour it hands over to more specific tools: immediate containment and suspect lot quarantine for product, evidence preservation for failure analysis, and andon escalation rules for the everyday abnormalities that should never grow into incidents.

What you need

  • The site emergency response plan and safety procedures: isolation, permits, spill response
  • A predefined call list with numbers by role and by shift
  • Printed protocol cards at control rooms and workstations
  • An incident log template, on paper or electronic
  • An evidence kit: tags, bags, sample bottles, camera, markers

What you get

  • A safe, stabilized situation
  • A stop or diversion point for suspect product
  • Preserved samples, parts and exported data
  • A time-stamped log of facts and decisions
  • A named incident leader and informed stakeholders

When to use it

When an incident hits and everyone improvises in a different direction.

How to do it, step by step

  1. Make safe: protect people and environment first — isolate energy, stop the flow, set the perimeter.
  2. Stop the spread: halt the process or divert product so that no more suspect output is made or shipped.
  3. Preserve evidence: freeze the scene, keep parts and samples, save control-system data.
  4. Inform: call the predefined list — supervisor, quality, HSE, customer contact if product has left.
  5. Appoint one incident leader and open a log with times, facts and decisions.

Worked example: Analyzer alarm on a food-grade acid line

Illustrative scenario — figures are realistic but not from a real company.

At 2:40 a.m., the in-line quality analyzer on a food-grade phosphoric acid packaging line alarms high. Two tote-filling stations are running, and a bulk tanker left the site three hours earlier. The night shift has four operators and a supervisor.

  1. Make safe: the operator confirmed there was no leak or exposure, then followed the standard procedure to close the product valve to filling; the board operator confirmed the process was stable.
  2. Stop the spread: filling stopped, totes filled since the last good lab sample were moved to a roped-off area, and product was recirculated to the rundown tank.
  3. Preserve evidence: the supervisor had the analyzer trends and batch record exported, and retained samples from the tank and the last three totes, each labeled with the time.
  4. Inform: the call card listed the quality on-call and the plant manager and, because a tanker had already left, the customer-service on-call, who contacted the carrier.
  5. Leader and log: the shift supervisor was named incident leader at 2:52 a.m. and opened the log; every call and decision was time-stamped.

Result. The tanker was held at the customer's gate pending results. Lab analysis at 6 a.m. showed the analyzer had drifted and the product met specification, so the tanker was released. The log let the day team review the event in 20 minutes, and the review added an analyzer cross-check step to the protocol card. The hold cost far less than shipping suspect acid would have.

Common pitfalls and how to avoid them

  • Starting to investigate before the situation is safe.Follow the order on the card; analysis waits until people, the environment and product are protected.
  • Several people giving orders at once.Name one incident leader within minutes and route decisions through that person.
  • Cleaning up or restarting to 'get back to normal'.Freeze the scene and export data first; restart only when the leader confirms evidence is secured and all safety conditions and permits are met.
  • An out-of-date call list.Review the list monthly and after every staffing change, and test it with a short drill each quarter.

Frequently asked questions

What should you do in the first hour of a quality incident?

Make the situation safe, stop more suspect product from being made or shipped, preserve samples and data, inform the people on your predefined list, and appoint one person to lead and keep a log. Analysis of causes comes after these steps. The exact actions depend on your site's emergency and quality procedures, which always take precedence over any generic protocol.

Who should be the incident leader?

Usually the most senior person on shift who knows the process, often the shift supervisor, until someone better placed takes over through an explicit handover recorded in the log. The leader coordinates and decides; they should not also be doing hands-on recovery work. What matters most is that there is exactly one leader and that everyone knows who it is.

How is a first-hour protocol different from an emergency response plan?

An emergency response plan covers fires, releases, injuries and evacuations and is driven by safety regulations. The first-hour protocol is broader and lighter: it also covers quality escapes and equipment failures that are not emergencies. For any safety event, the emergency plan leads, and the protocol's evidence, information and logging steps support it.

Origin

SiliciumHex original, drawing on common incident-response practice (make safe, contain, preserve, inform).

Used in these playbooks

Quality alert: the first 24 hours 1 day

One day to take control of a fresh incident: make safe, protect the customer, block every suspect lot, keep the evidence intact and pin down where the problem is — and is not.

  1. First-Hour Incident Protocol
  2. Immediate Containment Actions
  3. Suspect Lot Quarantine
  4. Evidence Preservation
  5. Is / Is-Not Analysis

Related methods

More in “Contain”

Protect people, the environment and the customer while the real fix is found.