All work

Offshore oil & gas · Client prototype

Two weeks,
from a meeting
to a platform.

A compliance client asked what we could do for the people on their rigs. We showed them a working system a fortnight later. This page is really about how fast we can build.

Why we built it

We sat down with their team. They make compliance software for offshore oil and gas, and everything they had solved was about equipment — valves, sensors, shutdown devices, the things that get tested and logged.

The people were the gap. Every crew member on a platform carries a stack of certifications with expiry dates, and somebody has to know, today, which ones are about to lapse, who needs a class booked, and who is not allowed on the next crew change.

They asked to see a demo of that. So the real question was never whether we understood offshore compliance. It was how much we could stand up before the next meeting.

What we decided to do

Not a clickable picture of a product. A working one.

Anyone can put screenshots in a slide. We built both halves of the real thing — what the compliance officer sees and what a crew member sees — sharing one engine and one set of real regulatory data, running on the actual calendar. Every date in it is computed from today, so it never goes stale.

Then we went past the brief and built the equipment side too, because the interesting problem was there: a safety device on a platform runs on two clocks at once. A calendar interval, and a hard ceiling on the days between tests. Miss the first and it is a warning. Miss the second and the component gets shut in.

A prototype on real data and an invented crew. Nothing you do leaves your browser.

What's inside

Two apps for two different jobs, built on one engine, plus a reader for the safety charts the whole thing depends on. The officer sees the whole platform; the crew member sees only their own record and their own areas.

  1. The officer's side
  2. 01The facility calendarWorking, in the demo
  3. 02The rosterWorking, in the demo
  4. 03The inbox and the confirm loopWorking, in the demo
  5. 04Tests — one test, the whole crewWorking, in the demo
  6. 05SAM, the assistantWorking, in the demo
  7. 06Equipment — the two clocksWorking, in the demo
  8. The crew member's side
  9. 07The front doorWorking, in the demo
  10. 08Your own calendarWorking, in the demo
  11. 09RoundsWorking, in the demo
  12. 10MessagesWorking, in the demo
  13. The chart reader
  14. 11Reading a SAFE chartWorking, partly shown

The officer's side

One person responsible for twelve people and twenty-eight devices on a platform in the Gulf. Six screens.

01

The facility calendar

Working · in the demo

Why

The officer's real question every morning is "who is about to lapse?" — and the answer is scattered across twelve personnel files and a spreadsheet somebody else keeps.

What it does

It opens on one month of the whole platform. Every coloured chip is one person's certification, on the day it expires. Colour is how urgent; the icon is what kind. Booked classes and test days sit on the same grid. A day with more than it can show folds into "+N more".

Under the grid, Up next: five cards, each naming a person and the thing that is due, each with one action — book it, message them, or confirm it is done.

A Guide panel alongside decodes the chips for anyone new, and collapses to a rail once they are not.

Look for: today's date carries a "Team test" chip with a live count — 3 of 12 have taken it. That number is the Tests screen, showing through.

02

The roster

Working · in the demo

Why

A calendar tells you what is coming. It does not tell you who is the problem.

What it does

Every crew member, ranked worst-first. The person with the most past-due items is at the top, always. Open anyone and you get their full record — every requirement their position owes, when they last did it, and when it is due again.

A Visualize panel turns the roster into two charts and four honest counts: Past due · No record · Needs booking · Fully current. "No record" is its own category on purpose — a certification nobody has entered is not the same as one that has expired, and treating them alike is how platforms get false confidence.

03

The inbox and the confirm loop

Working · in the demo

Why

The gap between "I did my H2S refresher" said in a hallway and the record actually being updated is where compliance goes to die. Somebody has to hear it, believe it, and type it in.

What it does

Every crew member has a thread with the officer. When a crew member reports a certification done from their own phone, the thread on the officer's side shows a "Needs confirmation" banner and a single button: Confirm completion. One tap updates the record, recomputes their calendar, and the crew member sees it on their side across a reload.

The officer can also send a scheduling card — a class, a date — that the crew member books with one tap on their end.

Look for: the unread badge on the Inbox tab. Open the thread behind it and confirm what is waiting.

04

Tests — one test, the whole crew

Working · in the demo

Why

Knowing the rules is a requirement too. An officer needs to prove the crew was tested on lockout, on confined space, on hot work — and to do it without pulling twelve people off shift on twelve different days.

What it does

The Tests screen lists every team test, upcoming and past, with live pass and fail counts as results come in.

Building one is the officer's job and the tool keeps it honest. The Test Builder draws from a bank of 43 written questions across three topics — Lockout / Tagout, Confined Space Entry, Hot Work. The officer goes question by question and either approves it or hits Redraft, which swaps in an alternate written for the same point. Nothing is generated on the fly; every question a crew member sees was written and approved by a person.

Then the officer sets a pass mark and picks the single day the whole crew takes it. The test lands on every crew member's calendar and on the facility calendar as one chip, with the count ticking up as people finish. On the crew side, SAM will run practice questions before the day.

Look for: "Lockout / Tagout Knowledge Check", pass mark 70, assigned to all twelve, 3 of 12 taken. Open the builder and redraft a question.

05

SAM, the assistant

Working · in the demo

Why

The officer does not want to browse. They want to ask "who hasn't booked?" and get a list.

What it does

SAM answers six standing questions — Who hasn't booked? Who's past due? What's on the calendar this month? and three more — and can draft a message to a named crew member in one tap.

SAM is not a language model. It computes every answer from the same engine that draws the calendar, which is why it is never wrong about a date and never invents a person. The client's rule was that this had to feel like their system, not like a chatbot bolted on — so it does.

06

Equipment — the two clocks

Working · in the demo

Why

This is the part that was not in the brief, and the part the regulation is actually about. A safety device on a production platform must be function-tested on a schedule — and the rule has two parts. A calendar interval, and a ceiling on the number of days between tests. Blow through the ceiling and the exposure is not a warning any more; it is a component shut-in.

What it does

All 28 safety devices across the platform's four areas, bucketed by how late their test is: past the ceiling, overdue, due this week, due this month, current. Filter by area. Open any device and the record says, in plain words, which clock it is on and what that means — and cites the regulation underneath.

"Past the 6-week ceiling — component shut-in exposure."What the record says on the red row. Then: "Per 30 CFR 250.880."

Thirteen device types are modelled to API RP 14C, each with its own test procedure and pass band. The two ceilings that matter most — once a calendar month not to exceed six weeks, and every three months not to exceed 120 days — are taken straight from the rule.

Look for: open Equipment and tap the red row at the top. That sheet is the whole thesis of the product in one screen.

The crew member's side

The same engine, seen by one person who wants to know: am I clear this month, and what do I have to do today? Eight screens; four worth walking.

07

The front door

Working · in the demo

Why

A crew member's certifications live in their wallet, their email and their memory. The system has to start from what they know, not from what a database assumes.

What it does

"Welcome to Bayou Star. Get started." Then a short wizard: your first name, your position, and when you last completed each thing your position owes. Your calendar is built from those answers. What the worker says is the source of truth — the system never assumes you are compliant because a record says so somewhere else.

Twelve positions, thirty-one rules for which position owes which requirement, twenty requirements in all.

08

Your own calendar

Working · in the demo

Why

"Am I clear this month?" should take one glance.

What it does

Your own certifications on a month, week or day view, with an Up next card on top. A red chip means it needs booking; it turns blue once a class is scheduled. Ask SAM "What's overdue?" or "Am I clear this month?" and it answers from your record.

The demo crew member is a production operator whose Confined Space Entry lapsed twelve days ago, whose H2S is due in nine, and whose Site Orientation is due in fifteen with a class already booked. That story holds on whatever day you open it, because every date is an offset from today.

09

Rounds

Working · in the demo

Why

Testing a device is a walk across a platform with a clipboard, in an order that only makes sense if you know the platform.

What it does

"Start rounds — 6 tests." It walks you device by device, in the physical order you would actually walk the platform, shows you how to test each one, takes the reading, and flags an out-of-tolerance result while you are standing there — set point 250 psi, plus or minus five percent, pass band 237.5 to 262.5. A result recorded here updates the officer's Equipment screen.

You only see the devices in your own areas: eighteen of the twenty-eight.

10

Messages

Working · in the demo

Why

The other end of the officer's inbox.

What it does

Your thread with the compliance officer. A scheduling card arrives; you book it with one tap. You mark a certification complete; the officer confirms it; your calendar updates. Nothing to chase.

The chart reader

11

Reading a SAFE chart

Working · partly shown

Why

Everything on the equipment side depends on knowing which safety devices a platform actually has. That inventory lives on SAFE charts — dense, scanned engineering tables, one row per component — and getting it into a system means somebody transcribes it by hand.

What it does

Upload the chart as a PDF. The page is turned into an image in your browser, a model transcribes the device entries on it, and a person confirms or corrects every single value before it counts. Corrections are kept alongside the original, forever, so a reviewer can always see what the model read and what a human changed.

The hard part is a rule most people get wrong: a row on a SAFE chart is not a device. A row can mean a device was deliberately not installed, with a reference to the analysis that justifies leaving it out. Read that as equipment and you create records for things that do not exist; read it as a gap and you raise a false finding on nearly every component. The reader works that out from the transcription itself, on every read, and never asks the model to guess it.

What the demo shows: the door. The reader is behind an access token because it stores real documents, so a visitor sees the gate and the disclosure and nothing behind them. The database and file store behind it are live.

Under the hood

What that fortnight contained

Officer app
6 screens
Crew app
8 screens
Requirements
20, each with a real
citation and interval
Crew & positions
12 people, 12 positions,
31 assignment rules
Devices modelled
28 across 4 areas
API RP 14C codes
13, each with its own
test procedure
Question bank
43 across 3 topics
Built with
React 19, Vite, TypeScript
Runs on
Cloudflare Workers,
D1 database, R2 storage
Every date
Computed from today
Lines of code
about 55,000

Every number is measured from the codebase. The officer and crew apps keep their state in the browser — nothing you do leaves your device. The chart reader is the one part with a live database behind it.

What to look for

It opens on a month of a whole platform's crew. Every chip is one person's certification on the day it expires. Colour is urgency, icon is kind.

Then open Equipment and tap the red row at the top. Past its six-week ceiling, component shut-in exposure, regulation cited.

Then Tests: the Lockout / Tagout check, 3 of 12 taken. Open the builder.

Then open the crew member's side and see the same platform from one person's seat.

A prototype built for a client, on a development URL. Never released. The client is not named here; the platform, the operator and all twelve crew members are invented.

NextSelvático