Back to blog
Product · 26 May 2026 · 6 min read

The Six-Check Right-to-Work Gate

Every contractor sign-in runs six independent checks and returns PASS, BLOCK or WARN — with a reason. A walk through the gate, the cascade, and why every decision is explainable.

Om Acharya
Om Acharya
Support Engineer

A maintenance electrician taps their phone at the site gate at 6:52 a.m. In the time it takes the screen to refresh, six separate questions get asked and answered about whether this specific person is allowed to start work today. They don’t see the questions. They see one of three words: PASS, BLOCK or WARN. If it’s a block, they also see exactly why.

That moment — the tap at the gate — is where Lattice Look Contractor Management turns a folder full of procurement-time paperwork into a live decision about the person physically standing in front of you. This post walks through the six checks behind it, the cascade that fires when a company lapses, and why every one of those decisions has to be explainable.

Why a gate, and not a checklist

Contractor vetting traditionally happens once, at procurement, in a folder. Someone confirms the company’s insurance, files a few licences, and the contract is signed. Then the folder ages. Certifications expire. Insurance lapses on renewal day. The person who actually turns up on a Tuesday in March isn’t always the person who was vetted in the contract.

The gate exists because the relevant question isn’t “did this company pass our vetting last year.” It’s “is this worker, from this company, allowed to work on this site, right now.” That question can only be answered at the moment of sign-in, against current data. So that’s where we ask it.

The six checks

Each sign-in evaluates six independent conditions. They run together, but they fail separately — which matters, because the reason a worker is blocked tells you what to fix.

  1. Company prequalification approved. The contractor’s company has completed prequalification and that approval is currently in force — not lapsed, not suspended.
  2. Company insurances current. Every required policy on the company’s insurance register — Public Liability, Professional Indemnity, and whatever else the site mandates — is in date. An expired Public Liability certificate is not a warning; it’s a block.
  3. Worker active and live. This is a real, active worker profile, not a deactivated, departed or duplicate record. The person at the gate maps to a profile we’re allowed to admit.
  4. Worker certifications current. The licences this work requires are present and in date: High Risk Work Licence (HRWL) for the relevant class, white card for general construction induction, trade qualifications. Each cert is tracked for currency and classified Green, Amber or Red.
  5. Induction complete. The worker has completed the inductions your site requires for the work they’re here to do — assessed against your organisation’s own competency requirements, not a generic checkbox. More on that in one matrix, two workforces.
  6. Geofence — on site. The check-in is happening inside the configured site radius. A sign-in from the car park down the road, or from home, doesn’t satisfy the gate.

The output is one of three states:

  • PASS — all six are satisfied. The worker is cleared to start.
  • BLOCK — at least one hard condition has failed. The worker cannot sign in, and the reason is named.
  • WARN — the worker is admitted, but something needs attention soon. An Amber certification approaching expiry is the canonical case: not lapsed yet, so not a block, but the supervisor and the worker both see it flagged.

The split between BLOCK and WARN is deliberate. A platform that blocks on everything teaches people to find ways around it; a platform that warns on everything blocks nothing in practice. Hard failures stop work. Soft ones surface early, while there’s still time to renew.

The cascade

The six checks aren’t a flat list of unrelated boxes. Two of them — company prequalification and company insurances — sit above the worker. When something breaks at the company level, it cascades down to every worker linked to that company, automatically.

The clearest example is a lapsed insurance policy. A contractor’s Public Liability certificate has an expiry date sitting in the insurance register. On the morning that date passes:

  • The company’s insurances-current check fails.
  • That failure suspends the company’s prequalification — the prequalification check now fails too.
  • Every worker linked to that company is blocked at the gate, because a worker can’t out-qualify their own employer’s lapsed cover.

Nobody had to notice. Nobody had to send an email, walk a list of names, or update a spreadsheet. One expiry date drove the whole cascade, and twelve workers who would otherwise have signed in at 7 a.m. are held at the gate with a specific, accurate reason until the company’s cover is reinstated. When the renewed certificate is loaded, the cascade reverses just as cleanly and they’re cleared again.

This is the part that’s genuinely hard to do on paper. A folder doesn’t suspend itself. A register that knows the relationship between a company, its policies, and its people does.

Why every block is explainable

A gate that says “no” without saying why is a gate people learn to resent and route around. So every BLOCK carries a plain-language reason: Public Liability insurance expired 24 May, or HRWL not current for this class, or site induction not completed. The worker sees it, the supervisor sees it, and it’s recorded.

This matters for more than user experience. When an automated system decides who can and can’t work, that decision should be reviewable by a person — and you can’t review a decision you can’t read. A reason that names the exact failed condition is one a supervisor can act on (renew the cert, reinstate the cover, complete the induction) and one a worker can fairly contest if it’s wrong. Opaque automated decisions are neither fair nor fixable. Explainable ones are both.

Every gate result — pass, block or warn, with its reason — is written to the immutable, tamper-evident audit trail. Months later you can show not just that a worker was admitted, but on what basis, against which current certifications, at what time, inside which geofence.

What the gate is really for

Under Australia’s model WHS laws, a PCBU’s duty of care toward people on its site is non-delegable. You can’t sign it over to the contractor’s company; the obligation to independently verify, monitor and document who is working on your site stays with you. We’ve made the full argument for that elsewhere — see your duty doesn’t stop at the gate.

The six-check gate is the mechanism that discharges that duty at the only moment it actually matters: the tap at 6:52 a.m., before any work has started. Six questions, asked against live data, answered in one of three words, every block explained, every decision recorded.

To see how the gate fits with geofenced check-in, the competency matrix and the sealed audit, start at Contractor Management. For how it sits inside the wider platform, see features and security.

contractors right-to-work access-control

Ready to see Lattice Look in action?

Five minutes to sign up. Free onboarding.