top of page

Muster Integrity: Are Your Missing Person Lists Actually Reliable?

Sep 13
16 min read

A muster procedure can look complete on paper and still fail the one question that matters during an emergency.


Who is actually missing?


That question drives rescue priorities, incident command decisions, fire team deployment, shutdown choices, and communications with families and regulators. It also decides whether responders enter a hazardous area for a real casualty, a paperwork error, or a person who left site an hour ago without swiping out.


OSHA’s emergency action plan requirements expect employers to have procedures to account for employees after evacuation. Offshore, marine, construction, mining, energy, utilities, and process operations often go further, using personnel-on-board systems, access control, muster cards, radio checks, roll calls, evacuation wardens, and electronic badging.


The gap is not the lack of a procedure. The gap is muster integrity.


Muster integrity is the confidence that the missing-person list reflects reality during a degraded, fast-moving emergency. It means the organization does not simply know who should be on site. It knows who is on site, where they were likely working, which muster point they reached, who may have bypassed the normal route, and which names on the exception list are data errors rather than casualties.


Wide-angle view of workers moving toward an outdoor muster point at an industrial site
A procedure is only useful if the headcount reflects the real population at risk.

Procedures Do Not Prove Accountability


Most high-risk sites can produce a muster procedure. Many can produce several. One for employees. One for contractors. One for visitors. One for marine transfer. One for shift change. One for confined-space rescue. One for emergency evacuation. One for security incidents.


The problem is that procedures often describe the intended flow of people. Emergencies reveal the actual flow.


In real operations, people move in ways the procedure does not fully capture.


A scaffolding crew starts early under a permit issued by another department. A vendor driver enters through a logistics gate and waits near a tank farm. A regulator arrives with a host but does not receive a badge because the visit is “short.” A marine technician transfers from a crew boat and goes directly to a package unit. A supervisor leaves the main plant to check a remote pump station. A contractor uses another person’s badge because access permissions were not set up in time. A nightshift worker remains in a workshop to secure hot work equipment after the alarm sounds.


None of this is unusual. It is normal work.


Human factors research has long shown that the gap between “work as imagined” and “work as done” becomes critical under time pressure, uncertainty, and degraded communication. Resilience engineering, including work by researchers such as Erik Hollnagel, David Woods, and Sidney Dekker, frames this as a system issue rather than a simple compliance issue. Procedures are necessary, but they rarely describe every adaptation people make to keep work moving.


Muster systems often fail because they are built around a clean site population:


  • Employees assigned to a known department

  • Contractors entered in advance

  • Visitors escorted and logged

  • Everyone badged in through one gate

  • Everyone evacuating to the assigned muster point

  • Communications working

  • Supervisors present with current rosters

  • No one moving between areas during the alarm


High-risk sites rarely operate like that.


OSHA’s standard for emergency action plans, 29 CFR 1910.38, requires procedures to account for employees after evacuation. That requirement is sound. It does not prescribe exactly how a complex site should maintain personnel accountability across nested contractor chains, mobile work groups, badge errors, marine transfers, or remote assets. That is where management systems and operational discipline matter.


A muster procedure answers, “What should happen?”


Muster integrity answers, “How do we know it happened, and how wrong could we be?”


The Missing-Person List Is a Safety-Critical Data Product


During an emergency, the missing-person list becomes safety-critical information.


It influences whether emergency teams search process units, accommodation blocks, substations, cargo holds, tunnels, cranes, excavations, laydown yards, workshops, and temporary facilities. It affects defensive versus offensive firefighting. It shapes rescue risk acceptance. It can redirect security, medical, and operations teams away from other urgent tasks.


A false negative is dangerous. That means a person is missing but does not appear on the list.


A false positive is also dangerous. That means a person appears missing but is safe elsewhere, off site, at another muster point, or never arrived.


Both failure modes matter.


A false negative can delay rescue or lead incident command to assume an area is clear. A false positive can send responders into smoke, fire, unstable structures, electrical hazards, chemical releases, or blast zones for someone who is not there.


The U.S. Chemical Safety and Hazard Investigation Board has repeatedly emphasized emergency planning, site control, communication, and pre-incident coordination in its investigation reports. The details vary by incident, but the theme is consistent. During high-consequence events, responders need accurate information about people, hazards, site layout, and changing conditions.


The National Transportation Safety Board and aviation regulators treat passenger and crew accountability as a core emergency response need. Maritime and offshore operations have similar expectations through passenger manifests, crew lists, station bills, and personnel-on-board controls. These systems exist because emergency response depends on reliable counts, not estimates.


The same logic applies inside a refinery, wind farm, mine, tunneling project, power station, shipyard, LNG facility, or large construction site.


The list is not an administrative artifact. It is an input to life-risk decisions.


Where Muster Integrity Breaks Down


The largest accountability failures usually come from ordinary weak points that were tolerated before the emergency.


They are not always dramatic. They often look like small exceptions.


Contractors And Subcontractors Create Moving Populations


Contractor-heavy sites have dynamic populations. Turnaround, outage, commissioning, construction, demolition, drilling, maintenance, and marine campaigns can multiply the number of people on site. The work changes daily. Crews split. Subcontractors bring additional specialists. Vendor technicians arrive for short tasks. People move between units as priorities change.


The access-control database may show that a contracting company is on site. It may not show the actual person, supervisor, work location, vehicle, or planned task. If contractor onboarding is handled separately from permit-to-work planning, the muster system may not know where the crew is expected to be.


Common failure modes include:


  • Contractor rosters uploaded before the shift, then changed in the field

  • Short-notice specialists admitted under another company’s booking

  • Supervisors holding paper sign-in sheets that never reach incident command

  • Multiple subcontractor layers without a single accountable lead

  • People badged into site but transported to remote work fronts with no location update

  • Contractors remaining after normal hours to finish work


The risk increases when the host organization treats contractor headcount as a procurement or security matter rather than a life-safety matter.


A practical test is simple. During a drill, select three contractors at random from different companies. Ask the incident management team where each person was assigned to work, who supervised them, and which muster point they should report to. If the answer takes more than a few minutes, the system is not giving emergency leaders the visibility they need.


Visitors And Delivery Drivers Fall Between Systems


Visitors are often accounted for through reception, host escort, visitor badges, or paper logs. Delivery drivers may enter through a logistics gate, guard shack, warehouse entrance, marine terminal, or construction access road. They may not attend site induction. They may stay with the vehicle. They may use restrooms, loading areas, weighbridges, marine offices, or laydown yards that sit outside normal evacuation zones.


These populations are easy to miss because they are transient and often peripheral to production. During an emergency, they still become persons at risk.


Delivery operations create several exposure scenarios:


  • A driver parks near hazardous inventory while waiting for offload

  • A courier enters a building during a gas alarm

  • A bulk chemical driver connects hoses under supervision, then the supervisor leaves

  • A marine supply driver moves between the quay and warehouse

  • A waste contractor attends multiple collection points in one visit


If the driver signs a delivery ticket but never signs into the personnel system, incident command may have no reliable record. If the driver signs into security but leaves through another gate, the missing-person list may show a false positive.


The fix is not to bury drivers in long induction processes for a ten-minute delivery. The fix is to define proportionate controls that still preserve accountability. That can include logistics gate registration, vehicle identifiers linked to driver names, geofenced access, escort accountability, radio contact at loading points, and clear exit confirmation.


Marine Personnel And Transfer Points Add Complexity


Ports, offshore installations, vessels, terminals, shipyards, and nearshore construction projects have additional accountability problems. People may move across interfaces controlled by different organizations. A terminal controls the jetty. A vessel master controls the vessel. A contractor controls a work party. A marine coordinator controls transfers. Security controls gate access.


The personnel-on-board number can drift when systems do not reconcile.


Examples include:


  • Technicians transferring from a vessel to an offshore facility

  • Vessel crew going ashore at a terminal for operational tasks

  • Terminal personnel boarding a ship during cargo operations

  • Shipyard workers moving across multiple vessels

  • Marine pilots, inspectors, surveyors, and regulators attending for short durations

  • Crew changes during partial shutdowns or bad weather windows


Marine and offshore industries use station bills, muster lists, passenger manifests, transit logs, and POB systems because abandonment, rescue, and evacuation depend on accurate numbers. The International Maritime Organization’s safety management expectations, offshore regulator guidance, and industry practice all treat emergency preparedness as a managed system, not a binder exercise.


The hard part sits at the interface. If a person crosses from one duty holder’s control to another, the accountability handoff must be explicit. A radio call is useful. A digital transfer record is better. Both need a fallback when systems fail.


Eye-level view of a marine gangway checkpoint with workers transferring between a vessel and a quay
Transfer points need clear accountability handoffs between organizations.

Remote Workers Are Often Invisible During Alarms


Sites with utilities, pipelines, mining areas, renewable assets, rail interfaces, power distribution, water infrastructure, and large construction footprints often have workers outside normal plant areas. They may work alone or in pairs. They may be inside substations, valve stations, remote pump houses, excavations, control huts, laydown yards, temporary workshops, or mobile equipment.


The alarm may not be audible. Radio coverage may be poor. Mobile service may be weak. Badge systems may only show site entry, not location. Supervisors may assume the person is in the main unit.


Remote work breaks muster integrity because the normal image of evacuation does not apply. The safest action may be to shelter, drive to a satellite muster point, proceed to a gate, contact a controller, or stay clear of a hazardous plume.


The emergency plan must define how remote workers are located and accounted for. That includes expected check-in intervals, lone worker devices where appropriate, radio protocols, GPS or vehicle tracking where justified, and preplanned local muster points.


This is not just a technology question. It is a control philosophy question.


If remote workers are allowed to change task location without updating supervision or control, the organization is accepting a weaker missing-person list during emergencies.


Badge Sharing And Access Workarounds Corrupt The Dataset


Access-control systems are only as reliable as the behaviors and controls around them.


Badge sharing, tailgating, piggybacking, borrowed passes, inactive credentials, manual gate overrides, and “known person” exceptions all degrade accountability. These failures often grow from operational pressure. A permit starts late. A contractor is blocked at the gate. A visitor has no prebooking. A supervisor wants the job started. Security staff recognize the person and wave them through.


Each workaround looks small. Together, they change the meaning of a badge record.


If a badge-in event does not reliably represent a person entering site, then the access-control database cannot serve as the sole muster baseline. If a badge-out event is often missed, the same problem appears in reverse.


Security and HSE teams sometimes treat this as a rule-breaking problem. It is also a system design problem. If legitimate access is slow, confusing, or frequently wrong, people will develop informal fixes. The corrective action must address both enforcement and process design.


Strong sites test the integrity of access data. They compare:


  • Badge records against turnstile counts

  • Contractor rosters against permit crews

  • Vehicle logs against personnel entries

  • Marine transfer records against POB systems

  • Visitor logs against host confirmations

  • Emergency drill counts against access-control reports


If these sources do not reconcile in normal operation, they will not reconcile during an emergency.


Manual And Digital Muster Both Fail In Predictable Ways


The debate between paper roll calls and digital muster often misses the point. Both can work. Both can fail. The question is whether the total system gives incident command a reliable, timely, and explainable picture.


Method

Strengths

Common Failure Modes

Manual roll call

Simple, visible, low technical dependency, usable after power loss

Outdated rosters, slow consolidation, transcription errors, duplicate names, weak coverage of visitors and mobile workers

Badge-based digital muster

Fast comparison of badge-in and muster scans, useful exception reports

Corrupt baseline data, badge sharing, device or network failure, people without badges, wrong muster area scans

Supervisor headcount

Uses local knowledge of crews and work fronts

Depends on supervisor survival, presence, memory, and current knowledge of crew movements

Access-control POB

Useful starting population, supports security and site control

Shows entry rather than location, misses noncompliant movements, can lag or fail during power or network disruption

Permit-linked accountability

Connects people to tasks and areas

Only works if permits list actual workers and changes are updated in real time

Radio or phone check-in

Valuable for remote or mobile personnel

Coverage gaps, channel congestion, battery failure, unclear message discipline


Digital systems can improve speed and reduce administrative load. They can also create false confidence. A dashboard with clean colors and precise numbers can hide messy source data.


Manual systems can be resilient when technology fails. They can also collapse under scale. A large outage or construction project with thousands of workers cannot rely on supervisors shouting names across multiple muster points and passing handwritten lists to incident command without expecting delay and error.


The strongest approach is layered.


A reliable muster system uses independent data sources that can challenge each other. Access control gives the initial site population. Permit systems show anticipated work locations. Supervisors verify crew status. Muster point scanners or wardens confirm arrivals. Security confirms exits. Marine or transport coordinators confirm transfers. Control room operators track remote workers and shelter-in-place groups.


This is basic redundancy, but with a key condition. Redundancy only helps when sources are truly independent enough to catch each other’s errors.


If every system relies on the same inaccurate badge database, the organization has repetition, not redundancy.


The Most Important Question Is Confidence, Not Completion


After an evacuation, emergency leaders often ask, “Is muster complete?”


A better question is, “How confident are we that the missing-person list is correct?”


Those are different questions.


Completion can mean every muster point submitted a count. It can mean the digital system stopped showing unscanned names. It can mean supervisors reported all crews accounted for. None of those conditions proves that the source population was accurate.


Confidence requires an uncertainty check.


Incident command should know the quality of the data behind the list. For example:


  • Did the access-control system operate normally before the event?

  • Were any gates on manual override?

  • Were contractors admitted through temporary access points?

  • Were visitors or delivery drivers on site?

  • Was a crew transfer, shift change, or marine movement in progress?

  • Were remote workers active outside alarm coverage?

  • Did any muster point lose communications?

  • Did any area shelter in place rather than evacuate?

  • Did any workers move to a nonassigned muster point?

  • Were any supervisors unavailable to confirm their crews?

  • Are there duplicate identities, aliases, or badge mismatches in the report?


This uncertainty does not excuse delay. It helps incident command make better risk decisions.


In aviation, emergency response planning places high value on accurate passenger and crew information because families, search teams, and emergency managers need reliable data. In process safety, the same discipline should apply to people on site. Incident commanders need to know whether a missing name represents a likely casualty, a data problem, or an unresolved uncertainty.


A practical missing-person report should include confidence markers, not just names.


For each unresolved person, incident command should be able to see:


  • Last confirmed entry or transfer

  • Employer or host

  • Expected work area

  • Assigned supervisor or escort

  • Assigned muster point

  • Last known communication

  • Permit or task association

  • Vehicle or vessel association, if relevant

  • Possible alternate safe locations

  • Data concerns, such as badge exception or manual gate entry


This helps responders prioritize. A person last associated with hot work inside a unit affected by fire is different from a driver who likely left through an unmanned gate but has no badge-out record. Both require resolution, but not the same rescue risk.


Warning Signs That Muster Integrity Is Weak


Weak muster integrity usually leaves evidence before an emergency. The warning signs are visible in audits, drills, shift handovers, access records, and contractor management.


Watch for these patterns.


Drills Always End With A Clean Count


If every drill produces fast, perfect accountability, the drill may be too controlled. Real emergencies include visitors, toilets, remote work, shift relief, blocked routes, radios that fail, and people reporting to the wrong place.


Good drills inject friction. They test gate exceptions, lost communications, contractor crew changes, multiple muster areas, and a person who is safe but not where the system expects them.


Muster Counts Depend On One Person


If one supervisor, receptionist, security officer, or emergency coordinator holds the practical knowledge needed to reconcile the list, the system is fragile. That person may be off site, injured, overloaded, or assigned to another emergency role.


Temporary Access Becomes Normal Access


Temporary badges, manual sign-ins, gate overrides, escort exceptions, and “known contractor” admissions should be rare and monitored. If they become routine, the POB number is suspect.


Permit Rosters Do Not Match Crews


Permit-to-work systems can help accountability only if they show real workers. If permits list a company name rather than crew names, or if field changes never update the permit, the link between work location and person is weak.


Visitors Are Managed By Hosts, Not The System


Host accountability is useful. It is not enough when a visitor separates from the host, moves to another area, or exits without confirmation. The site needs a record that incident command can access without calling multiple people.


Multiple Muster Areas Do Not Reconcile Quickly


Large sites often need several muster areas. That is sound. The risk appears when each point uses a different method, different roster, or different communication route. Incident command then receives fragments rather than a single accountable picture.


The Access System Is Treated As Truth


Access control is evidence. It is not truth. A mature organization knows its access-control error modes and tests them.


Actions That Improve Muster Integrity


Better muster integrity comes from designing accountability as an operational control. It should connect HSE, security, operations, contractors, emergency response, HR, marine logistics, and project controls.


Define The Master Population Source


Decide which system creates the official emergency population at any given time. It may be access control, a POB system, a project workforce system, or a combined emergency management platform.


Then define how other data sources update or challenge it.


For example, a refinery may use access control as the starting point, permit rosters as work-area context, visitor logs for hosted personnel, logistics gate records for drivers, and emergency scanners for muster confirmation. An offshore installation may use POB as the master, with helicopter manifests, vessel transfer logs, bed allocation, and control room check-ins as supporting evidence.


The key is ownership. Someone must own data quality before the alarm sounds.


Link People To Work Locations


A list of names is helpful. A list of names with likely locations is far better.


Permit-to-work, job planning, isolation control, confined-space entry, lifting plans, vehicle dispatch, and marine transfer records can all provide location context. This does not require tracking every footstep. It requires enough information to guide emergency decisions.


For high-risk tasks, the emergency system should know who is assigned, where they are working, who is supervising, and what special hazards may affect rescue.


Control Exceptions Instead Of Hiding Them


Every site needs exception handling. Deliveries arrive late. Regulators visit with little notice. A badge fails. A crew changes. A vessel transfer is delayed.


The issue is whether exceptions are visible.


Build a process that captures exceptions quickly and flags them for emergency use. A manual gate entry should not disappear into a paper log. A temporary badge should link to a real identity, host, company, and expiration time. A driver should link to a vehicle and destination. A visitor should link to a host and expected exit.


Exception data should be easy to enter and hard to ignore.


Design For Communications Failure


Emergency accountability must survive degraded conditions. Power may fail. Networks may slow. Radios may congest. Muster points may relocate. Smoke, weather, security threats, or floodwater may block routes.


This calls for fallback modes:


  • Printed current rosters at muster points, with controlled update times

  • Battery-backed muster devices

  • Radio protocols for count reports and missing-person names

  • Satellite or alternate communications for remote assets where justified

  • Predefined runners or message routes if electronic systems fail

  • Manual forms that match digital fields

  • Clear authority to establish alternate muster areas


The fallback must be practiced. A paper roster sealed in a cabinet is not a fallback if no one knows when it was printed or how to reconcile it.


Run Drills That Test The Data, Not Just The Movement


Many drills test evacuation time and alarm response. Fewer test the reliability of the missing-person list.


Drills should include data challenges:


  • A contractor who changed crews after the roster was issued

  • A visitor who arrived through a secondary gate

  • A delivery driver at a loading area

  • A remote worker outside normal alarm coverage

  • A person who reports to the wrong muster area

  • A badge reader failure at one muster point

  • A marine transfer in progress

  • A supervisor unavailable for crew confirmation


The exercise objective should be explicit. Can incident command produce a correct missing-person list, with confidence level and last known location, within the required decision window?


After-action reviews should separate movement issues from data issues. If the count was late, identify why. Was the baseline wrong? Were names duplicated? Did communications fail? Did one muster point use outdated rosters? Did contractors update their crew list? Did remote workers know the check-in protocol?


Audit Normal Operations For Emergency Reliability


Muster integrity is built on normal operating discipline.


Useful assurance activities include:


  • Comparing badge-in records with people physically present in selected areas

  • Sampling contractor rosters against permit crews

  • Checking visitor logs against host records and access data

  • Reconciling delivery gate logs with warehouse or loading records

  • Testing badge sharing controls and tailgating prevention

  • Verifying that temporary badges expire and link to real identities

  • Reviewing remote worker check-in compliance

  • Confirming that multiple muster points use the same naming and reporting rules

  • Testing system recovery after network or power loss


These checks do not need to be heavy. They need to be routine, documented, and acted upon.


Leadership Questions Worth Asking Before The Next Alarm


Senior leaders do not need to know every field in the muster database. They do need to know whether the system can support emergency decisions.


Ask direct questions.


  • What is our official source of personnel-on-board information?

  • How often is it wrong during normal operations?

  • Which groups are most likely to be missing from the system?

  • How do we account for contractors, subcontractors, visitors, drivers, marine personnel, and remote workers?

  • What happens if the access-control system fails?

  • What happens if a person reports to the wrong muster point?

  • Can we identify the likely work location of each missing person?

  • How do we know someone has left site if they did not badge out?

  • Which gates or transfer points use manual processes?

  • Have we tested muster during shift change, outage peaks, night work, severe weather, and communications loss?

  • During the last drill, did we test the missing-person list or only the headcount?


The best answer is not “we have a procedure.” The best answer explains the data sources, error modes, checks, fallback methods, and recent test results.


That is what reliable muster integrity looks like.


Professional Takeaway


Muster procedures matter, but they are only the visible layer. The real control is the integrity of the population data, movement information, confirmation process, and exception handling behind the procedure.


During an emergency, leaders do not need a neat report. They need a defensible answer to a hard operational question.


How confident are we that the missing-person list is correct?


If that confidence is weak, emergency teams may search the wrong place, miss the right place, or accept rescue risk based on bad data. Treat muster integrity as a safety-critical system. Test it under messy conditions. Reconcile the sources. Make exceptions visible. Build fallback methods that work without perfect technology.


The time to find the errors is during normal work, not when someone is unaccounted for.


Professional References And Further Reading


  • OSHA, 29 CFR 1910.38, Emergency Action Plans Requirements for emergency action plans, including procedures to account for employees after evacuation.


  • OSHA, 29 CFR 1910.119, Process Safety Management Of Highly Hazardous Chemicals Relevant for emergency planning interfaces in covered process facilities.


  • U.S. Chemical Safety And Hazard Investigation Board Investigation reports and safety videos addressing emergency response, site control, hazardous conditions, and incident command lessons in chemical and process industries.


  • UK Health And Safety Executive Guidance and regulatory material on emergency planning, offshore safety, human factors, contractor management, and major hazard control.


  • ISO 45001, Occupational Health And Safety Management Systems Framework for managing OH&S risks, emergency preparedness, operational control, contractor control, and continual improvement.


  • ISO 22320, Security And Resilience Emergency Management Guidelines For Incident Management Guidance on incident management, command, coordination, information management, and operational decision support.


  • International Association Of Oil And Gas Producers Industry guidance and recommended practices on emergency response, contractor management, offshore operations, and personnel safety.


  • Human Factors And Resilience Engineering Literature Work by Erik Hollnagel, David Woods, Sidney Dekker, James Reason, and related researchers on work as done, system defenses, organizational reliability, and decision-making under uncertainty.


bottom of page