Root Cause Workbench

Three levels of incident investigation. One evidence trail. No login, no cost, and nothing leaves your browser.

Most investigations stop at the person closest to the event. This tool is built to stop that happening. Every claim links back to evidence, and the built-in checks flag blame language, unsupported whys, weak controls and root causes that are really symptoms.

How it works

  • Level 1: Timeline and 5 Whys. For low-consequence events with a clear sequence.
  • Level 2: adds a Bowtie. Shows which barriers failed, which were missing, and how much you were relying on people being perfect.
  • Level 3: adds PEEPO. Pushes the analysis past people and equipment into procedures, organisation and leadership, where root causes usually sit.

Triage sets the level by potential consequence and complexity, not only by what happened. Start a case, log your evidence, build the analysis, then download the report as a Word document or save it as a PDF.

Your data stays with you

Everything you enter is stored in the browser you are using. Nothing is sent to me or anyone else. Export each investigation as a file to keep it, share it with your team or move it to another computer. Clearing your browser data will remove saved cases, so export anything you need to keep.

Worked example: Dreamworld, 2016

Click Compare the levels on the tool’s start screen to see the Thunder River Rapids Ride incident investigated at Level 1, 2 and 3, built from the Queensland Coroner’s published findings (2020). Level 1 finds a failed pump. Level 3 finds 30 years without an engineering risk assessment and two earlier incidents nobody learned from. The gap between them is the lesson.

Open the Workbench full screen

The Workbench is a structured thinking tool for training and practice. It does not replace a competent investigator, legal advice or your organisation’s investigation procedure. The Dreamworld example is an educational reconstruction from the public coronial record.

How to use the Root Cause Workbench

A step by step guide. Read the quick start, then open each step as you reach it in the tool.

Quick start

  1. On the start screen, click New investigation. Enter the facts in Case & triage and set actual and potential severity.
  2. Switch to the level the triage recommends.
  3. Log every piece of evidence in the Evidence register before you analyse anything.
  4. Build the Timeline, then the 5 Whys. Add the Bowtie at Level 2 and PEEPO at Level 3.
  5. State root causes, test them, and attach corrective actions.
  6. Clear the red notes in the Investigation check panel, then download the report as Word or save it as a PDF.
  7. Export the case (.json) before you close the browser. That file is your only backup.

Before you start: click Compare the levels on the start screen. It sets the 2016 Dreamworld Thunder River Rapids Ride incident side by side at Level 1, 2 and 3. Level 1 finds a failed pump and no automated shutdown. Level 3 finds 30 years without an engineering risk assessment, two near-identical earlier incidents that were never learned from, and audit recommendations never actioned. Same incident. The level you choose decides what you are able to find.

From the comparison you can open any level in full. The examples are read-only. Click Make an editable copy to experiment with one. You can return to the comparison at any time from the Compare the three levels button on an example.

Finding your way around

Area What it does
Start screen Shown on your first visit. Start a new investigation, compare the levels, reopen a saved case or import one. Get back to it with Start screen at the foot of the left rail.
Top bar The case menu switches between the worked examples and your own investigations. New investigation starts a blank case. L1 Simple, L2 Mid and L3 Complex set the level of the open case.
Left rail The investigation steps, in order. The coloured dot beside each step shows its status: green nothing flagged, amber something to check, red something to fix. The foot of the rail holds export, import, start screen and delete. On a phone the steps and these buttons sit above the form.
Centre The step you are working on.
Right panel The Investigation check. It re-runs as you type and lists every issue, with a link straight to the step it belongs to.

The tool saves as you type. There is no save button. On a phone or narrow screen the panels stack, so use Open the Workbench full screen for real work.

The eight steps

1Case & triageAll levels

This step records the basic facts and tells you how deep the investigation needs to go.

  1. Fill in the case details: investigation title, organisation, date of incident, location and lead investigator. Type the date however you like (14/05/2026 or 14 May 2026). It converts to 2026-05-14 when you leave the field.
  2. Set Actual severity. What harm occurred.
  3. Set Potential severity. The credible worst case. This is the field most people get wrong. A dropped load that missed a worker by a metre had a potential of Catastrophic, whatever the actual outcome.
Severity Means
Minor First aid or no harm
Moderate Medical treatment
Serious Lost time or hospitalisation
Major Permanent impairment
Catastrophic Fatality or multiple fatalities
  1. Write what happened. Facts only: who, what, where, when. Leave why for the analysis. If your summary already contains a cause, you have decided the answer before looking at the evidence.
  2. Tick any complexity factors that apply: multiple parties, contractors or departments; similar prior incidents or near misses; plant, design or engineering failure; notifiable, or likely inquest or prosecution.
  3. Read the Recommended level and click Switch to Level X if it differs from the current level.

How the recommendation works

  • The tool takes the higher of actual and potential severity. Minor or Moderate starts at Level 1, Serious at Level 2, Major or Catastrophic at Level 3.
  • Two or more complexity factors push it up one level.
  • A notifiable event, or one likely to reach an inquest or prosecution, is never below Level 2.

You can override the recommendation. If you run below it, the check panel raises a red note, and that note is printed as unresolved when you reach the report.

2EvidenceAll levels

Everything else in the tool links back to this register. A claim with no evidence ID behind it is an assumption, and the tool treats it that way.

  1. Click Add evidence item. The tool assigns an ID (E01, E02 and so on).
  2. Short title, for example “Maintenance log, conveyor 3, March to May”.
  3. What it shows. The specific facts, not your interpretation of them.
  4. Type: witness statement, document, CCTV / image, physical test, site inspection, data / record, incident report, expert report, legal record or other.
  5. Source / reference. Where someone else would find it: file name, record number, page or paragraph. Items with no source are flagged.
  6. Reliability:
    • Verified: confirmed by a record, test or physical evidence.
    • Corroborated: supported by at least one independent source.
    • Single source: one account, nothing confirming it yet.
    • Disputed: contradicted by another source.
  7. PEEPO tag: People, Environment, Equipment, Procedures or Organisation. This tells you where your evidence is concentrated.

The counters above the table show the spread by reliability and by PEEPO category. If almost everything is tagged People and Single source, you have interviewed the people closest to the event and stopped there.

Collect in this order: physical and recorded evidence first (the scene, CCTV, logs, maintenance and training records, risk assessments, prior incident reports), statements second. Records do not change their story. At Level 3, you will get a warning until at least one item is tagged Organisation.

3TimelineAll levels

Sequence first, causes later.

  1. Click Add timeline entry. A new entry copies the time of the previous one, so edit it straight away.
  2. When: type the date and time. 14/05/2026 2:05pm, 14 May 2026 14:05 and 2026-05-14 14:05 all work and convert to the same format. Add seconds (14:05:30) where they matter. For older events a date, or just a year and month (2014-11), is enough. Dates are read day first, Australian style.
  3. Type: choose the entry type (below).
  4. Describe what happened or what condition existed.
  5. Use the + evidence dropdown to link the evidence that supports the entry. Remove a link with the × on its tag.
Type Use it for
Event Something that happened
Condition A state of affairs that existed, such as a worker on their first day or a faulty alarm
Decision A choice someone made, such as reopening after a fault
Change A modification to plant, process, staffing or procedure
Precursor An earlier fault, near miss or incident that pointed at this one
Control failure A point where something should have stopped the sequence and did not
Outcome The result, including later findings or penalties

Entries sort by time automatically. Where two neighbouring entries both have times and fall within 24 hours, the gap between them is shown (for example +53 s). Those gaps matter. They show how long there was to intervene.

If the tool cannot read a date or time, a red message appears under the field and the entry sorts to the end of the timeline until you fix it.

A timeline that starts on the day of the incident is a timeline of the last few minutes. At Level 2 and above, the tool prompts you if nothing predates the incident date. Go back and find the faults, changes and decisions that set it up.

45 WhysAll levels
  1. Write the problem statement. Specific: what happened, to whom, when. “Worker injured” is not a problem statement. “Maintenance fitter’s hand drawn into the tail pulley of conveyor CV3 during cleaning, 14 May 2026” is.
  2. Name the chain after the line of causation it follows, for example “Why the guard was off”.
  3. Answer Why 1: why did the problem occur? Link evidence.
  4. Click Ask why again and answer why that was so. Repeat.
  5. Click Add causal chain for each separate line of causation.

When to stop

Stop when the answer is a condition the organisation controls. Do not stop when you reach a person. Five is a guide, not a rule. A chain shorter than five gets a tip, and one that ends in blame language gets a red note.

Stops too early: “The fitter did not follow the isolation procedure.”
Keep asking: “Isolation required a trip to a switch room 200 m away, during a 20-minute cleaning window set by production targets.”

Flags on each answer

  • Blame language. Triggered by words such as failed to follow, did not follow, careless, complacent, human error, operator error, inattentive, negligent, ignored, violated, should have known, reckless. The question to ask instead: what made that action likely, easy or reasonable at the time?
  • Unsupported. An answer with no linked evidence. Link something or treat it as a hypothesis to test.

At Level 2 and above, a single chain gets a prompt. Serious incidents almost never have one cause.

5BowtieLevels 2 and 3

The bowtie shows what should have prevented the loss of control (left side) and what should have limited the harm once it happened (right side).

  1. Hazard: the energy or condition with potential for harm. For example “Rotating tail pulley on a powered conveyor”.
  2. Top event: the moment control was lost. Not the injury. For example “Person’s body part enters the nip point while the conveyor is energised”.
  3. Click Add threat for each thing that could release the hazard.
  4. Under each threat, click Add preventive barrier. Barriers are numbered P1, P2 and so on.
  5. Click Add consequence for each outcome that could follow the top event, and Add mitigating barrier under each. These are numbered M1, M2 and so on.
  6. For every barrier set the control type (Elimination, Substitution, Engineering, Administrative, PPE), the status, and link evidence.
Status Means
Effective Worked as intended on the day
Degraded Present but partly working
Failed Present and did not work
Absent Should have existed and did not
Untested No evidence either way yet (the default)

Rate each barrier by what the evidence shows it did on the day, not by what the procedure says it does. A lockout procedure nobody could practically follow is Failed or Degraded, not Effective.

The summary strip counts barriers mapped, failed or absent, degraded, and the percentage at engineering level or higher. In the diagram, rounded barriers are administrative or PPE. If most of your barriers are rounded, the system was relying on people being perfect under pressure. Any threat or consequence protected only by administrative or PPE barriers is flagged.

6PEEPOLevel 3

PEEPO forces the analysis beyond the people and equipment nearest the event. Add factors under each of the five headings with Add factor.

Column Questions to ask
People Competence, workload, supervision, role clarity. What made their actions make sense at the time?
Environment Sightlines, noise, lighting, weather, layout, time pressure.
Equipment Design, interlocks, alarms, guarding, maintenance, modifications, controls layout.
Procedures Did the written procedure match the work? Was it clear, tested and usable under stress?
Organisation Risk assessment, learning from past incidents, audits, resourcing, governance, leadership decisions.

Classify each factor as Immediate cause, Contributing factor, Root cause or Not a factor, and link evidence.

  • An empty column is a finding. Either you ruled it out with evidence (add a factor marked Not a factor saying why) or you have not looked.
  • An empty Organisation column is a red note. That is where root causes usually sit.
  • A People factor classed as a root cause in blame language is a red note. Trace it back to the system that shaped the behaviour.
7Root causes & actionsAll levels

Root causes

A root cause is a system condition that, if fixed, stops this class of incident, not just this one event.

  1. Look at Candidates pulled from your analysis. The tool collects the last answer in each why chain, every Failed or Absent barrier (Level 2+) and every PEEPO factor classed as Root cause (Level 3).
  2. Click Promote on a candidate to turn it into a root cause, or Add root cause to write one from scratch. Usually you will combine several candidates into one clearer statement.
  3. Link evidence.
  4. Tick each of the four tests only if it is true:
    • Fixing it would prevent recurrence, not just this exact event.
    • It sits within the organisation’s control to change.
    • It is supported by linked, reliable evidence.
    • It describes a system condition, not a person’s act or attribute.

When you promote a candidate, the tool pre-ticks the evidence test if evidence is linked and the system test if no blame language is found. The other two are yours to judge. Each root cause shows Passes X/4 tests. Anything under 4 needs rewriting or more evidence.

Symptom: “Operator did not press the emergency stop.”
Root cause: “Emergency response depended on an operator noticing a hazard by eye and reacting within seconds, with no automated detection or shutdown.”

Corrective actions

  1. Click Add action and describe what will change.
  2. Set the Control level: Elimination, Substitution, Engineering, Administrative or PPE.
  3. Name an Owner (a role is fine) and a Due date or trigger, such as “Before restart”.
  4. Use + root cause to link the action to the root cause(s) it addresses. Every root cause needs at least one action.

Push every action as high up the hierarchy of controls as you can. The tool flags any action that relies on words like retrain, remind, toolbox, awareness, be careful, reinforce, counsel, discipline, refresher, re-induct, signage, whatever control level you give it.

Labelling “retrain operators” as Engineering does not make it engineering. The tool will tell you the label does not match the action, and it counts that action as administrative. If every action is administrative or PPE in substance, you get a red note: nothing has changed the design of the work.

8ReportAll levels

The report page shows the full investigation report exactly as it will download: case details, summary, root causes, corrective actions, timeline, causal chains, bowtie barrier tables (Level 2+), PEEPO table (Level 3) and the evidence register. Evidence IDs appear in square brackets after each finding.

  1. If a red DRAFT box appears at the top, the investigation check still has critical notes. They print in the report too, so nobody mistakes a draft for a finished investigation. Fix them before you issue it.
  2. Click Download Word (.docx) for an editable A4 report with page numbers. Add your organisation’s logo, sign-off block or distribution list in Word.
  3. Click Print or save as PDF, then choose Save as PDF as the printer. The tool’s menus and panels are left off the page.
  4. Click Export case (.json) to keep the editable case itself. The Word and PDF files cannot be imported back into the tool.

If a download does nothing inside this page, open the Workbench full screen and try again. Some browsers and workplace settings block downloads from embedded windows.

The Investigation check panel

Every note is tagged by how much it matters:

  • Fix: a structural failure. For example, running below the recommended level, no evidence, blame language in a final why or root cause, an empty Organisation column, or every action being administrative.
  • Check: a gap to close. For example, unsupported whys, barriers marked Failed with no evidence, root causes with no action.
  • Tip: a prompt to go deeper.

The score out of 100 drops 15 for each Fix, 5 for each Check and 1 for each Tip. Click the step name at the end of any note to jump to it.

A clean score means the structure holds. It does not mean the conclusions are right. The checks read words and links. They cannot tell whether your evidence actually supports what you have written. That judgement stays with you.

Saving, sharing and moving cases

  • Where your data lives: in this browser, on this device only. Nothing is sent anywhere.
  • What deletes it: clearing browser data, private or incognito windows (cleared when closed), switching browser or device, and some workplace IT policies that wipe browsers on logout.
  • Back up:Export case (.json) at the foot of the left rail or on the report page. Do this at the end of every session.
  • Restore or move:Import case, then choose the .json file. It opens as a new case. Importing the same file twice gives you two copies.
  • Share with your team: send the .json file. Each person imports it and works on their own copy. Changes do not sync, so agree who holds the master version.
  • Delete:Delete this investigation, then click again within a few seconds to confirm. This cannot be undone. Export first.

Things that catch people out

  • Changing level does not delete work. Dropping from Level 3 to Level 1 hides the Bowtie and PEEPO steps and removes them from the report. Switch back and they return.
  • Removing an evidence item also removes every link to it in the timeline, whys, bowtie, PEEPO and root causes. Any finding that relied only on that item will show as unsupported. If evidence was set aside rather than wrong, keep it and record why in its detail.
  • Removing a root cause unlinks it from its actions. Check those actions still point at something.
  • Evidence you log but never link is listed as unused. Either it matters and belongs in the analysis, or record why you set it aside.
  • Use a separate case for each incident. Click New investigation each time. Everything you have saved is listed on the start screen.
  • The embedded window can feel cramped.Open the Workbench full screen gives you the same tool and the same saved cases.

Choosing the level: common mistakes

  • Investigating the outcome, not the potential. A near miss with fatal potential is a Level 3 investigation.
  • Running Level 1 because it is quicker. Level 1 will find the pump and the operator. It will not find the missing risk assessment, the ignored precursors or the governance failure. That is the point of the Dreamworld comparison.
  • Stopping at the person closest to the event. If your root causes name a worker, keep asking why.