Controlled Documents

The Engineering Record

Software whose numbers end up in a report is built on paper as much as on code: requirements, verification dossiers, a hazard analysis, an architecture, a security position. This is the register of that paper. What exists, what number and version it carries, and where each document stands.

Register audited 7 Sep 2026 Software version at audit 1.6.1.0 Documents on file 59
Cover of ES-VV-002, the RULA verification and validation dossier ES-VV-002v1.5 V&V Dossier RULA Rapid Upper Limb Assessment Issued 2026-08-28
Describes software 1.6.0.0
Released under NDA
ES-VV-001v1.4 V&V Dossier REBA Rapid Entire Body Assessment Issued 2026-08-27
Describes software 1.6.0.0
Released under NDA
ES-VV-003v1.5 V&V Dossier NASA-TLX NASA Task Load Index Issued 2026-08-27
Describes software 1.6.0.0
Released under NDA
ES-VV-004v1.4 V&V Dossier NIOSH Revised NIOSH Lifting Equation Issued 2026-08-28
Describes software 1.6.0.0
Released under NDA
ES-VV-005v1.4 V&V Dossier ART Assessment of Repetitive Tasks Issued 2026-08-28
Describes software 1.6.0.0
Released under NDA
ES-VV-006v1.4 V&V Dossier MAC Manual Handling Assessment Charts Issued 2026-08-28
Describes software 1.6.0.0
Released under NDA
ES-VV-007v1.4 V&V Dossier RAPP Risk Assessment of Pushing and Pulling Issued 2026-08-28
Describes software 1.6.0.0
Released under NDA
ES-VV-008v1.1 V&V Dossier · Tier 3 ErgoLens Measurement chain feeding RULA and REBA Issued 2026-08-28
Describes software 1.6.0.0
Released under NDA
ES-VV-009v1.1 V&V Dossier · Tier 3 ErgoSense Measurement chain feeding RULA, REBA and NIOSH Issued 2026-08-28
Describes software 1.6.0.0
Released under NDA
ES-VV-010v1.3 V&V Dossier · Tier 1 Snook Liberty Mutual manual materials handling tables Issued 2026-08-28
Describes software 1.6.0.0
Released under NDA
ES-VV-011v1.4 V&V Dossier · Tier 1 THERP Technique for Human Error Rate Prediction Issued 2026-08-28
Describes software 1.6.0.0
Released under NDA
ES-VV-012v1.0 V&V Dossier · Tier 1 CREAM Cognitive Reliability and Error Analysis Method Issued 2026-08-29
Describes software 1.6.0.0
Released under NDA
ES-VV-013v1.2 V&V Dossier · Tier 1 HEART Human Error Assessment and Reduction Technique Issued 2026-08-29
Describes software 1.6.0.0
Released under NDA
ES-VV-014v1.0 V&V Dossier · Tier 1 SPAR-H Standardized Plant Analysis Risk, Human Reliability Analysis Issued 2026-08-29
Describes software 1.6.0.0
Released under NDA
ES-VV-015v1.2 V&V Dossier · Tier 1 SLIM Success Likelihood Index Methodology Issued 2026-08-29
Describes software 1.6.0.0
Released under NDA
ES-VV-016v1.3 V&V Dossier · Tier 2 SCTA Safety Critical Task Analysis Issued 2026-08-29
Describes software 1.6.0.0
Released under NDA
ES-VV-017v1.4 V&V Dossier · Tier 2 SHERPA Systematic Human Error Reduction and Prediction Approach Issued 2026-08-29
Describes software 1.6.0.0
Released under NDA

V&V dossiers ES-VV 43 on file · 17 shown

What This Page Is

The Paper Behind The Numbers

ErgoSphere is a library of published assessment methods, implemented as one desktop application. Each method is verified against the source that defined it, each tool is described as a set of functional requirements, and the whole product carries a hazard analysis, a security whitepaper and an architecture. Those documents are controlled: numbered, versioned, dated, and tied to the software build they describe.

The documents themselves are released on request under NDA, because the working inside them describes how the software is built as much as how it was checked. What this page publishes is the register: the fact that each document exists, the number and version it carries, and the rung it stands on. Nothing here is a forecast. A row changes when a document does.

How a method earns its dossier, and what the eight components are, is described on the Dossier Project page. This page is the inventory that programme produces.

What Changed

Formalised, and Made Public

What is new here is the formalisation and the publication, not the work. ErgoSphere shipped 1.6.0.0 with a suite of nearly eight thousand test methods, written alongside the tools over the life of the build, and 1.6.1.0 carries more than eleven thousand. The lookup tables, band edges and boundary rules those tests assert are the same ones the dossiers now cite.

The architecture document and the security whitepaper were written months earlier and had reached their third and second versions before this register existed. Drafts of much of the rest had been sitting in a working folder.

What The Dossier Project did was formalise all of it - number each document, version it, tie it to the build it describes - and then publish the register. None of that changes what the software does. It changes who is able to check it.

Formalising is not rubber-stamping, and this register would be worth little if it were. Reading a test against the publication it claims to implement is a different act from writing that test, and doing it has turned up real defects: tests that asserted, in the affirmative, that the software agreed with itself; a band grouping that disagreed with its own source at two ratings, both times optimistically; a method guide printing a severity scale that contradicted the numbers in the report two pages later. Each one is fixed, guarded by a named test, and written into the dossier it belongs to.

The documents say this about themselves where it counts. Every functional requirements document, from ES-FRD-002 onward, opens by stating it is a retrospective as-built record, drafted from the shipped code rather than written ahead of it, and every requirement in it carries whether a test keeps it true.

  • ES-ARC-000 · v1.3

    The system architecture, written months before this register and already at its third version when it was numbered.

  • ES-SEC-000 · v1.2

    The security whitepaper, on the same footing. Both were brought under document control and numbered on 2026-08-30.

  • 1.6.1.0

    11,162 test methods, counted 2026-09-07. The suite run of 2026-09-06 executed 14,706 test cases, because a theory with twenty rows runs twenty times. The Dossier Project audits that suite, and what it raises is recorded against the method it belongs to.

  • 2026-08-30

    The whole dossier moved into the source repository. Evidence for a version now branches, tags and ships with the code it makes claims about.

Document Numbering

How to Read a Number

ES

ErgoSphere. Every controlled document in the product starts here.

VV · Series

Which kind of document it is. Five series: VV, FRD, HAZ, SEC, ARC.

002 · Index

Three blocks. 000 is product-wide. 001 to 099 is a method's place in the programme. 100 and up is a capability's: a module of the product that is software rather than a published method. An index is shared across series, so ES-VV-002 and ES-FRD-002 are both RULA.

v1.5 · Version

The document's own version, separate from the number. A number never changes; a version moves every time the document is re-issued. Dossiers issue at 1.0. A functional requirements document issues below 1.0 and climbs as its requirements are confirmed against tests.

  • 000

    Product-wide

    One document that covers the whole product. The hazard analysis, the security whitepaper and the architecture each carry it, one per series.

  • 001 to 099

    A method

    Assigned once, in the order the method entered the programme, and never reused. REBA is 001 and RULA is 002 in every series they appear in.

  • 100 +

    A capability

    A module of the product with no published method behind it, verified as software against the standards it ingests. The compliance and assurance module is 100.

How to read a row

Number

The document's permanent identity. Quote it when requesting the document.

Document

The method, tool or subject, and for a dossier its tier, which sets what kind of evidence the dossier can carry.

Version · Issued

The version on the document's own title block and the date that version was issued. Both are read from the document, never from this page.

Describes

The ErgoSphere release the document was written against. A later release does not move a row on its own, only a re-issued document does.

Status

The rung the document stands on, and under it the stage: where the work has reached, in the register's own words. The rungs and stages are set out under the register.

  • ES-VV

    Verification and validation dossier

    One per method. Answers one question: does the software implement the published method faithfully? Provenance, implementation specification, golden cases, boundary behaviour, known deviations, limits of validation, and one section only an outside reviewer can sign.

  • ES-FRD

    Functional requirements

    One per tool. What the tool is required to do as software: document lifecycle, guided entry, persistence, reporting. Restates nothing from the dossier; where a number appears in both, the dossier is the one that is right.

  • ES-HAZ

    Software hazard analysis

    Product-wide. What happens when the software produces a wrong or missing output, and how likely that is to be noticed. It is a hazard analysis of the software, not of any workplace, and its only job is to order the test queue by consequence.

  • ES-SEC

    Security whitepaper

    Product-wide. How the application handles data and what it does not do: no cloud account, no server, all work local. The security position, stated so it can be checked.

  • ES-ARC

    System architecture

    Product-wide. How the system is put together: one task decomposition feeding every method, the registers that hold findings, and the sealed deliverable that leaves the building. The document the other four are read against.

The Register

Every Document On File

59 documents · 5 series · 0 independently verified

V&V dossiers ES-VV · 43

V&V dossiers - ES-VV · 43
NumberDocumentVersionIssuedDescribesStatus
ES-VV-001REBARapid Entire Body Assessment · Tier 11.42026-08-271.6.0.0In progressGolden cases written
ES-VV-002RULARapid Upper Limb Assessment · Tier 11.52026-08-281.6.0.0In progressGolden cases written
ES-VV-003NASA-TLXNASA Task Load Index · Tier 11.52026-08-271.6.0.0In progressGolden cases written
ES-VV-004NIOSHRevised NIOSH Lifting Equation · Tier 11.42026-09-061.6.0.0In progressGolden cases written
ES-VV-005ARTAssessment of Repetitive Tasks of the upper limbs · Tier 11.42026-09-061.6.0.0In progressGolden cases written
ES-VV-006MACManual Handling Assessment Charts · Tier 11.42026-08-281.6.0.0In progressGolden cases written
ES-VV-007RAPPRisk Assessment of Pushing and Pulling · Tier 11.42026-08-281.6.0.0In progressGolden cases written
ES-VV-008ErgoLensCamera pose measurement chain feeding RULA and REBA · Tier 31.12026-08-281.6.0.0In progressSources held
ES-VV-009ErgoSenseInertial suit measurement chain feeding RULA, REBA and NIOSH · Tier 31.12026-08-281.6.0.0In progressSources held
ES-VV-010Snook and CirielloLiberty Mutual manual materials handling tables · Tier 11.32026-09-071.6.0.0In progressGolden cases written
ES-VV-011THERPTechnique for Human Error Rate Prediction · Tier 11.42026-09-071.6.0.0In progressGolden cases written
ES-VV-012CREAMCognitive Reliability and Error Analysis Method · Tier 11.02026-08-291.6.0.0In progressGolden cases written
ES-VV-013HEARTHuman Error Assessment and Reduction Technique · Tier 11.22026-08-291.6.0.0In progressGolden cases written
ES-VV-014SPAR-HStandardized Plant Analysis Risk, Human Reliability Analysis · Tier 11.02026-08-291.6.0.0In progressGolden cases written
ES-VV-015SLIMSuccess Likelihood Index Methodology · Tier 11.22026-09-071.6.0.0In progressGolden cases written
ES-VV-016SCTASafety Critical Task Analysis · Tier 21.32026-08-291.6.0.0In progressProcess conformance walked
ES-VV-017SHERPASystematic Human Error Reduction and Prediction Approach · Tier 21.42026-08-291.6.0.0In progressProcess conformance walked
ES-VV-018SWATSubjective Workload Assessment Technique · Tier 11.12026-08-291.6.0.0In progressGolden cases written
ES-VV-019TRACErRetrospective and predictive Analysis of Cognitive Errors · Tier 21.12026-08-291.6.0.0In progressProcess conformance walked
ES-VV-020GDTAGoal-Directed Task Analysis · Tier 21.02026-08-301.6.0.0In progressProcess conformance walked
ES-VV-021SAGATSituation Awareness Global Assessment Technique · Tier 21.02026-08-301.6.0.0In progressProcess conformance walked
ES-VV-022DRTDetection-Response Task · Tier 21.02026-08-301.6.0.0In progressProcess conformance walked
ES-VV-023IWSIntegrated Workload Scale · Tier 21.12026-08-311.6.0.0In progressProcess conformance walked
ES-VV-024uFMEAuse Failure Mode and Effects Analysis · Tier 11.22026-09-061.6.0.0In progressGolden cases written
ES-VV-025URRAUse-Related Risk Analysis · Tier 21.02026-08-301.6.0.0In progressProcess conformance walked
ES-VV-026ATWITAir Traffic Workload Input Technique · Tier 21.22026-08-311.6.0.0In progressProcess conformance walked
ES-VV-027SNASocial Network Analysis · Tier 11.12026-08-311.6.0.0In progressGolden cases written
ES-VV-028EASTEvent Analysis of Systemic Teamwork · Tier 11.22026-08-311.6.0.0In progressGolden cases written
ES-VV-029HE-HAZOPHuman Error HAZOP · Tier 21.52026-09-011.6.0.0In progressProcess conformance walked
ES-VV-030ErgoGlareSolar Glare Hazard Analysis Tool, SGHAT · Tier 11.12026-09-011.6.0.0In progressSources held
ES-VV-031HTAHierarchical Task Analysis · Tier 21.42026-09-021.6.0.0In progressSources held
ES-VV-032ErgoRadarHolistic assessment framework of Stroeve, Kirwan and Everdij · Tier 21.52026-09-021.6.0.0In progressProcess conformance walked
ES-VV-033SARTSituational Awareness Rating Technique · Tier 11.12026-09-021.6.0.0In progressSources held
ES-VV-034GOMSGoals, Operators, Methods and Selection Rules · Tier 11.42026-09-021.6.0.0In progressGolden cases written
ES-VV-035CDMCritical Decision Method · Tier 21.12026-09-021.6.0.0In progressSources held
ES-VV-036NielsenHeuristic evaluation · Tier 21.12026-09-021.6.0.0In progressSources held
ES-VV-037AcciMapAccident mapping across socio-technical levels · Tier 21.22026-09-021.6.0.0In progressSources held
ES-VV-038ErgoActACT-R cognitive architecture · Tier 11.32026-09-021.6.0.0In progressSources held
ES-VV-039ErgoTraceSTAMP: STPA and CAST · Tier 21.12026-09-061.6.1.0In progressSources held
ES-VV-040SUSSystem Usability Scale · Tier 11.12026-09-061.6.1.0In progressSources held
ES-VV-041ErgoCompassBinary-Based Model method selection · Tier 11.12026-09-061.6.1.0In progressSources held
ES-VV-042ErgoAIRAlarm identification and rationalisation, ANSI/ISA-18.2 · Tier 11.12026-09-061.6.1.0In progressSources held
ES-VV-100Compliance and assurance capabilityCompliance engine and human factors assurance process · Tier 21.162026-09-011.6.0.0In progressSources held

Functional requirements ES-FRD · 13

Functional requirements - ES-FRD · 13
NumberDocumentVersionIssuedDescribesStatus
ES-FRD-002RULA toolFunctional requirements, retrospective as-built record0.52026-08-281.6.0.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-004NIOSH toolFunctional requirements, retrospective as-built record0.22026-09-061.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-005ART toolFunctional requirements, retrospective as-built record0.22026-09-061.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-006MAC toolFunctional requirements, retrospective as-built record0.22026-09-061.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-007RAPP toolFunctional requirements, retrospective as-built record0.22026-09-061.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-010Snook toolFunctional requirements, retrospective as-built record0.22026-09-071.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-011THERP toolFunctional requirements, retrospective as-built record0.22026-09-071.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-013HEART toolFunctional requirements, retrospective as-built record0.22026-09-061.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-015SLIM toolFunctional requirements, retrospective as-built record0.22026-09-071.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-024uFMEA toolFunctional requirements, retrospective as-built record0.22026-09-061.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-032ErgoRadar toolFunctional requirements, retrospective as-built record0.42026-09-061.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-034GOMS toolFunctional requirements, retrospective as-built record0.42026-09-061.6.1.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status
ES-FRD-100Compliance and assurance capabilityFunctional requirements, retrospective as-built record0.72026-09-011.6.0.0In progressRetrospective as-built record of the shipped tool, each requirement carrying its test status

Hazard analysis ES-HAZ · 1

Hazard analysis - ES-HAZ · 1
NumberDocumentVersionIssuedDescribesStatus
ES-HAZ-000Software Hazard AnalysisProduct-wide, rows added per tool0.22026-08-281.6.0.0In progressRegister guarded in the test suite, level 2

Security & privacy ES-SEC · 1

Security - ES-SEC · 1
NumberDocumentVersionIssuedDescribesStatus
ES-SEC-000Security and Data Privacy WhitepaperProduct-wide1.22026-08-30N/ACompletedProduct-wide, not on the verification ladder

Architecture ES-ARC · 1

Architecture - ES-ARC · 1
NumberDocumentVersionIssuedDescribesStatus
ES-ARC-000System Architecture DocumentProduct-wide1.32026-08-30N/ACompletedProduct-wide, not on the verification ladder
In progress Completed Internally verified Independently verified Text under a chip is the stage, in the register's own words
  • In progress

    The document exists and is issued, and sections remain open. Every dossier sits here until its internal review is signed.

  • Internally verified

    Complete to its template and signed by ErgoSphere's internal review. This is as far as anyone inside the company can move a document.

  • Independently verified

    Signed by a competent person outside ErgoSphere. No amount of internal work reaches this rung, which is what gives the other two their meaning. Where that reviewer accepted a licence under the Verification Cohort, it is recorded as a declared interest in the dossier's section 8.1 and released with the document every time.

  • Tier 1

    Quantified

    The source publishes values: lookup tables, constants, or a worked example with an answer. Its arithmetic can be reproduced, so the dossier carries golden cases encoded from the publication.

  • Tier 2

    Descriptive

    The source publishes a procedure, not a scored example. There is no number to reproduce, so a process conformance walk stands in and the golden-case row reads n/a. That means the row cannot move, not that the work was skipped.

  • Tier 3

    Measurement chain

    Implements no published method at all. ErgoLens and ErgoSense are sensing pipelines feeding RULA, REBA and NIOSH. The evidence that counts here is observer parity, and we do not hold it yet, which is why both read Sources held.

Completed sits outside those three rather than above them. The product-wide security and architecture documents carry no review sections and no independent signature to collect, so there is no rung for them to climb. It says the document is finished, not that anyone has checked it.

Access

Requesting a Document

Any document in the register is released on request, under NDA, to the customers, auditors and reviewers who need to verify what they rely on. Quote the number. If you are assessing ErgoSphere for work that has to stand up, ask about the document you actually care about and we will tell you where it stands and what it does not yet cover.

To request a document by number, or to ask where one stands, write to us.

Independent Verification

The Rung We Cannot Reach

We are a small firm. The methods are not ours - they belong to the people who published them and to the profession that uses them - and we are not in a position to have a laboratory check our arithmetic. So we are asking the people who would notice. If you use RULA in your work you already know where it bites, and an afternoon of that against a dossier is worth more than a procurement exercise.

It is also the only way the top rung on this page means anything. We cannot put ourselves there, by design. Every dossier in the register will read In progress or Internally verified until somebody outside this company signs its section 8, and no amount of work in here changes that.

Findings do not disappear into an inbox. A reviewer's finding is written into the dossier, raised as a numbered work package, answered in writing and carries a closed date. A qualified or negative statement is published as written. We think this is what the profession's software should look like; we would rather be told now if it is not.

  • § 8.1Your name, qualifications, the edition of the source you worked from, and any relationship to ErgoSphere, which includes this offer.
  • § 8.2Read the method's tables from your own copy of the source and write them into your column. Not from the tool, not from the dossier, not from the code. This is the check that catches transcription errors, and it only works if it is done blind.
  • § 8.3Work the prepared cases by hand, writing down your intermediate values before you look at what the tool produced.
  • § 8.4Then your own cases. Especially the awkward ones - the band edges, the contradictory inputs, the assessment with nothing filled in at all.
  • § 8.5Your findings, each with a severity. Ours is the next column: a written response, the number of the work package it raised, and the date it closed.
  • § 8.6Your statement, in your own words: what you checked, what you did not check, and what you are prepared to say about it.

Your name goes on the row. The register names its verifiers: your name, your credential, the software version you checked and the date, in the public row, for as long as it stands. If you would rather not be named - employer policy, a regulator role, expert-witness conflict rules - the row can carry the credential alone, and that is a choice you make at application, not one we make for you.

Your signature is pinned to the method, not to our release number. ErgoSphere increments often and almost none of it goes anywhere near the arithmetic you checked. A new version does not touch your verification and does not ask anything of you. What matters is whether the method you reviewed was itself amended - a lookup table, a rounding rule, a band edge, the computation sequence - and our own golden cases tell us that on every build.

If one is amended, we write down exactly what changed and, where it warrants it, ask for a short gap review of that change alone. Never a repeat of the dossier. Until that closes the row keeps your verification and states plainly what has moved since: independently verified at 1.6.0.0 · Table C amended at 2.1.0.0, gap review open. Your name is never carried forward onto a change you did not see, and never quietly taken off the work you did.

  • You verify 1dossier 6 monthsErgoSphere, full licence
  • You verify 3dossiers 12 monthsErgoSphere, full licence
Verification Cohort terms by application · screened · the licence does not depend on your verdict

Places are offered by application and at our discretion, and applying does not mean a place. We screen for two things: competence in the method, and independence - no current or pending commercial relationship with Ergonomics Engineered Pty Ltd. Which dossiers are available, and to whom, is our allocation, because the dossiers are not equal in size and we balance the mix. Dossiers are released for review under NDA in the ordinary way.

The licence is issued on submission of your completed section 8, whatever it says. It is not contingent on a favourable finding, on the number of defects you raise, or on your overall statement, and a review that concludes the implementation does not hold up earns the same licence as one that concludes it does. Your statement is published in the dossier as written. Your acceptance of a licence under this offer is recorded in section 8.1 as a declared interest and released with the document every time it is released.

Attribution is your choice at application: named in full, or by credential and jurisdiction alone. It is recorded against the document version and the software version you reviewed, and it stays there. Later releases of ErgoSphere do not affect it and create no obligation on you. If the method you reviewed is later amended, the amendment is documented against the row and we may ask you, or another reviewer, for a short gap review covering that change alone; declining costs you nothing and your statement continues to stand for the version you checked. A licence issued under this offer is for the named reviewer's own professional use, is not transferable, and does not renew automatically.

To apply, tell us which method you would review and what you do. A paragraph is enough. We will send you the dossier and the source list, and you will know inside an afternoon whether it is worth your time.

A Living Register

What Moves This Page

  • A document is issued or re-issued. A new row, or a version that moves. The desk gets a sheet for every row.
  • A status changes rung. An internal review is signed, or, for the first time, an external one.
  • A verified method is amended. Not a release - shipping a new version of ErgoSphere moves nothing on this page by itself. When the logic an outside reviewer actually checked is changed, the row names the amendment and carries a gap review until it is closed.
  • Every quarter, regardless. The register is re-audited against the documents and the audit date is refreshed, even when the news is "no change".

The third rung only moves when a competent person outside ErgoSphere signs. If that could be you, we would genuinely like to hear from you.

Register audited · 7 Sep 2026 The Engineering Record · ErgoSphere controlled documents
To Top