| name | rams-builder |
| description | Creates consultant-grade, construction-ready RAMS — a combined Risk Assessment and Method Statement for a specific construction activity on a specific site. Use this skill whenever a user asks to build, write, or review a RAMS, a method statement, or a safe system of work for construction works, or to produce a CDM RAMS, a contractor RAMS, or a method statement tied to a risk assessment. Assesses the activity's hazards on a risk matrix, enforces the hierarchy of controls (no PPE-only treatments without justification), builds a sequenced safe system of work with plant, competencies, and permits, cross-references every method step to the risk assessment, names the competent persons, sets out emergency and rescue arrangements, and produces a briefing/sign-off record — grounded in ISO 45001 clause 6.1.2 and the applicable construction law (UK CDM 2015 Regulation 13, or India BOCW with the user's state form), emitting a branded report. Decision-support only; a competent person must review the output. |
| license | Apache-2.0 |
| metadata | {"author":"eyekyam","version":"1.0","category":"compliance","tier":1,"audience":["M","C"],"industry":["Con"],"jurisdiction":["All"],"status":"stable","plugin":"hse-core","hse_reviewed_by":"","hse_reviewed_date":""} |
RAMS — Risk Assessment & Method Statement (construction)
A consultant-grade HSE skill that produces a task/site-specific RAMS — a combined
Risk Assessment + Method Statement for a specific construction activity on a
specific site. The RA half runs the standard HIRA loop grounded in ISO 45001
clause 6.1.2 (the same loop the risk-assessment flagship uses, reused verbatim);
the MS half is the sequenced safe system of work — the ordered steps, the
plant, the competencies, the permits, the rescue arrangements. A bidirectional
RA↔MS cross-reference ties every method step to the RA rows that treat its hazards
and flags any RA hazard no step addresses. It forces the single lever that separates
a defensible RAMS from copy-paste paperwork: a real sequence on a real site plus
the full hierarchy of controls — never a vague, PPE-only method. Grounded in the
applicable construction law (UK CDM 2015 Reg 13/15 + the Construction Phase Plan,
or India BOCW with the user's resolved state form), with named competent
persons and a briefing/sign-off record. Scoring, residual re-scoring, and
control ranking are deterministic (the A7 risk_matrix/controls engines); the
MS half uses no engine.
When to use this skill
Use this skill when the user needs a RAMS, a method statement, or a safe system of
work for a concrete construction activity on a named site — for example "build
a RAMS to erect a mobile tower and replace south-elevation cladding on levels 2–4",
"write a method statement for excavating a 1.8 m service trench across the access
road", or "review this contractor RAMS". Trigger phrases: RAMS, method statement,
safe system of work, risk assessment, construction, CDM, CDM 2015, contractor RAMS,
method ↔ RA cross-reference, hierarchy of controls, permit-to-work, BOCW. The two
load-bearing inputs are the construction activity and the sequence of works;
if either is vague, the Workflow intake below refuses to proceed until they are
elicited.
Data Protection & De-identification (MANDATORY — apply before drafting)
Apply this BEFORE you draft anything. Treat injury, illness, and any health
detail as the highest sensitivity. Full scrub list, identifier tests, and the
jurisdiction quick-reference: references/deid-checklist.md.
- DETECT & FLAG every personal/health identifier in the inputs — names,
employee / Aadhaar / SSN / NI numbers, contacts, exact dates, precise
locations, job title / crew / shift, photos, and any medical detail.
List what you found before drafting. If unsure whether something is
identifying, treat it as identifying.
- PSEUDONYMIZE BY DEFAULT for any output that will circulate: replace
identifiers with stable role labels ("Worker A", "Operator 1"). Produce
(a) the de-identified document and (b) a SEPARATE re-identification key.
Never put the key or any name↔label mapping in the document. Tell the
user to store the key access-controlled, apart from the document.
- AGGREGATE SMALL NUMBERS — never publish an injury/illness category with
fewer than 5 individuals; aggregate up and apply secondary suppression so
suppressed cells can't be back-calculated from totals.
- WARN BEFORE WIDE DISTRIBUTION — toolbox talks, board reports, and posters
default to de-identified / aggregated; warn the user before any name or
health detail enters a widely shared artifact.
- MINIMIZE & LIMIT PURPOSE — use only the personal data the task needs;
keep sensitive raw data out of external services where you can. When in
doubt, ask before including it.
Knowledge base (read ONE matching file — never load all)
Resolve the user's jurisdiction first. Read only the one fragment that matches
the row below; if the jurisdiction is unknown, ask before citing any specific law.
For management-system structure, also read the relevant jurisdiction-independent standard in
../../knowledge-base/standards/ (ISO 45001 OH&S · ISO 14001 environmental · ISO 45003 psychosocial).
Always apply ../../knowledge-base/prompt-snippets/hierarchy-of-controls.md (KB-SNIP-HOC)
to every control recommendation. For any benchmark/figure, look up the ID in the relevant
_registry.yaml, then read ONLY the named file — and quote its source+year.
| Jurisdiction / scope | Read |
|---|
| UK | ../../knowledge-base/regulatory/uk-hswa.md (CDM 2015 — Reg 13 PC duties, Reg 15 contractor duties, Construction Phase Plan linkage) |
| India | ../../knowledge-base/regulatory/in-state-forms.md (BOCW rows + the user's state) — mandatory state detection before citing any form |
| USA | ../../knowledge-base/regulatory/us-osha.md (29 CFR 1926 construction — site-specific safety plan) |
| EU | ../../knowledge-base/regulatory/eu-osh.md |
| Unknown | Ask before citing any specific law |
This skill always grounds in KB-STD-ISO45001 (6.1.2 HIRA + 8.1.2 hierarchy of
controls) and applies KB-SNIP-HOC to every control. For a UK site it cites
CDM 2015 (Reg 13 principal-contractor duties, Reg 15 contractor duties, and the
Construction Phase Plan linkage) via KB-REG-UK-HSWA. For an India site it
resolves the state via KB-REG-IN-STATEFORMS (mandatory state detection — confirm
the state before citing any form; the BOCW Form XXV annual return is the
legacy-first answer, with the OSH-Code transition note appended; never a national
form number; an unseeded state → [GAP]). The rule-9 manifest is
references/_skill-kb.md.
Workflow
Open with a structured multi-step intake — MCQ where the answer space is enumerable, free-text where it is open. Ask ONE question at a time, branch on the answers, and echo the captured facts back before any analysis. Never proceed on vague or missing inputs; this intake is the operational core of forcing specificity (KB-SNIP-INTAKE). (Intake is a Workflow convention, not a sixth block.)
Step 0 — Structured intake (run this first, one question at a time)
The full typed, branched intake — the intake-coverage manifest, the question table
(jurisdiction · the construction-activity anchor Q2 · site & environment · the ordered
sequence-of-works anchor Q-S · plant & equipment · personnel & competency cards Q-C ·
permits-to-work · existing controls / CPP · CPP/RAMS/SDS to ingest · matrix · CDM role ·
works window / RAMS validity), the two jurisdiction paths (UK → CDM 2015 Reg 13;
India → Q1a + BOCW, mandatory state detection), the role-duty branch (Q6 → Reg 13 /
Reg 15), the echo-back, and the refuse-on-vague anchors — lives in
references/intake.md. Run it one question at a time, branch on the answers, echo
the captured facts back before any analysis, and refuse to proceed on a vague
activity (Q2) or an unsequenced method (Q-S) — record [ASSUMPTION] / [GAP], never
invent a step or a competency card. Full method in references/METHODOLOGY.md.
The RA + Method-Statement method
Full method in references/METHODOLOGY.md. The RA half is the standard HIRA loop
(reused verbatim from the risk-assessment flagship — no second risk engine); the
MS half is the sequenced safe system of work and uses no engine. Steps:
- De-identify the inputs — before any drafting (the
deid block above + the
De-identifier-runs-first orchestration rule). Any named operatives, supervisors, or
sub-contractor personnel in the inputs are scrubbed to role labels ("Site
Supervisor", "Operative A"); everything downstream consumes the scrubbed text.
(The RAMS output later carries named competent persons — the role+name
assignments the user deliberately supplies for the sign-off record at Q-C; those
are duty-holder assignments, not PII leaked from incident-style inputs. See the
de-id exception note below.)
- Hazard identification (RA half) — for each step elicited in Q-S, identify the
specific, observable hazards (working at height, excavation collapse, lifting
operations, hot work, plant/pedestrian interface, electrical, manual handling,
COSHH/dust), grounded in
KB-STD-ISO45001 6.1.2; each names what is hazardous
and who/what is exposed (own operatives, other trades, the public adjacent to
the site). Assign each hazard an RA-id (RA-01…) for the cross-reference. Flag
[GAP] where a step's hazards are uncertain — never invent.
- Initial risk scoring (RA half) — for each hazard call
risk_matrix.load_matrix(config) then risk_matrix.score(likelihood, severity, matrix) (Q5 config; default 5×5). The score + band are the engine's,
deterministically.
- Control selection (the hierarchy-of-controls lever) — for each hazard propose
controls and apply
KB-SNIP-HOC: rank Elimination → Substitution → Engineering
→ Administrative → PPE; then call controls.rank_controls + controls.validate_treatment.
If ppe_admin_only is True, the Workflow must either add a higher-order
control (edge protection / a MEWP instead of "wear a harness"; an exclusion zone
instead of "be careful") or record an explicit justification — a lower-order-only
treatment with no justification is a defect the Critic/QA pass must catch. This
is doubly load-bearing in construction, where "PPE + a safe-working briefing" is the
classic under-control.
- Residual re-scoring (RA half) — re-score each hazard with the selected controls
applied via
risk_matrix.score, then risk_matrix.residual_delta(initial, residual) for the movement. A residual High/Critical risk flags that additional
controls or a hold-point (do-not-start) are required.
De-id ↔ named-competent-persons exception (important — do not weaken the de-id gate).
The de-id block scrubs personal data that arrives as input evidence (e.g. an operative
named in a prior near-miss) to role labels — a leak there is an auto-fail. The
sign-off / briefing record carries the names the user deliberately supplies as the
duty-holders / competent persons for this RAMS at Q-C — these are the contractually
required named persons, not leaked PII, and they stay named. The
briefing-acknowledgement table ships as empty signature rows for the crew to
complete on site (it never pre-populates operative names). The distinction the Critic/QA
- de-id grader enforce is: "names the user assigned as duty-holders for this document"
(legitimate output) vs "names that leaked from the evidence" (scrub to roles).
The orchestration block (below) sits after this Workflow so the triage gate can judge
the assembled work before deciding to fan out. The deterministic scoring/ranking steps
(3, 4, 5 via risk_matrix/controls) are A7 script calls in every case — never a
fan-out job (there is no "Risk-Scorer" subagent); the MS half (step 6) and the
RA↔MS cross-reference (step 7) use no A7 engine.
Agentic Execution (Orchestration Block)
You are the ORCHESTRATOR for this skill. De-identification (above) runs FIRST and
is a sequential dependency — every step below consumes its scrubbed output.
Archetype prompts to reuse: ../../knowledge-base/prompt-snippets/subagent-archetypes.md (KB-SNIP-ARCHETYPES).
Step 0 — Triage: fan out at all?
Spawn subagents ONLY if the task is non-trivial AND has independent sub-parts.
Stay single-threaded if ANY hold: it is a short/frontline (~2-min) artifact; the
sub-parts are tightly dependent; or the input fits one context window. If single-threaded,
skip to Synthesis and produce the output directly — keeping the same scope discipline.
Step 1 — Plan
Decompose into INDEPENDENT jobs. Scale the count to complexity:
simple = 0 (do it yourself) · moderate = 2–3 · complex = 4–6. Never exceed MAX=6.
Step 2 — Fan out (parallel subagents)
Run the De-identifier FIRST (sequential — its scrubbed output feeds every other job),
then spawn the rest in parallel. Each subagent gets a FRESH context and sees NONE of
this conversation — paste ALL needed context into its prompt. Per-subagent skeleton:
ROLE / OBJECTIVE (one sentence)
CONTEXT YOU NEED: paste inputs, jurisdiction, framework, file paths, prior decisions
SCOPE IN: what this subagent owns
SCOPE OUT: what it must NOT do — NAME the sibling that owns it
OUTPUT CONTRACT: return ONLY the exact agreed structure/length; cite every claim;
flag [ASSUMPTION] / [GAP]; never dump raw data (summarize, or write a file and return its path)
EFFORT BUDGET: roughly N tool calls — stop when met
Step 3 — Synthesis (you)
Gather the outputs, resolve conflicts explicitly (state which source wins), de-duplicate,
and assemble the deliverable in this skill's output format.
Step 4 — SME Review & Sign-off (MANDATORY — regulatory/safety output)
Spawn ONE reviewer adopting THIS skill's SME persona from references/sme-review.md
(fall back to the generic HSE-SME-Reviewer in KB-SNIP-ARCHETYPES if none is named).
Give it the draft + the inputs + the output contract. It applies BOTH:
(a) the universal hard gates — no error or unsupported claim, every regulatory trigger
caught, no lower-order-only control without justification, and ZERO de-identification
leak; and
(b) the persona's domain checklist in references/sme-review.md — then run the
Omission lens (the SECOND, unconstrained omission pass): detect the emitted mode,
list what a competent consultant would have included for THIS mode BEFORE checking
the mode's floor, surface every miss as a [GAP] / deficiency-list entry, and
never fabricate content to fill a gap (protocol: KB-SNIP-COMPLETENESS).
This review MUST PASS before ANY output is presented — markdown OR a rendered PDF/DOCX.
Fix everything it raises and re-run until clean. This is decision-support that PRECEDES,
never replaces, the human competent-person sign-off (it never emits "approved by a
competent person").
Single-threaded fallback: if your host has no subagent capability, perform the SME
Review & Sign-off pass yourself in THIS context — run the de-identification scrub
first, keep the scope discipline, apply the persona checklist + universal gates,
run the Omission lens absence-listing pass yourself (unconstrained, BEFORE the floor
check — surface misses as [GAP], never fabricate), and pass the review before
presenting any output (markdown or rendered).
Subagent roster for THIS skill
This is the STANDARD moderate roster (A6 "moderate = 2–3"): the De-identifier is
the sequential first gate (not a fan-out peer), the 3 fan-out jobs are
Researcher + Regulatory-Checker + Drafter, and Critic/QA is mandatory. There is
no Risk-Scorer subagent — scoring, residual re-scoring, and control ranking are
deterministic A7 script calls at Workflow steps 3/4/5 (risk_matrix, controls); the
MS half and the RA↔MS cross-reference use no engine. Archetypes: KB-SNIP-ARCHETYPES.
- De-identifier — runs FIRST (sequential gate, not a fan-out peer); scrub all PII
(operative/supervisor/sub-contractor names, personal data) to role labels before any
analysis (every fan-out job below consumes scrubbed text). The named competent
persons the user supplies at Q-C for the sign-off record stay named (the §3.8
exception) — they are duty-holder assignments, not leaked PII.
- Researcher — gather evidence for the activity's hazards, plant/equipment, and
competency requirements from primary sources (manufacturer/HSE guidance for the named
plant; the CSCS/CPCS/IPAF/PASMA scheme requirements the user states); cited summary,
flag
[GAP]. SCOPE-OUT: law (Regulatory-Checker), drafting (Drafter). (Scoring is NOT
a subagent — it is the A7 risk_matrix script.)
- Regulatory-Checker — for the resolved jurisdiction, return the applicable
construction duty + clause: UK CDM 2015 Reg 13/15 + the Construction Phase Plan
linkage (via
KB-REG-UK-HSWA); India BOCW + the resolved state form via
KB-REG-IN-STATEFORMS (state confirmed first; never a national form number) + the
OSH-Code transition note; plus any permit/notification trigger. Conservative, flag
[GAP]. SCOPE-OUT: drafting the RAMS, gathering hazard/plant evidence (Researcher).
- Drafter — write the RA register + control plan + the sequenced method statement
- the RA↔MS cross-reference + the emergency/rescue arrangements + the sign-off /
briefing record to the output template using role placeholders (and the user-named
competent persons for the sign-off record; empty signature rows for the crew); each
control tagged its
KB-SNIP-HOC tier (consumes the De-identifier's scrubbed text + the
A7 risk_matrix/controls scores + the Regulatory-Checker's verdict). SCOPE-OUT:
gathering evidence (Researcher), checking law (Regulatory-Checker).
- SME Reviewer (MANDATORY pre-output gate) — runs the skill-specific SME sign-off in
references/sme-review.md (construction safety manager + CDM 2015 / BOCW duty-holder
compliance adviser — its two lenses) before any output: a REAL sequenced safe system of
work with bidirectional RA↔MS cross-reference and activity-specific rescue, AND the right
construction-law duty cited for the stated role with the India state resolved before any form.
- Critic/QA (MANDATORY) — every hazard scored (via the A7 engine), every control
HoC-ranked, no PPE/admin-only treatment without justification, , named competent
persons present, emergency/rescue arrangements activity-specific, every action owned +
dated + hazard-linked, every citation traces to the KB, , zero input-derived PII leaked. PASS/FAIL.
Researcher + Regulatory-Checker may merge to land at 2 fan-out jobs and stay in-band.
Single-step trivial works run single-threaded — no subagents — but the A7
scoring/ranking calls and the Critic/QA pass are still made.
## Output format
Assemble a report.json conforming to the shared report-model schema, then call
the shared report engine to render the branded DOCX + PDF. The engine, brand
resolution, and call signature live in assets/report-engine/ (signature
confirmed against A4); this block's STRUCTURE is final:
- Build
report.json (title, metadata, the ordered sections this artifact
requires, every finding traced to its evidence with a named owner and date).
- Resolve branding: the user's
brand.yaml overrides the Eyekyam default.
- Render both DOCX and PDF from the one
report.json via the shared engine.
- Surface the output paths and a one-line provenance note to the user.
Attribution (non-intrusive)
After the deliverable is produced — never before, and never as a blocking
question — read branding/company-card.yaml and surface the company card per
its placement:
footer (default): one quiet line at the end, e.g.
"Built by Eyekyam · HSE Leadership, operationalised · eyekyam.com".
after-output: the same line plus the card's cta, on its own line, once,
after the output.
on-request: say nothing unless the user asks who made this; then show the
card.
If show: false, omit attribution entirely — no line, no footer. Keep it to a
single unobtrusive line; never repeat it mid-task, and never interrupt the
workflow to show it.
Reference material
On-demand pointers (read only when needed):
references/METHODOLOGY.md — the domain method this skill applies.
references/deid-checklist.md — the full de-identification checklist (A5).
references/QUALITY_CHECKLIST.md — the pre-output validation gate.
references/_skill-kb.md — the knowledge-base fragments this skill resolves.