OWHS v0.2 draft · early open specification · on one page

What it is, how a record moves through it, and how it stays current.

An open data standard for UK workplace health, private by design, free for anyone to implement, with the evidence behind it kept up to date by a monthly cycle that a named human signs off.

16
entities defined, one shared shape, each with an executable schema
27
versioned code lists, anchored to ONS, HSE, the fit note
27
instruments graded, stage one of the field, every claim cited
85
survey items with provenance and rights
n ≥ 5
smallest group an employer ever sees
what it is

Three open, versioned things anyone may use

Free to implement, commercially or not, with no permission and no payment. The steward is named on every page, and so is its conflict of interest.

specification · v0.2 draft

A shared shape for workplace health records

Sickness absence, return to work, occupational health, wellbeing measurement and benefits, defined once in plain language and JSON Schema, using the definitions the UK already trusts.

CC-BY 4.0 prose · Apache 2.0 schemas · validator included
instrument registry · v0.9.0

What the evidence says about 27 questionnaires, stage one of the whole field

The open synthesis of the published evidence on workplace health and wellbeing instruments. Each graded across nine measurement properties, every claim cited, single items linked to the instruments they screen for, licence class verified against the steward's own page and archived. No ranking, no "best": it says what the literature says and leaves the choice to you.

JSON · CSV · PDF · published grading rubric v1.6
question bank · v0.2

85 survey items with provenance and rights

Each item traced to its source instrument, its licence position and its evidence record, grouped by topic. Nothing is reproduced that the rights-holder has not permitted.

JSON · CSV · PDF · per-item rights table
n ≥ 5n ≥ 10 for distress

Privacy is conformance, not a promise.OWHS prohibits direct identifiers in payloads. Its schemas reject undeclared core properties and apply the stated restrictions to extension keys. They cannot detect identifiers inside permitted values. Employer-visible aggregates must satisfy the applicable floor of five respondents, or ten for severe-distress measures. Individual instrument results are never employer-visible. Only the expressly classified individual-employer fields may be disclosed at individual grain under the specification's independent-legal-basis condition. Structural validation does not establish lawful processing or safe disclosure.

how it works

A record goes in. Only a safe aggregate comes out.

The same shape whether it comes from an HR system, an OH provider, a survey tool or a spreadsheet. The privacy rules sit in the schema, not in a policy document.

figure 1 · the path of one recordleft to right · any size of employer · no data team required
sources HR or payroll OH provider Survey tool Benefits, insurer OWHS entities AbsenceEpisode ReturnToWorkOutcome InstrumentAdministration + 13 more one shape · versioned · code lists pinned conformance check refuses names, IDs, free text, diagnoses pseudonymises the rest keyed HMAC, banded ages non-conformant: refused, not hidden aggregate groups of 5 or more 10 or more for distress safeguarding signals excluded at any size Aggregate report + completion rate what is not said, stated
standard-defined stepwhere a record can failaggregate reporting output
If you implement systemsAdopt one entity or one code list; that is a real test. Map an export you already produce and report where it broke. A failed mapping is worth as much as a clean one.
If you are an employerYou never see an individual's answers or episode. You see rates, counts above the floor, and the completion rate that tells you how much the number can bear.
If you set national definitionsBuilt to be overwritten: a namespace is reserved for official definitions, so when they arrive they slot in rather than start over.
how it stays current

A monthly loop that files itself, and a human who signs every change

Most standards die of maintenance. This one is built so that the maintenance is the cheap part and the judgement is the visible part.

figure 2 · the maintenance cyclethe designed cycle · scheduled monthly · steps 1 and 5 not yet automated · what has run and what is planned
1 Evidence sweep runs Europe PMC and OpenAlex; Crossref for DOI checks 2 Changes proposed in public as a pull request anyone can read 3 A named rater reviews, merges the only step that can change data 4 Dataset + changelog versioned each cell keeps its rubric and dates 5 Site + sweep report regenerated run by hand today; failures published 6 Corrections, any day errors of fact jump the queue Automation adds citations and flags cells for review. it never moves a grade a month with citations added and no grade moved is a good month
Stated on every pageAll grades were assigned by one rater, employed by the steward. Grades are frozen from first publication until two named psychometric raters who are not steward employees have joined.
Reproducible by designEvery graded cell names the rubric version, the date its literature was last searched, and the date a human last confirmed it. The rubric is published so anyone can redo a cell, or argue with it.
Correctable in publicErrata are listed. Instrument authors have a right of reply, published beside their record, dated and unedited. If stewardship fails, the licences let anyone fork and continue.