Inside the standard

OWHS v0.2 draft · the shape of it, on one page · full specification readable and downloadable

This page is for the reader who wants to see the actual shape of the thing: the entities, a real record, and the rules that make a record valid. It summarises a specification that runs to full per-field tables, versioned code lists, worked JSON Schemas with passing and failing examples, and a reference validator, all readable and downloadable here ahead of the public repository.

The entities

EntityWhat it records
OrganisationThe employer: Companies House number, SIC code for ONS-comparable sector, size band. Identity for organisations, never for people.
OrgUnitTeam or department, the unit results are aggregated to.
WorkerPseudonymA person, pseudonymously: an opaque identifier plus banded demographics only. Names, emails and dates of birth are structurally forbidden everywhere.
AbsenceEpisodeOne episode of sickness absence, with the ONS reason taxonomy and working-days-lost semantics, a fit-note flag, work-relatedness, and provenance. Optional SNOMED clinical-cause extension for those licensed to use it.
ReturnToWorkOutcomeWhat happened after: outcome type, adjustments drawn from the fit note's own categories, and sustained-return checkpoints. The entity with no official taxonomy anywhere: insurer and OH case systems track this in proprietary, non-harmonised ways.
OHEpisodeAn occupational-health referral and its management-facing result: referral reason, assessment type, categorical fitness opinion. Diagnosis and clinical content cannot appear, by schema.
ReasonableAdjustmentAn Equality Act adjustment: category, status, review date. One of the few things lawfully individual and employer-visible, and enumerated as such.
WellbeingObservationOne answer to one survey item from any vendor's product, with construct code, native and normalised values, and a sampling-design descriptor so consumers know whether gaps are planned or dropout.
InstrumentAdministrationA completed validated instrument, referenced by citation and version, never reproduced: scores, band per the instrument's published cut-points.
MeasurementContextWhat makes scores comparable: producing system, scoring approach, window, known limitations.
BenefitEntitlementWhat support a workforce has: statutory (SSP semantics) and commercial (the UK market's own product vocabulary), with access routes and health-domain tags shared with measurement.
BenefitUtilisationWhether provision gets used: aggregate counts per service per period. Individual usage is never employer-visible.
AggregateReportEmployer-visible aggregate results: level, n, value with interval, completion rate, and suppression metadata recording what was withheld and why.
BenchmarkReleaseA published comparison set with composition disclosed: contributing organisations, sectors, size bands, sample sizes, validity window.
CrosswalkVersioned mappings from every construct to the HSE Management Standards, ISO 45003, and the reserved namespace for the Workplace Health Intelligence Unit.
DisabilityParticipation reservedThe WHIU's third measure, held deliberately minimal until national definitions exist.
RiskAssessment / WorkplaceIncident reservedReserved shapes for psychosocial risk assessments and RIDDOR-adjacent incident records, not built in v0.1 or v0.2.

Statutory health surveillance, sector screening and vendor-specific machinery live in named profiles that extend the core without touching it. The full catalogue, field tables and code lists are in the specification.

The entity map

The same model as a picture: how the seventeen entities relate, which flows aggregate, and where the reserved shapes sit. Drawn from the specification's data model.

figure · the entity map, drawn for v0.1 and unchanged in v0.2open full size
OWHS entity map, drawn for v0.1 and unchanged in v0.2 Nineteen boxes on a grid: organisation-level entities across the top, the worker pseudonym and its individual-level records in the middle, the shared definitions along the bottom, the aggregate report and benchmark release on the right, and two reserved names. Solid lines are structural references, dotted lines are the aggregation flow into the report, dashed lines mark reserved names. has scopes groups reports provides used via subject of resolved by recommends informs enacted in measures, scores produced under tagged with aggregated into aggregated into composed from scoped to references maps reserved reserved Organisation the employer, outer boundary OrgUnit team; smallest unit reported BenefitEntitlement what support the workforce has BenefitUtilisation counts per service per period WorkerPseudonym opaque, per employer, banded AbsenceEpisode one sickness absence ReturnToWorkOutcome what happened after WorkplaceIncident reserved, no fields yet OHEpisode referral to fitness opinion ReasonableAdjustment Equality Act s.20 adjustment AggregateReport aggregate results for release DisabilityParticipation org level, banded, n at least 10 InstrumentAdministration scores and band, never items WellbeingObservation one item, one occasion BenchmarkRelease comparison set, composition shown RiskAssessment reserved, no fields yet Crosswalk to HSE MS, ISO 45003, whiu: ConstructDomain one health-domain vocabulary MeasurementContext what makes scores comparable
organisation level individual records; field-level disclosure rules apply aggregate reporting output shared definitions reserved, no fields yet

Individual instrument results are never employer-visible. Only the expressly classified individual-employer fields may be disclosed at individual grain under the specification's independent-legal-basis condition. The diagram does not grant permission to disclose a record.

Solid lines are structural references. Dotted lines are the aggregation flow. Aggregate-only field values reach an employer through a report that satisfies the privacy profile. The expressly classified individual-employer fields have a separate, narrow disclosure condition; individual instrument results remain prohibited from employer-visible output. Dashed outlines are reserved names, listed since v0.1 and not yet built. Open the map on its own page.

A real record

This is a valid AbsenceEpisode, exactly as the schema accepts it:

{
  "episodeId": "abs-2026-000123",
  "pseudonymId": "owhs:pseudo:a1b2c3d4e5f60718",   // keyed hash; no name, ever
  "reasonCode": "musculoskeletal",               // ONS reason taxonomy
  "startDate": "2026-03-02",
  "endDate": "2026-03-13",
  "workingDaysLost": 9,                          // ONS 7.5-hour day unit
  "fitNoteFlag": true,
  "workRelatedFlag": false,
  "sourceProvenance": { "sourceType": "hris" }
}

And this is what the reference validator says about the same record with a name added, a raw employee identifier as its pseudonym, a free-text reason and no provenance:

[additionalProperties] <root>: Additional properties are not allowed ('name' was unexpected)
[required] <root>: 'sourceProvenance' is a required property
[pattern] pseudonymId: 'EMP-Jane-Smith' does not match '^owhs:pseudo:[0-9a-f]{16,64}$'
[enum] reasonCode: 'back-pain' is not one of ['minor-illness', 'musculoskeletal', 'other', 'mental-health', 'gastrointestinal', 'respiratory', 'eye-ear-nose-mouth-dental', 'genito-urinary', 'heart-blood-pressure-circulation', 'headaches-migraines', 'prefers-not-to-give-details']

That is the design in one demonstration: privacy violations are not policy breaches to be audited after the fact. They are invalid data.

The four visibility classes

ClassMeaning
openStructural metadata, never personal. May appear in any output.
aggregate-onlyEmployer-visible only through an AggregateReport clearing the floor: five people minimum, ten for severe-distress measures.
individual-neverNever leaves the producer at individual grain in any output, even to the employer. All instrument results. All safeguarding-category signals, at any group size.
individual-employerThe narrow, exhaustively enumerated exception: things an employer lawfully holds about an identified pseudonym under an independent legal basis, such as a released fitness opinion or an Equality Act adjustment. Never clinical content.

Three conformance levels

Level 1, schema-valid: the structures hold, the identifier ban passes, the cross-field rules fire. Level 2, current code lists: every coded value resolves against the versioned registries, and dates make sense. Level 3, privacy profile: the aggregation floors, visibility classes and safeguarding exclusions are enforced, and a producer that cannot clear a floor refuses to emit the value rather than hiding it. A producer declares the highest level it meets; a consumer states the minimum it accepts.

Read the whole thing

The full specification, schemas, examples, code lists and the honesty pass (our own list of the decisions most worth disputing) are published here, with an open change process at github.com/openworkplacehealth/OWHS. Two of the specification's siblings are already live on this site: the instrument registry and the question bank. The Measurement Companion (construct definitions, the framework crosswalk, comparability rules) is available on request from hello@openworkplacehealth.org.

Read the draft specification