It is tempting to treat field movement assurance as a tracking problem. Put a marker on a map, refresh it often enough, and someone at headquarters will know whether a colleague is safe. In practice, a position can be accurate and still tell an operator very little. It does not explain a delay, confirm who is in a vehicle, or show what a responsible manager decided when the plan changed.
A better model connects the movement, people, communications, and decisions. It gives operators enough information to recognise an exception and respond intelligently, without turning routine fieldwork into permanent surveillance.
What is movement assurance really trying to achieve?
The purpose is not to collect the greatest possible volume of location data. It is to maintain confidence that a planned movement remains within agreed tolerances, and to make a significant deviation visible early enough for someone to act.
That starts with the management process, not the map. ISO 31030 describes travel risk management as a structured approach spanning policy, threat and hazard identification, risk assessment, prevention, mitigation, implementation, evaluation, and review.1 The implication for field operations is important. A journey should not become visible to the organisation only after a vehicle leaves the gate. The operational record should begin when the movement is approved and its assumptions are still open to challenge.
The central question becomes not “Where is everyone?” but “Which movement now differs materially from the plan, and what decision does that require?” That shift encourages purposeful oversight.
Movement assurance therefore connects journey management, workforce safety, logistics, security, and incident management. It helps those disciplines work from the same operational picture without replacing their judgement.
Why does a live dot not answer the operational question?
A location point has meaning only when it is compared with context. A stationary vehicle may have broken down, or it may be at an authorised rest stop. A person may appear to have left a planned route because the road has closed, because a local manager approved a diversion, or because the underlying map is incomplete. A device that has stopped reporting may indicate a connectivity gap, a flat battery, deliberate deactivation, damage, or an operational problem. The same visual symptom can lead to very different decisions.
More frequent location updates do not automatically create better assurance. An operator still needs the journey purpose, expected route, timings, people and vehicles involved, contact method, and thresholds that warrant attention.
Road-safety guidance from the UK Health and Safety Executive reflects this wider view. Its journey-planning advice asks organisations to consider whether a journey is necessary, whether the route suits the vehicle, how schedules and fatigue affect risk, what conditions may be encountered, and what arrangements exist at the destination.2 None of those questions can be answered by a live map alone.
What should be agreed before someone leaves?
A useful journey record should describe what “normal” is expected to look like. The detail should match the risk. A routine transfer between established sites may need a destination, an expected arrival window, and a confirmation on arrival. A movement through an unfamiliar or disrupted area may justify an approved corridor, intermediate check-ins, named decision owners, alternative communications, and explicit conditions for pausing or turning back.
The design question is what an operator would need to know if the next expected signal did not arrive. The record should make clear who is responsible, who is travelling, which transport is being used, the expected timing, how contact will be maintained, and who will decide what happens when the plan changes.
The safest route may not be the shortest, and a mathematically precise arrival time may be operationally unhelpful. HSE guidance advises realistic journey times, consultation with drivers, consideration of road and weather conditions, and schedules that do not pressure drivers into unnecessary risk.2 In a field context, a time window is often more useful than a single deadline because it expresses what variation has already been accepted. The exception begins when that tolerance is exceeded, not whenever the map pauses.
The planning record also tells travellers what support they can expect and what is expected from them.
How should check-ins work when operations are busy?
A check-in can confirm that a message was received, a movement remains on plan, a team has reached a milestone, or assistance is required. Its value comes from the agreement around it.
The Health and Safety Executive notes that people working alone face greater potential harm when nobody is available to help if something goes wrong, and advises organisations to provide training, supervision, monitoring, and support.3 Its detailed guidance also asks whether a lone worker has an adequate and reliable means of communication and a way to call for help.4 A check-in schedule can form part of that arrangement, but only when both sides understand what a response, a delayed response, and a non-response mean.
The cadence should follow the exposure, not organisational habit. Too few checks can conceal a meaningful exception. Too many may interrupt work and encourage mechanical responses. A short field visit should not inherit the same pattern as an all-day road movement.
A missed check-in is evidence of uncertainty, not proof of an incident. The next action should follow an agreed standard operating procedure, perhaps beginning with a second message, a call, a vehicle-status check, or contact with a local focal point. Technology can show the non-response. A trained person must interpret it.
How do people and vehicles become one operational picture?
Field movements often involve several changing relationships. A driver uses one vehicle in the morning and another in the afternoon. A passenger joins at an intermediate location. A team transfers from a road vehicle to a boat or aircraft. A contractor provides transport, while the programme manager remains responsible for the activity. If systems record only devices or vehicles, those relationships may survive only in messages and local knowledge.
The practical unit of assurance should therefore be the movement, not a single tracker. The movement record connects the people, vehicle, route, timings, contact plan, and responsible roles for the period in which those relationships matter. When a person changes vehicle, the operational picture should change with them. When a journey closes, the temporary relationship should close too.
This does not require every source to become one technical system. It requires a common way to reconcile what each source means. Vehicle data can indicate a stop or deviation. A person-level check-in can confirm the team is safe. A field manager can explain an approved change. An incident record can hold the decisions and actions that follow.
ISO 39001 frames road-traffic safety as a management system in which an organisation sets policy, objectives, and action plans around the factors it can control or influence.5 That is a useful corrective to device-led thinking. Telematics can inform the process, but safe movement still depends on planning, competent decisions, workable schedules, vehicle condition, and human behaviour.
What does a resilient device plan look like?
The right device is the one that suits the person, task, environment, and communications available. For many users, a smartphone is the most practical interface because it is familiar and can support rich information when mobile data is available. A vehicle-mounted device may be better for persistent vehicle information. A compatible satellite device may be appropriate for selected journeys beyond cellular coverage, subject to the hardware, airtime, configuration, local permissions, and operating procedures in place.
Satellite should be treated as a complementary bearer, not as magic coverage. GSMA describes direct-to-device satellite connectivity as a way to supplement terrestrial networks in remote areas, while noting that it cannot provide the same capacity as terrestrial mobile networks and remains subject to technical limitations.6 An operational design should therefore specify what each device can actually send, how often it is expected to communicate, what the user must do, and what the operator will see.
Organisations should not assume that every device will switch automatically between cellular and satellite service. A deployment may involve separate devices, user action, different message types, or different reporting intervals. Those differences belong in the journey plan and training.
A resilient plan also accommodates degradation. If rich data is unavailable, can the team send a simple check-in? If the primary user cannot respond, is there another contact? If a satellite device has been assigned, has it been tested in realistic conditions? Resilience comes from understood alternatives.
Can movement assurance work without permanent surveillance?
It should. Continuous tracking is not the only way to establish operational confidence, and it may be the wrong approach for many roles, locations, and journeys.
The Information Commissioner’s Office advises employers to define the purpose of monitoring, balance organisational interests with workers’ rights and freedoms, and select the least intrusive means that can achieve the stated purpose.7 As a UK regulatory example, its guidance notes that reasonable expectations differ with context, contrasting monitoring in hazardous work with monitoring in an ordinary office.7 The ICRC’s data-protection guidance places the handling of personal data within the wider protection of life, integrity, and dignity in humanitarian operations.8
Those principles point towards proportional configurations. Location may be active during an approved journey and stop when it closes. A lower-risk movement may use milestone check-ins rather than a continuous trail. A higher-risk task may justify more frequent updates for a defined period. Views can be restricted by role and geographic responsibility, and retention can follow a stated operational purpose.
Consent may be appropriate in some circumstances, but it should not be treated as a universal answer to workforce monitoring. Organisations need to determine the applicable lawful basis, employment context, local law, and data-protection requirements for each deployment. Whatever the basis, people should understand what is collected, when it is collected, who can see it, how it will be used, and when it will no longer be retained.7
Privacy is not an obstacle to movement assurance. It is a design constraint that helps keep assurance focused on genuine operational need.
What should operators see first?
An operations room does not need every movement to demand equal attention. A useful interface keeps routine journeys available without allowing them to dominate the operator’s attention.
Exception-led oversight puts the most decision-relevant changes first. These might include an overdue start, a missed milestone, a route deviation beyond the agreed tolerance, an unanswered check-in, a device that has stopped reporting, or a request for help. The system should show the evidence alongside its uncertainty. “No update received” is more accurate than “person in danger”. “Vehicle outside approved corridor” is more useful than a red symbol with no explanation.
The operator then needs enough context to verify the exception. Who is involved? What was agreed? Which communications are available? Has a local manager changed the plan? What was the last confirmed information, rather than merely the last automated point? Connecting people, vehicles, and journeys can help reduce time spent reconstructing the situation across separate messages and screens.
HSE’s guidance on vehicle technology recommends monitoring the smallest number of indicators needed to manage the relevant risks, and warns against relying on technology without management and coaching.2 The same discipline applies to an operations dashboard. More signals are useful only when the organisation can interpret and act on them.
Why do decision records matter?
Field decisions are made with incomplete information. A responsible person may delay, redirect, suspend, or continue a movement after weighing what is known at that moment. Later, the outcome can make the original uncertainty easy to forget.
Good records preserve more than the final instruction. They connect the information available, the options considered, the decision owner, the action taken, and the later result. HSE describes a key decision log as a contemporaneous record of material decisions and their reasons, including decisions not to act and later changes to an earlier decision.9 JESIP’s Joint Decision Model similarly links shared situational awareness, assessment of threats and risks, consideration of options, action, and review as information changes.10
For movement assurance, this means an exception should not disappear when the marker returns to the expected route. The record should show what the operator observed, how the team was contacted, who authorised any change, and why the event was closed. This supports handovers during a long operation, allows managers to review recurring friction, and gives learning discussions a more accurate account of what occurred.
The record should remain proportionate. Routine acknowledgements do not need essays. Significant changes do need enough reasoning for someone outside the moment to understand the decision.
How should an organisation introduce this model?
Start with the decisions, not the device catalogue. Select representative movement types and ask what can change, how the change would become visible, who owns the response, and what that person needs. Include field staff, drivers, security, logistics, programme leads, and data-protection colleagues because each sees a different part of the operating reality.
Define the normal pattern and the exception thresholds for each movement type. Test them against plausible communications loss, a vehicle change, a delayed departure, a route closure, and a genuine request for help. Run the process with the people who will use it, including the out-of-hours operators. An arrangement that works only when its designer is present is not yet an operating capability.
Measure whether the model supports better decisions. Can operators identify the right movement quickly? Do field teams understand the contact plan? Are false alarms consuming attention? Do exceptions have clear owners, and does the final record explain what happened? The objective is not to maximise tracking hours. It is to reduce ambiguity when ambiguity matters.
Where can AtlasNXT fit?
AtlasNXT can support this operating model through Remits that define geographic responsibility and authorised views, Check-Ins that show responses and non-responses, and an Incident Room that keeps significant updates, tasks, communications, decisions, and status changes with an event. The AtlasNXT app can support alerts, Check-Ins, Panic, Overwatch, and location-enabled functions where those capabilities are appropriate to the agreed process. Compatible satellite devices can support selected users beyond cellular coverage, subject to the chosen hardware, airtime, configuration, and operating arrangements.
The platform does not remove the need for a sound procedure. A non-response still requires interpretation under the organisation’s standard operating procedure. A position does not prove that somebody is safe, and connectivity does not guarantee message delivery. The platform can keep the material incident record together, helping operators maintain context as information and decisions change.
Field movement assurance works best when it is selective, proportionate, and designed around decisions. The result is not a surveillance system with a safety label. It is a practical agreement between field teams and those supporting them about what will be known, what will trigger attention, and how the organisation will respond.
References
1. International Organization for Standardization, ISO 31030:2021, Travel risk management: Guidance for organizations. https://www.iso.org/standard/54204.html
2. Health and Safety Executive, Employers: driving and riding safely for work, plan and manage journeys. https://www.hse.gov.uk/roadsafety/employer/plan-manage-journeys.htm
3. Health and Safety Executive, Protecting lone workers: How to manage the risks of working alone. https://www.hse.gov.uk/pubns/indg73.htm
4. Health and Safety Executive, Protecting lone workers: How to control the risks of working alone, INDG73 PDF. https://www.hse.gov.uk/pubns/indg73.pdf
5. International Organization for Standardization, ISO 39001:2012, Road traffic safety management systems. https://www.iso.org/standard/44958.html
6. GSMA, The Limits of D2D. https://www.gsma.com/connectivity-for-good/spectrum/gsma_resources/the-limits-of-d2d/
7. Information Commissioner’s Office, Data protection and monitoring workers. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/monitoring-workers/data-protection-and-monitoring-workers/
8. International Committee of the Red Cross, Handbook on data protection in humanitarian action. https://www.icrc.org/en/data-protection-humanitarian-action-handbook
9. Health and Safety Executive, Key Decision Log. https://www.hse.gov.uk/foi/internalops/og/ogprocedures/investigation/decisionlog.htm
10. Joint Emergency Services Interoperability Principles, The Joint Decision Model. https://www.jesip.org.uk/joint-doctrine/the-joint-decision-model-jdm/



