SAFVR

MOOSH by SAFVR · UK-first

Turn workplace signals into psychosocial risk action.

MOOSH helps HR and EHS teams assess organisational psychosocial risk, review controls, consult workers, and build an evidence trail—without exposing individual responses.

Designed around HSE Management Standards and ISO 45003 guidance · Human-reviewed AI · Privacy-first cohort reporting

Isometric workplace cutaway showing anonymous cohort and operational signals flowing through a privacy-safe assessment layer to human review, worker consultation, and evidence.
Cohort-level assessment
Authorised human review

01 / Definition

What is organisational psychosocial risk management?

It is the systematic identification and control of workplace conditions—such as demands, control, support, relationships, role, and change—that may create work-related stress or harm.

MOOSH is designed as the operating layer between assessment and action: it connects approved signals to cohort-level risk, human-reviewed controls, worker consultation, effectiveness review, and a linked evidence trail.

02 / The operating gap

Surveys stop before the work changes.

Fragmented today

  • Anonymous surveys in one system
  • Absence and workload signals in another
  • Incidents and support cases elsewhere
  • Manual spreadsheets for actions and evidence

MOOSH operating loop

  • Cohort-level signals are assessed together
  • Risks retain score and source lineage
  • Controls are drafted, reviewed, owned, and tested
  • Consultation and assurance evidence stay linked

03 / Signal fusion

Explainable risk, with its sources still attached.

MOOSH is designed to combine anonymous cohort check-ins with approved operational indicators while preserving lineage, freshness, and confidence. Named employees never become one opaque risk score.

Permitted inputs

Cohort + operations

  • Anonymous check-ins
  • Approved operational signals
  • Source freshness visible

Versioned assessment

01

Inherent

02

Exposure

03

Current

04

Residual

Confidence reflects unavailable or stale sources

Human-reviewed outputs

Controls to evidence

  • Control review
  • Consultation record
  • Evidence chain
Identified support / incident routeStructurally separate · never joined to assessment

Sources: Anonymous check-ins and approved operational indicators remain attributable to their source and freshness state.

Anonymous cohort check-ins and approved operational signals enter a versioned assessment. Identified support and incident records use a separate route that never joins the assessment rail.

04 / How it works

Assess. Score. Control. Consult. Review. Assure.

A risk score is a starting point. Each material risk moves through a human-controlled loop until ownership, effectiveness, residual risk, and evidence can be reviewed.

AI drafts. Authorised people decide.

Assess: Collect fixed, versioned workplace-risk items at an approved cohort level.

Assess, Score, Control, Consult, Review, and Assure. AI drafts while authorised people make every control decision.

05 / Protected views

One system. Deliberately different views.

Access narrows with responsibility. Organisation assurance does not expose individual check-ins, and a manager view remains aggregate-only when the approved threshold is met.

Protected product view

HR / EHS

Organisation-level risks, controls, consultation, and evidence status.

Role-scoped
01

Risk register

02

Control ownership

03

Consultation evidence

04

Evidence coverage

OrganisationAllowed
Team aggregateAggregate only
Own recordNot available
  • HR / EHS: Organisation assurance. Organisation-level risks, controls, consultation, and evidence status.
  • Manager: Approved team aggregate. Own-team trends only when the approved anonymity threshold is met.
  • Employee: Own record. Private check-in summary, support choices, and personal requests.
  • Board / assurance: Organisation assurance. Residual-risk trend, exceptions, approvals, and framework coverage.

06 / Human review

Consultation is an operating step, not a survey follow-up.

Worker representatives, HR/EHS reviewers, and control owners can connect the risk signal to the proposed change, record alternatives or dissent, and return reviewed evidence to the next assessment cycle.

AI drafts. Authorised people decide.

MOOSH is designed to assist review—not replace worker consultation, competent people, occupational health, HR, or DPO judgement.

Isometric consultation room where worker representatives and authorised reviewers connect aggregated workplace signals to controls, evidence, and a review feedback loop.

07 / Privacy architecture

Privacy is part of the workflow.

Anonymous assessment and user-initiated support serve different purposes. MOOSH is designed so their routes remain structurally separate instead of being merged into one employee profile.

Isometric privacy diagram showing anonymous cohort assessment and user-initiated support records travelling through separate routes that never join.
01

Cohort protection

Planned for the MVP: results are suppressed below the approved anonymity floor, subject to deployment policy.

02

Data separation

Designed so anonymous assessments remain separate from identified support and incident records.

03

Manager isolation

Designed so managers receive permitted team aggregates, not individual assessment responses.

04

Pre-processing gate

No live processing should begin until the applicable legal, DPIA, jurisdiction, and deployment controls are approved.

08 / Deployment path

From baseline to assurance.

The sequence begins with readiness and approved boundaries—not live data collection.

  1. 01

    Confirm organisational structure and the active UK framework pack

    Owner, decision, source, and evidence remain attached to the stage.

  2. 02

    Complete the privacy and deployment readiness gate

    Owner, decision, source, and evidence remain attached to the stage.

  3. 03

    Invite an approved cohort to baseline and pulse check-ins

    Owner, decision, source, and evidence remain attached to the stage.

  4. 04

    Fuse approved operational signals and compute cohort risk

    Owner, decision, source, and evidence remain attached to the stage.

  5. 05

    Review, assign, consult on, and test controls

    Owner, decision, source, and evidence remain attached to the stage.

  6. 06

    Generate a reproducible leadership or audit evidence pack

    Owner, decision, source, and evidence remain attached to the stage.

09 / Standards + oversight

Guidance mapped. Claims qualified. Decisions human.

These references guide the intended workflow. They are not certifications, endorsements, or a substitute for deployment-specific legal and competent-person review.

MOOSH does not claim ISO certification, HSE approval, or blanket GDPR compliance. Public implementation claims remain subject to product and legal approval.

10 / FAQ

Questions privacy and risk owners should ask.

01Is MOOSH a mental-health diagnostic tool?

No. MOOSH is designed for organisational psychosocial-risk management. It does not diagnose conditions, predict individual illness, or rank employees.

02Can managers see individual employee answers?

MOOSH is designed so managers receive only permitted team aggregates when the approved anonymity threshold is met. Individual assessment responses are not a manager view.

03What happens when fewer than five people respond?

The MVP is planned to suppress a visible slice below the approved anonymity floor and show an insufficient-data state instead. The final threshold behavior remains subject to deployment policy and legal approval.

04What data can MOOSH connect to?

The intended assessment route can use anonymous check-ins and approved operational indicators such as workload, absence, and incident trends. Every source must be explicitly approved, scoped, and freshness-checked for the deployment.

05Does AI make decisions about employees or controls?

No. AI may draft or assist with control options from approved sources. An authorised person must review, change, approve, or reject the draft before it becomes a decision.

06How does MOOSH support HSE and ISO 45003-aligned work?

MOOSH is designed around the HSE Management Standards areas and ISO 45003 psychosocial-risk guidance, connecting assessment to controls, consultation, review, and evidence. This does not constitute HSE approval or ISO certification.

07What must happen before live employee data is processed?

The intended process requires an approved jurisdiction pack plus deployment-specific legal, privacy, retention, security, and DPIA readiness decisions before live processing begins.

08How long does a pilot or deployment take?

Timing depends on organisational scope, cohort design, data-source readiness, procurement, and privacy approvals. A confirmed plan and duration are agreed after discovery; no universal pilot duration is promised on this page.

11 / Request a demo

Move from workplace signals to defensible action.

See how MOOSH can map assessment, controls, consultation, and assurance around your organisation.

Request a MOOSH demo