Accessing Hazards
Open the Hazards page from the left sidebar. The page displays all identified hazards with their risk levels, and you can switch between list view and risk matrix view.
Creating a Hazard
- Click New Hazard to create a new hazard record.
- Enter a descriptive name (e.g., “Battery thermal runaway”).
- Add a description explaining the hazardous condition.
Risk Assessment
Every hazard is assessed using two dimensions that combine to determine the overall risk level.Severity Levels
How bad could the outcome be?
Likelihood Levels
How often might this occur?
Risk Matrix
Severity and likelihood combine in a 5×4 matrix to determine the risk level:
Use the Matrix View toggle to see all hazards plotted on the risk matrix. Click any hazard to see its mitigation path traced across the matrix.

Potential Harm Classification
Beyond the hazard condition itself, document what harm could result:Harm Types
- Fatality
- Severe injury
- Moderate injury
- Minor injury
- Mission loss
- System loss
- Major damage
- Minor damage
- Environmental damage
Loss Domains
Who or what is affected:- People — Personnel safety
- Mission — Operational objectives
- Asset — Equipment and systems
- Environment — Environmental impact

Risk Control Path
The Risk Control Path shows how controls reduce risk from the initial assessment to the residual (final) level. Each control action is added in order of effectiveness.Adding Control Actions
- Click Add Control in the Risk Control Path section.
- Select the control type from the hierarchy of controls.
- Enter the resulting severity and likelihood after this control is applied.
- Document the rationale explaining why this control reduces risk.

Control Type Hierarchy
Controls are ordered by effectiveness (most effective first):
Control Status
Track the implementation state of each control:Verification Evidence
For verified controls, document:- Verification method — Test, analysis, inspection, or demonstration
- Verification date — When verification was completed
- Evidence reference — Test report ID, analysis document, etc.

Disposition
The disposition indicates the current risk acceptance state:
When accepting a residual risk, document:
- Accepted by — Name or role of accepting authority
- Acceptance date — When acceptance was granted
- Rationale — Why the residual risk is acceptable
- Scope — What configuration or version this applies to
Traceability
Assigned Systems
Link hazards to the Parts that could cause them or be affected. This maintains traceability between your safety analysis and system architecture.Mitigating Requirements
Link requirements that implement hazard controls. This ensures your requirements trace back to safety needs and vice versa.Interfaces
Link interfaces that are relevant to the hazard. This helps identify critical connections where hazards could propagate between system components.Views
List View
The default view shows hazards as expandable cards with:- Hazard ID and name
- Current risk level badge
- Severity and likelihood
- Disposition status
- Quick access to edit details

Risk Matrix View
Toggle to the matrix view to see:- All hazards plotted by severity (X-axis) and likelihood (Y-axis)
- Color-coded cells showing risk levels
- Mitigation paths showing how controls reduce risk
- Click hazards to see their control path traced across the matrix

Filtering and Search
Use the filter bar to narrow the hazard list by:- Risk Level — Extreme, High, Medium, Low
- Severity — Catastrophic through Negligible
- Likelihood — Frequent through Improbable
- Disposition — Unacceptable, Controlled, Accepted, Eliminated
Best Practices
- Write clear hazard descriptions — Describe the unsafe condition, not the consequence. “Battery overheating” not “Fire causes injury.”
- Be consistent with severity/likelihood — Use your organization’s definitions or adopt MIL-STD-882 criteria.
- Document rationale for risk assessments — Explain why you chose a particular severity or likelihood level.
- Apply controls in priority order — Start with elimination and work down the hierarchy. Lower-tier controls should supplement, not replace, higher-tier ones.
- Verify controls before acceptance — Don’t accept residual risk until controls are verified effective.
- Maintain traceability — Link hazards to affected Parts and mitigating Requirements for complete coverage.
Permissions
Hazard management respects model permissions:
Viewers can browse hazards but cannot modify them.