Frequently asked questions
Quick answers, pulled from the help centre guides. Each one links to the full step-by-step guide.
Getting started
Why won't my document generate?
The most common reason: company details aren't complete. Company name, company address (address line and postcode) and company email are required before any document generates — they appear on your PDFs. Fill them in Settings and retry; the message tells you exactly which field is missing.
Full guide: Set up your company details (required before generating)
Why was I asked for my company details when I signed up?
If you created your account through the Start your project flow on our website, the final step is Add your company details — Your company name and Your company address. Answering there completes this Settings step for you, so generating won't stop to ask for company details. Your company email defaults to your login email. You can change any of these later in Settings.
Full guide: Set up your company details (required before generating)
Is my company address the same as the site address?
Almost never — they're two different things and both appear on your documents. The site address is where the work is happening, which on domestic jobs is your customer's home. Your company address is your own trading address: it prints under your company name in the header of every RAMS, CPP, induction and emergency plan the account generates, so it identifies you as the contractor who issued the paperwork. Type your own address in the company field even if you're working a job round the corner. If you spot the wrong one on a document, fix it in Settings under Company Address and regenerate — the header picks up the new value.
Full guide: Set up your company details (required before generating)
Can I add my logo?
Yes — on Pro and above, upload your company logo from the Company Logo field in Settings and it appears on every generated document in place of the Starter watermark. If your plan doesn't include logo upload, that field shows a lock with an Upgrade to add your logo button instead of an upload control — it takes you to the pricing page. Accounts grandfathered into branded PDFs keep the upload control.
Full guide: Set up your company details (required before generating)
What is the "How did you hear about us?" question?
A one-time, optional question so we know which channels actually reach builders. At sign-up it's an optional How did you hear about us? dropdown on the company-details step — pick an option (or leave it on Choose one) and click Continue as normal. If you didn't answer there, a small card asks once more at the top of your Dashboard: pick an option and click Save answer, or click Don't ask again and it never comes back. It's voluntary, it can only be answered once, and the answer is stored with your account — included in your data export and deleted with your account.
Full guide: Set up your company details (required before generating)
Does Main Contact Name change a team member's login name?
No. Main Contact Name and Company Email are company-profile details used on your paperwork. Every team member keeps their own login name and login email for account activity such as requesting and approving documents.
Full guide: Set up your company details (required before generating)
How do notices at the top of the app update?
When you are signed in, service notices appear at the top of the app. The page checks for notices every five minutes and when you return to a hidden browser tab. Choose Dismiss (the X on the notice) to hide it. If the dismissal could not be saved, the notice may return on a later check. A temporary check failure keeps any notice already shown on screen.
Where is the What's New page?
It is at thesitebook.co.uk/changelog. You can also reach it from the footer of our public pages — Pricing, Features, Help and so on — under Resources, What's New. That footer is not part of the signed-in app, so from inside your account type the address or use the clickable link in the steps below. You do not need to be signed in either way.
How often is it updated?
We add an entry when a change worth telling you about reaches the live site, which is most weeks. Entries are dated by the day it went live, not the day we finished building it — so something we have finished may not appear until it has been released to everyone.
Why can I not see a feature listed there?
Two common reasons. It may be included on a higher plan than yours — each entry names the plan it needs, so check that line first. Or it may still be finishing testing: anything marked Early access is not switched on for everyone yet, and the entry says how to ask for it.
Does it list fixes as well as features?
No. The page covers changes you would notice as a builder — new features, improvements to existing ones, and new guides. Routine bug fixes and behind-the-scenes work are not listed.
Where do changes to cookies or privacy get announced?
Not on What's New — the policies themselves are the record, so the current position is always in one place rather than spread across dated entries. They are at thesitebook.co.uk/legal/privacy and thesitebook.co.uk/legal/cookies, both linked in the footer of our public pages under Legal. You are told directly when it matters: for a material change to the Privacy Policy we notify you by email or an in-app notice, and where a change needs a decision from you, such as a cookie choice, you are asked on screen at the time. The Cookie Policy carries a Last updated date at the top so you can see when it last changed.
How do I use a saved site on a project?
On the project's Details tab (and when creating a project), the Site section shows a "Use a saved site" dropdown — picking one fills the address and any nearest hospital confirmed for that exact address, and links the project to that site. The People section has matching "Use saved contact" dropdowns.
What does linking a project to a saved site do?
It groups the job with the others at that place, and on the Business plan it decides what site supervisors see: a supervisor assigned to a saved site (Team page) can open exactly the projects linked to it. Editing either the project's address or the saved site's address clears the affected project links, so access for one physical place never moves to another by accident.
What contact types can I save?
Client, Principal Contractor, Principal Designer, Architect, Structural Engineer and Emergency contacts.
What should I store here?
Company-level paperwork you get asked for on every job: public liability, employers' liability and professional indemnity insurance, your health & safety and environmental policies, and certifications. Store it once — it's available across all your projects.
Full guide: Store company documents: insurance, policies, certifications
Does it track expiry?
Yes — give a document an expiry date and its status turns amber as renewal approaches and red once expired, so a lapsed insurance certificate can't sit unnoticed.
Full guide: Store company documents: insurance, policies, certifications
What file types can I upload?
PDF, DOC, DOCX, or an image (JPG, PNG, WebP, HEIC).
Full guide: Store company documents: insurance, policies, certifications
Does the mobile app need access to my photo library?
No on Android: Photo opens Android's system photo picker and The Site Book receives only the image you select — no photo-library permission is requested. On iPhone or iPad, iOS may ask for photo-library access; you can limit access in iOS Settings. File opens the system file browser and needs no photo permission on either platform.
Full guide: Store company documents: insurance, policies, certifications
Do documents added in the mobile app open on the website?
Yes — documents added in the app (via Photo or File) sit on the same list — Settings → Company Docs on the website, More → Company documents in the app — and open with View, exactly like web uploads. Documents are stored privately, so each view opens through a fresh secure link rather than a permanent public address — an old link you saved or forwarded stops working after a while; open it from the list again instead.
Full guide: Store company documents: insurance, policies, certifications
Projects
How many projects do I get on the free plan?
Starter includes one real project free — no card needed — with unlimited documents on it, covering the core RAMS, Construction Phase Plan and site induction workflow. Pro (£39/mo, or £360/yr billed annually) unlocks unlimited projects.
Why can't I start a new job?
Three things stop it. If your Dashboard shows View all projects where New Project used to be, you are on the account as a team member — only an account owner or admin can start a job, so ask one of them. If it shows Upgrade to add more projects, either you are on Starter and already have your one project, so you need Pro at £39/mo for a second, or the subscription has been cancelled and the account is read-only until you reactivate it under Settings, then Billing. Site supervisors do not have a Dashboard at all — they go straight to their assigned projects and cannot start jobs. If you built a job on our website before signing in, the screen that turns you away tells you whether that draft is still saved, and until when — and while it is, a panel at the top of the Dashboard says so — Finish saving if you can start jobs, otherwise that the job is waiting for an owner or admin to pick it up on that same device (site supervisors have no Dashboard, so they never see it).
I built a job before signing in and cannot find it. Where is it?
While it is still recoverable, your Dashboard shows a panel at the very top naming the job and the date and time it is saved until. If you are an account owner or admin it says Finish saving and you can click straight through; if you are a team member it says the job is waiting for an owner or admin, because only they can start a job. The panel only appears in the same browser you started the job in, because that is where the job is held — it will not follow you to another device, another browser, or a private window, which is also why the owner or admin who picks it up has to sign in on that same device. If the panel is not there, that job can no longer be recovered, so start a new one from New Project. Site supervisors have no Dashboard and so never see the panel.
What does the role question change?
Your CDM role (Principal Contractor, Only Contractor, or Subcontractor) decides which documents and steps apply — subcontractors get a shorter flow and don't see the pre-construction plan upload. You can change the role later from the project overview.
I don't have the postcode yet — can I still start?
On our website, yes. If you're building the job through Start your project before signing in, put in whatever you have ("the old barn, Lower Farm Road" is fine) and carry on — a short note under the Site address field reminds you to add the postcode later, but it never stops you previewing or saving. Inside the app it's a different story: New Project asks for a Postcode as part of the site address, and the Emergency Plan wizard on the mobile app asks for one too — so have it to hand once you're set up. What the postcode buys you is the nearest A&E lookup. When you come to generate your CPP, RAMS, site induction or emergency plan, the project's Site Safety Setup asks for the nearest A&E — click Look up nearest A&E from the site address, or type the hospital in yourself. We never guess a location for a safety document: if we can't place the address, or there's no A&E within 20km, we say so and leave the field for you to fill.
What can the AI pull out of a pre-construction plan?
Upload the PCPP PDF your client sent and the AI reads every page — site address, client details, hazards and team members — and sets the project up for you. You review everything before it's final.
Why doesn't the RAMS wizard ask for my assembly point?
Because you set it once on the project's Details tab, under Emergency Information. Your CPP, RAMS, Site Induction and Emergency Plan all draw from there — you're never asked twice. Change it in one place and regenerate the documents that use it.
Full guide: Edit project details — and set emergency info once
Can I change my CDM role after creating the project?
Yes — the top of the Details tab has the role selector (Principal Contractor, Only Contractor, Subcontractor). Changing it adjusts which documents and tabs apply.
Full guide: Edit project details — and set emergency info once
I changed the site address and my assembly point, isolation points and A&E are now blank — why?
Those three answers describe a place, not the work: the fire assembly point is where this site's crew musters, the utility isolation points are where this site's shut-offs are, and the nearest A&E is worked out from this site's address. When you move the job, any values left unchanged from the old address are cleared rather than printed on the new site's Emergency Plan. You can replace the assembly point, isolation points or A&E while changing the address in the same save; replacements you actually type are kept for the new address. For the hospital, use Look up nearest A&E from the site address or enter a confirmed A&E manually. Until all three are filled in, your CPP, RAMS, Site Induction and Emergency Plan stay locked and the generate screen names the missing field. Everything else on the project — scope, dates, people, site rules, welfare — is untouched.
Full guide: Edit project details — and set emergency info once
Does opening a project after switching accounts move it to that account?
No. Opening a legacy project or changing your selected account does not change who owns that project. Some account-scoped integrations may not be available for a legacy project until its account ownership can be established from reliable records. Contact support if you need help confirming ownership; do not assume that opening the project transfers it.
Full guide: Edit project details — and set emergency info once
How do I find the nearest A&E?
In the Emergency Information section, click "Look up nearest A&E from the site address" — it finds the closest hospital from the site address you've entered. A full postcode makes it far more reliable, so add one if the address doesn't have it yet. If we can't place the address, or there's no A&E within 20km, you'll be told to enter it manually rather than shown a guess — we never put an invented location on a safety document. You can always type it in yourself.
Full guide: Edit project details — and set emergency info once
Why was I asked to review the latest project details and generate again?
Someone edited or imported project details while your PDF was being prepared. The Site Book discards that older snapshot instead of publishing it as current. Review the latest details, then click Generate again.
Full guide: Edit project details — and set emergency info once
What's the difference between filling fields and uploading a PCPP?
Same result, less typing. Upload your client's Pre-Construction Information Pack as a PDF (up to 25MB) and the AI extracts the details — you choose "Fill empty fields only" (the default) or "Overwrite all fields with AI". Word files (DOC/DOCX) can be uploaded too, but only as the stored source document: AI extraction works on PDFs, so export the pack to PDF first if you want the fields filled.
Full guide: Site Info: upload a PCPP and manage site background
Why can't I see the Site Info tab?
It shows when you're running the job (Principal Contractor or Only Contractor). Subcontractor-role projects don't have it — your PC holds the pre-construction information.
Full guide: Site Info: upload a PCPP and manage site background
Who can edit site information?
Owners and admins. Other team members can view it read-only.
Full guide: Site Info: upload a PCPP and manage site background
Why are my CPP, RAMS, induction and emergency plan locked?
Those four core documents only generate once all 11 site safety details are filled — they draw on these fields, so generating without them would produce unsafe blanks. Lightweight CPPs and Toolbox Talks are exempt from this lock, though Toolbox Talks have a separate prerequisite of their own: on projects where you're running the job, the Documents tab keeps them locked until the project has a generated RAMS ("You need your RAMS before this — create it first"). The locked card on the Documents tab says how many safety details are still needed and takes you straight to the setup flow.
Full guide: Site Safety Setup: fill the 11 details that unlock your documents
Do I have to finish it in one go?
No, but save before you leave — your answers only live in the browser until saved. Click Next through to the last step (Emergency & first aid), where the finish button reads Save progress until all 11 are filled; clicking it saves everything you've typed across all three steps. You'll get an honest count of what's still needed, and the core documents stay locked until every field has something in it.
Full guide: Site Safety Setup: fill the 11 details that unlock your documents
Where do I edit these details later?
On the project's Details tab, under its Safety and Emergency Information sections — the setup flow and the Details tab edit the same single-sourced fields. Remember that generated documents are frozen snapshots: after changing a safety detail, regenerate a document for the change to appear in it.
Full guide: Site Safety Setup: fill the 11 details that unlock your documents
Why can't I edit site safety details in the mobile app?
In the Site Book app the setup flow's Finish setup button, the AI draft buttons and the A&E lookup need an owner or admin account — a team member can read every detail but the save is refused, so the app doesn't offer the controls. They're also unavailable while a plan is inactive or mobile writes are switched off. Owners and admins edit the same fields on the web under the project's Details tab.
Full guide: Site Safety Setup: fill the 11 details that unlock your documents
Why do some fields say "From your PCPP"?
If the project was created from an uploaded PCPP/PDF, the AI extraction pre-fills what it found and the flow opens with "We filled N of 11 from your PCPP". Fields it filled carry a From your PCPP badge — review and confirm or edit them before saving, and fill the ones it couldn't.
Full guide: Site Safety Setup: fill the 11 details that unlock your documents
Why does my RAMS refuse to generate without a task?
A RAMS must include a method statement, and method statements are built from your trade tasks. Add at least one task on the Methods tab (or in the RAMS wizard's "What you're doing" step) and it unlocks.
My trade or task isn't in the library — what do I do?
Add it under "Custom work types": set the trade, task name and method statement, and tick "Save to my library for reuse" so it's there for the next job. On the mobile app's Methods screen, tap Add a task and use New custom task — that adds it to the project you're on; saving a task to your own library for reuse on future jobs is a website feature.
If I edit a method statement here, does the issued RAMS change?
No — generated documents are frozen snapshots. Edit the task, then regenerate the RAMS so the PDF picks up your wording, and workers re-sign the new version.
If I edit a custom task on a project, does my saved custom work type change?
No. Adding one of your saved custom work types to a project copies it onto that project. Edits (and deletions) on the project copy apply to that project only — your saved type in Your custom tasks stays exactly as it was, and every future snapshot starts from it.
Why can't I add or edit tasks in the mobile app?
Adding, editing and removing tasks needs an owner or admin account. Team members can open the Methods screen and read every task and its method statement, but the editing controls are hidden for them — ask an owner or admin to make the change. The controls are also hidden while a plan is inactive.
What if the connection drops while I add a photo in the app?
In your project's Photos screen, a queued photo waits for the next sync. Leave that upload in the queue rather than selecting the same photo again. If the photo already reached the server before the connection dropped, sync finishes adding that saved photo to the project.
Why does the mobile app say a photo type is unsupported?
The app accepts JPEG, PNG, WebP and HEIC photos. If the selected file is another format, or your phone cannot provide enough information to identify it, export a copy as JPEG or choose another photo and try again.
Which image types work?
JPG, PNG, WebP and HEIC (iPhone photos upload as-is and are converted automatically), up to 25MB each on the website or 20MB in the mobile app. The website lets you select several at once. If an upload comes back saying the photo is too large to process, it was shot at a resolution beyond what we can convert — re-take or export it as a JPG, or turn off your camera's maximum-resolution HEIF setting.
What can I do from the mobile Photos screen?
Open your project and tap Photos. With an active Starter, Pro, Business or Site Control plan and project write access, tap Add a photo to upload. Tap a photo or its title to open Edit photo title, then choose Save. Use Include in CPP to select it for your document, or the trash icon (Delete photo) to remove it. If your account is read-only, the mobile write switch is off, or your project role cannot edit evidence, Add a photo and Delete photo are hidden; title and CPP controls remain visible but disabled, and you can still view existing photos.
Can the mobile app see my whole photo library?
No on Android: Add a photo opens Android's system photo picker and The Site Book receives only the image you select. On iPhone or iPad, iOS may ask for photo-library access; you can limit access in iOS Settings.
Do photos taken in the mobile app appear on the Photos tab?
Yes — photos you add in the app's project Photos screen are the same Photos tab, and they display on the website exactly like web uploads. Photos are stored privately, so each view opens through a fresh secure link rather than a permanent public address — an old link you saved or forwarded stops working after a while; open it from the Photos tab again instead.
How do photos get into my CPP?
Tick "Include in CPP" on each image you want — the CPP wizard's Site Photos step picks them up.
Is there a limit on how many photos go in a CPP?
There's no set number — every photo you tick is included, in the order you selected them, and they're resized automatically when the PDF is built. The only exception is an unusually large set: if the document would take too long to build, the photos that didn't fit are left out and the wizard names them, so you can untick the ones that matter least and generate again.
The wizard said a photo couldn't be added — what now?
The message names each photo and the reason, and what to do depends on which reason you see. If it couldn't be downloaded, isn't a supported image, or is stored outside this app's storage, the file itself is the problem — delete it on the Photos tab, upload it again, then regenerate. If it says the photo is over 60 megapixels, the image's resolution is beyond what the PDF can take (this can happen with plans exported at print resolution) — export it at a lower resolution or as a JPG, replace it on the Photos tab, then regenerate. If it says the document took too long to build or reached its maximum size, there was nothing wrong with the photo: the set was simply too large, so untick the ones that matter least and generate again. Re-uploading won't help in that case. Everything else in the CPP is unaffected either way.
I generated a CPP and photos are missing from the PDF
Documents are fixed snapshots of the moment they were generated, so adding or fixing a photo never changes an existing PDF — you have to regenerate. Open the document and choose Regenerate, and the current set of ticked photos is used.
How does the RIDDOR flagging work?
Automatically. A fatal or major-severity incident, a dangerous occurrence, or a description mentioning things like fractures, hospitalisation or seven-day absences gets flagged "RIDDOR may apply" with a reason and a link to HSE guidance. Check the actual legal category: a reportable dangerous occurrence or specified injury requires notification without delay and a report received within 10 days; over-seven-day incapacity has a 15-day deadline. Reporting to the HSE is still your action — once you've done it, click "Mark as reported to HSE" so the record shows it.
Full guide: Log incidents and near misses (with RIDDOR flagging)
Should I log near misses too?
Yes — Near Miss is the default type for a reason. A logged near-miss trail shows an inspector you spot and act on hazards before they become injuries.
Full guide: Log incidents and near misses (with RIDDOR flagging)
Can a site supervisor delete an incident?
No. Site supervisors can log and update incident evidence on their assigned projects, but the native app does not offer them permanent deletion. Incident removal is restricted to account owners and admins because the record may contain RIDDOR and audit evidence.
Full guide: Log incidents and near misses (with RIDDOR flagging)
What if the mobile app says Save not confirmed?
On the mobile incident form, tap Retry same details to retry the saved attempt. Before sending, the app stores its details securely on this device. An unconfirmed attempt survives closing the app or an expired login; sign back into the same user, account and project with current access to recover it. Recovery never sends automatically. Deliberately signing out or switching users clears this local recovery.
Full guide: Log incidents and near misses (with RIDDOR flagging)
What if the app says the incident changed while I was editing it?
That refusal is deliberate. If someone else saved a change to the incident after you opened it, the app will not overwrite their record — it shows "This incident changed while you were editing it. Refresh and try again", refreshes the incident, and leaves your wording on the form. Re-check the incident against their change and save again.
Full guide: Log incidents and near misses (with RIDDOR flagging)
Which plan includes the incident log?
Pro and above, on both the website and signed-in mobile app. Accounts with retained Incident Log access and projects bought through our setup service keep it working.
Full guide: Log incidents and near misses (with RIDDOR flagging)
What permit types are there?
Six: Hot Works, Working at Height, Confined Space, Electrical Isolation, Excavation, and General for anything else.
When does a permit expire?
At the end time you set when issuing it. Active permits are listed separately from expired and revoked ones, so the live picture is always at the top.
Can I cancel a permit early?
Yes — account owners and admins click Revoke Permit on the active permit. Revoking can't be undone; issue a fresh permit if the work resumes.
What if the mobile app says Save not confirmed?
On the mobile permit form, tap Retry same details to retry the saved attempt. Before sending, the app stores its details securely on this device. An unconfirmed attempt survives closing the app or an expired login; sign back into the same user, account and project with current access to recover it. Recovery never sends automatically. Deliberately signing out or switching users clears this local recovery.
Which plan includes permits to work?
Pro and above, on both the website and signed-in mobile app. Accounts with retained Permits access and projects bought through our setup service keep it working. On mobile, an account owner or admin with retained access can still issue a permit; Starter accounts see an advisory before the form.
How is this different from Permits to Work?
Permits to Work is for permits you issue on a site you run. Client Permits is the other direction — a permit your client hands to you on their site. The client keeps the original paper, so your photos are your record.
Who can record a client permit?
Account owners, admins and site supervisors — the supervisor at the gate is usually the person handed the permit. Team members see the list read-only. Removing a permit is owner/admin only.
What if the permit came as a PDF?
Upload the PDF instead of a photo — the Add button accepts both. It's stored on the job, and up to 20 permit PDFs per pack are merged into the audit pack (the pack's cover lists any it couldn't include, and they all stay on the Client Permits page).
Do client permits appear in the audit pack?
Yes — the pack lists them separately from permits you issued, and the captured documents themselves are embedded so an inspector or insurer can read the issuer's name and signatures. Very photo-heavy projects are capped at 60 embedded photos per pack (the pack says so when that happens); every capture always stays on the Client Permits page.
Which photos can I choose in the mobile diary?
Choose JPEG, PNG, WebP or HEIC photos. If the app cannot identify a supported format or read the photo, choose another copy or export it as a JPEG and try again. A failed selection does not clear notes or photos already in your draft.
Will editing my notes remove the entry’s photos?
No. Changing only the notes in the mobile app keeps the entry’s photos, weather and worker count. Photos are removed when you explicitly remove or replace them. Unused files are scheduled for cleanup; a photo still used by another record, including a supervisor’s recoverable deleted entry, stays protected.
What does a diary entry record?
Date, workers on site, weather, temperature and wind speed, what work was done (the only required field), issues or safety concerns, delays, visitors, and photos.
Why bother with a daily diary?
Because six months later, "what happened on the 14th?" decides disputes, delay claims and insurance arguments. HSE inspectors regularly ask for site diaries too. A short entry with a photo is cheap insurance.
Do photos taken in the mobile app show on the website?
Yes. The diary is one record on both: an entry written or a photo attached in the app appears on the website's Site Diary tab, and clicking a photo's thumbnail opens it full-size. Photos are stored privately, so each view opens through a fresh secure link rather than a permanent public address — an old link you saved or forwarded stops working after a while; open it from the diary again instead.
Can I delete a diary entry?
Yes, and what happens depends on who you are. When an account owner or admin deletes an entry it is gone for good. When a site supervisor deletes one (a Business and above role) it is hidden but kept, so an owner or admin can restore it — including its photos. That is deliberate: a site diary is evidence, so the person running the site can correct a mistake without being able to destroy the record.
Do diary entries appear in the audit pack?
Yes. Entries that have not been deleted are listed in the Audit Pack and in the merged PDF, with the date, weather, workers on site, work done, issues or delays, and how many photos are attached. On a very long-running project the pack lists the most recent 500 entries and says so in the section header. Deleted entries are left out of the Audit Pack. They do still appear in a Download my data request, marked as deleted and showing who deleted them — that download is a legal record of everything we hold about you, not a compliance document you would hand to a client.
Which plan includes the Site Diary?
Pro and above, on both the website and signed-in mobile app. Accounts with retained Site Diary access and projects bought through our setup service keep it working.
What if my delete reports an error but the entry is gone?
On the mobile app, deleting an entry that was already removed counts as done, not a failure — if the connection dropped after the delete landed, tapping Delete again simply confirms it.
When does a project need an F10?
Under CDM 2015: construction work lasting more than 30 working days with more than 20 workers on site at once, or exceeding 500 person-days. The page checks your project's duration and workforce automatically and tells you either way.
Full guide: F10 notification: check if you need one, and prepare it
Who is responsible for notifying the HSE?
For a commercial project, the client is responsible for notification. For domestic projects, client duties normally pass to the contractor on a single-contractor job or the principal contractor when more than one contractor is involved. A principal designer can take on those domestic-client duties by written agreement. Check who holds the duty for your project; see the HSE guidance for commercial clients and domestic clients.
Full guide: F10 notification: check if you need one, and prepare it
Does The Site Book submit the F10 to the HSE for me?
No — the HSE only accepts F10s through its own online form. We pre-fill the data for you to copy across, link you to the HSE portal, and record the date once you mark it submitted.
Full guide: F10 notification: check if you need one, and prepare it
Can I record the F10 from the mobile app?
Yes. In the Site Book app, open the project and tap F10 Notification under Compliance. Open HSE F10 portal takes you to the HSE form in your browser; back in the app, tap Mark F10 as notified and confirm with Mark notified to record today's date (Update notification date re-stamps it; Clear notification removes it). The app doesn't run the notifiability check — do that on the web page. Recording the F10 needs Pro (£39/mo) or above. The app checks your access for the project when it opens the screen: if F10 isn't included it shows an upgrade prompt instead of the Mark F10 as notified button, and if it is — including a project with the setup service purchased, or an account with legacy F10 access — the button is there with no prompt. If access cannot be checked, reload the screen and try again. An open confirmation is cancelled when your account, role or project access changes; open a new confirmation once access is available.
Full guide: F10 notification: check if you need one, and prepare it
The check says my project isn't notifiable — is that recorded?
Yes, the page states the project doesn't exceed the thresholds, based on the details you've entered. If the job grows (longer duration, more workers), update the project details and check again — notifiability can change.
Full guide: F10 notification: check if you need one, and prepare it
Which photos can I attach to a mobile inspection or defect?
Choose JPEG, PNG, WebP or HEIC photos, no larger than 20 MB each. If the app cannot identify a supported format or read the photo, export a copy as JPEG or choose another photo and try again.
Full guide: Plant & Equipment: run one live register of your kit
What happens if my mobile Plant save is interrupted?
If you change account, project or access while a photo is being chosen, copied or uploaded, that foreground attempt stops and you can start it again in the correct place. Once the app says the inspection, defect or corrective action is queued, its exact details and copied photos can sync in the background while you are signed in to the same owning account. When the app queues a save after a connection failure, it keeps any confirmed photo uploads and retries the remaining photos with the same inspection or defect. Older pending Plant records that cannot prove their owning account stay parked in Sync for recovery; The Site Book does not assign them to the account you happen to have open or silently discard them.
Full guide: Plant & Equipment: run one live register of your kit
Who can manage the plant register?
Account owners and admins can add items, upload and review evidence, and change requirements. Members can view the register. Site Supervisors do not see the company register.
Full guide: Plant & Equipment: run one live register of your kit
How do I return equipment marked under repair to service?
Open the item's page in Plant & Equipment and select Return to service. An account owner or admin records what was done and who checked that the item is safe to use again. This also works for items imported from a spreadsheet as under repair. Close any safety-critical corrective actions first; the return and its notes stay in the item's history.
Full guide: Plant & Equipment: run one live register of your kit
Why does an item show grey instead of green?
Grey means no requirements have been configured yet, so nothing has been checked — it is deliberately not the same as compliant. Add at least one requirement and the item will go green, amber or red based on real evidence.
Full guide: Plant & Equipment: run one live register of your kit
Does The Site Book decide my inspection intervals?
No. Requirements and intervals are yours to set, based on your equipment, risk assessment, manufacturer guidance and competent-person advice. The Site Book tracks what you configure — it never asserts a statutory interval for you.
Full guide: Plant & Equipment: run one live register of your kit
What happens to history when I archive an item?
Nothing is deleted. Archiving keeps every certificate, review decision and event in the item's history — it comes off the live register, and retired items stay searchable under the status filter.
Full guide: Plant & Equipment: run one live register of your kit
What happens to Plant when I archive a project?
The archive confirmation warns that any open Plant assignment periods will close on the archive date. Remove equipment first if that date is not the real leaving date. If you continue, the project is archived, every remaining open assignment becomes Removed at one timestamp, and the full assignment and event history is preserved. Reactivating the project does not reopen those historical periods; assign an item again to start a new one.
Full guide: Plant & Equipment: run one live register of your kit
What can someone see when they scan an equipment label?
The public page shows only the asset number, name, category, make, model and recorded operational status. It does not expose certificates, references, contacts, notes, people, customer details, serial numbers, files or project information, and it offers no public action for recording a check or reporting a defect. An already printed label keeps this restricted read-only view if the account later drops below Business; its private-record sign-in action is removed, private destinations and every Plant change remain locked, and The Site Book can still disable all labels with the Plant rollout switch.
Full guide: Plant & Equipment: run one live register of your kit
Documents
Do I need a CPP for a small domestic job?
CDM 2015 requires a construction phase plan for every construction project, sized to the job. For straightforward domestic jobs where you're the only contractor, we offer a lightweight CPP — the same document type, proportionate content.
What's the difference between the lightweight and full CPP?
The lightweight wizard is a shorter path for domestic only-contractor jobs. You can switch to the full wizard at any point if the job warrants it — both produce a proper CPP.
Is the CPP free?
Yes — CPP generation is included on every plan. Starter gives you one free real project with no card required; upgrade to Pro at £39/mo when you need project two, your logo or PDFs without the Starter watermark.
Why is it sending me to the CPP first?
When you're running the job, your Construction Phase Plan needs to exist before RAMS — the RAMS draws on it. Generate the CPP from the Documents tab first, then come back.
What's the score on my finished RAMS?
Every document gets a site-specificity score out of 100. Above 70 shows as "Tailored to your site"; lower scores list concrete suggestions — vague phrases like "appropriate PPE", missing site details, weak controls — with a Re-check button once you've tightened them.
Can workers sign the RAMS digitally?
Yes, on Business and above — turn on RAMS sign-off from the project's Access tab (the "RAMS sign-off" setting, tick "Required") and every worker gets it in their crew-link portal alongside inductions and toolbox talks.
My RAMS names the wrong works supervisor — why?
The Works Supervisor dropdown on the wizard's Who's working step decides who the RAMS names. It opens on the supervisor from your project's People section — shown with (from project details) after their name when they are not on the crew, or as their own entry in the worker list when they are. Leave it as it opens and the RAMS names that person. If you picked a different worker from the list, that person is saved back to the project as the works supervisor too. In the Site Book app's RAMS editor, the Works supervisor field opens with the same person from the project: type a different name only if somebody else is supervising the work — it is saved to the project as the works supervisor when you generate — or leave it blank to keep the project's supervisor. A name you type takes its phone number from that person's entry on the project's Workers screen; anyone else is saved without one, so correct a misspelt name — or re-enter the number — on the website under the project's Details tab → People → Works Supervisor instead. Either way, the RAMS names one person: the Works Supervisor row, the ★ against their name in the personnel list and Approved by all show them (unless your account prints its default approver on Approved by — see the Document approvals article). Set the right person in Edit project → People, then regenerate the RAMS: generated PDFs are frozen snapshots, so earlier versions keep the old name.
Why does the Personnel list on my RAMS differ from what the wizard showed?
The Personnel table prints each selected worker's record as it stands on the project when you generate — their name, role, company and the First Aid and Fire Warden ticks. Whatever the wizard showed when you opened it is not used, and anyone you selected who has since been removed from the project is left off, because a RAMS must never list somebody who is not on the job. To change what prints, open the project's Workers tab (on the website, or the project's Workers screen in the app), update the worker there, then regenerate the RAMS. Generated PDFs are frozen snapshots, so a version you already have keeps what was true when it was made.
My RAMS says "Not named" where the works supervisor should be — what does that mean?
Nobody is recorded as the works supervisor on that project, so the RAMS says so in plain words instead of leaving the row blank. Add one in Edit project → People — the Works Supervisor name and phone — then regenerate the RAMS. Generated PDFs are frozen snapshots, so the version you already have keeps saying Not named. If the project has the phone number but no name, the row shows Not named followed by that number: the contact is never dropped from a safety document.
Is RAMS generation on the free plan?
Yes. RAMS, CPPs and site inductions are all included on Starter's one free real project, with no card required. Upgrade to Pro at £39/mo when you need project two, your logo or PDFs without the Starter watermark.
I can't find a substance in the catalogue — what now?
Upload the manufacturer's Safety Data Sheet: click Upload SDS, drop the PDF, and the AI extracts hazard statements, PPE, first aid, exposure limits and disposal information. Review each field (they're confidence-badged), then click Add to my COSHH library.
Do COSHH records carry across projects?
Yes — your COSHH library is account-wide. Assess a substance once and reuse it on every project. Substances also appear in the RAMS wizard's COSHH step.
Which plan includes COSHH?
COSHH is included on Pro (£39/mo) and above, on both the website and signed-in mobile app. If your plan doesn't include it, the COSHH card on the project's Documents tab and the COSHH tab show an upgrade prompt instead — accounts with grandfathered COSHH access and projects set up by our setup service keep it working. On mobile, an account owner or admin with retained access can still use Add; Starter accounts see an advisory before the form. Older app versions that search without choosing a project still work for paid and grandfathered accounts.
Do workers sign COSHH assessments?
No — workers can read COSHH assessments in their portal, view-only. Sign-off is collected on inductions, toolbox talks, emergency plans and (optionally) RAMS.
Can I try a site induction free?
Yes — site inductions are included on every plan. Starter gives you one free real project with no card required: create your account, set up that project, then generate the induction from its Documents tab. Upgrade to Pro at £39/mo when you need project two, your logo or PDFs without the Starter watermark.
Full guide: Site inductions: generate, deliver and collect signatures
How do workers sign the induction?
Send the project's crew sign-off link. Each worker picks their name, reads the induction on their phone and signs — every induction automatically requires sign-off from every active worker on the project.
Full guide: Site inductions: generate, deliver and collect signatures
What happens when I add a worker after the induction is generated?
New active workers are enrolled for sign-off too — the Worker Sign-Off panel shows them as pending until they've read and signed.
Full guide: Site inductions: generate, deliver and collect signatures
Which languages are available for multilingual crews?
On Business and above, key site H&S details can be shown to workers in Polish, Romanian, Lithuanian, Bulgarian, Russian, Ukrainian, Portuguese and Spanish. English is always the authoritative record, and you can review every translation before workers see it.
Full guide: Site inductions: generate, deliver and collect signatures
How do attendees sign?
Two ways. In person: click Collect Signatures on the talk's document page — the deliverer signs first, then the phone is passed round and each attendee signs in turn. Remotely: workers sign through the crew link like any other sign-off document, or use the "Share link for remote attendees" after the deliverer has signed.
Can I create several talks at once?
Yes — select more than one topic in the wizard and it switches to batch mode, creating them all in one go (batch skips the per-talk AI review step).
Which plan includes toolbox talks?
Pro (£39/mo) and above, on both the website and signed-in mobile app. Accounts with retained Toolbox Talks access and projects bought through our setup service keep it working.
Why doesn't the wizard ask about my fire strategy or assembly point?
Those are set once in your project's Details tab under Emergency Information — fire strategy, assembly point, nearest A&E, first aid, emergency procedures, scenarios and utility isolation points all flow into the plan automatically. Incident (RIDDOR) reporting is included for you.
Do workers sign the Emergency Plan?
Yes — emergency plans always collect worker sign-off, same as site inductions and toolbox talks. Send the crew link and track it on the Worker Sign-Off panel.
How do I find an older document?
Open Documents from the main navigation. The newest documents appear first, 24 at a time. Use Next page and Previous page below the list to browse your history, or enter a project name, document type or Toolbox Talk topic in Search documents and press Search to search across all your projects. Topic search includes older Toolbox Talk versions; each result card shows the latest version. Clear search returns to the newest documents. A project can appear on more than one page when it has many documents.
What if the connection drops while signing a shared document?
For a document's View & Sign share link, reopen the same link. The page checks whether that exact signing attempt was saved before asking you to continue, even when the signed PDF still needs repair. A saved signature stays confirmed while the PDF problem is shown separately. If the check cannot confirm the result, choose Retry this signing attempt and enter the details again. The protected attempt stays the same, so a late response cannot create a duplicate. When collecting signatures on your own device, use Check again or Retry this signing attempt; both keep the same unconfirmed attempt. This is the document link created with Share on the document page, separate from the project crew link.
Why does a signed PDF preview say it is still preparing?
A preview can open a signed copy that is already ready, but it cannot rebuild or publish one. The stored signed file is checked before a signed download, preview or shared link offers it, and during signing recovery. An already-open preview may keep showing the verified copy it loaded. If the stored file is missing, damaged or cannot be verified, new downloads and shared signed links stay unavailable and the page asks you to retry or contact support. If a new signature was added and the signed PDF is still preparing, retry the signed download. An authorised download repairs a copy only after any required approval and issue confirmation are still valid. If someone signs while your download is being prepared, wait a moment and choose Download Signed PDF again on the document page.
What does an unverified older signed copy mean?
The retained PDF stays available as historical evidence, but we cannot confirm that it includes every recorded signature. Do not treat its availability as that confirmation. A signature certificate on an older original may also explain that no earlier reference was recorded, so the original file’s identity at issue cannot be verified. Contact support to review the retained evidence; regenerating creates a new version and does not repair the old audit history.
Why can't I share this document?
Share stays unavailable while a document is a draft, and pressing Share tells you which step is missing. If nothing has been generated yet, create the document first. If it has been generated but still shows a Review Required badge on the project's Documents page: on a Site Induction or Emergency Plan, open it and click ✓ Approve & Lock Document (or Review & Approve from the Documents page). Other document types have no in-app approve button — click Regenerate to issue a fresh version, which clears the draft state. Either way, Share works as soon as the document is out of draft.
Why don't I see Create share link, Approve or Mark reviewed in the mobile app?
In the Site Book app a document's Actions card shows only what your account can do. Create share link and Edit / regenerate need an owner or admin account on every plan. On Business and Site Control plans, Approve and Mark reviewed are owner/admin too; on Starter and Pro any team member can use them. Everyone can still open and download the document. The controls also hide while a plan is inactive or mobile writes are switched off.
What can the person I share with actually do?
Your choice when creating the link: "View & Sign" lets them read and add a signature (name, role, company, consent); "View only" is read-only. Links can expire after 7, 30 or 90 days, or never — and you can revoke a link at any time.
What happens when I regenerate a document?
A new version is created. Anyone holding a share link to the old version sees a "this document may be out of date" warning, worker sign-offs reset to pending for the new version (old signatures are kept as evidence), and manager acknowledgements are marked superseded. Regenerate whenever project details change — the PDF is a frozen snapshot.
Does the QR code on a printed document expire?
No — the QR code printed on a generated PDF ("Scan to view digital version") keeps working until you revoke sharing, so a copy pinned on-site stays scannable indefinitely. If you regenerate the document, that old QR code isn't updated — scanning it shows a notice that a newer version exists and points to it.
Why does my PDF have a footer on the free plan?
Starter PDFs include The Site Book footer watermark and don't use your company branding. Pro and above add your company logo and remove the Starter watermark.
What should I do if document generation times out?
Try Generate again. A timed-out attempt does not issue a new document version unless its audit record and any required worker sign-offs were saved with it, so retrying cannot leave the project showing a half-finished version.
What do the score bands mean?
Above 70: "Tailored to your site" — good, with optional tips. 40–70: suggestions to strengthen the document. Below 40: things to review — usually missing site details or vague phrases an inspector would query.
Full guide: The site-specificity score: prove your documents aren't templates
What kind of things get flagged?
Vague phrases like "appropriate PPE" (which PPE?), a missing site address or access details, no nearest-hospital information, weak or generic controls. Each suggestion says what to change in plain English.
Full guide: The site-specificity score: prove your documents aren't templates
How do I act on a suggestion?
Edit the wording it points at — in the document editor or the underlying project detail it names — then click "Re-check →" on the score panel to re-score. The suggestions are guidance to apply yourself, not automatic rewrites.
Full guide: The site-specificity score: prove your documents aren't templates
Do I have to use approvals?
No — they're off by default. Smaller teams can keep issuing documents straight after the review-and-confirm step. Turn approvals on when you want a named second pair of eyes before anything leaves the business.
Who can approve a version?
Only the named approver on the request. Owners and admins choose who that is per request (with an optional account-wide default), but they can't approve on the named person's behalf — that's the point of the routing.
Which name and email does an approval use?
The requester and approver names come from their separate login identities, and the notification goes to the email address of the login selected as approver. Company Profile fields such as Main Contact Name and Company Email are document contact details; they do not change who requested an approval or where the selected approver's notification is sent.
Why does the PDF name someone other than the person who approved it?
The Approved by line prints your account's default approver at the moment the document was generated — it's a snapshot, not a live pointer. A request can be routed to a different named approver afterwards, and the default approver can change too; the frozen PDF follows neither. When that happens, the document page's Approval before issue panel shows a short notice, and it says something different depending on why: if a request has since been routed to someone other than the printed approver, it names both people; if the line wasn't filled from a default approver when the version was generated (for any reason — approvals were off then, the plan wasn't Business yet, or the configured approver wasn't eligible), it names whichever value was actually printed, or says the line is blank if nothing was typed in the wizard. Either way it points at Regenerate to refresh the printed name — or, if you don't have access to regenerate, at an owner or admin who does. The live per-version decision — who was asked, who approved it, and when — is on that same panel; the same decision's durable audit trail sits under Business review history. If a document needs to name the right person, change the default approver on the Team page (or route the request to someone else) and regenerate.
What happens when a version is rejected?
The rejection and its reason are recorded against the version, the document is flagged as needing review, and download/share stay blocked. Fix the issue, then request approval again — or regenerate, which creates a new version to approve.
Do workers see a document before it's approved?
They can't sign it. While approvals are on, worker sign-offs for a version are only issued once the named approver approves it — the document doesn't appear in the crew's to-sign list, and nobody can record a signature against it, until then. Approving the current version sends the pending sign-offs out automatically. One caveat: on projects with the full Site Access portal switched on, the portal's document library is a separate surface and can still display the latest generated PDF before approval — the gate controls signing, plus your team's download and share actions, not that library view.
What if our plan changes?
The approvals gate only applies while your account is on Business or Site Control. If the plan lapses, documents are never stranded — the gate stands down and the ordinary review-and-confirm step still applies.
Can my client respond without an account?
Yes. Anyone you share a document with by link can record Approve, Request changes or Reject (with a comment) — no login needed. Their response appears on the document page under Client responses.
Our approver belongs to a different account — can they still decide?
Yes. A named approver only needs an active membership in the account that owns the document — it does not have to be the account they currently work under. Their pending requests appear on the Approvals page whatever account it lives in, and the Open link takes them straight to the document, where they can read the PDF and record the decision. While they are deciding they see the document in review mode only — no share links or management actions are offered on that view, and issuing the document stays blocked until they approve.
What happens to an open request while it stands down?
Nothing is lost. If approvals are switched off, or the plan drops below Business, the request is parked: it disappears from the Approvals page and cannot be decided, and documents issue under the ordinary review-and-confirm step instead. Switch approvals back on and the same request reappears, still pending, ready for the named approver to decide. A request that has already been decided, rejected or superseded never reopens access to the document by itself.
Workers & sign-off
Why did the app ask me to sign in while updating a worker?
If your sign-in expires, the app returns to sign-in even if you have left the worker form. Sign in again and check the worker record before trying the change again.
What if the app says the record changed while I was editing it?
That refusal is deliberate. If the worker or one of their certifications was saved by someone else after you opened the editor — a teammate editing on the website, for example — the app refuses the save with "This record changed while you were editing it. Refresh and try again" rather than overwriting their version, and nothing you typed was kept on the record. Close and reopen the worker to load the saved version, check it against your wording, then apply your change again.
What's the difference between the Workers directory and a project's Workers tab?
The Workers directory (sidebar → Workers) is your account-wide team list — add someone once with their certs. A project's Workers tab is who's on that specific job: add them there to include them in the project's inductions and sign-off records.
How do expiry alerts work?
Each certification records an expiry date. As it approaches, the worker's compliance status turns amber, then red when expired — with a dashboard banner telling you how many certs need attention, and email reminders so nothing lapses quietly.
Is cert tracking on the free plan?
The account-wide Workers directory with cert tracking is Pro (£39/mo) and above. Adding workers to a project — for inductions and sign-offs — works on every plan. If an older Starter account retained cert tracking, the mobile app still lets the server check that access when you save; the Pro notice is guidance rather than a disabled form, and any refusal is shown with the server's explanation.
Does the mobile app need access to my photo library?
No on Android: Attach file on a certification and Add evidence photo on a right-to-work check open Android's system photo picker, and The Site Book receives only the image you select — no photo-library permission is requested. On iPhone or iPad, iOS may ask for photo-library access; you can limit access in iOS Settings.
Do certification files open on the website as well as in the app?
Yes — files attached with Attach file on a certification, and right-to-work evidence, open from the worker's record under Workers in the sidebar (View on the certification), whichever side they were added on. Certification files are stored privately, so the website and app request a fresh secure link only when you press View or View file; they do not open or save the permanent storage address. An old link you saved or forwarded stops working after a while — open it from the worker's record again instead. Right-to-work evidence links receive the same checks. If the file cannot be verified for your account and that worker, it is shown as unavailable.
Do workers need an account or an app to sign?
No. The crew link opens in their phone browser. They pick their name from your project worker list, read each document and sign — nothing to install, no login to create.
Full guide: Get your crew to sign off documents from their phones
Which documents do workers sign off?
Site inductions, toolbox talks and emergency plans always collect sign-off on every plan. On Business and above you can additionally require RAMS sign-off per project (Access tab). Construction Phase Plans don't collect worker sign-off, and COSHH assessments are shown to workers view-only.
Full guide: Get your crew to sign off documents from their phones
What if the link gets shared outside my crew?
Workers can only pick names already on your project worker list — nobody can add themselves. If a link leaks, press New link on the Workers tab: the old link stops working immediately.
Full guide: Get your crew to sign off documents from their phones
What stops a worker signing off as someone else?
On Business and above you can switch on sign-off PINs: each worker sets 4 numbers the first time they sign and enters them to sign after that, so a sign-off is tied to the person who made it. It's off until you turn it on — see the sign-off PINs article.
Full guide: Get your crew to sign off documents from their phones
Is the crew sign-off link on the free plan?
Yes — worker sign-off works on every plan, including Starter.
Full guide: Get your crew to sign off documents from their phones
What problem does this actually solve?
Your crew link is shared with everyone on site, and workers sign by picking their name from the roster. Without a PIN, anyone holding the link can pick another name and sign. With PINs on, the sign-off also requires the PIN registered to the selected worker, which deters casual name-picking and records that extra check. It does not prove biometric identity: someone who knows or first sets that PIN could still use it.
Full guide: Add PIN evidence to shared-link document sign-off
Do workers set their own PIN, or do I?
They do. The first time a worker signs after you switch PINs on, they're asked to choose 4 numbers and type them twice. After that they enter the same PIN to sign. You never see it — you can only reset it.
Full guide: Add PIN evidence to shared-link document sign-off
A worker has forgotten their PIN. What do I do?
Reset it. Owners and admins use the Sign-off PINs card on the project's Workers tab; a Site Supervisor uses the Crew tab. The worker is asked to set a new PIN the next time they sign.
Full guide: Add PIN evidence to shared-link document sign-off
A worker is locked out after too many wrong tries. Do I need to do anything?
Usually not. Five wrong tries locks that name for 15 minutes, then it unlocks by itself — so a worker on a site with no manager around isn't stranded. Only reset the PIN if they genuinely can't remember it.
Full guide: Add PIN evidence to shared-link document sign-off
Does a worker need a different PIN for each of my sites?
No. A worker sets one PIN for your company and uses it on every one of your projects that asks for one. Someone who signed on your last job doesn't have to set it up again on the next.
Full guide: Add PIN evidence to shared-link document sign-off
Does this slow down checking in?
No — checking in and out is untouched, because it isn't a sign-off. PINs apply to signing documents: RAMS, emergency plans, site inductions and toolbox talks. One PIN entry covers 30 minutes on that phone, so a worker signing several documents in one go is only asked once.
Full guide: Add PIN evidence to shared-link document sign-off
How do PINs work in the mobile app?
The same as on the web. When a worker signs a document in the app on a site that asks for a PIN, they're prompted to set one the first time and to enter it after that, and one entry covers 30 minutes of signing in the app. The one difference: the app needs a connection for the PIN step. Offline, the app tells them to connect to sign rather than queueing the sign-off, so a PIN-protected sign-off is never recorded without the PIN check.
Full guide: Add PIN evidence to shared-link document sign-off
Will turning this on affect crews who are already signing?
It's off until you switch it on, and it stays off for every new account too. Nothing changes for anyone until you decide. Once on, workers on affected projects set a PIN the next time they sign.
Full guide: Add PIN evidence to shared-link document sign-off
How strong is a 4-digit PIN really?
It's a second check on a link that's already private, not a password. What stops guessing is the lockout: five wrong tries and that name is locked for 15 minutes, which makes working through 10,000 combinations hopeless. Four digits was chosen so a worker in gloves on a cold site can actually use it.
Full guide: Add PIN evidence to shared-link document sign-off
Can a worker sign for someone else?
Each worker claims their own name and gets their own personal portal link. Signatures are recorded against the claimed name with a timestamp. Like any signature process, tell your crew to sign for themselves — the audit record shows exactly which name signed, from which claimed identity, and when.
Full guide: What your workers see when they open the crew link
Can workers skim straight to the signature?
No — the portal walks each document step by step, and workers have to page through the content before the sign step unlocks. Each sign-off records how the read was proven.
Full guide: What your workers see when they open the crew link
What about COSHH assessments?
Workers can read COSHH assessments in the portal, but COSHH is view-only — it doesn't collect signatures.
Full guide: What your workers see when they open the crew link
Why did everyone go back to pending after I regenerated a document?
That's deliberate. Sign-offs are tied to the exact document version a worker read. When you regenerate, the old signatures are kept as evidence of what each worker actually saw, and everyone gets a fresh pending sign-off for the new version — so your records always show who has signed the current document.
Why doesn't my CPP have a sign-off panel?
Construction Phase Plans don't collect worker sign-off — they're your plan of how the site is run, not a document workers attest to. Site inductions, toolbox talks and emergency plans always collect sign-off; RAMS sign-off can be required per project on Business and above (Access tab).
Do I need to refresh the page to see new signatures?
No — the panel updates itself every 30 seconds while the page is open, and there's a refresh icon on the panel if you want to check right now.
What's in the Audit-Ready Pack?
A cover summary; project documents and version history; worker certification, right-to-work and CSCS status; Site Diary entries and photo counts; attendance; worker document sign-offs; evacuation roll-calls; inspections and corrective actions; plant that reached the site, including removed history; incidents; COSHH; and permits. Deleted Site Diary entries are excluded. Any section limited for a long-running project states the full total and what is shown.
Full guide: Export your audit trail with the Audit-Ready Pack
Which plans include the Audit-Ready Pack?
Pro and above, on both the website and signed-in mobile app. The Documents-page card appears on Principal Contractor and Only Contractor projects; subcontractor projects can use the project's Export audit pack action instead. Projects bought through our setup service keep access. In the mobile app, when the server confirms your account has no access, Audit Pack shows a Pro feature explanation with Open upgrade page and Try again. You can also upgrade through More → Account & plan → Manage on web. Returning to the app refreshes access; Try again immediately reloads this project’s pack history. Other loading failures show an error with a retry control.
Full guide: Export your audit trail with the Audit-Ready Pack
The pack says some documents are missing — what does that mean?
If a project document or approved Plant evidence file couldn't be retrieved, the pack names it rather than silently shipping incomplete. Restore or re-upload the named evidence, or regenerate the named project document, then build the pack again.
Full guide: Export your audit trail with the Audit-Ready Pack
Why is there a separate Plant Evidence Appendix download?
The main pack appends the complete deduplicated set of relevant approved Plant PDFs and images when it fits its safe build limit. The separate appendix is always available when relevant raw Plant evidence exists, and has a larger safety limit for evidence-heavy projects. If the main pack cannot safely append the complete set, its cover says so and keeps the historical Plant summary intact.
Full guide: Export your audit trail with the Audit-Ready Pack
What's the difference between the sidebar Subcontractors page and a project's Subcontractors tab?
The sidebar page is your account-wide directory — a firm's insurance, RAMS and liability documents carry across every project. A project's Subcontractors tab is which firms are on that job, with per-project scope, supervision and RAMS reference.
Full guide: Track subcontractors: insurance, RAMS and expiry alerts
How do the expiry alerts work?
Each document records an expiry date. Firms show as Compliant, Attention or Blocked, and a banner flags anyone with expired or missing documents so you know who to chase before it bites.
Full guide: Track subcontractors: insurance, RAMS and expiry alerts
What does "working under your direction" change?
It classifies the firm's people as workers under your control — confirming it adds them to your worker register, so they're included in inductions and sign-off records. Firms "managing their own work" stay separate.
Full guide: Track subcontractors: insurance, RAMS and expiry alerts
Which plan includes subcontractor tracking?
The reusable account-wide subcontractor directory is Pro and above, on both the website and signed-in mobile app. When the server reports that your account no longer has directory access, the app hides saved firms in the account directory and the project picker, including any firm details or edit form already open. Reopen the directory after access is restored to load fresh firms. Firms already on a project remain visible. Linking, viewing or unlinking a firm on one project stays available on Starter because it is core project and RAMS paperwork. The Business evidence review workflow is Business and above. Tracking what each firm owes you for each package of work — with due dates and overdue states — is coming to Business plans.
Full guide: Track subcontractors: insurance, RAMS and expiry alerts
Site access & team site tools
How do I reply to or close an RFI in the contractor app?
For a project whose owning account is on Site Control, open the project in the contractor app and tap RFIs, then open the request. Add a reply with Add comment, attach a file with Attach file, or use Close RFI when the request is resolved. If your project access or contractor identity changes while you are choosing a file or sending a reply, reopen the RFI under your current identity. Check the thread and attachments before trying again: a request already sent may have been saved even if its confirmation did not reach the app.
Can I attach a file when I answer an RFI on the web?
RFIs are a Site Control feature. Open the project's Site Info tab (under Setup if you use the New project view), find the request under RFIs and click Answer. The Answer attachment URL field accepts an external link only — an https:// address for a drawing or document hosted somewhere else, such as your client's file share. A link to a file stored in The Site Book (a site file, a plant photo or another RFI's attachment, for example) is refused with an error and the answer is not sent. That stops a reply from exposing an unrelated private file to the contractors who read the RFI. To share one of your stored files with them instead, an owner or admin adds it under Site files on the same Site Info tab, so it goes through the normal portal visibility controls.
Can I answer or reopen an RFI that has been closed or voided?
No. RFIs are a Site Control feature: on the project's Site Info tab (under Setup if you use the New project view), Answer and Close are shown under RFIs only while a request is Open or Answered — you can add a follow-up answer to an Answered one. Once an RFI is Closed or Void, the dashboard and the contractor app both treat it as final: it cannot be answered, closed again or reopened from either. If you see "This RFI has been closed or voided" after clicking Send answer or Close, someone closed it (or the contractor did, from the app) after your page loaded — reload the page to see its current status. Your answer was not saved, so nothing half-sent is left behind. A contractor who taps Close RFI in the app on an RFI that is already closed or voided sees a message saying so, and nothing changes. If the project is linked to Procore, Procore's status takes precedence for a linked RFI: one reopened in Procore reopens here on the next sync.
Does using the contractor app create a company account for me?
No. Your contractor access stays linked to the sites you have been given access to. Opening an internal company link does not create a separate company account or give you access to company management screens. If you also need internal team access, ask the company owner or an admin to invite you to their team.
How many portal users do I get?
Business includes 50 active site portal users across your account (Site Control is unlimited). The Portal users section shows both counts — this project and account-wide. A worker added to a project gets a worker portal identity and counts in the active total while they have active project access, including through crew sign-off. Worker setup is designed never to stop site work: if adding a project worker crosses the included allowance, the account cap is raised automatically and the overage is recorded for a capacity conversation. Other manual additions or reactivations at a reached cap ask you to deactivate someone or contact us for an agreed limit increase. Deactivating someone frees capacity without deleting their identity or recorded sign-off and attendance history. There is currently no published per-user add-on rate.
How does a portal user log in?
They don't need an account — each portal user gets a personal magic link (Copy it from their row and send it). It opens their site portal with the project's details, documents, COSHH information and files.
What does “active sites” mean in the contractor app?
The workspace picker shows an active-site count beside each linked Site Access identity. It includes jobs where Site Access is switched on, jobs where that worker has a current document to sign, and jobs sharing view-only COSHH information. A current sign-off-only job still counts even when the wider Site Access tools are not switched on. The count matches the sites you can open: an archived job can still count while its active grant provides Site Access or view-only COSHH information. Removed project access and deactivated portal identities stop counting.
A portal link was shared or leaked — how do I cut it off?
On the worker's row in Portal users, click Rotate link (owners and admins only). This creates a new link and stops the old one working straight away, so a forwarded or bookmarked copy no longer opens the portal — and any contractor-app sign-in made with the old link is disconnected too. Then Copy the new link and send it to the worker; opening it restores their access (including re-linking the app). The worker's identity, sign-off and attendance history are kept — only the link changes. Rotate the link instead of Deactivate when you want to keep the worker but replace the link.
Why is the contractor app checking my access again?
When your linked worker identity or project access changes, the contractor app checks your current access before showing the site details. If it switches to another worker identity automatically, it clears the previous identity's saved site information first. This also applies when an earlier identity becomes available again, so you only see information for the identity you are using now.
How do I upload paperwork in the contractor app?
On projects whose owning account has Site Control, open the project in the contractor app, tap Credentials, choose My paperwork or — if you manage the contractor company — Company paperwork, select the paperwork type, then tap Upload and choose a PDF or image from your phone. If you lose connection, the app saves the upload for the next sync and shows a waiting message. Leave that queued upload to sync instead of choosing the same file again; if the file already reached the server, sync finishes attaching that saved file to the credential. If your worker identity or project access changes while you are choosing or uploading a file, you may need to reopen Credentials and choose the file again once access is restored. Uploads already saved for later can continue in the background while you remain signed in and have access.
Do portal links expire?
There is no fixed expiry date, but a link that goes unused for 90 days is switched off automatically. Any use resets the clock — opening the link, signing a document, checking in at the gate (including a remembered device), acknowledging the site induction, or using the contractor app. So a worker on your site regularly is never affected; this only retires links nobody has touched for three months. If you think a link has been shared, use Rotate link to replace it straight away rather than waiting.
A worker's link stopped working and nobody deactivated them
It was probably retired for inactivity — links unused for 90 days switch off automatically, so an old forwarded copy cannot sit valid forever. Nothing is lost: their old identity, sign-off records and attendance history are all kept and still appear in your audit pack. To bring them back, add them again in Portal users (Access tab): enter their name and company and click Add portal user, then Copy their new link and send it. A retired person does not appear in the list, so there is no row to rotate — adding them creates a fresh identity with a brand-new link, which is deliberate, because the retired link must stay dead. One thing to expect: because it is a new identity, they will be asked to sign the current RAMS again before they can check in.
Can I let a team member run site access without making them an admin?
Yes — under Site access managers, assign an account member to this project. They get attendance and access-request visibility for this project only; full portal-user management stays with owners and admins.
Is Site Access on Pro?
No — the Site Access management surface (portal, attendance and files) is Business and above. Worker document sign-off via the crew link works on every plan and does not require those management screens. Putting a worker on a project still creates their worker portal identity for the job and includes them in the active portal-user count while assigned.
What happens when a required RAMS sign-off blocks Smart Gate check-in?
The worker's access can be approved while attendance stays off site. The gate page keeps that approved request ready: complete the required RAMS sign-off from the worker's site portal, return to the open gate page and choose Try check in again. The continuation uses the same private request and does not upload a second CSCS card or create a duplicate access request. If delivery was interrupted, it safely retries the worker's approval email before continuing. It then checks that both the worker and their project access are still active, and a successful check-in sends the project's configured attendance notifications.
How do workers check in?
From their side — through their portal link, or on Site Control through the site entrance QR. You see the live list on the Access tab and can check anyone out manually.
Full guide: Site attendance: who's on site, history and reports
Someone forgot to check out — can I fix the record?
Yes. In Attendance history, click Correct on the row, set the right times, add a correction note and save. Corrections are recorded, not silent edits.
Full guide: Site attendance: who's on site, history and reports
What if the app loses connection just after I end an evacuation?
Once the app confirms the evacuation ended, it keeps that record in Recent evacuations even if the next refresh fails. Where several marshals are working at once, the app keeps the latest confirmed roll-call and orders Recent evacuations by when they started, rather than by which response arrives last. The roll-call PDF needs a connection to download. Failed refreshes show the last confirmed information with a warning; a confirmed loss of access hides the affected information instead. If you open the app, or switch back to it, more than about four hours after the last confirmed refresh, the evacuation screen shows Roll-call hidden instead of the stored copy until you reconnect and the next refresh succeeds — this protects people's details if access was revoked while the device was offline. A roll-call already on your screen is not cleared just because time passes, or when you briefly open a system panel such as Control Centre; that check happens only when you open the app or switch back to it. The stored copy is also dropped once the app can confirm the evacuation was started, ended, or corrected someone from safe back to unaccounted on another device while it was closed, so a reopened app never shows a roll-call state that another marshal has already superseded.
Full guide: Site attendance: who's on site, history and reports
Where's the monthly H&S report?
In the H&S attendance section header: "Download monthly H&S CSV" and "Download monthly H&S PDF" cover the current month, alongside full exports and the audit log.
Full guide: Site attendance: who's on site, history and reports
What file categories are there?
Drawings, plans, H&S documents, procedures, RAMS, CPPs, emergency information and other — the category shows in the portal so people find the right file fast.
What does "Requires acknowledgement before work starts" do?
It marks the file as must-read: you can then request acknowledgements and see who has confirmed reading it — the evidence trail that the drawing revision or procedure actually reached the crew.
What happens when I replace a file?
You choose: re-request acknowledgements for the new version, or replace quietly without new requests. Re-requesting is the right call when the content change matters on site.
How is this different from worker sign-off?
Worker sign-off is the crew attesting they've read and signed a document. Manager acknowledgements are the management layer — the people running the job confirming the current version before work starts. Both are version-aware.
What do I get on Business vs Site Control?
Business includes read acknowledgements on site files ("Requires acknowledgement before work starts") and the internal Business review history on documents. Requesting manager acknowledgements against a generated document version is Site Control.
What happens to acknowledgements when I regenerate the document?
They're marked Superseded — the record of who confirmed the old version stays, and you can request acknowledgements again for the new one.
Does the Business review history send emails?
No — it's an internal evidence log. The buttons record review states (in review, reviewed, approved, changes needed, superseded) against the document without triggering any external workflow.
Does this email the subcontractor or give them an upload portal?
No — it's deliberately your internal record of what you checked and what you concluded. It doesn't send evidence request emails or open a self-upload portal for the firm.
What evidence types can I record?
RAMS, insurance, liability, H&S policy, training, certificates, and other — each with an optional file link, expiry date and your review note.
Who can record and approve evidence?
Owners and admins, on Business and above.
What happens if I change account while editing an inspection in the app?
The app clears the old account's open inspection form and corrective-action dialog. Open the inspection again in the correct account before saving. A delayed result from the previous account will not close your new form or show an error against it. If you close a cancellation dialog and open another, enter the reason in the new dialog before confirming.
Which plan includes inspections?
Business and above. The tab is visible on every plan so you can see what it does; below Business it shows the upgrade path instead of records.
Can I assign an action to someone on site?
Yes — each corrective action takes a responsible person and a due date, and actions can be assigned to portal users. Track them Open → In progress → Done.
Will I be reminded to inspect?
Yes — every Monday, the account owner gets one email listing any active project that hasn't had an inspection recorded in the last 7 days (projects in their first week are skipped). Record a weekly walkaround and the reminder stays quiet. Turn notifications off in Settings to stop these emails.
What does "Summarise with AI" do?
It turns your rough walkaround notes into a tidy inspection summary — you review it before saving, like everything AI-drafted.
Site Control
Can someone check in without doing the induction?
No — induction acknowledgement is a hard gate in every mode. The check-in button stays disabled until they've confirmed the induction.
Full guide: Site Control: entrance QR, contractor self-join and gate policy
Do I have to approve every contractor manually?
Your choice — the Gate sign-in policy sets it: Balanced (sign in now, verify CSCS after — recommended), Controlled (everyone waits for approval), Trusted firms (known companies go straight in), or Open (lightest checks). For security, a request that uses an existing worker's email from an unrecognised device always waits for manager review rather than attaching to that worker automatically.
Full guide: Site Control: entrance QR, contractor self-join and gate policy
What happens if the QR poster leaks off site?
Treat a leaked QR as live: in Balanced and Open modes a newcomer who acknowledges the induction can sign in immediately (CSCS is verified after). Hit Regenerate or Disable on the Access tab straight away — the old QR stops working immediately — or switch the gate policy to Controlled so everyone waits for approval.
Full guide: Site Control: entrance QR, contractor self-join and gate policy
What counts as a plot signed off?
Every trade on the plot showing Signed. A trade signs off one of two ways, depending on your project's mode: you mark it signed manually, or the contractor signs a document via a sign-off link — which records the trade as signed immediately, and lets the signer send the certified PDF to the account owner and the contractor with Finish & email the signed copy. The exact signed revision, message and recipient are fixed before delivery. If two people finish at the same time, they reuse the same delivery. If a provider result is uncertain, the page shows that delivery is pending while bounded automatic retries run; it asks you to contact support instead of risking a duplicate once delivery needs manual checking.
Can I create fifty plots at once?
Yes — "Add a range" generates numbered plots in one go (Plot 1 … Plot N).
Is there a limit on how many plots a project can have?
Yes — 500 plots per project, which covers any single development (a typical one has around 55). Both Add a plot and Add a range stop at that ceiling: if a range would take you past it, nothing is created and you'll see "This project already has N plots — the limit is 500. Delete some plots before adding more." Re-running a range you've already added is fine — plots that already exist don't count towards the limit again.
The page says "Preparing your signed copy…" after signing — is something wrong?
No — that's normal. After a signature is captured, the signed copy (the original document with the signature page attached) is put together in the background. The Download Signed Copy button — and Finish & email the signed copy — become available as soon as it's ready. If it's still preparing when the page closes, reopening the same sign-off link picks up where it left off.
What if single sign-on cannot be verified temporarily?
If The Site Book cannot check your account or sign-on provider, access pauses until the check succeeds. Retry shortly; the mobile app keeps this as a temporary error rather than signing you out. A service outage does not switch off your company’s SSO requirement.
Full guide: Enterprise integrations: SSO, API keys and webhooks
What if a mobile sign-in ends while SSO is required?
The mobile API checks the current sign-in and refuses access when the account's SSO policy is not satisfied. In the app, enter your work email and choose Continue with SSO to open your company's identity provider. Access resumes only after the app verifies the new session. Older app versions should use the website to sign in through the identity provider.
Full guide: Enterprise integrations: SSO, API keys and webhooks
Can the API create or update data?
No — the v1 API is read-only by design. Scopes cover projects, documents, workers, certifications and attendance, rate-limited at 120 requests a minute. Full reference at thesitebook.co.uk/docs/api.
Full guide: Enterprise integrations: SSO, API keys and webhooks
How do I set up SSO?
SSO set-up is done with our team — Okta, Microsoft Entra ID or any SAML 2.0 provider. Email [email protected] to arrange set-up with the team. Once active, go to Settings → Integrations → Manage SSO and select "Require SSO" to enforce it for your whole team. Switching Require SSO on refuses any session that started before the switch — everyone on your domain signs in again through your identity provider, on the web and in the mobile app. The account owner keeps break-glass access.
Full guide: Enterprise integrations: SSO, API keys and webhooks
What does an older, non-SSO session still reach once Require SSO is on?
On the website, a session that did not come through your identity provider is sent to the "Your organisation requires single sign-on" screen throughout the app, including when someone follows a link between pages. The surrounding web actions refuse it too: opening a site file download link or resuming a checkout after sign-up lands on that same screen, and upgrade, feedback, the dashboard call-back card and the start-a-project steps show a single sign-on message instead of going ahead. The screen's "Sign out and use SSO" action opens the login page for another attempt. In the native app, enter your work email and choose Continue with SSO; the app verifies the resulting session before reopening account data. Public pages such as pricing still load. Links that carry their own access rather than a login — a contractor's portal link or a document share link — keep working on their own terms.
Full guide: Enterprise integrations: SSO, API keys and webhooks
What events do webhooks send?
Documents generated and signed, certificates expiring, workers checking in, inductions acknowledged, a document version sent for named approval, a version approved by its named approver, and an approved document published to your SharePoint site — each signed with HMAC-SHA256 so your systems can verify it. Webhooks never carry the PDF itself. The three document approval and SharePoint events carry identifiers only (fetch the exact version through the public API if you need it); the other events include names such as the worker, signer or certificate holder, so treat your receiving system as holding personal data.
Full guide: Enterprise integrations: SSO, API keys and webhooks
Team & billing
How much does it cost?
Starter is £0 — one real project, free, no card needed. Pro is £39/mo, or £30/mo billed yearly (£360/yr). Business is £199/mo. Site Control, the per-site tier for principal contractors, is £675/site/mo plus a £5,000 setup, sales-led.
Can I cancel anytime?
Yes — Settings → Billing, no minimum term, no cancellation fees. You keep access until the end of your billing period, your documents are never deleted, and you keep read-only access to your history afterwards. Read-only means exactly that: your projects and documents stay readable and your data stays exportable, but your own team cannot change anything — no new jobs and no edits to projects, workers or documents — whether signed in on the web or the phone app, through a saved draft from our website, or through a Zapier step that creates a job or adds a worker, which will start returning an error. The one exception is safety recording, which stays open wherever your plan still includes it — document sign-offs and sign links, the crew sign-off link and workers' own sign-offs. A blocked change shows a message explaining that the account is read-only. While your account still has the plan and permissions for each control, you can use its web revocation actions to tidy up access: on Business or Site Control that includes removing team members and cancelling invitations, and eligible accounts can revoke share links, API keys, webhooks and connected apps. If cancellation moves the account to Starter, Business-only team controls pause until you reactivate under Settings, then Billing.
Is there a free trial or a refund policy?
You don't need a trial — Starter gives you one real project completely free, no card required, and it stays yours. On paid plans there's no minimum term: cancel anytime and you keep access until the end of the billing period, so there's nothing to claw back.
How do I invite team members?
Business and above includes up to 10 internal team logins — owners invite admins or members from Team settings; admins can invite members. Pro is one internal login, with read-only document sharing for clients and principal contractors.
Do the website and mobile app include the same plan features?
Yes. Your plan and retained feature access apply in both places. Site Diary, incidents, permits, toolbox talks, COSHH and the Audit-Ready Pack require Pro or above; a project bought through our setup service keeps its project-scoped Pro tools. Project subcontractor paperwork stays available on Starter because it is part of the core RAMS workflow, while the reusable account-wide subcontractor directory requires Pro.
Can I see Business before I buy?
Yes. You can request a focused 20-minute Business walkthrough around your team and live jobs before deciding. The form asks for your role, team size, active-job count and main need so the demonstration can stay relevant; timing and extra context are optional. Your request is saved before the booking page opens, so we can follow up if you leave without choosing a time. Business is £199/mo, and direct checkout remains available if you are ready to start without a walkthrough.
How do I compare products for my business size?
Open the website's Compare page at `/compare`, choose a page type such as Head-to-head, then select your size. The size choice puts matching comparisons first without hiding the others. Site Control — per-site contractor access is prioritised only for 20–100 person firm and 100+ enterprise; smaller businesses see the ordinary product comparisons first.
Can I export my data?
Yes — open Settings → Export Data and select Download my data. The ZIP includes your current account's project records, document metadata and complete frozen H&S review draft history, together with available files within the export limits. Available anytime, including after cancelling. Wait for the download to finish, then check its notes for any unavailable or oversized files and save missing originals separately from the relevant project.
How do I permanently delete my account?
Open Settings → Delete Account, read the warning, then type DELETE to confirm. Export anything you need first: deletion cannot be undone. Records owned solely by you are removed. If you contributed to another company's shared account, its projects, saved sites, contacts, COSHH library and legally retained compliance or finance evidence stay with that account; your user link is reassigned, removed or anonymised. The Privacy Policy explains the limited legal and anti-resurrection records that may remain.
Why did I receive a Trustpilot review email?
If marketing email is still enabled, we may send one review request shortly after you generate a document, while the result is fresh. If you have not left a review, we may send one final reminder a week later. Every review email includes an unsubscribe link; open it and confirm to stop the reminder and other marketing emails for that address. The address stays opted out even if a new demo or account record is created later; only a separate, verified re-consent process could switch marketing back on.
Why did I receive a setup, demo follow-up or account progress email?
If marketing email is enabled, we may send a short setup guide, demo follow-up, review request, monthly summary or another message that matches where you have reached. These are scheduled after relevant milestones rather than sent at an exact minute. If a scheduled run is interrupted, unfinished recipients remain eligible for the next successful run; where messages form a sequence, a newer relevant step replaces an outdated earlier one instead of stacking both together. Every marketing email includes an unsubscribe link.
What payment methods are accepted?
All major credit and debit cards via Stripe — Visa, Mastercard, American Express. Payments are secure and PCI compliant.
What happens if a payment fails?
While we retry the payment, your account keeps working normally — on the web and in the phone app alike. For the account owner, a red banner appears at the top of every page with an Open billing portal button — use it to update your card or pay the outstanding invoice. You can also sort payment any time under Settings → Billing. Team members see a heads-up version of the banner instead — only the account owner can fix payment, so their banner carries no billing buttons. On Pro, if the payment still hasn't gone through after 10 days your account moves back to Starter — your projects and documents are kept, you lose Pro features, and the account becomes read-only until payment is sorted; paying restores them automatically. We apply that switch across your account in one transaction; if a temporary system error prevents every part from completing, nothing is switched and a later run retries. Business and Site Control accounts aren't subject to that 10-day step — they keep working while we get in touch to sort payment personally, including when a Site Control renewal invoice has passed its due date. On any plan, if the subscription is eventually closed or cancelled because payment never completes, the account moves to Starter and becomes read-only in the same way — and paying brings your plan straight back. While the account is read-only, everyone on it can still open its projects and documents, and Download my data under Settings → Export Data keeps working, but changes made by your own signed-in team (a new job, an edit, a new worker) — and by any Zapier step that creates a job or adds a worker — are refused with a message explaining why, and the account unlocks as soon as the payment goes through. On Starter you also cannot start a new job if you already have one, so any Zapier Create Project step will fail until the plan is back. Safety recording stays open wherever your plan still includes it: on the web, document sign-offs captured on your own device, new sign and share links for your documents and your project's crew sign-off link all keep working, and workers' own sign-offs carry on as normal, on the web and in the app. A read-only account is on Starter, so safety tools that come with a paid plan — such as incident records, inspections, site check-ins, join-request reviews and evacuation roll-calls — stay available only if your plan still includes them. The account owner can still use revocation controls included in the account's current plan and permissions: share links, subcontractor request links, project manager access, API keys, webhooks and connected apps keep their usual plan and role checks, and Business-only controls — such as removing team members — pause while the plan is Starter. An internal team invitation cannot be accepted into a read-only account until its owner fixes billing, even if the invited person's own account is healthy.
How do I change or withdraw analytics and advertising consent?
Select Cookie preferences in the site footer. Choose Accept all or Reject all, or select Choose cookies to switch Analytics, Advertising and More relevant advertising on or off and then Save choices — essential cookies stay on either way. More relevant advertising is a separate permission that requires Advertising, so switching it on also switches Advertising on, and switching Advertising off switches it off. Rejecting a category takes effect immediately in that browser: our optional first-party identifiers for that category are removed and new collection stops, rejecting Advertising also clears stored advertising attribution, and rejecting More relevant advertising stops Google building a remarketing audience from your visit. If you make an explicit choice before signing in, that choice follows the same browser into the signed-in session; if you are the billing owner, it is then saved against your account. A choice deferred while you are already signed in is bound to that signed-in user, so a different owner using the browser must confirm their own choice. A team member's choice stays in their own browser and cannot change the owner's account setting. We ask again after 180 days. One exception is permanent: if you previously withdrew Google Ads server-side matching for your account — by rejecting Advertising while signed in, or through the email-verified withdrawal form — accepting Advertising again does not re-enable that matching, and the banner shows a dismissable notice confirming it stays withdrawn. A Site Control enquiry or Business walkthrough request can be withdrawn separately through the email-verified withdrawal form on our Cookie policy page. When a paid Pro checkout is measured server-side, it uses the settled checkout amount and its exact Pro plan; the same current advertising consent and permanent withdrawal rules apply.
Does an invited teammate need their own subscription?
No. Admins, members and site supervisors use the plan and billing state of the account they joined. Only the account owner manages that subscription; a site supervisor cannot open account or billing settings.
What can each role do?
Members can work in the account, but they cannot start a job — only an owner or admin can create a project, so a member should ask one of them to set the job up. Admins can also manage projects and site access, and invite members or site supervisors. Owners can additionally manage the team itself — change roles, remove members and invite admins. Site supervisors are different: they get a field-only login that can write the Site Diary, Inspections, Incidents and Photos only on the sites or one-off projects you assign, plus a Crew tab listing those sites' worker names and PIN status so they can reset a forgotten sign-off PIN — and nothing else.
What is a site supervisor login for?
For someone who runs the site day to day but should not see your documents, pricing or settings. They log in, pick a project, and can fill in the Site Diary, record Inspections and corrective actions, log Incidents and add Photos. They also get a Crew tab — the site's worker names and whether each has a sign-off PIN set, with one action: reset it. No contact details, no editing, no crew link. A site supervisor uses a normal team seat.
Do site portal users count against my team seats?
No. Team seats are internal logins. Site portal users (workers, subcontractors, visitors using the portal) are managed per project and counted separately.
How many logins do I get?
Business includes up to 10 internal team logins as standard (£199/mo). The Team page shows how many seats are reserved, including pending invitations.
When do I get the free month?
When someone who signed up through your link starts their first paid subscription — not just on signup. The month is added to your subscription automatically, and it stays counted even if they later cancel.
Does it count if they were already paying?
No. The credit is for builders whose own first paid subscription starts through your link. Someone who already has their own Pro, Business or Site Control subscription — or who has had one before and cancelled — won't be counted. Invited team members on someone else's Business or Site Control account are different: they haven't paid for their own subscription, so their first personal paid plan can still earn you the credit.
How do I track my referrals?
The Invite & Earn page shows two counters: people who signed up with your link, and how many of them started a paid plan. If someone has just signed up or paid, refresh the page to update both counters.
Integrations
What does the Google Drive integration do?
Use Export to Google Drive from a project to send the latest generated RAMS, CPP and COSHH PDFs to your own Drive. The one-click export creates a The Site Book folder and organises files in a project subfolder. It is an on-demand export, not an automatic per-signature sync. If your account uses named document approvals, a document whose latest version has not been approved yet (never requested, still waiting for approval, or sent back) is skipped, and the export tells you how many were left out. Draft previews are never exported.
What can Zapier trigger on?
Three events: New Project Created, Worker Added to Project, and Document Generated. Zapier can also create a project or add a worker in The Site Book. Generate a personal API key under Settings, then Integrations, and use it in your Zapier dashboard to connect 5,000+ apps. When Zapier asks for a New Project sample during setup, it shows up to three of that account's most recent projects through the same key; create a test project and retry if the list is empty. A key is permanently pinned to the account where you generated it: accepting an invitation or changing your primary account does not move that key or open another account's projects. Generate a separate key for each account you automate; Settings labels every key with its account and offers Generate key for current account whenever the selected account has none. It does not raise your plan or role. Owners and admins can Create Project, while a team member can use account reads, Add Worker and the three account event triggers. Site supervisors are field-only and cannot use account-wide Zapier data.
Why does the Zapier card say my key cannot create jobs?
Because you are signed in as a team member, and only an account owner or admin can start a job. The key is still generated and can read that account, add workers and drive its three event triggers — but any Create Project step will be refused. The notice beside a newly generated or replaced key always describes that key's account and role, even when this login has keys for several accounts. Ask an owner or admin to generate the key from their own login and reconnect the Zap. Changing plan makes no difference, because this is about your role, not your plan. Site supervisors are field-only: they cannot generate a key, and a retained key is paused with role_forbidden if the login is later changed to that role.
My Zapier Create Project step returns 403. Why?
Read the error field in Zapier — it names the cause. feature_locked means this account no longer includes Zapier, for example after a downgrade from Pro to Starter: the existing key and event subscriptions are paused, not deleted, and resume when the account returns to Pro or above. role_forbidden means the key belongs to a team member or site supervisor, and only an account owner or admin can start a job: generate the key from an owner or admin login instead. Upgrading will not help that role restriction. free_project_limit can apply only when a Starter account has retained grandfathered Integrations access and already has its one project. A read-only message means the account has moved to Starter with a payment still outstanding, or its subscription was cancelled (a card payment that is only being retried never causes it): the account owner can settle the payment or reactivate under Settings → Billing. entitlement_unavailable means we could not confirm the account's access at that moment — run the Zap again shortly.
Connecting says it was started from a different login, or that I was signed out. Why?
A connection must finish in the same signed-in login that started it. When you click Connect Google Drive, Connect Xero or Connect Slack (Business plan and above), the approval screen that follows is tied to your login, and the connection is saved only if you come back to The Site Book still signed in as that same person. If someone sends you a Connect or approval link they started themselves, it is refused and nothing is connected, so another account can never be linked to your Drive, Xero or Slack. The message then reads "this connection was started from a different login". If you were signed out along the way it reads "you were signed out before the connection finished", and a link that is too old or damaged reads "the connection link was invalid or has expired". In each case, sign in as yourself, open Settings → Integrations and click the app's Connect button again. Procore is not yet publicly launched. For Site Control accounts invited to early access, the same login rule applies: on Settings → Integrations click Manage Procore, then Connect Procore, and a refused connection shows the same messages on that Procore page.
Why can't I connect an app while my account is read-only?
Connecting Google Drive, Xero, Slack or Procore saves a new connection. While a card payment is only being retried your plan keeps working, Connect included. Once the account is read-only — its plan has moved to Starter because a payment is still outstanding, or its subscription was cancelled — Connect is refused even though you can still view your existing records and reach Settings → Billing. If the payment state changes while you're approving access with the app, The Site Book checks again before saving and explains that the account is read-only. For Site Control accounts invited to Procore early access, a project, worker, RFI or inspection import also checks the account again before saving fetched changes, so an import already in progress stops if billing makes the account read-only. The account owner can settle the payment or reactivate under Settings → Billing. Once an invited Site Control account is writable again, open Settings → Integrations → Manage Procore and use Import or Re-import for projects, or Sync RFIs or Sync inspections for those records. For another app, use its Connect button under Settings → Integrations.
Xero says no organisation was chosen, or Sync with Xero says no organisation is connected. What do I do?
The Site Book creates client contacts in one Xero organisation, which you choose on Xero's permission screen after clicking Connect Xero on Settings → Integrations. If Xero comes back without an organisation, nothing is connected and the message reads "no Xero organisation was chosen": click Connect Xero again and pick the organisation you invoice from. Your Xero login needs access to that organisation, so if it has none, ask whoever runs your Xero to invite you first. If your Xero login has several organisations, choose only the one you want contacts created in. Sync with Xero is on each project's Overview, in the Export & share card (or inside Documents, export & share). An existing connection that is missing its organisation picks it up from Xero automatically the first time you sync. If Sync with Xero says "No Xero organisation is connected" — for example because the organisation was removed from The Site Book in Xero — click Go to Integrations on that message, then Connect Xero on the Xero card and choose your organisation.
What is Slack Site Ready?
On Business and above: ask "Site Ready" from Slack and it combines the project's compliance state with recent site-channel context into a red/amber/green digest — with the blockers and one-click actions like sending sign-off links. It's on-demand, not a notification feed.
Which plans include integrations?
Google Drive, Xero and Zapier come with Pro and above. Slack Site Ready is Business and above. SSO, the read-only REST API and webhooks are Site Control only — see the Enterprise integrations article.
Who can set this up?
It's part of Site Control. The Site Book's support team binds your Microsoft Entra tenant to your account first — email [email protected] to get started. Once that's done, an account owner or admin points it at a SharePoint site from Settings → Integrations → Microsoft 365, which needs your organisation's IT admin to grant consent and a site permission first (we'll send them exactly what to run).
What actually gets published?
Only a document's CURRENT version, once it has been approved through Document approvals AND issue-confirmed (the same liability tick required before anyone can download or share it). If the version has a signed copy, that's what goes to SharePoint; otherwise the approved PDF goes. Drafts, pending-approval versions and rejected versions are never published.
What happens if I disconnect or pause it?
Nothing already copied to SharePoint is recalled — those copies stay in SharePoint as your own retained history. Pausing or disconnecting only stops copies going out, and it never stops you confirming a document for issue. If Publish automatically after approval is on, anything approved while publishing is paused (or while your Microsoft connection is disabled, or your destination is waiting to be re-verified) isn't lost — it waits in Delivery history as Paused and publishes automatically once publishing is available again. The same goes for a manual publish: Publish to SharePoint or Confirm issue & publish on a document's page still records your confirmation straight away, and the document is held as Paused and goes out once when publishing is available again if that same version and approval are still current. A held document that hasn't been confirmed for issue yet also waits for that confirmation before anything is sent. Nothing is queued while no destination is connected — your confirmation is still recorded, and the message tells you nothing was published to SharePoint. Pause publishing only holds SharePoint uploads: Teams notifications, including approval-request cards, keep sending. To stop those, turn off Channel enabled in the Teams notifications section of the same settings page. The approval itself always stays recorded in The Site Book regardless of what happens on the SharePoint side.
Does a newer signed copy replace the one already in SharePoint?
No — SharePoint never overwrites or renames a file it already has. A new signature revision publishes as its OWN file (revision noted in the name and in the history table) when "Publish new signed copies automatically" is on, or when you retry manually. Nothing is silently replaced.
Is there a size or file-count limit?
Each document is capped at 25 MB (the same limit The Site Book stores generated PDFs under). There's no limit on how many documents publish over time.
Can I get a public sharing link from this?
No — this only copies files into your own SharePoint library, using your organisation's existing SharePoint permissions. It doesn't create public or anonymous sharing links.
Does The Site Book connect to Teams directly?
No. The Site Book posts to your own Power Automate flow's webhook trigger; your flow is what posts the Adaptive Card into your Teams channel. The Site Book never holds a Teams token or Teams channel access.
Full guide: Post Teams notifications when a document is approved or published
Who can see the Teams message?
Everyone in the channel your flow posts to. The card carries the project name, document type and version, and (for an approval request) the assigned approver's name — treat the channel's own membership as who can see that.
Full guide: Post Teams notifications when a document is approved or published
Does approving a document in Teams do anything?
No. The card is a notification only — it links back to The Site Book. The approval decision itself always happens in The Site Book, never in Teams or in Power Automate.
Full guide: Post Teams notifications when a document is approved or published
What does "Accepted" mean, versus "Posted"?
Accepted by Power Automate — check the channel for the card; if it doesn't appear, open the flow's run history in Power Automate. That's deliberately not a stronger claim: the webhook trigger returns its response BEFORE "Post card in a chat or channel" actually runs, so Accepted doesn't prove the card was posted, only that Power Automate received the request. You may occasionally see "Posted" instead, which IS a confirmed receipt — but only a flow with an extra Response action reports it, and that action is itself a Premium one. The recommended template never adds it, so don't add it yourself just to see "Posted" — see "Accepted, but no card appeared?" below if a card seems to be missing.
Full guide: Post Teams notifications when a document is approved or published
I got "Accepted", but no card appeared in the channel — what do I check?
In roughly this order: (1) Open the flow in Power Automate and check its run history — did "Post card in a chat or channel" actually run, and did it succeed? A failed step there explains a missing card even though the trigger itself returned Accepted. (2) Is the flow posting to a standard or shared channel? Microsoft doesn't support posting to a private channel this way — if you picked a private channel, rebuild the flow pointing at a standard or shared one. (3) Check your Teams admin centre's app permission policies — the Workflows app itself can be blocked or restricted there, independently of anything in Power Automate. (4) The service-principal check isn't the cause here — Accepted already shows the request got past it (a rejected id would have come back 401/403, not Accepted). Still worth confirming on the trigger itself that "Who can trigger the flow?" isn't set to an empty list or "Any user in my tenant", both of which also return Accepted but leave the flow open to anyone in your tenant.
Full guide: Post Teams notifications when a document is approved or published
What is a shared-access flow URL, and why does The Site Book warn about it?
Power Automate can restrict the webhook trigger to "Specific users in my tenant" (recommended — see below) or leave it open to "Anyone", in which case the URL itself carries a `sig=` signature that acts as the credential. The Site Book detects that pattern in any letter case — `sig=`, `Sig=` or `SIG=` are all treated the same — and the acknowledgement checkbox appears on the Flow webhook URL field as soon as you paste a URL like that, before you try to save. You must tick it to save the URL, because anyone who obtains that URL could trigger your flow.
Full guide: Post Teams notifications when a document is approved or published
My flow's URL won't save, and the error mentions logic.azure.com and sig=
A URL on the `logic.azure.com` host family is a plain Azure Logic App rather than Power Automate itself, and Azure Logic Apps has no "Specific users in my tenant" restriction The Site Book can verify — so a URL on that host is only accepted if it carries a `sig=` shared-access signature (and you tick the shared-access acknowledgement). If you built this from the Teams webhook template, go back to the trigger and copy its webhook URL again — a correctly built flow's URL normally ends in `.environment.api.powerplatform.com`, which The Site Book accepts with "Specific users in my tenant" and no `sig=`.
Full guide: Post Teams notifications when a document is approved or published
Why does my test notification keep failing with 401 or 403?
The flow's trigger almost always needs "Specific users in my tenant" set to The Site Book's service principal object id (shown on this settings page once your Microsoft tenant is connected). Check that id is listed as an allowed caller on the trigger, then send another test.
Full guide: Post Teams notifications when a document is approved or published
What happens to notifications while the channel is paused or disabled?
Nothing is sent — The Site Book checks the channel is enabled immediately before every send, never after the fact. Turning Channel enabled back on immediately re-queues any notification that this channel paused specifically for being switched off — you don't need a separate step for those. If The Site Book support disables your Microsoft connection (see Pause, resume and disconnect below), any notification paused specifically for that reason resumes automatically the moment support re-enables it — again, no separate step needed. A notification paused for a different reason (your plan, or the Microsoft 365 integration being switched off account-wide) does not resume just from that — use Resume paused, in the Teams notifications section of Settings → Integrations → Microsoft 365, next to Send test notification, once the underlying issue is fixed. Nothing is retried automatically forever, and notifications queued under a flow URL you've since replaced are cancelled rather than sent under the new one.
Full guide: Post Teams notifications when a document is approved or published
Does pausing SharePoint publishing also pause Teams notifications?
No. Pause publishing (the last tick-box on the SharePoint card of Settings → Integrations → Microsoft 365) only holds SharePoint uploads. Approval requests are not paused, so their Teams cards keep posting while SharePoint publishing is paused. A document held because publishing is paused posts its Published to SharePoint card when it actually publishes, after you untick Pause publishing. To stop Teams cards, turn off Channel enabled in the Teams notifications section of the same page — it sits below Delivery history.
Full guide: Post Teams notifications when a document is approved or published
A notification sat paused for a while — could it post a stale card once it's resumed?
No. Immediately before sending — not when it was first queued or paused — The Site Book re-checks that the event type is still switched on under Choose which events notify, and, for an approval-requested card, that the approval hasn't since been re-requested to someone else, approved, rejected or cancelled. If either has changed, the notification is cancelled instead of posted, so resuming a backlog (or fixing a broken flow and sending a test) never surfaces a card for something that's no longer current.
Full guide: Post Teams notifications when a document is approved or published