Record what happened, get it to the right person, and keep the paperwork.
The Incident Report feature lets employees report workplace incidents such as accidents, safety issues, policy violations, or damaged equipment. Authorized managers can review and manage incidents until they are closed. Incident records are never deleted, helping maintain a clear history for safety, accountability, and compliance.
Where to Find It #
- All the reports you can see: Dashboard → Report → Incident
- One report’s full details: open any row from that list (Action menu → View)
- Set up Status, Severity and Incident Types: Dashboard → Admin → Incident Config
- Who can do what: Dashboard → Admin → Permission → Report
Who Can Use This Feature #
Incident Reporting is included in the higher subscription plans only. If your company’s plan does not include it, the page will tell you: “This feature is not available on your current plan.” On those plans the Report permission group and the Incident Config permission are also hidden from Admin → Permission, so if you cannot find the incident permissions at all, check your plan first.
The Subscriber Admin always has full access. Everyone else gets access from Dashboard → Admin → Permission → Report, where these five permissions live:
- Create Incident Report (For Own) — action: Create. Lets the person file a report about themselves only.
- Create Incident Report (For All) — action: Create. Lets the person file a report about any employee, themselves included.
- View Incident Report (For All) — action: View. Lets the person see every report in the company.
- Edit Incident Report (For Own) — action: Update. Lets the person edit only the reports where they are the Reported By employee.
- Edit & Discard Incident Report (For All) — action: Update. Lets the person edit any report, mark reports as completed, and discard completed ones.
A separate Incident Config permission controls the admin setup page — it is not one of the five above. See the Incident Configuration guide for that page.
Permission Behavior
- “For All” includes “For Own”. Someone with Edit & Discard (For All) does not also need the “For Own” version.
- Everyone can open the list page. No permission is needed to reach Report → Incident — the permissions decide what you find inside it.
- Even without any incident report permission, employees can still see incidents they reported themselves or that were reported about them. They can only View these reports, and the + New Incident Report button is not available.
- There is no permanent delete. Instead a completed report can be discarded, which takes it out of active tracking but keeps it stored for history and audits.
All of these permissions can be assigned directly to an employee, or to an entire team at once (so everyone on that team inherits them). See the Permissions Management guide for how to assign permissions.
Who Can See a Given Incident Report #
You can open an incident report if any one of these applies to you:
- You are the Subscriber Admin.
- You have View Incident Report (For All) permission.
- You are the employee the report is about.
- You created the report, including reports you created on behalf of someone else.
- You are an Incident Manager for that report’s Incident Type.
Being an Incident Manager does not automatically give you access to every report. You can only see reports you created, reports about you, and reports for the incident types you manage. To see all company reports, you also need View Incident Report (For All).
Before You Start #
Set these up once, at Dashboard → Admin → Incident Config, before anyone needs to file a report:
- Add your Status values (for example Open, Under Review, Resolved) and mark one as the default. New reports always start on the default status. If no default is set, the create form shows “No default status is set. Please set a default status in Admin → Incident Config first.” and nobody can submit a report.
- Add your Severity values (for example Low, Medium, High).
- Add your Incident Types (for example Fire, Injury, Theft) and give each one its Incident Manager(s) — the people who should handle that kind of incident.
If you skip this, the dropdowns on the create form will simply be empty. Set up at least a few values in each list first.
Full details are in the Incident Configuration guide. Two things about managers are worth knowing here, because they surprise people:
- Making someone an Incident Manager automatically gives them Create Incident Report (For All) and Edit & Discard Incident Report (For All) if they don’t already have these permissions. These permissions apply across the whole company, not just the incident type they manage.
- If you later remove them as an Incident Manager, these permissions are not removed automatically. If needed, remove them manually from Admin → Permission.
- The person will also receive an in-app notification when they are added or removed as an Incident Manager.
Create an Incident Report #
- Go to Dashboard → Report → Incident.
- Click + New Incident Report. (If you cannot see the button, you do not have either Create permission.)
- Fill in the details.
- Upload attachments if you have any.
- Click Add. You will see “Incident report created successfully”, and the report appears in the list right away.

The form asks for:
- Incident name — required, up to 100 characters. A short headline, such as “Slipped on wet floor in canteen”.
- Reported By — the employee the report is about. With Create Incident Report (For Own) this is locked to you. With Create Incident Report (For All) you can pick anyone (the list shows active, licensed employees, and you can search by name or email).
- Incident type — required, picked from the types set up in Incident Config.
- Incident Manager(s) — filled in for you as soon as you choose the type. You cannot pick these yourself. If that type has nobody assigned, it says “No manager assigned to this type”.
- Severity — required, picked from the severities set up in Incident Config.
- Status — shown but not selectable. Every new report starts on your company’s default status.
- Incident date — required, and includes a time as well as a date. This is when the incident actually happened, which can be earlier than today.
- Incident location — optional, up to 200 characters.
- Media — optional. A link to a video, image, document or anything else useful that lives outside Office-X. It is shown on the report’s details page, so anyone who can open the report can follow it.
- Incident details — required, up to 500 characters. What happened, in your own words.
- Attachments — optional. Images or PDF files, up to 5 files, each up to 2MB.

Good to know: every report gets its own Request ID the moment it is created. It is the first column on the list, you can search by it, and it is the ID quoted in every notification and email about that report, so it is the easiest way to talk about one specific incident with a colleague.
View Incident Details #
Open any report from the list to see everything about it. The details page has two tabs: Overview and Attachments.

The Overview tab is in three parts:
- Reporter Information — the person the report is about: their name and employee ID, plus Designation, Department and Email. The Incident Manager(s) for the report are shown here too.
- Incident Report Details — Incident Name, Severity, Incident Type, Location, Incident Date, Last Updated, the Media link, and the full Incident Description. The current state is shown as a badge at the top: your status label while the report is open, or Completed / Discarded once it reaches that point.
- Timeline — the history of the report, explained just below.
The Attachments tab lists every uploaded file with its icon and file name, and lets you preview it or download it. If there are none it says “No attachments available for this incident”.

The Timeline (Who Did What, and When) #
At the bottom of the Overview tab, the Timeline is the report’s own history. It is a simple table with three columns — Date, Status and Action By — and it is the quickest way to answer “who moved this, and when?” without asking anyone.
- The first row is the report being filed, showing the status it started on and who submitted it. There is no separate “Reported” row — that first status is the report being created.
- Every status change adds a row, with the new status, the date and time, and the person who changed it. Nothing is overwritten, so you can see the whole path the report took.
- Completed adds a green row showing who completed the report and when.
- Discarded adds a red row showing who discarded it and when.
Edit Incident Report #
Edit appears in the Action menu when you have the right permission and the report is still open. Incident Managers can edit the reports for the types they manage, because they are granted the “For All” permission automatically.

What you can do in the form depends on which permission you hold:
- Edit Incident Report (For Own): You can edit only incident reports where you are the Reported By employee. The Reported By field cannot be changed. You also cannot Mark as Completed or Discard the report.
- Edit & Discard Incident Report (For All) — you can edit any report, change Reported By, tick Mark as Completed, and discard a report once it is completed.
Completed reports cannot be edited by anyone — not even a “For All” holder or the Subscriber Admin. The Edit option disappears.
Good to know: The Incident Manager(s) field cannot be edited manually by anyone. It always shows the managers assigned to the report’s Incident Type. To change the managers shown there, update the manager list under Admin → Incident Config.
Mark as Completed #
Mark as Completed is a checkbox inside the Edit form, not a separate button. You will see it only if you hold Edit & Discard Incident Report (For All) (or you are the Subscriber Admin), and only while the report is not completed yet.

Tick it, save, and the report:
- is marked Completed, and shows a Completed badge in the Status column instead of your status label;
- is locked from any further editing, for everyone;
- gains a Completed row in its Timeline, recording you and the date;
- becomes eligible to be discarded;
- notifies the reporter that their report is done.
This is what protects a finished record from being quietly changed later.
Discard Incident #
Office-X never permanently deletes an incident report. Discard is how you take a finished report out of active tracking while keeping it on file.

The Discard option shows up only when all three are true: the report is completed, it is not already discarded, and you hold Edit & Discard Incident Report (For All) (or you are the Subscriber Admin).
Click it and a Confirm Discard window asks: “Are you sure you want to discard this completed incident report? This action cannot be undone.” That warning is exact — there is no undo anywhere in Office-X once a report is discarded.
After discarding, the report:
- shows a Discarded badge and cannot be edited or discarded again;
- gains a Discarded row in its Timeline, recording you and the date;
- stays stored for history and audits, and can still be found with the Discarded filter;
- notifies the reporter that it has been discarded.
Incident Lifecycle #
A report’s state is not one single field moving through fixed stages. It is really three separate things:

- Its Status — one of your own labels from Incident Config (Open, Under Review, and so on). It is descriptive only: you can change it as often as you like while the report is open, and it does not lock or unlock anything by itself.
- Whether it is Completed — a simple yes/no, set with the Mark as Completed checkbox. Yes means locked.
- Whether it is Discarded — a simple yes/no, which can only be set after Completed, and is permanent.
In practice the journey is: created → status changes as the work goes on → marked Completed (now locked) → optionally Discarded (out of active tracking, still on file). Only completed reports can be discarded.
Working an Incident as an Incident Manager #
Here is what happens, start to finish, when someone reports an incident of a type you manage.

- It reaches you straight away. The report appears in your Report → Incident list the moment it is filed, and you get a notification. If you manage several types, all of their reports arrive in this same one list — use the Incident Type filter to look at one type at a time.
- Keep people posted while you look into it. Open the same Edit form everyone else uses and move the Status along (for example from “Open” to “Under Investigation”). The reporter is notified each time, and every change is added to the Timeline.
- Close it when you are done. Tick Mark as Completed in that same Edit form and save. The report locks for everyone and the reporter is told it is complete — so make any last edits before you tick it.
- Tidy up if you want to. You can then Discard it to take it out of active tracking. The reporter is notified, and it stays on file for audits.
What happens when the Incident Manager(s) change
People move teams and change roles, so at some point an admin will edit an Incident Type at Dashboard → Admin → Incident Config and swap its managers. The same note is shown right there on the Edit Type screen, and this is what it means:
- Open reports are handed over to the new manager(s). As soon as you save, every report of that type that is not yet completed or discarded is reassigned. The new managers can see and work them immediately; the old managers stop seeing them (unless they also filed or created one of them). You do not have to touch the reports one by one.
- Completed and discarded reports keep the manager(s) they had at the time. They are finished records, so they are left exactly as they were — whoever handled a report back then stays on it, and a newly added manager does not inherit the closed history.
- The permissions follow automatically. Anyone newly named as a manager is granted Create Incident Report (For All) and Edit & Discard Incident Report (For All) on save if they are missing them — that is exactly what the on-screen note means by “granted automatically on save if missing”. Removing a manager does not take those permissions away again, so remove them by hand from Admin → Permission if you need to.
- Both sides get a notification — the people added, and the people removed — naming the type, so nobody is left wondering why reports appeared in or vanished from their list.
Finding the Reports You Need #
The toolbar above the list helps you get to the right report quickly.

- Search — looks in the Incident Name and the Request ID only. It does not search the description, the location or people’s names.
- Filters — open the Filters button for three of them:
Click Apply to use them and Clear to reset. Whatever is switched on is shown as a badge under the toolbar, so a short list never looks like a mystery.
- Status — your own status labels from Incident Config, plus two extra choices at the bottom of the list: Completed and Discarded. Those two are not statuses you set up; they are the lifecycle flags, and they are how you pull up finished or discarded reports.
- Incident Type — one of your configured types.
- Incident Date — a From and To range, matched against when the incident happened (not when it was reported).
- Columns — turn any column on or off to suit how you work.
- Rows per page — 10, 20 or 30.
- Sorting — click a column heading to sort.
The columns are: Request ID, Incident Name, Created By, Reported By, Incident Managers, Incident Type, Severity, Status, Reported Date (when it was filed), Incident Date (when it happened), Attachment and Action.
Good to know: Once an incident report is Completed or Discarded, the Status column shows a Completed or Discarded badge instead of the report’s original status label. The original label is still saved on the report, and you can see its full history in the Timeline.
Notifications, Emails and the Activity Log #
Four things send a notification. Each one always creates an in-app notification, and separately tries to send an email. The email only goes out if your company has an active email template for “Incident Report” and a working email (SMTP) setup — otherwise it is quietly skipped and only the in-app notification arrives. The recipient also needs an email address on file.
1. A report is created
- Who gets it: the Incident Type’s current managers. If that type has no managers set up, the Subscriber Admin gets it instead, so a report never goes unnoticed.
- In-app: “New Incident Report” — “A new incident report [ID] ‘[Incident Name]’ has been reported and needs your attention.”
- Email to the managers: a new report needs their attention, with the incident name, type, severity, who reported it, and a link straight to the report.
- Email to the reporter: a separate confirmation that their report was submitted and is now under review.
2. The status label changes
- Who gets it: the reporter only — and nobody at all if the reporter made the change themselves.
- In-app: “Incident Report Status Updated” — “The status of your incident report [ID] ‘[Incident Name]’ has been updated to [New Status].”
- No email for this one — in-app only.
3. The report is marked completed
- Who gets it: the reporter only — again, nobody if they completed their own report.
- In-app: “Incident Report Completed” — “Your incident report [ID] ‘[Incident Name]’ has been marked as completed.”
- Email: confirms the report is complete.
- Managers are not separately notified when a report they manage is completed — only the reporter is.
4. The report is discarded
- Who gets it: the reporter only — and nobody if they discarded it themselves.
- In-app: “Incident Report Discarded” — “Your incident report [ID] ‘[Incident Name]’ has been discarded.”
- Email: confirms the report has been discarded.
Good to know: Notification or email issues do not stop an action from being completed. Even if a notification cannot be sent, the status change, completion, or discard still goes through successfully.
Good to know: Creating, editing, completing, or discarding an incident report is recorded in the Activity Log, including who made the change and when. Together with the report’s Timeline, this gives you a clear record of what happened to the report.
Your Daily Routine #
If you just need to report something:
- Go to Dashboard → Report → Incident and click + New Incident Report.
- Fill in the name, type, severity, when and where it happened, and what happened. Attach photos or a PDF if you have them.
- Click Add. Note the Request ID — that is how you refer to it later.
- Watch your notifications. You will be told when the status changes, and when the report is completed or discarded.
- Open the report any time and check the Timeline to see where it stands and who moved it.
If you handle incidents:
- Check Report → Incident for new arrivals, or follow the link in your notification.
- Filter by Incident Type or Status to see what still needs work.
- Open a report, read the details and attachments, then use Edit to move its Status along as you go. The reporter is kept informed.
- When it is genuinely finished — and after any last edits — tick Mark as Completed. This locks it for everyone.
- Optionally Discard it to clear it out of active tracking. This cannot be undone, and the record stays on file either way.
Summary #
Incident Report gives you a controlled way to record, work and keep workplace incidents.
- Admins set up Status, Severity and Incident Types (with their managers) in Admin → Incident Config, and hand out the five permissions in Admin → Permission → Report. Everyone works the reports from Report → Incident.
- Visibility is wider than “mine vs. everything”: it also covers whoever filed a report on someone else’s behalf, and whoever manages that report’s Incident Type.
- Naming an Incident Manager grants company-wide create and edit-and-discard rights automatically — worth remembering before you assign one.
- Changing a type’s managers hands over the open reports at once and leaves the completed and discarded ones untouched.
- Managers are told the moment a report of their type is filed, and reporters are kept in the loop at every step — status change, completion and discard.
- Completing locks a report, discarding is permanent, nothing is ever deleted, and the Timeline plus the Activity Log record who did what.