Most cellars don't have a safety problem on paper. They have a stack of laminated procedures, a couple of MSDS binders, and maybe a whiteboard someone updates when they remember. The problem shows up at 6:40 a.m. during harvest when a cellar hand climbs a ladder over an open tank to grab a sample, nobody's tagged the CO₂ risk that morning, and the safety binder is sitting in an office two buildings away.
That gap — between documented procedure and what actually happens on the cellar floor at crush — is where people get hurt and where regulators find their teeth. This post covers three specific pieces: a daily hazard check your crew runs before they touch anything, a confined-space permit that actually gates entry, and an incident-closure loop that ties corrective action back to your QA and traceability records so nothing stays "open" forever.
A solid cellar safety SOP for a winery isn't a document. It's a set of small, enforceable checkpoints that fire at the right moment.
Why cellar safety fails even when the paperwork exists
The failure pattern is almost never "we didn't have a procedure." It's timing and ownership.
Confined-space entry into tanks is the obvious killer — CO₂ and inert gas displace oxygen fast, and a tank that read fine yesterday can be lethal today after a punch-down cycle or a nitrogen sparge. But the paperwork problem is more mundane: the permit exists as a PDF, someone prints it once a season, and then entries happen without anyone re-running the checklist because "we did that tank last week."
A few patterns show up over and over in small and mid-size cellars:
-
The daily check is verbal. The cellar lead says "watch the CO₂ in tank 7" at the morning huddle. Two hours later a temp worker who wasn't at the huddle walks over there.
-
Permits get pencil-whipped. Someone signs the confined-space permit at the end of the day for three entries that already happened, which defeats the entire point of a gate.
-
Incidents close without a fix. A near-miss gets reported, someone says "we'll be more careful," and there's no record connecting that event to a changed procedure. Six weeks later the same near-miss happens at the next tank over.
The thread connecting all three: safety records live in a different world from your operational and QA records. Your cellar safety SOP should sit in the same system where crews already log fermentation samples and additions, because that's where their attention actually is.
The daily hazard check: 90 seconds, done before the first task
The point of a daily hazard check isn't to be thorough. It's to be fast enough that crews actually run it every single shift. A two-page form gets skipped by week two of harvest. A short check that gates the first task of the day gets done.
Streamline your winery operations effortlessly.
Corkyly helps you track, manage, and optimize every step from vine to bottle.
- Vineyard & production tracking
- Customer relationship management
- Inventory & sales analytics
No credit card required
Here's what a crew-ready daily cellar check looks like — kept tight on purpose:
-
Gas/ventilation status — Are ventilation fans running in tank rooms? Any tanks under active ferment or inert gas? Flag which tanks are "hot" today.
-
Open-tank and fall exposure — Any open manways or tanks without guarding? Any ladder/platform work planned over open vessels?
-
Chemical staging — Caustic, peracetic, SO₂ solutions staged safely? Eyewash and shower verified functional (a 5-second flush test)?
-
Electrical/slip — Cords across wet floors? Pump cabling near drains? Standing water near panels?
-
Hot work / forklift — Any welding, grinding, or forklift traffic overlapping with foot traffic today?
-
Crew coverage — Who's the designated first-aid/entry-attendant on shift today, and are they actually here?
Each line is a yes/flag, not an essay. What tends to work best is making the check block the shift's task list — the crew can't check off "start pumpover on tank 12" until the hazard check for that room is completed by someone. That's the small design decision that separates a real check from decorative paperwork.
The part most cellars miss: the daily check's real job is to surface which tanks are dangerous today, then push that into the confined-space permit process. If tank 7 is flagged as "under nitrogen" on the morning check, any confined-space permit for tank 7 should be pre-loaded with that hazard.
This diagram shows the workflow from running the daily hazard check to unlocking shift tasks and pre-loading permits.
That small push — check then unlock — is what makes people actually do the short form every shift.
Confined-space permits that actually gate entry
A confined-space permit only matters if a person cannot enter the tank until it's signed off. Everything else is theater.
The core failure is that permits get treated as documentation of an entry rather than authorization for one. The fix is sequence: the permit must be completed and approved before entry, and it must carry a hard expiry.
A workable cellar confined-space permit template covers:
| Field | Why it matters | Common failure |
|---|---|---|
| Tank/vessel ID | Ties to your traceability records | Generic "tank" with no ID means no audit trail |
| Atmospheric test (O₂, CO₂) with reading + time | This is the whole ballgame | Reading taken once, entry happens 3 hrs later |
| Ventilation/purge confirmation | Proves the space was made safe | Assumed, not verified |
| Attendant name (outside person) | Legally and practically required | One person entering alone |
| Entry window / expiry time | Permit shouldn't cover the whole day | "Valid all shift" = worthless after conditions change |
| Isolation/lockout of pumps, gas, agitators | Prevents equipment starting mid-entry | Skipped for "quick" entries |
| Rescue plan reference | Retrieval, not just intent | "We'll pull them out" with no harness |
The pattern that causes deaths: a permit issued at 8 a.m. with a good O₂ reading, then a "quick re-entry" at 2 p.m. under the same permit after the tank sat sealed for hours. The atmosphere changed; the permit didn't. Your permit template needs a re-test trigger any time the space has been closed or conditions changed, and any time the entry window has lapsed.
When a permit process is overkill: genuinely open-top vessels with continuous ventilation and no gas hazard don't need the full confined-space machinery — but they do need fall protection on the daily check. Don't burn crew patience running full permits where the hazard is fall, not atmosphere. Match the control to the actual risk, or your crew starts ignoring all of it.
Incident-closure CAPA: stop closing incidents with "be more careful"
This is the part most cellars get wrong even when they run permits well. An incident or near-miss gets logged, then nothing structurally changes. The record sits "reported." Closure means someone typed a note.
Real closure means a corrective and preventive action (CAPA) loop that ends with a changed procedure or control and a verification that it worked. The same logic you'd apply on the quality side — the discipline in a continuous winery QA system with pass/fail gates and CAPA loops maps almost directly onto safety incidents. A near-miss is a failed gate; the CAPA is how you keep it from failing the same way twice.
-
Capture — What happened, which tank/area, which task, who was involved, what conditions (pull the day's hazard check automatically).
-
Immediate action — What was done in the moment to make it safe.
-
Root cause — Not "worker error." Ask why the system allowed it. No re-test? No attendant assigned? Permit expired and nobody noticed?
-
Corrective action — Fix this specific instance.
-
Preventive action — Change the SOP, checklist, or permit template so the whole class of incident is less likely. This is the step everyone skips.
-
Verification + closure — Confirm the change is in place and actually used on a later date. Only then does it close.
The near-miss that gets a real preventive action is worth more than ten "training reminder" closures. If your CO₂ near-miss on tank 7 results in a permanent gas-flag field on the daily check that auto-populates the permit, you've eliminated a category of risk — not just scolded a person.
Tying safety records to QA and traceability
Keeping all of this in one operational system instead of a separate safety binder isn't about tidiness — it's that safety events and quality events share the same root data. A confined-space entry happens on a specific tank, on a specific date, tied to a specific lot. When something goes wrong, you want the incident, the permit, the hazard check, and the lot's processing history to line up on one timeline.
That linkage does a few concrete things:
-
Regulatory closure gets simpler. When an inspector asks "show me your confined-space entries for October and the corrective actions from any incidents," you're pulling one connected record, not reconstructing from three sources.
-
You catch patterns tied to specific operations. If most CO₂ flags cluster around a particular ferment stage, that's the same trend-watching discipline you'd apply in fermentation monitoring SOPs — and the safety and quality signals often point at the same operational moment.
-
CAPA doesn't fall through the cracks. Open safety actions show up in the same task view as everything else the crew owns, so they don't quietly age out.
This is where AI-assisted operational software earns its place — not by "managing safety," but by handling the boring enforcement: firing the daily check as a required task before the shift's work unlocks, flagging permits approaching expiry, nudging an open CAPA that's been sitting for two weeks, and auto-attaching the day's hazard conditions to any permit issued for a flagged tank.
The crew still does the judgment. The system just won't let steps get silently skipped.
A real scenario
A roughly 18,000-case cellar ran confined-space entries the way most small operations do: a printed permit book, filled in when someone remembered, checks handled verbally at the morning huddle. During harvest, with two temps who missed most huddles, they had two near-misses in three weeks — one worker started climbing into a tank that had been under nitrogen with no atmospheric re-test, caught only because a full-timer walked in.
Both got "reported." Neither changed anything, because there was no step forcing a preventive fix.
They rebuilt around three enforced checkpoints: a 90-second daily hazard check that had to be completed before any tank work unlocked, a confined-space permit with a mandatory O₂/CO₂ re-test any time a tank had been sealed or the entry window lapsed, and a CAPA loop that wouldn't let an incident close without a named preventive change plus a verification date.
The shift wasn't dramatic on paper. Over the next season they actually logged more near-misses — which was the point, because people started reporting them instead of shrugging. But entries-without-a-current-atmospheric-reading dropped to zero, and the two recurring risk categories (nitrogen tanks and open-manway ladder work) each got a permanent checklist field. When their insurer's loss-control inspector came through, the whole confined-space history and its corrective actions pulled in one pass instead of a half-day scramble.
Where to start
You don't need to overhaul everything before crush. Pick the highest-consequence gap first, which for almost every cellar is confined-space entry.
-
Write the confined-space permit template with a hard entry window and a re-test trigger. Make signed approval a precondition of entry, not a record of it.
-
Cut your daily hazard check down until crews will actually run it every shift — six lines, not two pages — and wire it so it gates the first task.
-
Rebuild your incident form so nothing closes without a preventive action and a verification date.
-
Connect the three so a flagged tank on the morning check pre-loads the permit, and every incident pulls the day's conditions automatically.
The goal isn't a thicker binder. It's a cellar safety SOP that fires at the exact moment a crew member is about to do the risky thing — and won't let the shortcut happen quietly. Get that right and the audit trail, the regulatory closure, and the traceability all come along for free, because they're built from the same records your crew was already going to touch.
The goal isn't a thicker binder. It's a cellar safety SOP that fires at the exact moment a crew member is about to do the risky thing — and won't let the shortcut happen quietly. Get that right and the audit trail, the regulatory closure, and the traceability all come along for free, because they're built from the same records your crew was already going to touch.
Ready to elevate your winery management?
Join 500+ wineries using Corkyly to increase operational efficiency, boost customer loyalty, and grow sales.