Why your PHA and your SIS shouldn’t live in different tools
Most teams build their safety lifecycle across a patchwork of spreadsheets and point tools — a PHA here, a LOPA there, SIL verification somewhere else. Kenexis® Open-PHA® and Kenexis® SIS applications close that gap by keeping every stage of the lifecycle on one governed platform.
A process hazard analysis identifies a hazard. A LOPA credits a safeguard. A SIL verification study proves that safeguard meets its target. On paper, that’s one continuous chain of reasoning. In practice, at most sites, it’s three separate files, three separate logins, and a lot of re-typing in between — and every hand-off is a place where the record can drift from reality.
We built Kenexis® Open-PHA® and Kenexis® SIS to close that gap. They aren’t two products that happen to share a login page. They’re one platform, so the hazard you identify today is still traceable, still governed, and still accurate by the time it’s a verified safeguard in the field.
Your LOPA becomes your SIL verification — automatically
An Independent Protection Layer defined in an Kenexis® Open-PHA® LOPA links directly to its matching Instrumented Protective Function in the Kenexis® SIS application. The result you generate in the hazard study doesn’t need to be re-entered downstream — it flows forward.

A field-level, sync-aware engine shows exactly what matches and what’s changed between the PHA safeguard and the SIF — so a study update in one place is visible, not silent, in the other.
Every protection layer gets a home — not just the high-integrity ones
LOPA routinely credits safeguards that aren’t full Safety Instrumented Functions: alarms with operator response, interlocks, BPCS-based trips. Individually modest, they still do real work in the risk model — and industry practice is increasingly clear that they deserve the same lifecycle discipline as SIFs, scaled to their integrity.
Kenexis® Open-PHA® gives these low integrity protection layers (LIPL) a dedicated register — type, instrument tag, selected SIL, required response time, test interval, and a safety-critical flag — captured in the same study as the PHA that credits them, not in a spreadsheet three systems away. That’s the difference between a safeguard with an owner and a test plan, and a safeguard that’s really just an assumption.
A protection layer that earns credit in your LOPA but has no linked record, no test interval, and no traceable owner isn’t really governed. It’s a line item.
Access control built for how real teams work
None of this matters if the platform underneath it isn’t trustworthy. Governance in the Kenexis Integrated Safety Suite isn’t a single role switch — it’s layered: view/edit/owner grants at the user, group, study, directory and facility level; an audited access gate that never leaks whether a study even exists to someone who shouldn’t see it; per-tenant SSO over OIDC and SAML, run by your own admins; and SCIM provisioning to keep user access in sync with your identity provider automatically.

Standards are catching up to what good practice already required
With low-integrity protection layers increasingly expected to carry the same kind of lifecycle discipline as SIFs — identification, functional requirements, bypass management, testing, and management of change — the case for keeping every protection layer in the same system as the hazard analysis that credited it has never been stronger. Teams that already have that continuity are simply ready. Teams that don’t are facing a reconciliation project.
A short readiness checklist
- Inventory every instrumented safeguard you credit in LOPA — SIF and non-SIF alike.
- Trace each one from the PHA that identified it through to the verification (or LIPL-Low Integrity Protection Layer record) that governs it.
- Check for re-typing. If a credited IPL has to be manually re-entered into your verification tool, that’s a gap.
- Confirm ownership. Every protection layer should have a test interval, a bypass procedure, and an owner.
- Ask who can see what. If access control isn’t granular below “everyone with a login,” it isn’t finished.
From the first hazard to the last verified safeguard
See how Kenexis® Open-PHA® and Kenexis® SIS keep your protection layers connected, governed, and audit-ready — without leaving one platform.