The desk work of building a maintenance programme, compressed. The Toolbox walks a five-step chain: classify criticality to NORSOK Z-008, build an ISO 14224 failure-mode analysis, select a maintenance strategy per mode with RCM, assemble the generic maintenance concept, and generate the work instruction. Each step feeds the next, and you can stop at any of them.
Alongside that sit four tools for equipment already running: root cause analysis, PM optimisation, bad actor analysis and spare-parts / holding policy.
Every analysis output — the classification, the FMECA, the RCM decision and the maintenance concept — names the clause or code table behind it, so a reliability engineer can check the result rather than take it on trust. The work instruction at the end of the chain is the deliberate exception: it is a document for the person doing the job, carrying the safety requirements, the steps, the readings and the sign-off, and it inherits its basis from the concept it was generated from. Criticality classification and bad actor analysis are free forever, unlimited, no card.
The steps are not the problem. The joins are.
Nobody in maintenance is confused about the steps. Criticality gets classified. Somebody writes down how the thing fails. Somebody decides what to do about each way it fails. Somebody writes the job card. The methods are not secret either — Z-008, ISO 14224 and RCM are published documents, and there is no shortage of people who will run any one of them for you.
What goes missing is everything between them. The criticality study lands as a spreadsheet nobody opens again. The FMECA gets built from scratch because whoever ran it could not find the criticality classes, or found them and did not trust them. Strategy is decided per asset rather than per failure mode, because the failure-mode list never arrived in a shape you could decide against. By the time a job card exists, its connection to the consequence class that justified it is a memory in one person's head. Every step was done properly. The programme still cannot be defended.
That gap costs twice. Once while building, because each step re-derives what the previous one already established. And again three years later, when someone asks why this pump is on a monthly route and the honest answer is that it always has been.
So the Toolbox is built as one chain rather than four good tools in a row. Each step reads what the last one produced instead of asking you to retype it, and every output names the standard clause behind it. What that buys is less about speed than about trace: from a job card back to the concept, back to the strategy, back to the failure mode, back to the consequence class that justified any of it — without depending on the memory of whoever ran the study. The judgement calls stay yours. What the chain guarantees is that the call you made at step one is still visible at step five.
The workflow, end to end
The five steps below run in order. You can stop at any point and take the output away, and you can start at step one without ever paying anything — criticality classification is free and unlimited.
Consequence classification across safety, environment, production and cost — the C1–C3 class that decides how much maintenance the item deserves.
NORSOK Z-008Failure modes, effects and criticality for the item, coded so they travel: the same vocabulary your CMMS and your reliability data already use.
ISO 14224 · IEC 60812A maintenance strategy per failure mode — condition-based, time-based, failure-finding, redesign or run-to-failure — rather than one blanket policy for the asset.
RCMThe generic maintenance concept for that equipment class: the tasks the strategies imply, their intervals and the disciplines that carry them, gathered into one plan.
Concept BuilderThe job itself: task steps, safety and isolation notes, tools and materials, in a shape a CMMS will accept.
Work instructionThe criticality class constrains which strategies are defensible. The failure modes constrain which concepts can match. The concept determines what the work instruction has to contain. Each of those is a real narrowing rather than a hand-off. Two people running the same asset will still word things differently — most of the chain is AI-drafted — but they are choosing inside the same constrained space, and every choice carries the clause that allowed it. That is what makes two studies comparable, and what makes a reviewer able to find the step where they diverged.
What each tool does
The Toolbox is organised into two tracks. Develop is the five-step workflow above — the work of building a programme. Operate is what you reach for once the programme is running and things start breaking. You switch between them in the app.
Consequence-based classification to NORSOK Z-008 — safety, environment, production and cost, with the barrier logic that decides whether an item is a safety-critical element. Unlimited on every account. See the method guide.
Failure mode, effects and criticality analysis per ISO 14224, with the Annex B codes, and severity, probability and detectability combining into a criticality number you can rank on. Three of the four IEC 60812:2018 criticality methods are there, switchable on the same ratings: the familiar RPN = S×P×D of Annex B.4.2; ARPN = S+P+D of Annex B.4.3, which adds log-calibrated ranks instead of multiplying ordinal ones and so behaves like a real scale — B.4.3 requires the same fixed multiple on all three scales, and a sum of uncalibrated ranks is not an ARPN, so the Toolbox keeps that calibration on screen rather than leaving it implied: ×√10 per level by default, with ×2 and ×10 selectable; and the criticality matrix of Annex B.3.2, plotted as a grid with your failure modes in it, which uses consequence and likelihood only and leaves detectability out — often the honest choice for maintenance work, since how easily a failure is caught is a property of the monitoring you are about to design. IEC 60812 says that where RPNs are similar the higher-severity mode is addressed first (B.4.2, and B.4.3 for ARPN). The Toolbox goes one step further and bands maximum severity high outright, under all three methods — note that is our rule for the matrix, which has no severity provision of its own. See the method guide.
Strategy selection per failure mode rather than per asset — the logic that separates a condition task from a scheduled replacement from an honest run-to-failure. See the method guide.
Assembles the generic maintenance concept: the tasks, intervals and disciplines belonging to that equipment class, ready to become a PM plan. See the method guide.
Turns a concept into the job a technician actually receives — ordered steps, acceptance checks, hazards called out where they occur. See the method guide.
For when you already know what you have: describe the equipment, optionally with an O&M document attached, and get the closest generic maintenance concepts ranked, with a confidence score per match so a weak match announces itself rather than hiding. It does not run the chain: it derives no failure modes and selects no strategy of its own. But the concept it returns is not a bare reference — its maintenance lines already carry a maintainable item, a failure mode, a strategy, a PM type and an interval, and the Toolbox groups them into interval cards and cascades the periodic ones, so a longer interval also carries the tasks of the shorter ones and can go straight to the work-instruction generator. Condition-based and externally-referenced intervals are left out of that cascade and run on their own trigger. That is a pre-written schedule for the equipment class, handed over whole. Nothing in it was reasoned out for your asset except the choice of concept — so read the candidates, pick one, and own what it says.
Structured RCA on a failure event using 5-Whys or Fishbone (fault-tree analysis to IEC 61025 is coming), with candidate causes proposed per IEC 62740 and ISO 14224 — every one editable. See the method guide.
Ranks the equipment consuming your maintenance budget, so improvement effort starts where the money actually is. Also free. See the method guide.
Reviewing an existing PM programme against what actually failed — the loop that stops a programme drifting into over-maintenance. Upload your plan register, PM completion history and failure history; it issues a verdict per plan line against NORSOK Z-008:2024 §11.5, with the evidence, the clause and the sample size attached. Benchmarks are the peer group inside your own fleet and the GMC library. See the method guide.
Which spares to hold, where, and how many — built on NORSOK Z-008:2024 Clause 12, which is normative and says the assessment shall rest on the consequence classification. Takes the criticality you have already run, plus the demand rate and lead time you supply. It will not compute a level for a capital spare — §12.5 says those shall be assessed case by case.
Where it fits — and where it doesn't
The Toolbox is a drafting instrument, not an oracle. It is worth being clear about which is which before you build a programme on it.
✓ A good fit if…
- You are standing up a maintenance programme and need the steps to connect, not merely to get done.
- You can describe the equipment — its functions, its duty, what happens when it stops. O&M documentation sharpens the answer, but no tool here requires one: the GMC Matcher runs on the equipment fields alone, and the chain asks for a manual only at the last step, where the work-instruction generator offers it as optional.
- You want the programme anchored in NORSOK Z-008 and ISO 14224 rather than in one planner's habits.
- You need the same equipment to get the same answer twice, across different people.
- You are validating work you already did and want a structured second opinion.
✗ Not a fit — yet
- A substitute for engineering judgement. Every output is a draft for a competent person to accept, amend or reject. It is not an approval.
- A safety case. Criticality output informs SCE identification; it does not discharge your duty to do that assessment properly.
- A CMMS. It produces what goes into yours. It does not hold your work orders or your history.
- Nothing to describe it with. The chain runs on what you know about the equipment. If nobody can say what it does or what its failure costs, no tool can start — the matcher will take an O&M document instead of a typed description, but only because the document is where it reads that description from.
- Bulk migration. It works asset by asset. A ten-thousand-tag migration is a consulting engagement, not a subscription.
Everything the Toolbox produces is a first draft in your vocabulary and to your standard. That is a large saving on a task most teams hate. It is not, and is not sold as, a replacement for the person who signs the programme off.
What is free, what is paid
Two tools are free because they are the ones everybody needs and the ones most often skipped: criticality classification and bad actor analysis. The paid tiers are metered by analysis — a token per run — rather than by seat.
Unused analyses roll over for one month, and plans cancel any time. Full detail on the pricing page.