Qooling
Cloud platform for quality, health, safety and environment management: documents, risks, incidents, audits and ISO certification evidence in one place.
You can absolutely build a register: incidents in, corrective actions out, documents with version numbers, a dashboard that looks convincing. What you cannot build in a session is the thing anyone actually buys, which is an evidence trail an external ISO auditor will accept without argument, plus a mobile flow that a warehouse worker will actually use to report a near miss. Compliance software lives or dies on immutable audit logs, controlled document approval with signatures, retention rules and the fact that the vendor, not you, is the one explaining the system during a certification audit. A personal replacement also makes little sense here: this is inherently multi-user, and the value appears only when an entire site logs into it. Build the register if you want to understand your own processes; do not put your certification on top of it.
Build verification: not recorded. How we judge buildability
What you give up
- Auditor familiarity: external certification bodies have seen the commercial tools and know what to click
- Immutable, tamper-evident audit logging and controlled document sign-off, which is the whole point of the category
- A field-usable mobile app for incident and near-miss reporting with photos, offline
- Prebuilt ISO 9001 / 14001 / 45001 / 27001 templates, risk matrices and clause mappings you would otherwise write from scratch
- Someone else being accountable when the system fails during an audit or a serious incident investigation
Why people still pay
Because compliance is a social process, not a data model. Getting fifty people across three sites to report incidents, sign off documents and close corrective actions requires a tool that everyone tolerates, a mobile app that works in a loading bay, and a paper trail that survives an auditor picking a random clause and asking for proof. Companies also pay for someone to blame: if the certification audit goes badly, a vendor with ISO-shaped templates and support is a better story than a spreadsheet-plus-side-project maintained by whoever built it before they left.
Your build guide
The stack, security requirements, and agent rules for a focused replacement.
Before you start
- A machine or small VPS to host it
- File storage for document attachments and photos
- Someone willing to define the clause-to-evidence mapping by hand
- Backups you actually test, since this data is the audit
Use these project rules and optional skill references alongside the prompt. Review each skill before adding it to your agent; the AGENTS.md export includes the same guidance.
Project rule, data: Data model:.
Project rule, behavior: Incident: type (incident, near miss, unsafe situation), date, site, reporter, description, severity 1-5, photos, status (open, investigating, closed).
Project rule, recovery: Out of scope: mobile app, offline capture, email notifications, e-signatures, multi-tenant, ISO clause libraries, permissions and roles.
Implementation plan
Phase 1, architecture and data
SQLite via Prisma, file at ./data/qhse.db. Data model:.
Phase 2, implement
Incident: type (incident, near miss, unsafe situation), date, site, reporter, description, severity 1-5, photos, status (open, investigating, closed).
Phase 3, implement
Risk: hazard, activity, likelihood 1-5, impact 1-5, computed score, existing controls, owner, review date.
Phase 4, review and output
Action: title, source (incident or risk or audit), owner, due date, status, closure note, closed date. In scope: seed script with two sites, five people, sample incidents and risks. CSV export for every list. Overdue highlighting.
Phase 5, recovery and acceptance
Out of scope: mobile app, offline capture, email notifications, e-signatures, multi-tenant, ISO clause libraries, permissions and roles. Verify this invariant with a saved fixture: A failed or blocked source must be labelled unknown; rerunning the scan must not duplicate the same finding ID. State the practical limit: Auditor familiarity: external certification bodies have seen the commercial tools and know what to click.
Build a self-hosted single-organisation QHSE register. This is a learning and internal-tracking tool, not a certification system, and it should say so on the dashboard. Stack, no substitutions: - Next.js (App Router) with TypeScript and Tailwind - SQLite via Prisma, file at ./data/qhse.db - Local disk storage for attachments under ./data/uploads - Single shared password from AUTH_PASSWORD in .env, cookie session, no user accounts, no OAuth, no cloud services, no telemetry Data model: - Person: name, email, site - Incident: type (incident, near miss, unsafe situation), date, site, reporter, description, severity 1-5, photos, status (open, investigating, closed) - Risk: hazard, activity, likelihood 1-5, impact 1-5, computed score, existing controls, owner, review date - Action: title, source (incident or risk or audit), owner, due date, status, closure note, closed date - Document: title, code, current version number, category, owner, review date, uploaded file per version, status (draft, approved, retired) - AuditLog: append-only table, every create and update writes actor, timestamp, entity, field-level before and after JSON. Never allow deletes on this table in application code. Screens: - Dashboard: open incidents, overdue actions, risks above score 15, documents past review date - List and detail views for each entity, with inline forms, no modals-only flows - Risk matrix view: 5x5 grid, colour by score, click a cell to see the risks in it - Evidence pack: pick a date range, get a single printable HTML page with all incidents, actions, risks and document versions in it, plus the relevant audit log rows In scope: seed script with two sites, five people, sample incidents and risks. CSV export for every list. Overdue highlighting. Out of scope: mobile app, offline capture, email notifications, e-signatures, multi-tenant, ISO clause libraries, permissions and roles. On the dashboard, print a fixed banner: "Internal tracking only. Not an audited compliance system." Include README with setup, .env.example with AUTH_PASSWORD, and a backup script that copies ./data to a timestamped folder.
$ open in your agent (prompt prefilled, you press enter), copy the prompt or copy AGENTS.md · generated from this app's build plan
prompt copied. want to know what dies next week?
new verdicts + top votes, weekly. free. one-click out.
No prior-art project is listed yet. Compare the scoped build with the paid product before choosing.
Questions about Qooling
Can you build your own Qooling with AI?
A full replacement is not the recommended project. You can absolutely build a register: incidents in, corrective actions out, documents with version numbers, a dashboard that looks convincing. What you cannot build in a session is the thing anyone actually buys, which is an evidence trail an external ISO auditor will accept without argument, plus a mobile flow that a warehouse worker will actually use to report a near miss. Compliance software lives or dies on immutable audit logs, controlled document approval with signatures, retention rules and the fact that the vendor, not you, is the one explaining the system during a certification audit. A personal replacement also makes little sense here: this is inherently multi-user, and the value appears only when an entire site logs into it. Build the register if you want to understand your own processes; do not put your certification on top of it.
What does the Qooling build prompt cover?
The prompt starts with this scope: A local single-tenant QHSE register: log incidents and risks, attach corrective actions with owners and due dates, keep versioned controlled documents, and export a read-only evidence pack per standard clause. Full-product capabilities excluded from the comparison include: Auditor familiarity: external certification bodies have seen the commercial tools and know what to click; Immutable, tamper-evident audit logging and controlled document sign-off, which is the whole point of the category; A field-usable mobile app for incident and near-miss reporting with photos, offline. Follow the implementation plan and its prerequisites before expanding the build.
How do I use the prompt, AGENTS.md and agent skills?
Start with the Qooling prerequisites and stack, then copy the prompt into your coding agent. Save the project rules as AGENTS.md in the project root. Linked skills are optional packages or source instructions for specific tasks; review their current contents and install only those matching the chosen stack. A skill does not supply API credentials or verify the finished app.
How long will this Qooling project take?
The catalogue estimate is a weekend for the limited scope. Setup, integration approvals, debugging, deployment and ongoing maintenance can add time. This is an estimate, not a delivery guarantee.
What would I give up by replacing Qooling?
Auditor familiarity: external certification bodies have seen the commercial tools and know what to click; Immutable, tamper-evident audit logging and controlled document sign-off, which is the whole point of the category; A field-usable mobile app for incident and near-miss reporting with photos, offline; Prebuilt ISO 9001 / 14001 / 45001 / 27001 templates, risk matrices and clause mappings you would otherwise write from scratch; Someone else being accountable when the system fails during an audit or a serious incident investigation. Because compliance is a social process, not a data model. Getting fifty people across three sites to report incidents, sign off documents and close corrective actions requires a tool that everyone tolerates, a mobile app that works in a loading bay, and a paper trail that survives an auditor picking a random clause and asking for proof. Companies also pay for someone to blame: if the certification audit goes badly, a vendor with ISO-shaped templates and support is a better story than a spreadsheet-plus-side-project maintained by whoever built it before they left.
What can I use instead of building Qooling?
No alternative is listed in this entry yet. That is a gap in this catalogue, not proof that no suitable product exists. Compare the paid product and the proposed scope before committing to a build.