The short answer: Under 29 CFR 1910.147(f)(3), when servicing or maintenance is performed by a crew, craft, department, or group, the group lockout procedure must give each worker a level of protection equivalent to a personal lockout device. In practice each authorized employee affixes their own lock to the group lockbox when they start work and removes it only when they stop, so no one can re-energize the machine while another person's hands are still in it. Before that work begins, 1910.147(d)(5) requires all stored or residual energy to be relieved, disconnected, or restrained, and 1910.147(d)(6) requires the authorized employee to verify that isolation and de-energization have actually been achieved. Locking the disconnect is only the start of the sequence, not the whole of it.
What is group lockout, and when does OSHA require it?
Group lockout is the procedure that applies whenever more than one person services a machine at the same time, and it is required by 29 CFR 1910.147(f)(3)(i), which states that when servicing or maintenance is performed by a crew, craft, department, or other group, they must use a procedure that affords each employee a level of protection equivalent to a personal lockout or tagout device. On a millwright job, that is the normal case, not the exception: a gearbox change, a conveyor rebuild, or a press overhaul routinely puts electricians, mechanics, and riggers on the same equipment within the same shift.
The reason the standard singles this out is that individual lockout breaks down as soon as the crew grows. If one worker locks the disconnect and everyone else relies on that single lock, the person who applied it controls when the machine comes back, and they cannot know whether a colleague is still reaching into a nip point two frames away. Group lockout closes that gap by making protection personal again: the machine cannot be released until every worker who is exposed has removed their own device. The procedure is what turns a shared job back into individual accountability.
How does a group lockbox keep every millwright accountable?
A group lockbox works by capturing the keys to the machine's isolation locks, then requiring each worker to lock that box with their own padlock. 1910.147(f)(3)(ii)(D) states the rule plainly: each authorized employee must affix a personal lockout or tagout device to the group lockout device, group lockbox, or comparable mechanism when they begin work, and remove those devices when they stop working. The box cannot be opened, and the machine cannot be re-energized, until the last personal lock comes off.
The standard also assigns the coordination that keeps the box honest. 1910.147(f)(3)(ii)(A) vests primary responsibility in an authorized employee for a set number of workers under a group device, 1910.147(f)(3)(ii)(B) requires a provision for that authorized employee to ascertain the exposure status of each group member, and 1910.147(f)(3)(ii)(C) assigns overall job-associated lockout control to an authorized employee who coordinates the work forces and ensures continuity of protection. Read together, these mean the lockbox is not just a container for keys: it is paired with a named person who knows who is exposed and confirms it before anyone releases the equipment.
Why does stored energy stay dangerous after the power is locked out?
Stored or residual energy is the energy still held in a machine after its power source is isolated, and it is dangerous precisely because the disconnect being locked makes the equipment look safe when it is not. 1910.147(d)(5)(i) requires that following the application of lockout or tagout devices, all potentially hazardous stored or residual energy be relieved, disconnected, restrained, or otherwise rendered safe. That energy hides in raised rams and loads held up by gravity, in hydraulic and pneumatic accumulators and pressurized lines, in springs under compression or tension, in flywheels and rotating masses that coast, in capacitors holding a charge, and in thermal systems. Locking the electrical disconnect does nothing to any of it.
A Tennessee FACE investigation shows the mechanism. In a NIOSH-supported Tennessee FACE report, a 51-year-old maintenance worker was replacing a hydraulic seal on a forklift carriage lift mechanism on February 28, 2014. The raised carriage and forks were held up only by resting the fork tips on the edge of a shipping container, because a pallet blocked a closer position. As the worker tightened a hydraulic fitting, the fork tips slipped off the container edge, and the carriage fell and pinned him. The investigators pointed to working under an unsecured raised load, the absence of written maintenance procedures and a task hazard analysis, and the need for an energy-control procedure covering both the unsecured load and the hydraulic pressure. The transferable point for millwrights is that a load held by gravity or fluid pressure is stored energy under 1910.147(d)(5), and it has to be blocked or relieved, not balanced, before hands go underneath.
Where energy can build back up, the duty continues. 1910.147(d)(5)(ii) requires that if there is a possibility of reaccumulation of stored energy to a hazardous level, verification of isolation must continue until the servicing is complete or the possibility no longer exists. A bled hydraulic line that can repressurize from a leaking valve, or a capacitor bank that recharges, is not a one-time check.
How do you verify a zero-energy state before work starts?
Verification means the authorized employee physically confirms the machine is at a zero-energy state before anyone touches it, and it is a required, separate step. 1910.147(d)(6) requires that prior to starting work on equipment that has been locked or tagged out, the authorized employee verify that isolation and de-energization have actually been accomplished. Verification is not reading the position of a switch. It is trying to start the machine at the operator controls after locking out, returning those controls to the safe position, and using the right instrument to confirm dead where electrical energy is involved, before returning to the work.
That step sits at the end of an ordered sequence, and the sequence only protects a crew when every stage is completed in turn. The table below sets out the application-of-control sequence that 29 CFR 1910.147(d) requires, which is the same for a lone technician and for a group, with the group provisions of (f)(3) layered on top.
| Step | What 1910.147 requires | Clause |
|---|---|---|
| Prepare for shutdown | Identify the energy sources and the means to control them before shutting down | 1910.147(d)(1) |
| Shut down the machine | Turn the equipment off using an orderly shutdown procedure | 1910.147(d)(2) |
| Isolate the energy | Operate each energy-isolating device so the equipment is isolated from its energy sources | 1910.147(d)(3) |
| Apply the locks | Affix lockout or tagout devices to each energy-isolating device | 1910.147(d)(4) |
| Relieve stored energy | Relieve, disconnect, restrain, or otherwise render safe all stored or residual energy | 1910.147(d)(5) |
| Verify isolation | Verify that isolation and de-energization have been accomplished before starting work | 1910.147(d)(6) |
How is lockout protection kept continuous across a shift change?
A multi-day machine rebuild has to hand protection from the off-going crew to the oncoming crew without ever leaving the equipment unlocked, and 1910.147(f)(4) requires specific procedures for exactly that. The standard calls for procedures used during shift or personnel changes to ensure continuity of lockout or tagout protection, including an orderly transfer of device protection between off-going and oncoming employees, to minimize exposure to hazards from unexpected energization, start-up, or the release of stored energy. The group lockbox makes this workable: oncoming millwrights apply their personal locks before the off-going crew removes theirs, so the box is never without a lock on it.
The failure mode this prevents is the gap. If the night crew removes its locks and clears out before the day crew arrives and applies theirs, the machine sits controlled by no one, and anyone who walks up can energize it. Building the transfer into the procedure, rather than leaving it to whoever is around at 6 a.m., is what keeps the zero-energy state intact across the handover.
Where does ANSI/ASSP Z244.1 extend the OSHA rule?
ANSI/ASSP Z244.1, the consensus standard on the control of hazardous energy, goes further than 29 CFR 1910.147 in one area that matters to maintenance teams: what to do when full lockout is not feasible for a task. Z244.1 is a voluntary consensus standard, so it is advisory rather than enforceable in the way the OSHA rule is, but OSHA has formally recognized the standard, and it establishes lockout as the primary method while addressing alternative methods for controlling hazardous energy where lockout cannot be applied.
For a millwright team, the practical value of Z244.1 is its structured treatment of tasks such as certain troubleshooting, adjustment, or process-verification work that cannot be done on a fully de-energized machine. Rather than treating those as an excuse to skip control, the consensus standard pushes teams toward a documented risk assessment and engineering-based alternative methods that still protect the worker. Compliance with 1910.147 is the enforceable floor. Using Z244.1 to design the harder cases, and keeping group lockout and stored-energy relief as the default for everything else, is how a maintenance program stays defensible and keeps its crews out of machines that only look dead.



