Skip to main content

Update: Golden thread, gateways, safety case & KBI on every plan — User manual

Product documentation

Threadsovereign user manual

Start-to-finish workflows for Principal Designers, Accountable Persons, Building Safety Managers, residents, clients, and contractors — with official legislation links. App screen paths are shown as /routes for use after you sign in.

How to use this manual

Read sections in order for a full lifecycle walkthrough, or jump from the contents list. Paths like /occupied/kbi are screens inside the signed-in app at threadsovereign.io — they are not public pages on this website.

1. Start here — what Threadsovereign is for

Threadsovereign helps UK organisations keep building-safety records accurate and auditable under the Building Safety Act 2022.

Use this manual if you are a Principal Designer, client, contractor, Accountable Person (AP), Building Safety Manager (BSM), resident, or platform admin. Each section walks through the real screens in order.

The platform stores your golden thread (living safety information), supports gateway packages during design and construction, and supports occupied-phase duties once people live in a higher-risk building (HRB).

Threadsovereign does not replace the official Building Safety Regulator (BSR) portal or legal advice. You still submit to the BSR where the law requires it; this product helps you prepare, evidence, and track that work.

Tip: If there is immediate danger to life, call emergency services first. Record the incident in the portal only after people are safe.

2. Sign in and which portal you use

Your role decides which home screen you land on. You only need a browser and your login.

Step by step

  1. Open the app at threadsovereign.io and go to Sign in (/login).
  2. Enter the email and password your organisation gave you.
  3. After sign-in you are taken to your portal home (for example /dashboard for PD, /occupied for AP/BSM, /resident for residents).
  4. Use the left navigation (or mobile menu) to move between pages. Bookmarks work — copy the address bar URL to share a screen with a colleague.
  5. To change password or recover access, use Forgot password (/forgot-password) and follow the email link.
  6. To start a trial before you have a login, use the free trial page on this website (/onboarding).
  • PD / design team → /dashboard, /projects, /gateway-submissions, /documents
  • AP / BSM → /occupied (statutory pages work on Starter; maintenance needs Professional+)
  • Resident → /resident
  • Client → /client
  • Contractor / supplier → /contractor
  • Platform admin → /admin
  • Compliance content editors → /compliance (Professional+ read, Enterprise write)
  • Integrations (Professional+ unless noted): /settings/integrations — Google Calendar, Outlook Calendar, SMS (Twilio), Teams/Slack webhooks, DocuSign handover e-signatures (when configured). Enterprise: Autodesk APS pilot for Revit, AutoCAD, and ACC (shared OAuth; browse, selective import including DWG/DXF, re-sync; no in-product Viewer yet). Asite and Procore: submit an in-app CDE integration request — support-led onboarding; there is no self-serve or live in-product OAuth for Asite/Procore today.
  • Professional+ also includes advisory drafting (starting text for BSR correspondence, risk entries, and complaint responses — you edit before save; never auto-submits) and natural-language search that maps queries to existing filters (advisory only).

Tip: Subscription tier never blocks statutory occupied workflows (safety case, KBI, occurrences, complaints). Only optional tools such as maintenance CMMS and some integrations need Professional or Enterprise.

3. Design & construction — Principal Designer journey

From first project to controlled documents, risks, tasks, and team — the path before and during gateways.

The PD portal is for design and construction. It works for HRB and non-HRB projects. Gateway and golden-thread rules apply when the project is marked as a higher-risk building.

Step by step

  1. Open /dashboard to see portfolio status.
  2. Go to /projects → New project. Enter name, address, and whether the building is an HRB. HRB status cannot be turned off later (safety rule).
  3. Open the project → invite people on /team (or project settings → team). Assign PD, client, and contractor roles carefully.
  4. Upload controlled documents on /documents. Mark golden-thread documents correctly — approved golden-thread files cannot be silently edited; use supersession for a new version.
  5. Record risks on /risks and tasks on /tasks. Link documents where they support a risk or task.
  6. Use /sign-off-queue for pending approvals.
  7. When ready for regulator stages, open /gateway-submissions (see section 4).
  8. Before occupation, complete handover (section 5).

Pages in the app (after sign-in)

  • PD dashboard /dashboard
  • Projects list /projects
  • New project /projects/new
  • Documents (golden thread) /documents
  • Risks /risks
  • Tasks /tasks
  • Team /team
  • Sign-off queue /sign-off-queue
  • Suppliers /suppliers
  • Activity log /activity

Tip: Every safety-relevant change should leave an activity log entry (via logActivity). Occupied mutations stamp buildingId so multi-HRB orgs can filter GET /api/activity?buildingId=. If you cannot explain a decision from the record alone, add evidence before you move on.

4. Gateway submissions (G1, G2, G3) — start to finish

Gateways are legal hold-points for higher-risk buildings. Threadsovereign tracks readiness and status; you still use the BSR process for formal regulator submission.

Gateway 1 is at planning. Gateway 2 is before construction starts. Gateway 3 is at completion, before occupation. The platform enforces allowed status transitions so you cannot skip steps.

Step by step

  1. Open /gateway-submissions and select the project (or open the project then gateway pages).
  2. Gateway 1 — /gateway-submissions/g1: complete planning-stage evidence and record submission status when you have lodged with the regulator.
  3. Gateway 2 — /gateway-submissions/g2: work through the checklist, attach evidence, use change control at /gateway-submissions/g2/changes, preview at /gateway-submissions/g2/preview, then mark submitted at /gateway-submissions/g2/submitted when the BSR package is lodged.
  4. Gateway 3 — /gateway-submissions/g3: completion evidence and status before residents move in.
  5. Track BSR registration on /gateway-submissions/registration and correspondence on /gateway-submissions/correspondence.
  6. Review history on /gateway-submissions/history.
  7. CDM duties (client duties, construction phase plan, F10) live under /gateway-submissions/cdm?projectId=… for construction-phase compliance alongside gateways.

Pages in the app (after sign-in)

  • Gateway hub /gateway-submissions
  • Gateway 1 /gateway-submissions/g1
  • Gateway 2 preparation /gateway-submissions/g2
  • Gateway 2 change control /gateway-submissions/g2/changes
  • Gateway 2 preview /gateway-submissions/g2/preview
  • Gateway 2 submitted /gateway-submissions/g2/submitted
  • Gateway 3 /gateway-submissions/g3
  • BSR registration tracking /gateway-submissions/registration
  • BSR correspondence /gateway-submissions/correspondence
  • Submission history /gateway-submissions/history
  • CDM 2015 (client duties, CPP, F10) /gateway-submissions/cdm

Tip: Never mark a gateway “approved” in Threadsovereign unless that matches the real regulator outcome. False status breaks your audit trail.

5. Handover to occupation

Handover packages the information the AP needs to manage the building safely after construction (BSA s.76). Keep this distinct from later occupied-phase AP change-of-person transfers under s.90.

Construction-phase handover (this section) is not the same as BSA s.90 information transfer when the Accountable Person changes in occupation — that workflow lives on the occupied AP screens (section 6).

Product AP/BSM responsibility-transfer records (role handover between people) are also separate from s.90 packs, and BSA s.94 is the regulator complaints system — not AP role transfer.

Step by step

  1. Open the project → Handover (or /projects/[projectId]/handover).
  2. Complete the checklist at …/handover/checklist.
  3. Add as-built drawings and O&M manuals on the drawings and om-manuals pages.
  4. Use formal handover (…/handover/formal) for BSM fields: complete mandatory checklist items, tick all six legal declarations, then submit to lock the package.
  5. DocuSign BSM sign-off is available only after the package is locked (Professional+; when configured). Preview the package before lock — locked records are part of the golden thread.

Pages in the app (after sign-in)

Tip: Handover is not optional paperwork — incomplete handover is a common cause of occupied-phase information gaps.

6. Occupied phase — Accountable Person & BSM (start to finish)

After residents move in, Part 4 duties apply: safety case, KBI, occurrences, engagement, complaints, registration changes, s.90 AP information transfer, and BSR returns.

Use the building selector (top of occupied pages) when your organisation manages more than one HRB. Always check the building name before you save.

Threadsovereign prepares and evidences occupied work. You still file on the official BSR / GOV.UK portals where the law requires it — the product does not auto-file occurrences, KBI, or registration changes to HSE.

Step by step

  1. Open /occupied — hub for all occupied tools.
  2. AP dashboard /occupied/ap — obligations checklist; download the common-parts notice PDF and post it physically in the building. From here also manage BSA s.90 information-transfer attestation when the Accountable Person changes (all eight mapped pack themes under SI 2024/41 reg.13 — presence attestation; legal adequacy remains your judgement).
  3. AP/BSM responsibility transfer (product role handover) is a separate record from s.90 packs — do not confuse either with BSA s.94 (regulator complaints).
  4. BSA readiness — start at /occupied/compliance (scorecard), /occupied/portfolio (all HRBs), /occupied/statutory-calendar (deadlines), /occupied/evidence-packs (inspection manifests). See section 8.
  5. BSM dashboard /occupied/bsm — daily tasks (saved on the server) and open issues.
  6. Safety case /occupied/safety-case — Structured tab: complete all risk-management principles, SMS policies, testing schedule, and emergency plan. Publish requires a linked resident-communication engagement point (reg.10). Submit only when validation passes. Adequacy of the safety case remains duty-holder judgement.
  7. KBI /occupied/kbi — complete all 16 categories (including outbuildings). When the register is complete, prepare and attest your KBI pack in-platform, then file on the official BSR portal and record the HSE/BSR reference — Threadsovereign does not auto-submit KBI to the BSR.
  8. Building Assessment Certificates — see section 7 (BAC direction, 28-day clock, pack, refusal/appeal).
  9. Occurrences /occupied/issues — record mandatory occurrence reports under BSA s.87 / SI 2023/907 reg.6. Give notice to the BSR as soon as reasonably practicable. Where a full report is required, the statutory clock is 10 calendar days from the day the occurrence came to the AP’s attention (set or confirm the attention date when you mark BSR-reportable; the platform defaults attention to create time if unset). Prepare evidence in-platform; file on the official portal and record the reference — no auto-file.
  10. Complaints /occupied/issues — SI 2023/907 reg.12 requires acknowledgement as soon as reasonably practicable, timely handling, published timeframes, and a reconsideration route — it does not fix a national 10 working-day response clock. Threadsovereign applies a platform policy SLA of acknowledgement plus substantive response within 10 UK working days (excluding weekends and England & Wales bank holidays), with a 15 working-day reconsideration window under the same policy. Acknowledge promptly so the policy clock is accurate.
  11. Schedule 3 information requests — fulfil or refuse with linked documents (AP dashboard tracks a separate 20 UK working-day info-request SLA target).
  12. Open /occupied/activity for the golden-thread audit log for this building (backed by GET /api/activity?buildingId=).
  13. Engagement /occupied/engagement-strategy and /occupied/residents — resident engagement strategy and communications. For statutory complaint/info-request outcomes use Respond on residents (opens the issues sheet); use Log note only for freeform notes.
  14. Registration changes /occupied/registration-changes — under SI 2023/315 reg.4, notify the BSR within 14 relevant days of becoming aware of prescribed registration changes. Record the change and evidence; file on the official portal.
  15. Annual return /occupied/bsr-return — one return per HRB building per year. Record BSR annual HRB fee amounts and receipts on the building record.
  16. FRA / fire doors / EEIS & PEEP /occupied/fra — fire risk assessments, door inspections, evacuation arrangements. Threadsovereign is not a certified FRA product; keep assessor identity and review dates current.
  17. Part 5 remediation /occupied/remediation and /occupied/qualifying-leases — defects, orders, landlord certificates, leases.
  18. Maintenance /occupied/maintenance — schedules (Professional+ tier only).
  19. Building safety statements and BSR visit / fee receipt fields sit on the building record alongside BAC and returns — keep them current for inspection day.
  20. Governance extras: /occupied/bsr-submissions, /occupied/duty-holder-competence, /occupied/bsr-insolvency, /occupied/resident-access, /occupied/competency-matrix, /occupied/engagement-effectiveness.

Pages in the app (after sign-in)

  • Occupied hub /occupied
  • AP dashboard (incl. s.90) /occupied/ap
  • BSA compliance scorecard /occupied/compliance
  • Multi-HRB portfolio readiness /occupied/portfolio
  • Statutory deadline calendar /occupied/statutory-calendar
  • BSA evidence packs /occupied/evidence-packs
  • BSM dashboard /occupied/bsm
  • Safety case /occupied/safety-case
  • Key Building Information /occupied/kbi
  • Issues / occurrences / complaints /occupied/issues
  • Engagement strategy /occupied/engagement-strategy
  • Residents & requests /occupied/residents
  • Registration changes (SI 2023/315) /occupied/registration-changes
  • BSR annual return /occupied/bsr-return
  • FRA, fire doors, EEIS & PEEP /occupied/fra
  • Remediation (Part 5) /occupied/remediation
  • Qualifying leases /occupied/qualifying-leases
  • Maintenance (Professional+) /occupied/maintenance
  • BSR submissions & SPOC /occupied/bsr-submissions
  • Occupied documents / BAC /occupied/documents
  • Occupied activity log /occupied/activity
  • Competency matrix (PAS 867) /occupied/competency-matrix
  • Engagement effectiveness (reg.10) /occupied/engagement-effectiveness
  • Duty-holder competence records /occupied/duty-holder-competence
  • MOR educational guide
  • AP software overview

Official law and guidance

Tip: Complaint and Schedule 3 clocks in the product are platform policy SLAs (UK working days; E&W bank holidays excluded) unless the statute sets a different rule — reg.12 does not fix a national 10 WD complaint deadline. Occurrence reports use calendar days from AP attention under reg.6.

7. Building Assessment Certificates (BAC)

When BSR directs the Principal Accountable Person to apply for a BAC, track the 28-day window, assemble the pack, file on GOV.UK, and record refusal or appeal steps.

A Building Assessment Certificate is a post-occupation BSR assessment. It is not Gateway 1–3 and is not the same as merely publishing a safety case. PAPs cannot self-nominate — the regulator directs the application.

Threadsovereign helps you prepare and evidence BAC work. You still submit on the official BSR portal; the platform does not auto-file or guarantee approval.

For a public marketing overview see the BAC readiness software page; for the written procedure guide see the BAC application blog post (both linked under routes below).

Step by step

  1. When BSR directs a BAC application, open /occupied/documents (BAC) for the selected HRB and record the direction date and BSR reference — this starts the 28 calendar-day clock.
  2. Assemble the submission pack completeness view: safety case report, resident engagement strategy, mandatory occurrence reporting system evidence, and (if applicable) serial numbers of compliance notices currently in force.
  3. Resolve pack gaps via the linked workflows (safety case, engagement strategy, issues/MOR, BSR compliance notices) before portal day.
  4. Prepare for filing on GOV.UK — use attestation / portal follow-up patterns for other outbound BSR work; record the HSE/BSR reference after you submit.
  5. If refused: record refusal, review steps, and First-tier Tribunal appeal fields, deadlines, and outcomes on the building record.
  6. Track renewal_due_date and early-reassessment flags after incidents, material building changes, or remediation completion; watch scorecard and statutory calendar reminders.
  7. Keep registration contacts current via /occupied/registration-changes (14-day BSR notify) — adjacent to BAC readiness.

Pages in the app (after sign-in)

  • Occupied documents / BAC /occupied/documents
  • Safety case (pack input) /occupied/safety-case
  • Engagement strategy (pack input) /occupied/engagement-strategy
  • Occurrences / MOR evidence /occupied/issues
  • Compliance notices (serials) /occupied/bsr-compliance-notices
  • Registration changes (14-day) /occupied/registration-changes
  • BSA compliance scorecard /occupied/compliance
  • Statutory deadline calendar /occupied/statutory-calendar
  • BAC readiness software (marketing)
  • BAC application guide (blog)

Tip: Treat BSR direction as the operational start of the 28-day clock. Do not invent a self-started BAC application as if it were a statutory call-in.

8. BSA readiness — scorecard, portfolio, deadlines, packs

Turn Part 4 records into inspection readiness: what is incomplete, what is due, and what to take to the BSR.

These tools do not create new legal duties. They surface gaps against instruments you already use in Threadsovereign (BSA s.88, SI 2023/909 Part 4, SI 2023/907, SI 2023/396, SI 2023/315, SI 2024/41, Part 5).

There is no public BSR duty-holder API. Evidence packs prepare manifests and deep links; you still submit on GOV.UK and record the HSE reference under BSR submissions.

Advisory document pre-fill (Professional+) extracts text from an uploaded PDF into a draft form. Platform validators only check whether fields were found — not whether they are legally adequate. Nothing is submitted to the BSR automatically.

Document completeness scanning (Professional+) flags whether expected sections are present against human-written BSA validators. FRA completeness scanning remains disabled pending legal review — do not treat FRA scan as live.

Professional+ also offers advisory drafting tools (starting text for correspondence, risks, complaints) and natural-language search mapped to filters — both advisory; never auto-submit.

Step by step

  1. Open /occupied/compliance for the selected HRB — review the scorecard percentage and each SI-cited gap.
  2. Click Open on any critical or attention item to jump to the workflow that fixes it (KBI, safety case, issues, FRA, engagement, registration changes).
  3. If you manage more than one HRB, open /occupied/portfolio — buildings are sorted lowest readiness first.
  4. Open /occupied/statutory-calendar — toggle This building vs All HRBs for attention-based occurrence clocks, registration 14-day clocks, BAC 28-day clocks, and review dates.
  5. Open /occupied/evidence-packs — use AP inspection pack before a visit; gateway pack for SI 2023/909; resident rights pack for SI 2024/41; Schedule 8 pack for Part 5; download the cryptographic inspection bundle when counsel or BSR asks for a manifest.
  6. Professional+: on the scorecard page, upload a PDF under Occupied documents, choose KBI / SMS / engagement / FRA target, Extract fields, review checkboxes, Apply selected as draft, then open the form and verify before any BSR submission.
  7. Open /occupied/competency-matrix for PAS-style duty-holder competence evidence — the platform records evidence you supply; it does not certify competence.
  8. Open /occupied/engagement-effectiveness for SI 2023/907 reg.10 activity metrics.
  9. PD: open /change-control-impact to see open design changes and golden-thread update actions before Gateway 3.
  10. Download statutory deadlines as ICS from /occupied/statutory-calendar.

Pages in the app (after sign-in)

  • Compliance scorecard /occupied/compliance
  • Portfolio readiness /occupied/portfolio
  • Statutory deadlines /occupied/statutory-calendar
  • Evidence packs /occupied/evidence-packs
  • Competency matrix /occupied/competency-matrix
  • Engagement effectiveness /occupied/engagement-effectiveness
  • Change control → golden thread /change-control-impact

Tip: Run the scorecard before any BSR assessment visit. Fix critical items first (overdue occurrences, missing FRA, incomplete KBI). These readiness tools are on every plan (Starter+) — they are part of the BSA statutory floor, not a Professional upgrade.

9. Residents — your rights and how to use the portal

Residents of higher-risk buildings have legal rights to safety information and to raise concerns and complaints.

If there is immediate danger, call 999 first. Use the portal after people are safe.

Step by step

  1. Sign in and open /resident.
  2. Read building safety information on /resident/safety (includes duty-holder contacts and notices).
  3. Download documents you are entitled to on /resident/documents (single file or Download All ZIP).
  4. Raise a safety concern, information request, or formal complaint on /resident/request. Keep a copy of the reference number shown after submit.
  5. Track messages on /resident/messages.
  6. Update profile and notification preferences on /resident/profile and /resident/settings.
  7. If a complaint response is unsatisfactory, use the reconsideration option on /resident/request when it is offered.

Pages in the app (after sign-in)

  • Resident home /resident
  • Building safety information /resident/safety
  • Documents /resident/documents
  • Requests & complaints /resident/request
  • Messages /resident/messages
  • Resident help /resident/help
  • Settings /resident/settings

Tip: Information requests and complaints create formal records. Duty-holders track complaints against a platform policy SLA under reg.12 (not a fixed national statutory 10 WD clock). Use the request form for statutory matters; use messages for routine questions.

10. Client portal — approvals and evidence

Clients review progress and approve decisions with evidence, not on trust alone.

Step by step

  1. Open /client for your project list.
  2. Clear /client/approvals with a clear decision and notes.
  3. Review /client/documents (use Download All for a ZIP pack when reviewing a milestone). Building Safety Levy fields (liability, amount, receipt) can be recorded for developer clients.
  4. Open a project at /client/projects/[projectId] for messages and detail.
  5. Check /client/notifications for alerts.

Pages in the app (after sign-in)

  • Client home /client
  • Approvals /client/approvals
  • Documents /client/documents
  • Notifications /client/notifications
  • Settings /client/settings

11. Contractor & supplier portal

Contractors only see projects they are assigned to. Keep tasks, documents, certifications, and RFIs current.

Step by step

  1. Open /contractor.
  2. Work tasks on /contractor/tasks (filter by project when needed).
  3. Upload evidence on /contractor/documents.
  4. Keep certifications current on /contractor/certifications (download uses your uploaded file).
  5. Raise and answer RFIs on /contractor/queries — you can only create RFIs for projects you are a member of.
  6. Use project detail /contractor/projects/[projectId] for deep links into tasks and documents.

Pages in the app (after sign-in)

  • Contractor home /contractor
  • Tasks /contractor/tasks
  • Documents /contractor/documents
  • Certifications /contractor/certifications
  • RFIs / queries /contractor/queries
  • Notifications /contractor/notifications

Tip: If a project is missing from your list, ask the PD to add you as a project member — you cannot invent access by guessing a project ID.

12. Platform admin & compliance CMS

Admins govern organisations and users. Compliance CMS holds shared regulatory content (not per-building data).

Step by step

  1. Platform admin: /admin for organisations, users, billing, audit log, and settings.
  2. Create tenants at /admin/organisations/new — Companies House number must be a valid 8-digit UK company number or a company name that resolves uniquely via the lookup.
  3. Invite users from organisation detail when onboarding a tenant.
  4. Compliance CMS: /compliance for checklists, regulations, sources, versions, alerts, and horizon items.
  5. Reading compliance content needs Professional+. Writing/publishing needs Enterprise.

Pages in the app (after sign-in)

  • Admin home /admin
  • Organisations /admin/organisations
  • Create organisation /admin/organisations/new
  • Users /admin/users
  • Billing /admin/billing
  • Audit log /admin/audit-log
  • Compliance CMS /compliance
  • Checklists /compliance/checklists
  • Regulations library /compliance/regulations
  • Horizon register /compliance/horizon

13. Law library — full official links

Bookmark these official sources. Threadsovereign implements workflows against them; the law remains the authority.

Open any link below in a new tab. Prefer legislation.gov.uk for the legal text and GOV.UK for practical guidance.

Official law and guidance

14. Troubleshooting

What to do when something blocks you.

For product support, email support@threadsovereign.co.uk with portal, page URL, time, what you clicked, what you expected, and a screenshot.

For life-safety emergencies, follow building procedures and call emergency services — do not wait on the portal.

  • Wrong portal after login — ask an org admin to check your role on /team.
  • Page asks you to upgrade — you may be on a paid-only feature (for example maintenance). Statutory occupied pages should not paywall.
  • Cannot see a building — use the building selector; confirm you are in the correct organisation.
  • Cannot edit an approved golden-thread document — create a superseding version instead.
  • Gateway status rejected — the transition is not allowed; check permitted next states on the gateway page.
  • Resident cannot open a document — only client-visible documents for their building are available.
  • Occurrence deadline looks wrong — confirm the AP attention date when marking BSR-reportable (reg.6 uses calendar days from attention, not create date alone).
  • Complaint SLA looks like a legal deadline — treat the 10 UK working-day product clock as platform policy under reg.12, not a fixed national SI clock.
  • KBI or MOR “submitted” in-app — still file on the official BSR portal and record the HSE reference; the product does not auto-file.
  • Asite/Procore not connecting — there is no self-serve OAuth; use the in-app CDE request (Enterprise support-led).