Category: Operational Resilience Tags: duty of care, travel risk, people risk, crisis management, accountability, employee privacy, location data
The question always arrives in the same shape and it always arrives fast. Something happens in a city: an earthquake, a coup attempt, an attack, a wildfire that closes the airport. Within about ten minutes somebody senior asks a question that sounds simple. Do we have anyone there? I have watched capable organizations take most of a day to answer it, not because the information did not exist, but because it existed in five places that had never been introduced. Travel bookings were in the corporate booking tool, unless the person booked their own. Badge records covered the offices, which told you who normally worked there rather than who was in the country. The HR system held a work location field last updated when the person was hired. A few teams kept their own spreadsheets. Meanwhile the people themselves were texting their managers, and their managers were texting each other, and the actual roll call was being assembled in a group chat by whoever happened to be awake.
The company was not negligent about safety. It had an evacuation policy, a travel insurance program, a security vendor on retainer, and a crisis team with a documented charter. What it did not have was the join. Every ingredient of an answer was present and no system held the sentence.
The Obligation Attaches Whether You Systemize It or Not
Duty of care is the general obligation an employer carries to take reasonable steps to protect the people it sends into harm's way, and it does not wait for you to build a program. It arrives through several channels at once: general employment and occupational safety law in most jurisdictions, specific statutory duties in some, contractual commitments to clients about the staff placed on their sites, and the plain expectation of the workforce. I am not offering legal advice here and the specifics vary enormously by country, so the boundaries are a question for counsel rather than for me. But the practical shape of the standard is consistent enough to plan against, and it is not a demand for perfect safety. It is a question about foreseeability and reasonableness: did you know, or should you reasonably have known, that this location carried this risk, and did you take reasonable steps in response?
Both halves of that question are evidentiary, which is what makes this a governance problem rather than a security one. Answering it after an incident means reconstructing what you knew and when, what your own screening said about that location, what you told the traveler, and what you did when conditions changed. An organization that assembles its roll call in a group chat has no record of any of it. It may well have acted reasonably, and it will struggle to demonstrate it, which in front of a regulator, a court, or a bereaved family is much closer to the same thing than anyone is comfortable admitting.
The Location Data You Already Have and Never Joined
The encouraging part is that almost nobody needs new collection. The data exists, scattered across functions that have no reason to talk. Travel bookings live with the travel team or the booking platform. Badge and access records live with physical security. Work location and employment status live in the HR system. Expense claims reveal where people actually were, after the fact. Device and network telemetry knows more than anyone wants to say out loud. Contingent workers and contractors usually appear in none of these, which is its own hole, since your duty toward them is rarely as clean as procurement assumes.
Each of those systems is owned by a different function with a different purpose, and none of them was built to answer a geographic question under time pressure. The work is joining them onto a coordinate system and deciding, in advance, which sources are authoritative for which population. That is the same argument I made in the map is the missing control, applied to people rather than sites and vendors: geography stored as a text field in five systems is not location data, it is five text fields. Once people are on the same map as your sites, your vendors, and your hazard picture, the ten-minute question becomes a query rather than an investigation.
Remote Work Deleted the Site List
There is a structural change underneath this that many programs have not absorbed. For most of the history of corporate crisis management, knowing where your people were meant knowing where your offices were, plus a travel list. The office list was the people list. That assumption is now false in most companies, and it fails in both directions.
It fails outward, because a meaningful share of the workforce is nowhere near a facility, including people who relocated during the remote years and never updated a system that nobody asked them to update. When something happens in a mid-sized city where you have no office, the honest starting answer at most companies is that they do not know whether they have staff there, and the reflex to check the site list returns a confident and wrong no. It also fails inward, because the office list overstates presence: a badge record from a hybrid office says who has access, not who is in the building on a Tuesday. Both errors are dangerous in the same way, which is that they produce a clean answer with nothing behind it. The correction is unglamorous, which is to maintain a work-location attribute for every worker as a governed field with an owner and a refresh expectation, rather than as a hiring artifact nobody has touched in three years.
Knowing Is Half. The Response Has to Already Exist
Locating people is necessary and it is not sufficient, and I have seen programs stop at the dashboard because the dashboard demos well. What turns knowledge into duty discharged is the part that runs afterward: a defined way to reach every affected person, a way for them to respond that works when the network is degraded, a rule for what happens when someone does not respond within a set time, and a named person authorized to spend money on evacuation or accommodation without convening a committee. That last one decides more outcomes than any technology in this article. The thresholds have to be set in advance too, because the middle of an event is the worst possible time to invent the criteria for pulling people out, and the pressure at that moment always runs toward waiting one more day.
This is the same command structure I described in incident command is the backbone of resilience, pointed at people instead of systems, and it needs exercising for the same reason. A tabletop that assumes everyone answers their phone tests nothing. The useful version assumes three people do not respond, one is in a location the map scored as elevated a week ago and nobody read, and the decision maker with spending authority is on a flight.
The Privacy Problem Is Real, and Minimization Is the Answer
Everything above describes building a system that tracks where employees are, and it would be dishonest to present that without saying plainly that it is one of the more invasive things a company can build. Employee location is sensitive personal data. In the EU and several other jurisdictions it carries specific obligations, works councils have a legitimate say, and a system built for safety that quietly becomes a productivity monitor will destroy the trust the program depends on. People who believe the tool is watching them will route around it, and then the roll call is wrong precisely when it matters.
The discipline that keeps this defensible is minimization, and it is worth designing in from the first day rather than retrofitting after a works council asks. Collect the coarsest location that answers the question, which is almost always city or country rather than continuous position. Tie collection to a stated purpose and enforce that boundary technically rather than by policy promise. Set retention deliberately, since a duty of care use case rarely needs location history beyond the period of exposure. Be explicit with the workforce about what is collected, why, who can see it, and what it will never be used for. And keep access narrow, because the crisis team needs this and the reporting layer does not. Those are exactly the commitments that end up in a customer's questionnaire and a regulator's file, which is the connection back to treating those promises as controls rather than as sentences.
None of this makes the ten-minute question comfortable. It makes it answerable. The gap between a company that says we have four people in that city, two have confirmed they are safe, one is at a hotel eleven kilometers from the affected area, and one has not responded in ninety minutes, and a company that says we think so, let me find out, is not a gap in caring. Both organizations care. It is a gap in whether anyone did the joining work on an ordinary Tuesday, months earlier, when there was no emergency and no reason to think about it at all.
Put people on the same map as everything else
The PivotRisk risk intelligence map already scores any address against live hazard, jurisdictional and infrastructure signal, with every figure sourced and nothing fetched until you ask. Score the cities where your people actually are, and see what the screening picture says before the ten-minute question arrives.
Open the Risk Map