Kepla-EHS User Manual
This manual explains every part of Kepla-EHS in plain language, written for people who have never used an occupational health, safety, or compliance system before. You do not need any background in this field to follow along — each section explains not just how to use a screen, but why it exists and what problem it solves for your organization.
You will only see tiles on your home page for the modules your role has been given access to — it is normal and expected for two people at the same company to see different tiles. If something described here isn't visible to you, ask your administrator or supervisor whether your role should include it (see Organization Setup, Roles & Permissions).
Tip: use the Print / Save as PDF button above to get a offline copy of this entire manual — your browser's print dialog lets you choose "Save as PDF" as the destination instead of a physical printer.
Contents
- Getting Started: Signing In & Account Security
- Finding Your Way Around
- Organization Setup (Employees, Sites, Equipment, Roles)
- Shared Tools You'll See Everywhere
- Employee Health
- Compliance Management
- Risk Assessment
- Audits & Inspections
- Medical Chart
- Drug Testing
- Case Management (Disability & Absence)
- SEG Management
- Survey (Industrial Hygiene Sampling)
- Lab Requisition
- Ergonomic Assessments
- Environmental Compliance
- Dashboard
- Metrics
- Report Builder
- Security Administration
- Glossary of Terms
- Troubleshooting & FAQ
1. Getting Started: Signing In & Account Security
Signing in with a password
Go to the Kepla-EHS sign-in page and enter the Username and Password your administrator gave you, then click Sign In. Passwords must be at least 12 characters — this is a security requirement, not a suggestion, and common/easily guessed passwords are rejected automatically.
Signing in with a passkey
Instead of typing a password every time, you can sign in with a passkey — a secure credential tied to your device (fingerprint, face recognition, PIN, or a physical security key). On the sign-in page, click Sign in with a passkey and follow your device's prompt.
Signing in with SSO (Single Sign-On)
If your organization has connected Kepla-EHS to its own identity provider (for example Okta, Microsoft Entra ID / Azure AD, or Google Workspace), you'll see a Sign in with SSO button on the sign-in page — sometimes labeled with your company's own name for it, like "Sign in with Okta." Click it and you'll be sent to your organization's usual login screen instead of typing a separate Kepla-EHS password.
Not every organization has SSO turned on — if you don't see the button, your organization is using Kepla-EHS's own username/password (and optionally passkey/2FA) sign-in instead, described above. Both can be offered at the same time; if you're not sure which one you should use, ask your administrator.
The first time you ever sign in
Most organizations using Kepla-EHS require every user to register a passkey before they can use the system — this is a one-time setup step. The first time you sign in with your username and password, you'll be walked through registering a passkey on your device. If you don't complete this, you won't be able to get past the sign-in screen — this is intentional, not a bug.
Two-Factor Authentication (2FA / TOTP) — optional extra protection
In addition to (or instead of, depending on your organization's settings) a passkey, you can turn on Two-Factor Authentication: a 6-digit code from an authenticator app on your phone (like Google Authenticator or Authy) that changes every 30 seconds. Turn this on from Account Settings → Two-Factor Authentication → Set Up 2FA — you'll scan a QR code with your authenticator app and enter the code it shows to confirm setup.
Managing your account
Click your username in the top-right corner of any page to open Account Settings. From there you can:
- Change your display theme.
- Set up, view, or (if not required company-wide) disable Two-Factor Authentication.
- Add, rename, or remove passkeys registered to your account.
If you lose access to your passkey or authenticator app
You cannot simply reset these yourself the same way you'd reset a forgotten password, because that's exactly what makes them secure. Use Request a Passkey Reset on the sign-in page (or ask your organization's Security Administrator directly) — a staff member with Security Administration access will need to approve the reset before you can register a new passkey.
Automatic sign-out
For the protection of sensitive health and compliance data, Kepla-EHS automatically signs you out after 20 minutes of inactivity. If this happens, simply sign back in — nothing you already saved is lost.
Too many failed sign-in attempts
After 5 incorrect password attempts, your account is temporarily locked for security. Wait about an hour and try again, or ask your organization's Security Administrator to unlock it immediately (see Security Administration).
2. Finding Your Way Around
The navigation bar
Every page has a dark blue bar across the top. On the left is the Kepla-EHS logo (click it any time to return to your home page) and a menu link to this User Manual. Administrators also see a handful of company-structure links here — Org Hierarchy, Regions, Facilities, and Equipment — since those don't have a tile of their own on the home page. Anyone with access to any security-related screen also sees a Security link (see Security Administration below). On the right are Saved Views, your username (which opens Account Settings), and Sign out.
Your home page
When you sign in, you land on a home page showing a tile for every module you're allowed to use, each with a short description — this, not the top navigation bar, is where you open Employee Health, Compliance, and every other module. Administrators also see extra tiles here for Employees and Roles & Permissions. If you see no tiles at all, you haven't been assigned a role yet; ask your supervisor or administrator to grant you one (see Roles & Permissions).
Why don't I see everything my coworker sees?
Kepla-EHS deliberately shows different people different things, based on two independent settings:
- Which modules you can use — e.g., you might have access to Employee Health but not Drug Testing.
- Which records you can see within a module — e.g., a supervisor at one clinic location typically sees only that location's employees, cases, and records, never another location's.
This is intentional and protects sensitive data — see Roles & Permissions below for how it's configured.
Lists, filters, and forms — patterns you'll see everywhere
Almost every module works the same basic way: a list screen shows existing records with an "Add New" button, clicking a row opens a detail screen with full information and related history, and an edit form lets you change details. Once you're comfortable with one module, the rest will feel familiar.
3. Organization Setup
These screens are typically used by administrators to set up the company structure that every other module relies on. Regular users usually only need to read this section to understand terms used elsewhere.
Org Hierarchy: Region → Facility → Department
Kepla-EHS organizes your company as a tree: your Organization (the whole company) contains one or more Regions (optional — for companies with several geographic areas), each containing Facilities (a specific site or building, e.g. "Main Hospital"), each containing Departments. Every employee, case, exam, and record ultimately belongs to a facility and (usually) a department — this is the backbone that makes site-based permissions and reporting possible. View the whole structure at any time under Org Hierarchy, where you'll also find links to edit your Organization's own name, and to the screens described next.
Job Roles, Hazard Types & Exposure Profiles
Three related picklists, all reachable from Org Hierarchy: Job Roles are the job titles you assign to employees; Hazard Types are the shared vocabulary of hazards your organization tracks (noise, chemical exposure, ergonomic strain, etc.); an Exposure Profile bundles one or more hazard types together (e.g. "Lead-Exposed Worker" might bundle "Lead" and "Respiratory Hazard") and gets assigned to employees on their Employee record. Exposure Profiles are what drive automatic exam scheduling — see Employee Health.
Modules
Under Org Hierarchy → Modules, an administrator can turn an entire feature off for everyone — regardless of anyone's individual Role — without affecting anyone's specific permissions. Useful if your organization doesn't use a particular module (e.g. Drug Testing) and wants it out of the way entirely rather than just ungranted.
Employees
The Employees screen is your staff directory — every worker record other modules (exams, cases, assessments) attach to. Each employee record holds their name, employee ID, job title, department, site, manager, employment status (active/inactive/terminated), employee type (full-time/part-time/contractor), union status, and contact email (used for automatic reminders like recall notifications).
To add a new employee:
- Open Employees from your home page.
- Click Add Employee.
- Fill in their name, ID, job title, department, and facility.
- Save. They'll now be selectable throughout every other module.
Roles & Permissions
This is the control center for who can see and do what. A Role (e.g. "Facility Supervisor," "Nurse," "Safety Manager") is a named bundle of permissions: for each module, whether holders of that role can View it, Edit it, or neither. A role by itself grants no one anything — it must be assigned to a specific user, and that assignment also sets which facility/department(s) that person can see data for (or "all facilities," for someone like a corporate administrator).
To give someone access to a module:
- Open Roles & Permissions.
- Create a role (or use an existing one) and toggle View/Edit for the modules it should cover.
- Click Assign on that role, choose the user, and choose which facility/department(s) they should see — or "all facilities" for company-wide visibility.
- Save. The user will see the new module the next time they load a page.
Need to change where an existing assignment applies? Click Edit next to it in the Assigned Users list to change its facility/department scope directly, instead of removing it and assigning again.
Equipment
Tracks physical assets — PPE, machines, monitoring instruments — that need periodic calibration or inspection. Set a last calibration date and a calibration interval (in months) and Kepla-EHS automatically calculates the next due date and flags items as upcoming, due soon, or overdue — no manual tracking spreadsheet required. The Due List view shows only what needs attention soon.
5. Employee Health
Employee Health is the largest module — your organization's occupational medicine and injury/illness record system. It's organized into four related areas, all scoped to your assigned facility/department like every other module.
Exams & Medical Surveillance
Record occupational health exams — immunizations, bloodwork, respirator fit tests, hearing tests (audiograms), spirometry, and others your organization configures. Each exam type has its own set of result fields; some (like bloodwork) automatically flag a result as abnormal if a value falls outside the configured reference range, though staff can always override the automatic suggestion.
Exams can also be scheduled proactively: an Exposure Profile (e.g. "Lead-Exposed Worker") defines which exam types a group of employees need and how often. Kepla-EHS then calculates each employee's next-due date automatically and sends repeated recall reminder emails until the exam is actually completed — you don't have to manually track a spreadsheet of who's due for what.
The rule connecting an Exposure Profile to the exams it requires is called an Exam Requirement — set these up under Employee Health → Exam Requirements: pick the exposure profile, the exam type, how often it repeats (or leave blank to use that exam type's own default), and a grace period (how many days past due before a status flips from "due" to "overdue"). Exposure Profiles themselves are managed under Org Hierarchy → Exposure Profiles, where you also choose which hazard types each one bundles together.
To record an exam:
- Open Employee Health → Exams → New Exam.
- Choose the employee and exam type, then click Load Result Fields — the form will change to show the fields specific to that exam type.
- Fill in the results and click Save Exam.
Injury & Illness Cases (Incident Management)
Log workplace injuries and illnesses in the level of detail U.S. OSHA record-keeping requires. Opening a case captures whether it's an injury or illness, its classification (e.g. first aid only, days away from work), and flags for particularly sensitive situations like needlestick injuries.
From a case, you can add individual injuries (body part and nature), print an Employer's First Report or an OSHA-301-style form, and export your OSHA 300 log as a spreadsheet. Cases can also be automatically linked to the Risk Assessment for the job/task where the incident happened, so investigators can immediately see what hazard controls were already in place.
Fitness for Duty & Work Restrictions
Record a determination of whether an employee is fit to return to work, fit with restrictions, or not fit — and list the specific restrictions (e.g. "no lifting over 20 lbs") as a timeline attached to that determination. A determination can optionally link back to the injury/illness case or exam that prompted it.
Exposure Monitoring
Record workplace exposure sample results (e.g. noise or chemical readings). Samples can be tied to a specific employee, or left unassigned for area-level monitoring where no single person is being measured.
6. Compliance Management
Keeps track of the legal, regulatory, and internal obligations your organization must maintain, and the permits that prove you're meeting them.
- Legal Requirements — a library of obligations (regulatory, corporate, permit-related, or management-system) that you can link to the specific facility or department they apply to.
- Permits — track a permit's expiration and see its live status: active, due soon, overdue, or no expiration for permits that don't expire.
- Compliance Calendar — one screen listing every upcoming/overdue permit and compliance action, sorted by due date, so nothing falls through the cracks.
You can generate a compliance Action directly against a requirement (e.g. "renew our wastewater discharge permit") — this reuses the same Findings & Actions system described earlier, so it shows up on the assignee's task list the same way any other action would.
7. Risk Assessment
A structured way to identify hazardous jobs and tasks, score how risky they are, and prove that safety controls actually reduce that risk over time.
How scoring works
Your administrator configures one or more Risk Factors under Risk Assessment → Risk Factors (commonly Severity and Likelihood), each with several selectable levels (e.g. Severity: Minor / Moderate / Serious / Severe). A formula (e.g. Severity × Likelihood) combines your selections into a numeric score, which is then mapped to a color-coded band (Low / Medium / High). The formula itself is set under Scoring Settings on that same screen, written as simple arithmetic over your risk factors' codes.
To assess a job or task:
- Add the job/task under Job/Process Inventory if it isn't listed yet.
- Open it and click New Assessment.
- Select the factor levels that describe the risk before any controls are in place — note the resulting score/band.
- Select the factor levels again for after your controls (guards, PPE, procedures) are applied.
- Save. The before/after scores prove how much your controls actually reduced the risk.
When conditions change, click New Version rather than editing the old assessment — this creates a fresh, dated copy pre-filled with the previous answers so you only need to update what changed, while keeping a full history of how the risk score trended over time. You can also attach reference procedures and see which compliance requirements a job is linked to.
8. Audits & Inspections
Runs recurring site walkthroughs and checklists — built on the same Questionnaire tool described earlier — and automatically turns failed answers into Findings your team can act on.
An Inspection Profile defines a checklist (a Questionnaire), how often it repeats, which inspector(s) and site(s) it applies to, and (optionally) which compliance requirement it verifies. Kepla-EHS generates the actual scheduled Inspections for you and can remind the assigned inspector by email as the due date approaches.
To perform a due inspection:
- Open Audits & Inspections and find your inspection in the due list.
- Open it and answer each checklist question.
- Submit. Any answer configured to indicate a problem automatically creates a Finding — you don't need to separately remember to log it.
9. Medical Chart
A single, chronological view of one employee's health history — clinic visits, immunizations, and work restrictions all pulled together from records entered elsewhere in Employee Health, so clinical staff don't have to hunt across several screens.
- Search or browse employees (scoped to the facilities you can see) and open their chart.
- Allergy Alerts — record allergies with a severity level; active alerts display as a prominent warning banner right at the top of the chart. Entered one in error? Click the small × on the badge to deactivate it — it's kept (not erased) as clinical history, just no longer shown as an active alert.
- Documents — upload physician's notes or other medical paperwork; uploaded files appear both in a documents list and merged directly into the employee's timeline. Use Remove next to a document to take it back down.
10. Drug Testing
Manages both scheduled random testing programs and one-off, for-cause tests, plus alcohol testing.
Random selection
Define a Random Pool — the group of employees eligible for random selection, optionally narrowed by facility, department, or job role. Running a random draw uses a cryptographically strong random number generator (not just an ordinary shuffle) and creates a permanent audit record of exactly who was eligible, how many were requested, who was actually selected, and when — so the fairness of the draw can always be demonstrated later if questioned. Review that full history any time under Random Pools → Selection Runs.
Recording a test
Each test tracks a collection status (scheduled, tested, refused, or excused) and, separately, individual results for each substance in the panel plus an optional alcohol result. The overall result (positive/negative/refused/excused) is calculated automatically from those individual entries — you never have to manually decide and re-enter that summary yourself.
11. Case Management (Disability & Absence)
Tracks workers' compensation, short-term/long-term disability, and FMLA claims — a different concept from the Injury & Illness Cases in Employee Health, though a workers'-comp claim can optionally link back to the workplace incident that caused it.
- Absences & Restrictions — log time away from work and any number of work restrictions in a single entry (list each restriction on its own line); lost time, restricted time, and remaining benefit days are all calculated for you. Use Remove to take back an entry logged in error.
- Case Activities — a running log of calls, independent medical exam visits, and other case-administration touchpoints, each with time spent and cost.
- Documents — attach physician correspondence, physical therapy notes, return-to-work notes, and test results specific to this claim; Remove is available here too.
- Case Letters — generate an acceptance, denial, or benefit notification letter from a pre-approved template, automatically filled in with the employee's and claim's details.
The list of standard reasons someone can be absent (Absence Reasons) is configured under Case Management → Absence Reasons by an administrator.
12. SEG Management
Create a SEG, give it a name, assign member employees and/or linked job/processes, and optionally tie it to a specific facility. Once defined, a SEG can be referenced by a Survey sampling plan (see the next section) so exposure monitoring results are organized by group.
13. Survey (Industrial Hygiene Sampling)
Records quantitative exposure sampling — noise, chemical, or dust measurements — against a defined exposure limit.
An Agent is the substance being sampled for (e.g. Respirable Crystalline Silica, Lead, Noise). A Sampling Plan defines a testing effort, optionally linked to a Risk Assessment and/or a SEG. Each individual Sample can be personal (tied to one employee) or area-level (left unassigned). Once you enter a measured value and its exposure limit, Kepla-EHS automatically calculates the percent of the limit and flags whether it's an exceedance — you don't have to do that math by hand. Agents, sampling plans, and individual samples can all be edited later from their respective screens if a detail needs correcting.
14. Lab Requisition
Manages sending Survey samples out to an accredited lab for analysis and recording what comes back.
To send a sample to a lab:
- From a sample's row in a Sampling Plan, click Send to Lab.
- Choose which lab and submit the requisition. A tracking number is generated automatically.
- When results come back, open the requisition and record the value, unit, and upload the lab's report file.
- Click Apply to Sample to explicitly copy the lab's reported result onto the original sample record — this is a deliberate, separate step so a result is never silently overwritten without someone reviewing it first.
The list of labs you work with is configured under Lab Requisition → Labs, editable at any time.
15. Ergonomic Assessments
Scores physical job tasks — most commonly manual lifting — for injury risk, using recognized industry formulas rather than subjective judgment alone.
Select an Ergonomic Tool (for example, the NIOSH Lifting Equation), then enter the requested measurements (weight lifted, distances, frequency, and posture-related multipliers). Kepla-EHS computes the score and its risk band (Low/Medium/High) automatically. A result that lands in a high-risk band automatically generates a Finding so it enters your team's normal follow-up process, the same way a failed audit question would.
16. Environmental Compliance
Tracks air emissions calculations for your facilities, along with the chemicals and control equipment behind them.
- Chemical library — reference data (e.g. CAS number, physical properties) for substances you handle. Editable any time.
- Emission Sources — a specific piece of equipment or process at a facility that emits something (e.g. a parts washer or solvent tank), optionally linked to a control device (e.g. a filter). Editable any time.
- Emission Calculation Methods — a formula (e.g. an AP-42-style mass-balance calculation) your organization defines once and reuses. Editable any time.
- Control Device Types — the picklist of control-equipment categories (e.g. baghouse, scrubber) offered when linking a control device to a source. Editable any time.
When you record an emission calculation, the result is permanently frozen at that moment — even if the underlying formula is edited later, previously calculated results never silently change. This preserves an accurate historical record for regulatory reporting. If a formula is broken or references a value that wasn't provided, the record still saves with a clear Error badge rather than showing a wrong number.
17. Dashboard
Build a visual home screen made of indicators — small widgets, each sourced from a Saved View — so you can see the state of your program at a glance instead of digging through list screens.
Indicator types include:
- Number — a single count or figure.
- Table — a compact list of matching records.
- Bar Chart — a visual comparison across a category (e.g. findings by facility).
- Indicator Card — a number compared against a target range, with a color that shows whether you're on track.
You can keep a dashboard personal (only you see it) or mark it shared with everyone or specific roles — click Edit on a dashboard you own any time to rename it or change its sharing. If a table indicator would return an unreasonably large number of rows, Kepla-EHS shows a warning instead of silently loading a huge table — you can still choose Load Anyway if you really want to see it all.
18. Metrics
Tracks KPIs (Key Performance Indicators) — a number that summarizes performance against a goal, trended over time.
A Metric starts from a Saved View, then adds: an aggregation (count, sum, or average of a chosen field), a target value to compare the result against, and optionally a monthly trend and a breakdown by a category such as facility. Kepla-EHS shows whether you're currently On Target or Below Target, computed automatically and always scoped to what you're allowed to see (a facility-scoped supervisor sees their own site's number, not the company-wide total). Click Edit on a metric any time to adjust its definition.
19. Report Builder
Create ad hoc reports on any data type you have access to, or use one of the pre-built Standard Reports your organization ships with (for example, "Open Incidents by Site" or "Overdue Actions by Assignee").
A report can output as a table, a chart, or a single number, and — for reports whose author allowed it — certain filters can be adjusted at the moment you run the report (for example, changing an "overdue as of" date) without changing the saved report definition for everyone else. Reports can be exported to CSV, and scheduled to be emailed automatically to a distribution list on a recurring basis. An Edit link appears on a report's detail page if you own it — Standard Reports can't be edited or deleted, by design, so everyone can always count on them being there.
20. Security Administration
Every security-related screen — company-wide login policy, SSO configuration, and per-user account actions — lives behind one Security link in the navigation bar (and on the Account Settings page). That page shows only the cards you're actually allowed to open: Security Policy and SSO Settings require staff access, while Security Administration, Passkey Reset Requests, and the Action Log require the Security Administration permission on your role. Someone can hold either set, both, or neither — the Security link itself only appears if you hold at least one.
The Security Administration screens below are visible only to users whose role has been granted the Security Administration permission — typically IT or a designated administrator.
From here, an authorized administrator can create a new account, or help a user who is locked out or has lost access to their credentials, without needing that user to already be logged in:
- Create User — set up a brand-new account with a username, email, and temporary password. A Role and scope (all facilities, one facility, or one department) can be assigned right on this same screen so the account can see data immediately — leave Role blank to assign one later under Roles & Permissions instead. See Bringing someone on before they have SSO access for the most common reason to use this screen.
- Reset a password — set a new temporary password (you'll re-enter your own password to confirm the action, since the locked-out user can't prove who they are by logging in).
- Reset passkeys — clear all registered passkeys so the user can register a new one on their next sign-in.
- Reset 2FA — clear a user's authenticator app setup so they can set it up again.
- Unlock an account — immediately clear a lockout caused by repeated failed sign-in attempts, instead of making the person wait out the cooldown period.
- Grant/Revoke SSO Exemption — flip whether this specific account can still use local sign-in when Require SSO for all users is on; see that section for when you'd use this. A grant always comes with a number of days and expires on its own — see below.
The user list itself is filterable — useful when you need to answer a request quickly instead of scanning every account by eye. Alongside the search box (matches username, name, or email), filter dropdowns narrow the list to any combination of SSO Exempt (Yes/No, meaning currently exempt — an expired exemption counts as No), 2FA (Enabled/Not enabled), Passkey (Registered/None), and Status (Locked out/OK) — for example, "SSO Exempt: No" plus "2FA: Not enabled" finds everyone who both needs SSO and hasn't set up a second factor yet. Filters combine with each other and with the search box; Clear resets everything.
A safeguard applies to the four actions on an existing account: accounts belonging to system administrators (staff or superuser accounts) can only be managed by a superuser — a regular Security Administration user will see an access denied page. Creating a new account never grants staff or superuser status regardless of who creates it — that remains a separate, more restricted action. Every one of these five actions, including account creation, is permanently recorded in an audit log showing who did what, to whom, and when. That log cannot be edited or deleted, by anyone.
SSO Settings
From Security → SSO Settings, an administrator can connect Kepla-EHS to your organization's identity provider so users can sign in with SSO instead of (or alongside) a Kepla-EHS password. Both of the following can be turned on independently, and either can be used at the same time as regular password/passkey sign-in — turning on SSO never removes that fallback:
- OpenID Connect (OIDC) — the modern standard used by Okta, Microsoft Entra ID / Azure AD, Google Workspace, and most cloud identity providers. You'll need the Client ID, Client Secret, and a handful of endpoint URLs from your identity provider's admin console; the screen shows the exact redirect / callback URL to give them in return.
- SAML 2.0 — the older, still widely used enterprise standard, common where a specific IT/security policy requires it. Paste the metadata your identity provider gives you (either the XML directly, or a URL Kepla-EHS can fetch it from); the screen shows the entity ID / metadata URL and ACS URL to give your identity provider's administrator in return.
Automatically create an account on first SSO login is off by default — with it off, SSO can only sign in someone who already has a Kepla-EHS user account with a matching email address; anyone else sees a "contact your administrator" message instead of getting in. Turning it on lets Kepla-EHS create a new account automatically the first time a valid SSO user signs in, but that new account is only ever authenticated — it starts with the default role you choose here and no facility/department scope, so it can't see any records until you assign one under Roles & Permissions.
Requiring SSO for everyone
Test SSO end-to-end first — sign in with it yourself and confirm it works — then turn on Require SSO for all users near the bottom of the SSO Settings screen. Once enabled, the regular username/password/passkey sign-in form stops working for ordinary accounts: anyone who tries it is signed out immediately with a message pointing them to the SSO button instead.
Two deliberate exceptions, so this can never lock everyone out at once:
- Superusers are always exempt, automatically, with no setting to configure. This guarantees at least one way in to fix things — including turning this very setting back off — if your identity provider ever breaks or is unreachable.
- Any account can be individually marked exempt. This is what answers "how does someone without SSO access yet sign in?" — see the next section.
How someone without SSO access signs in when SSO is required
This is exactly what Create User is for. That screen has a checkbox, Exempt from SSO requirement, checked by default, plus a number field — Exempt for how many days (30 by default) — a contingent worker, new hire waiting on their company identity, or anyone else without SSO access yet gets a local account that keeps working through the regular sign-in form for that many days, even while Require SSO for all users is on for everyone else. They still go through your organization's normal 2FA/passkey requirements if you have those on — the exemption is only from the SSO requirement, not from Kepla-EHS's own security policy.
For an account that already exists, a Security Administrator can grant or revoke this same exemption any time from that user's page (Security Administration → [user] → Grant/Revoke SSO Exemption). Granting always asks for a number of days — there's no permanent bypass, by design.
Setting up OIDC, step by step
OIDC is a two-way handoff: your identity provider needs to know about Kepla-EHS, and Kepla-EHS needs to know about your identity provider. You'll go back and forth between the two admin consoles once or twice — that's normal, not a sign something's wrong.
- Open SSO Settings in Kepla-EHS first and copy the redirect / callback URL shown at the top — you'll need it in the next step.
- In your identity provider's admin console, create a new application (Okta calls it an "app integration," Azure/Entra calls it an "app registration," Google calls it an "OAuth client"). Choose the OIDC / OpenID Connect / "Web application" option — not SAML.
- When asked for a redirect or callback URL, paste the URL you copied in step 1.
- Save the application. Your identity provider will now show you a Client ID and Client Secret — copy both somewhere safe for a moment (the secret is usually only shown once).
- Your identity provider also has four endpoint URLs, usually listed together on the same app page or in a "well-known configuration" / "discovery document" link. You need all four: Authorization endpoint, Token endpoint, Userinfo endpoint, and JWKS endpoint.
- Back in Kepla-EHS's SSO Settings, fill in Client ID, Client secret, and the four endpoints, then turn on Enable "Sign in with SSO" (OpenID Connect) and click Save Settings.
- See Testing your connection below before telling anyone to use it.
- Go to console.cloud.google.com (a free Google Cloud project is fine — it doesn't need billing enabled).
- APIs & Services → OAuth consent screen: set a name (e.g. "Kepla-EHS"), a support email, and choose User type: Internal if you want sign-in restricted to your own Workspace domain (recommended).
- APIs & Services → Credentials → Create Credentials → OAuth client ID, application type Web application, name it "Kepla-EHS," and paste Kepla-EHS's redirect/callback URL into Authorized redirect URIs.
- Click Create. Google shows you the Client ID and Client secret — copy both into Kepla-EHS's SSO Settings.
-
Google's four endpoint URLs are fixed and the same for every Google Workspace organization — copy these exactly:
Authorization endpoint: https://accounts.google.com/o/oauth2/v2/auth
Token endpoint: https://oauth2.googleapis.com/token
Userinfo endpoint: https://openidconnect.googleapis.com/v1/userinfo
JWKS endpoint: https://www.googleapis.com/oauth2/v3/certs - Save, turn OIDC on, and test.
Setting up SAML, step by step
- Open SSO Settings in Kepla-EHS first and copy the entity ID / metadata URL and ACS URL shown at the top.
- In your identity provider's admin console, create a new custom SAML application (not OIDC/OAuth).
- When asked for the service provider's details, give it Kepla-EHS's Entity ID and ACS URL (from step 1) and set the Name ID format to Email, with the Name ID value mapped to the user's email address.
- Your identity provider will now show (or let you download) its own IdP metadata — either a single XML file/URL, or separately an SSO URL, Entity ID, and signing certificate.
- Back in Kepla-EHS's SSO Settings, paste that metadata into IdP metadata XML (preferred — it doesn't depend on your identity provider's website being reachable every time someone signs in) or, if you'd rather Kepla-EHS fetch it live, put the link in IdP metadata URL instead.
- Turn on Enable "Sign in with SSO" (SAML 2.0) and click Save Settings. (SP private key/certificate are optional — only needed if your identity provider specifically requires Kepla-EHS to sign its sign-in requests.)
- See Testing your connection below before telling anyone to use it.
- In the Google Admin console (admin.google.com — this is different from the Cloud Console used for OIDC above): Apps → Web and mobile apps → Add app → Add custom SAML app.
- Name it "Kepla-EHS" and click through — Google now shows you its SSO URL, Entity ID, and Certificate (also downloadable as a single metadata XML file). Copy the metadata XML into Kepla-EHS's IdP metadata XML field.
- On the next screen ("Service provider details"), enter Kepla-EHS's ACS URL and Entity ID (both shown at the top of Kepla-EHS's SSO Settings screen), set Name ID format to EMAIL, and Name ID to Basic Information > Primary email.
-
Optional but recommended: under Attribute mapping, map Google's First name and Last
name fields to app attributes literally named
first_nameandlast_name— Kepla-EHS looks for those exact names to fill in a new user's name automatically. - Turn the app ON for the organizational unit or group you want to allow (e.g. everyone, or just a specific department) — Google apps are off by default for all users until you explicitly turn them on.
- Save Kepla-EHS's SSO Settings with SAML enabled, and test.
Testing your connection
Before announcing SSO to anyone: sign out of Kepla-EHS, load the sign-in page in a private/incognito window, and confirm the SSO button appears with the label you expect. Click it, sign in with a test account, and confirm you land back on Kepla-EHS's home page. Then check Roles & Permissions to confirm that account ended up with the access you intended.
Common problems while setting up:
- "redirect_uri_mismatch" (OIDC) — the callback URL saved in your identity provider doesn't exactly match the one Kepla-EHS's SSO Settings screen shows (including
https://and the trailing slash). Copy it again and compare character-for-character. - "invalid_client" or "unauthorized_client" (OIDC) — Client ID or Client secret was mistyped, or the secret shown in Kepla-EHS is stale because it was regenerated on the identity provider's side after you saved it here.
- Certificate/signature errors (SAML) — usually means the pasted metadata is out of date, most often because the identity provider rotated its signing certificate. Re-copy the current metadata and save again.
- "Single sign-on failed. If you believe you should have access, contact your administrator." right after signing in at the identity provider — the sign-in itself succeeded, but Kepla-EHS couldn't match or create an account for that person (see below).
Bringing someone on before they have SSO access
Turning SSO on for your organization doesn't take away Kepla-EHS's own username/password (plus 2FA/passkey) sign-in for existing accounts — the two exist side by side by default, and even if your organization turns on Require SSO for all users, individually-exempted accounts keep working the regular way. This means you have a built-in way to get a contingent, temporary, or newly-hired worker into Kepla-EHS before they've been issued a company identity — a contractor who hasn't been added to Google Workspace yet, for example — without waiting on that approval:
- Go to Security Administration → Create User and fill in a username, their email address, name, and a temporary password. Their email matters: use whatever address they'll eventually be issued by your identity provider, if you already know it — see the note below on why. Leave Exempt from SSO requirement checked (the default) so this account keeps working even if your organization later turns on Require SSO for all users — and set Exempt for how many days to roughly how long you expect the wait to be. If it runs out before they're actually onboarded, granting more time from their account page is a one-step action; see Requiring SSO for everyone for why exemptions always expire.
- Pick a Role and a scope (all facilities, one facility, or one department) right there on the same Create User screen, or leave Role blank and assign one afterward under Roles & Permissions — exactly as you would for any other new user.
- Give them the username and temporary password through whatever secure channel your organization already uses. When they sign in for the first time, they'll go through Kepla-EHS's own first-time setup — if your organization requires 2FA or a passkey company-wide, they'll be walked through setting that up immediately, same as anyone else. That satisfies your MFA requirement for them without needing SSO at all.
- If they also need an HR-style record (for Employee Health, exams, etc., not just login access), create that separately under Employees — it's not required just to sign in.
21. Glossary of Terms
- Passkey
- A secure sign-in credential tied to your device (fingerprint, face, PIN, or security key) that replaces typing a password.
- 2FA / TOTP
- Two-Factor Authentication using a time-based, 6-digit code from an authenticator app, as a second proof of identity beyond your password.
- SSO (Single Sign-On)
- Signing in to Kepla-EHS using the login your organization already provides for its other work tools, instead of a separate Kepla-EHS password.
- OIDC / SAML
- The two technical standards Kepla-EHS supports for SSO — OpenID Connect (OIDC) is the newer, more common one; SAML 2.0 is older but still required by some organizations' IT policies. Which one (or both) your organization uses is configured under SSO Settings.
- Identity provider (IdP)
- The outside service (e.g. Okta, Microsoft Entra ID, Google Workspace) that verifies your identity when you sign in with SSO.
- Role
- A named bundle of module permissions (View/Edit) that gets assigned to users.
- Facility / Department scoping
- The rule that limits which records a user can see, based on the site(s)/department(s) their role assignment covers.
- Saved View
- A reusable, named filter/column/sort combination for browsing or reporting on a type of data.
- Finding
- A logged problem or observation that needs follow-up, whether entered by hand or generated automatically by another module.
- Action
- A specific assigned task with a due date, usually attached to a Finding.
- OSHA Recordable
- A U.S. workplace injury/illness classification that legally must appear on the annual OSHA 300 log; Kepla-EHS determines this automatically from the case details you enter.
- SEG
- Similar Exposure Group — employees and/or jobs grouped together because they share a similar exposure to a hazard.
- Industrial Hygiene (IH)
- The discipline of measuring and controlling workplace exposures (noise, chemicals, dust) to protect worker health.
- Exposure limit
- The maximum safe level of exposure to a substance or hazard, used to judge whether a sample result is acceptable.
- NIOSH Lifting Equation
- A standard formula used in Ergonomic Assessments to score the injury risk of a manual lifting task.
- KPI
- Key Performance Indicator — a number tracked over time against a target, to judge whether a program is succeeding.
22. Troubleshooting & FAQ
I signed in but I don't see any modules.
You haven't been assigned a Role yet, or your assigned role has no modules granted. Ask your administrator to set this up under Roles & Permissions.
I was signed out unexpectedly.
Kepla-EHS automatically signs everyone out after 20 minutes of inactivity, for data security. Just sign back in.
I forgot my password.
Kepla-EHS does not currently offer a self-service "forgot password" email link. Contact your organization's Security Administrator, who can reset it for you from Security Administration.
My account says I'm locked out.
This happens automatically after 5 failed sign-in attempts. Wait about an hour, or ask your Security Administrator to unlock it immediately.
I lost my phone / authenticator app / security key.
Use "Request a Passkey Reset" on the sign-in page, or contact your Security Administrator directly — they'll need to approve a reset before you can register a new one.
I don't see a "Sign in with SSO" button.
Your organization hasn't turned SSO on, or you're on a screen without it. Sign in with your Kepla-EHS username and password (and passkey/2FA if you've set one up) instead, or ask your administrator whether SSO should be available to you.
I clicked "Sign in with SSO" but got sent back with an error.
This usually means either your organization's identity provider doesn't yet have a Kepla-EHS account matching your email address, or the connection between Kepla-EHS and your identity provider needs attention. Contact your Security Administrator — they can check the SSO Settings screen or, if needed, turn on automatic account creation for SSO sign-ins.
I can see a module but can't add or edit anything in it.
Your role likely has View-only access to that module. Ask an administrator to grant Edit access if you need it, under Roles & Permissions.
A coworker at another site can see records I can't, or vice versa.
This is expected — visibility is scoped by facility/department per user, not shared company-wide by default. Speak to your administrator if you believe your assigned scope is incorrect.
How do I get a paper or PDF copy of this manual?
Click the Print / Save as PDF button at the top of this page, then choose "Save as PDF" as the destination in your browser's print dialog.