What a Contractor Compliance Dashboard Needs to Show
A contractor compliance dashboard has to answer four questions at a glance: who is on site now, what expires this month, what is blocking a start, and what has been rejected and why. Totals are the trap. A headline saying most of your contractors are current tells you nothing about the handful who are not, or which of those is booked on site on Thursday. The exceptions are the dashboard.
I run product at ComplyFlow, which means I spend a lot of my week watching people use a compliance dashboard in the two minutes they have before a meeting. It is the single most opened page we build, and the easiest one to get wrong, because the wrong version looks better in a screenshot than the right one.
What Changed in April 2022.
On 21 April 2022 we shipped a rebuild of the contractor Dashboard. Alerts became Requirements. A badge went at the top of the page showing the total number of outstanding requirements. The filters moved into a side panel, with visual tags that appear as you apply them and can be closed to drop a filter. The icons were redrawn, and a toggle was added so dismissed alerts could be brought back into view.
That was four years ago, and the page has moved on since. The current behaviour is documented in the Help Centre guide to the Requirements Dashboard, which is the description to trust rather than this announcement.1
What has not changed is the question underneath it, which is the rest of this post.
The Four Things a Dashboard Has to Answer.
A contractor compliance dashboard earns its place by answering four questions without a click. Everything else is a report.
Who Is on Site Right Now.
An approvals record tells you who was cleared. It does not tell you who walked through the gate 20 minutes ago, and those are different facts on any live site. In ComplyFlow this is the Live Access Dashboard, which shows real-time site access activity including personnel movements and access status, and is granted to a staff user through the Site Access Monitor permission.2 If your system cannot answer this one, the rest of the dashboard is a filing cabinet with a chart on the front. Our site access page covers the gate side of it.
What Expires This Month.
Expiry is the failure mode nobody causes. A licence, an insurance certificate, or a ticket simply reaches its date, and a workforce that was ready on Friday is short on Monday without a single mistake being made. The Requirements Dashboard filters include Expired and Expiring Soon for exactly this reason.1 The useful version of this tile is not a count. It is a list, ordered by date, with the name of the person or company beside each one.
What Is Blocking a Start.
A start date is the only deadline on a compliance dashboard that costs money when it slips. Blocking is also not one state. A requirement nobody has uploaded needs a phone call to the contractor; a requirement already sitting with a reviewer needs a phone call to the reviewer. ComplyFlow distinguishes these: a requirement raised by a client either goes for review by ComplyFlow, goes for review by the client, or uploads straight through.1 A dashboard that shows both as ‘outstanding’ has thrown away the difference that decides who you ring.
What Was Rejected, and Why.
A rejection with no reason attached produces a phone call, an email, and a resubmission of the same document. Put the reason on the row. The contractor reading it should be able to fix the problem without asking anyone what the problem was, and that single design decision removes more admin than any amount of automation elsewhere.
Why a Total Is the Wrong Number.
Picture the tile most dashboards open with: 412 contractors, 96% current. It is a true number, and a useless one.
Nobody has ever done anything with it. The work sits entirely in the fraction it averages away: the 17 records that are not current, which of those 17 belongs to a company booked on site on Thursday, and which one is an insurance certificate rather than a toolbox talk. A percentage is a fact about the population. The job is a fact about the exceptions.
The test I use on our own screens is simple. If a number on the page cannot change what somebody does in the next hour, it is a report, and it belongs on a reporting page where somebody can sit down with it. A dashboard is for the exceptions, sorted so the most expensive one is at the top.
Four People, One Set of Data, Four Screens.
The same contractor compliance data has at least four readers, and they want different things from it.
A safety manager wants the exceptions by risk: who is unqualified for the work they are booked to do. A gate supervisor wants one question answered in three seconds, at a gate, often on a phone. A procurement lead wants it by supplier, because their unit of work is a company and a contract, not a person. A CFO wants the exposure: which obligations are unevidenced, and on which sites.
Build one screen for all four and you get a screen that is nearly right for nobody. ComplyFlow applies permissions either at organisation level or at site level, and site-level permissions are the recommended default; security defaults let a permission set for a role, such as a safety manager, be applied to a cohort of users rather than configured one person at a time.3 That is the mechanism, but the design point comes first: decide who the screen is for before you decide what goes on it. Our safety and WHS and procurement pages set out what each of those two actually needs.
What Has to Happen When It Turns Red.
A dashboard that shows a problem and does not start the chase is a report with colour in it.
Every red line needs three things: an owner, an action you can take from the row, and a way to hand it to the person who can actually clear it. In ComplyFlow, an administrator who wants a worker to fix their own requirement dismisses the alert, which hides it from the administrator’s dashboard while leaving it on the worker’s, and the dismissed items can be toggled back into view.1 That is a handover, not a disappearance, and the distinction is the whole design.
Judge a dashboard on what happens after the red appears. Everything before that is decoration.
Score the Next Demo Against the Four Questions.
If you are specifying one, write the four questions above at the top of the requirements document and score every vendor demo against them. Most demos will show you a chart first; ask to see the exception list instead, then ask what happens when you click a row.
If you are building the workflow behind it, our workforce compliance page covers how the records are kept current, and our post on setting up a contractor portal covers the adoption problem, which is the part that decides whether any of this gets used. Or book a demo and open the exception list with us.
Sources
Written by
John McCannHead of Product, ComplyFlow
John has led ComplyFlow’s product since 2021, including its AI document review, its AI agents, and its MCP server. He writes about what AI can and cannot be trusted to do in safety and compliance work, from building it.
Writes about: AI in compliance, Product and integrations, Data and reporting
Questions
Questions People Ask About This.
What should a contractor compliance dashboard show?
Four things, each worth a tile: who is on site right now, what expires in the next month, what is blocking a start date, and what has been rejected and why. Anything that cannot change what somebody does today belongs in a report rather than on the dashboard.
Why is a headline compliance percentage not enough?
Because it averages away the only records that need work. A percentage tells you the shape of the whole population; the job in front of you is the handful of exceptions inside it, and which of those is due on site this week. A dashboard that shows the average and hides the exceptions has inverted its own purpose.
What changed in the ComplyFlow contractor dashboard in April 2022?
Alerts were renamed Requirements, a badge was added at the top of the page showing the total number of outstanding requirements, filters moved into a side panel with visual tags you can close to remove a filter, the icons were redrawn, and a toggle was added to show or hide dismissed alerts. That was four years ago, and the Help Centre carries the current description.
Should everyone see the same dashboard?
No. A safety manager, a gate supervisor, a procurement lead, and a CFO want four different screens off the same data. ComplyFlow applies permissions at organisation level or at site level, and security defaults let a permission set for a role be applied to a cohort of users rather than configured one by one.
What happens in ComplyFlow when a contractor requirement is rejected or unmet?
The requirement stays on the dashboard until it is completed. An administrator who wants a worker to fix their own requirement can dismiss the alert, which hides it from the administrator's dashboard while leaving it on the worker's, and a toggle brings dismissed items back into view.
See it against your own contractors, sites, and rules.
Book a 30-minute demo. We will show ComplyFlow working with your kind of sites, your kind of contractors, and your requirements. No slides, no hard sell.
- ISO 27001
- Hosted on AWS
- Microsoft & Okta SSO
- API & MCP
- Data in Australia
Compliance you can prove, instantly.