In work planning, the document does not describe the safety controls, it creates them. A hazard written into the plan gets a control assigned to it. A hazard left out gets nothing, because nothing downstream goes looking for it. The same is true of qualifications: the plan is what triggers the check that the person doing the work is certified for it.
The quality checks in work planning depend almost entirely on a reviewer noticing something. We built a Work Planning and Control drafting tool in Legion Intelligence to see whether a reviewer's attention could be aimed better. What we found had less to do with how fast a draft comes together than with what the draft leaves out.
Why does drafting a Work Planning and Control document take so long?
Work Planning and Control (WPC) is how U.S. Department of Energy national laboratories plan, authorize, and safely carry out work, from routine maintenance to experimental operations. A WPC document defines the scope, prerequisites, procedures, hazards, and controls for a specific piece of work. Work can begin only when the required authorizations are in place and safety controls are implemented. Drafting one takes time because the guidance that governs the work lives in several places, and none of it is written for the specific job being planned.
WPC authors must consult Department of Energy (DOE) health and safety standards, Environment, Safety, and Health (ESH) manuals, and previously approved WPCs covering similar work. Each source contributes something, and each has to be interpreted against the actual conditions of the proposed activity. The finished plan has to address permitting, equipment, personal protective equipment, qualifications, stop-work conditions, roles, and acceptance criteria.
Any solution has to address three distinct challenges:
- Assembly. Distributed guidance has to become consistent sections that describe the actual work.
- Completeness. Somebody has to notice the hazard, control, or qualification nobody wrote down.
- Coordinated review. Each reviewer needs the right context and the right permissions, with a clear path back to revision.
Assembly is just the start. Ensuring completeness and coordinating expert review are harder. Here's how we approach each.
How does Legion assemble a draft?
Legion assembles a draft from a prompt describing the work, then builds the plan in stages rather than returning a finished document.
An author describes the activity. Legion draws on the available source collections, DOE standards, approved WPCs, and ESH manuals, and populates the work plan sections. It summarizes what it did and flags the decisions it made along the way. The author edits inline or asks for changes in conversation before moving forward.
That staging is deliberate. A single-shot document generator produces something that reads as finished, which invites the author to skim it. Building in stages, with the system reporting its own decisions, keeps the author in the position of assessing the content rather than receiving it.
How does Legion identify gaps, and why is gap analysis more important than speed?
Gap analysis matters more than drafting speed because AI does not fail loudly in safety documentation. It produces work that reads right and is likely missing something.
A language model will produce a hazard section that reads correctly, follows the house format, and is missing a control. Nothing about the output signals the omission. A human author working from a blank page knows what they have not gotten to yet. A human author reviewing a populated draft may not.
So Legion checks the draft against six categories (safety, compliance, operations, quality, completeness, and traceability) and gives the reviewer a ranked list of what is missing. The list is deliberately short. Forty observations get skimmed the same way a finished-looking draft does, so the value is in naming the few decisions that carry consequence.
The point is to aim expert judgment at the part of the document that needs it, not to replace it.
How does Legion keep review under human authority?
Review stays under human authority through role-based permissions and a staged approval chain that no agent moves on its own.
The designated subject matter expert edits the sections assigned to them. The rest of the document stays read-only. They can assess the prioritized gaps, review supporting images, and approve or reject. Approval advances the plan to a manager for a complete read-only review. Rejection returns it to the author for revision.
Final approval adds the plan to the approved WPC collection, where it becomes source material for the next one. The author can see approval status throughout.
What we have not measured yet
The tool is in beta, in final testing with 40+ users at a U.S. Department of Energy national laboratory, ahead of a wider launch.
Once we go live with the broader organization, we can gather metrics for overall draft-to-approval cycle times and how frequently system-identified gaps represent risks that human reviewers might otherwise have overlooked.
The part we expect to matter most over time is the smallest one: approved plans returning to the collection they were drafted from. A work plan is a record of decisions somebody already made and somebody already approved. In the document workflows we have seen, that record gets filed and never read again. Returning approved plans to the collection is what makes the next plan easier to write.
Work planning is one of several document-driven processes in laboratory environments where the review chain is the control. See how Legion supports science and research.



