Integrated Automation AHA (Activity Hazard Analysis / Job Hazard Analysis)

Updated 2026-06-23

An Integrated Automation AHA (Activity Hazard Analysis / Job Hazard Analysis) heads the integrated-automation division — the systems that tie a building's separate systems (HVAC, electrical, lighting, security, fire, and more) into one integrated automation and management layer that monitors and controls them centrally. It's the master integration on top of the individual control systems, and the detailed docs cover its facility controls and equipment control.

Why integrated automation needs its own AHA

Integrated automation sits above the individual building systems and commands them. Physically, installing it is light work — networks, servers, controllers, and integration hardware. The hazard, as with any direct-digital control but now at building scale, is what the integration commands: it can operate real equipment across many systems at once, from a central point, remotely. So commissioning and testing the integration can start fans, pumps, dampers, generators, and more — across HVAC, electrical, and other systems — from a workstation, with no one at the equipment expecting it. The integration multiplies the reach of the control that the BACnet and instrumentation docs describe, extending it across every system it ties together.

Three concerns anchor the division: installing the integration infrastructure, the control of physical equipment across systems, and the network and commissioning concerns.

Breaking integrated automation into steps

  • Confirm the integrated systems, architecture, and points from the submittal
  • Install the integration network, servers, and controllers
  • Integrate the individual building systems into the platform
  • Configure and program the integration and its sequences
  • Commission the integrated control, coordinating every equipment operation
  • Verify the integration across all systems and turn over

The hazards step by step

The control of physical equipment across systems

The defining hazard is that the integration commands real equipment across many systems, centrally and remotely. A technician commissioning an integrated sequence can start or stop fans, pumps, dampers, generators, and other equipment across HVAC, electrical, lighting, and beyond — from one workstation, out of sight of the equipment. So an integration test can put someone at risk on equipment floors away, in a system the tester isn't even thinking about, because the integration reaches across them all. So commissioning the integration is coordinated with the same rigor as any equipment start, scaled to the full breadth of systems it controls: the crew knows what every test will operate, across every integrated system, and clears people from all of it before the command goes in. The integration's cross-system reach is what makes this the central concern.

The network and cyber integrity

The integrated platform is networked — servers, controllers, and the individual systems all communicating — so it depends on a sound, secure network, and its integrity has physical consequences because the network commands physical equipment. The install builds that network properly, and the security of the integrated control system (covered in depth by the cybersecurity and risk-framework docs in this division) is a real concern precisely because a compromised or misconfigured integration can command equipment wrongly. So the network is built and secured as infrastructure that controls physical systems, not just as data plumbing.

The integration-system install

The physical install — mounting servers and controllers, running the integration network, and connecting to the individual systems — is low-hazard, comparable to any network and controls install: at height in the mechanical and electrical spaces, into panels that may share space with line voltage, with the ordinary access and energized-panel cautions. The risk isn't in the hardware install; it's in what the finished integration commands.

The multi-system coordination, code, and fundamentals

Coordination across all the integrated trades (HVAC, electrical, fire, security, and others), the applicable codes and standards, and the general controls fundamentals — energized-panel discipline and start coordination — apply throughout.

A simple Integrated Automation AHA structure

StepHazardControlStandard
Commission integrationCross-system equipment operationKnow what each test operates across systems; clear the fieldOSHA 1910.147
Build/secure networkCompromised control integritySound, secured network as physical-control infrastructurecyber/spec
Install servers/controllersFalls; energized panelsFall protection; treat panels as liveOSHA 1926.501
Integrate systemsMiscoordinationCoordinate across all integrated tradescommissioning plan
Turn overUncontrolled sequencesVerify integrated sequences with full coordinationcommissioning std.

Where the cross-system reach defines the division

Integrated automation concentrates its risk in one place: the breadth of what it commands. The install is trivial next to the fact that the finished system operates equipment across every building system it ties together, from a central point. So the plan is about the discipline around commissioning that integrated control — knowing and clearing everything a test can operate, across all systems — and about the network integrity that keeps the commands sound. The detailed docs build the facility controls and equipment control on this foundation.

From the field: what actually goes wrong

The signature incident mirrors the BACnet one but wider: a technician commissions an integrated sequence and starts equipment on a floor, or in a system, where someone is working — because the integration reaches across systems the tester wasn't focused on, and the field didn't know a test was coming. The breadth is the danger: the more systems the integration ties together, the more places an uncoordinated test can reach. The lessons: treat every integration test as a cross-system equipment operation, know exactly what it will operate across all systems, clear and confirm the field before commissioning any sequence, keep the field and the integrator in constant communication, and build the controlling network soundly and securely.

The bottom line

An Integrated Automation AHA heads a division whose physical hazard is small and whose command reach is the largest in the building — it operates equipment across every system it integrates, centrally and remotely. Install the network and servers safely, but put the discipline where the risk is: coordinate every integration test as a cross-system equipment operation with the field confirmed clear, and build and secure the controlling network as the physical-control infrastructure it is. The facility-controls, equipment-control, cybersecurity, and risk-framework docs build on this.

Frequently asked questions

What is integrated automation?

It's the layer that ties a building's separate systems together into one integrated automation and management system. Rather than HVAC controls, lighting controls, electrical monitoring, security, and fire systems each operating in isolation, integrated automation connects them onto a common platform (network, servers, and controllers) that monitors and controls them centrally, and lets them interact (for example, coordinating HVAC, lighting, and security by occupancy). This is Division 25 — the master integration on top of the individual control systems (like the HVAC DDC covered in Division 23). This AHA heads the division; the detailed docs cover the facility controls, the control of facility equipment, and the cybersecurity and risk framework that protect the integrated system.

Why is controlling physical equipment the main hazard?

Because integrated automation commands real building equipment — and now across many systems at once, from a central point, remotely. So when a technician commissions or tests an integrated sequence, actual equipment responds: fans, pumps, dampers, generators, and more can start or stop across HVAC, electrical, and other systems, and the technician issuing the command may be nowhere near any of it. That means a test can endanger someone working on equipment on another floor, in a system the tester isn't focused on, because the integration reaches across them all. So the breadth of control is the hazard — more systems integrated means more places a command can reach — and commissioning it requires knowing and clearing everything a test can operate, across every integrated system. The cross-system physical control is what makes this the central concern.

Isn't the hardware install low-risk?

Yes — installing the integration hardware (servers, controllers, and the network) is genuinely low-risk, comparable to any network and controls install: at-height access in mechanical and electrical spaces, and energized panels that require the usual live-panel caution, but nothing that concentrates serious injury. The risk lives almost entirely in what the finished, programmed integration commands — its ability to operate equipment across the building's systems. So, like the BACnet DDC doc, this plan spends little on the install and puts nearly all its attention on the command discipline around commissioning and on the network integrity that keeps those commands sound.

How does this relate to the HVAC controls and BACnet docs?

Those cover the control of a single system (HVAC) — the instrumentation, the devices, and the BACnet DDC that runs the HVAC. Integrated automation (Division 25) sits above them, tying HVAC together with the other building systems (electrical, lighting, security, fire) into one integrated platform. So it carries the same core hazard — commissioning that starts equipment under command — but extends it across all the integrated systems rather than just HVAC. In effect, it's the building-wide, cross-system version of the DDC concern. The detailed Division 25 docs (facility controls, equipment control, cybersecurity, risk framework) build out this integration layer.


Written by Mustafa Tok, CSP, ASP, CHST — OSHA Authorized Outreach Trainer with 14+ years of international construction safety experience across federal, heavy civil, and industrial projects.