Skip to content

Chemical Safety Assistant

A Thai-language web application that retrieves chemical safety information from the Safety Data Sheets held by one automotive parts manufacturing plant, for the safety officers, supervisors, store officers and workers who handle chemicals there. It works with no network connection.

This file is a glossary and nothing else — no implementation detail, no decisions. Decisions live in docs/adr/. Every term used in a research note, ADR, spec or ticket must appear here.

Language

The content split

Safety-Critical Content: Any information that can change what a person wears, touches, or does in an emergency — hazards, PPE, spill response, first aid, storage. It is always Extractive. Avoid: safety info, safety data (ambiguous with Safety Data Sheet)

Conversational Content: Everything the app says that is not Safety-Critical Content — navigation help, term definitions, question rephrasing. It may be generated by a model. Avoid: chat content, non-critical content

Chrome: Whatever the app supplies to name, frame or match content — field labels, route names, the emergency bar's wording, the terms Routing matches against without ever showing them, a layout's furniture, a neutral surface colour. It is always authored, never generated, and it never restates what a document says. Where chrome is something the app says it is also Conversational Content; where it is a colour or a term matched against but never shown, it is not. Chrome may never be model-generated, whatever the rest of that category may be (D-146). Avoid: UI text, boilerplate, labels, copy

Appbar: The Chrome bar directly under the Escalation strip, carrying a surface's title, a back control where there is somewhere to go back to, and the Corpus freshness indicator (D-156). It is never where Escalation lives. Avoid: header, toolbar, top bar, title bar

Navigation Bar: The persistent Chrome bar at the foot of every Handler surface, carrying only destinations that need no Chemical Record — Home, Search, Recently viewed, Settings (D-157). A surface of a record is never in it, and no part of it uses the alarm colour. Avoid: tab bar, menu, bottom tabs, footer

Design Token: A named value the design extract binds and every surface spends: colour, spacing, surface treatment, card, border and radius (D-142), and type scale and motion (D-158, D-159). A surface names a token, never a raw value, and a source sweep fails a build that names one. Avoid: variable, theme value, style constant

Extractive: Displayed verbatim from a Source Span, with its origin visible to the user. The opposite of paraphrased. Avoid: quoted, retrieved, grounded

Extractive Summarisation: Choosing which Source Spans matter and laying them out as labelled fields, without altering their words. This is the only summarisation the product performs on Safety-Critical Content. Avoid: summarisation (unqualified), AI summary, digest

Source Span: The specific passage of a specific SDS Section that a piece of Safety-Critical Content is taken from. Travels with the content wherever it is displayed. Avoid: citation, reference, excerpt

Not Stated: The app's answer when an SDS was consulted, the question fell inside a field the Chemical Record curates, and that field holds no Source Spans at all — so the document is silent. A field that holds spans is never Not Stated, whatever the retrieval score: it is shown. A statement about a supplier's document, and a correct outcome rather than a failure. It is never the answer when nothing was consulted — see Not In Corpus, Outside The Record and Corpus Unavailable, which are the other three reasons the app cannot answer. Avoid: no result, unknown, not found, no data

Not In Corpus: The app's answer when the Corpus holds no Chemical Record for what the user identified. Nothing was consulted, so nothing can be reported silent. The user's next step is a binder, not the app. Avoid: not found, unknown chemical, unsupported, no match

Outside The Record: The app's answer when a Chemical Record exists but the question falls outside the fields it curates. The SDS is held and reachable; it simply was not curated for that. Distinct from Not Stated, which claims the document itself is silent. Avoid: out of scope, not covered, unsupported field

Corpus Unavailable: The app's answer when the device holds no verifiably complete Corpus, so no document was consulted at all. A statement about the device, where Not Stated is a statement about a document. The two are never rendered as the same answer, and there is no state between them: a Corpus either verifies or is absent. Avoid: not found, offline, empty, no data, partial corpus

The data

SDS: Safety Data Sheet — the supplier-issued document that is the sole authority for Safety-Critical Content. The Corpus holds the copies The Plant itself keeps on file. Always abbreviated, never spelled out in the interface. Avoid: MSDS, datasheet, safety sheet

SDS Section: One of the sixteen numbered sections the GHS format obliges every SDS to carry. Sections are referred to by number and name: Section 4 First-aid measures, Section 8 Exposure controls / personal protection. Avoid: chapter, part, heading

Section Heading: The name of one of the sixteen SDS Sections, held as a fixed Thai and English pair per number. A constant of the GHS format rather than content taken from any document, so it is neither curated per document nor translated at runtime. Handler-facing surfaces show the Thai string and the Curator's surfaces the English one (D-133); a Section reaches a device as its number and its name rather than as one rendered string (D-149). The English is fixed by GHS Annex 4; the source of the Thai strings is not yet cited by any artifact here (ADR-0075). Avoid: section title, section name, label

Corpus: The complete curated set of SDS documents the product can answer from, sourced from The Plant's own holdings. A chemical outside the Corpus has no answer. Avoid: database, library, catalogue

Published Version: One publish of the whole Corpus: a version string, the moment it was published, the documents it covered, and the payload the gate checked and devices received. Every past version stays readable from its own payload rather than from today's rows, so what a version shipped cannot change after it shipped (D-167). Exactly one Published Version is the one devices pull. Avoid: release, build, snapshot version, corpus version

The Plant: The single automotive parts manufacturing site this prototype is built for. Supplier of the Corpus and home of the users interviewed. Generalising to other sites means swapping the Corpus, not changing the product. Avoid: the factory, the customer, the client

Study Area: The one production area inside The Plant whose chemicals the Corpus is sized to cover, and where the needs study runs: the area that uses น้ำยาล้างชิ้นงาน, the proof chemical. Coverage inside it is complete; a chemical outside it has no answer and says so. The Corpus is sized by this area rather than by a document count. Avoid: department, zone, site, line, scope

Curation: The human act of admitting an SDS to the Corpus — selecting it, recording its Provenance, verifying its extracted text against the rendered page, choosing which Source Spans a Chemical Record shows, performing Reconciliation, and reviewing its Curated Translation where one is needed. Every irreversible judgement in this product happens here. Avoid: ingestion, import, onboarding

Reconciliation: The human act of resolving a Restriction found elsewhere in a document against a Source Span about to be shown — deciding whether it applies, and attaching a caveat if it does. Happens at Curation, never at display. Avoid: conflict resolution, cross-referencing

Reconciliation Gap: One pairing of a Restriction with a selected Source Span in the same document that no Reconciliation has yet resolved. Pairwise: a Restriction judged against one span is still a gap against every other span it bears on. A document with no gaps may equally be one fully judged, one holding no Restriction, or one nothing has been selected from. Avoid: unresolved restriction, outstanding conflict, pending reconciliation

Restriction: A span expressing exclusion, incompatibility, prohibition or negation, anywhere in an SDS. Scope for Reconciliation is the whole document, not one SDS Section. Avoid: warning, caveat, limitation

Stored Copy: The file of an SDS as The Plant holds it, kept at admission and read from for every page a curator verifies and every Source Span taken from it. A Chemical Record, a Source Span and a published snapshot can each depend on one, so it is kept for as long as the Corpus is. Avoid: upload, file, attachment, document blob

Provenance: The origin record kept for every document in the Corpus: supplier, revision date, and how the copy was obtained from The Plant. Avoid: metadata, source info

Curated Translation: A Thai rendering of a Source Span, produced and reviewed by a person at Curation time and stored as a Corpus artifact. Distinct from runtime translation, which the product does not do. Avoid: translation (unqualified), localisation

Curated Explanation: A plain-language explanation of one term, written and reviewed by a person at Curation and stored as a Corpus artifact. Displayed verbatim like any other curated text; never composed at the moment it is read. Distinct from a Curated Translation, which renders a Source Span rather than defines a word. Avoid: definition, tooltip, gloss, generated explanation

Curated Escalation: The text directing a user out of the app to real help — call hotline 1669, evacuate, seek medical attention — written and reviewed by a named person at Curation and shipped with the app shell, so it is present whenever the app is and does not go with an evicted Corpus. Until a site authority signs it, it is the hotline alone, which asserts nothing about The Plant and needs no signature. Safety-Critical Content, displayed verbatim with its origin visible, where that origin is site procedure or Thai emergency services rather than an SDS Section. The set of acts it may carry is closed: it never carries a hazard, PPE, storage or first-aid-step claim, which still require a Source Span. Avoid: emergency text, disclaimer, boilerplate, generic escalation

Chemical Record: The structured view of one SDS — identity, hazards, health effects, PPE, storage, first aid, spill response. Identified by product name, supplier and revision date; one SDS makes one record, so two revisions of a product are two records. Avoid: chemical entry, substance record, product

Formulated Product: A chemical sold as a blend under a trade name — a cleaner, degreaser, coolant, adhesive or coating. Has a supplier and no CAS Number, and is the common case on a production floor. Avoid: mixture, compound, formulation

Pure Substance: A single-component chemical, which therefore carries a CAS Number. The exception on a production floor, not the rule. Avoid: chemical, reagent

CAS Number: The CAS Registry Number, the globally unique identifier for a Pure Substance. An optional attribute of a Chemical Record, never its key — a Formulated Product has none. Preferred target of Identification when the label shows one. Avoid: chemical ID, registry number

Routing Threshold: The confidence floor below which Routing declines to single out a Source Span, showing the curated field whole instead. It does not decide whether an answer is given: a field that holds spans is always shown. Fixed by a person at Curation and stored as a Corpus artifact, never tuned at runtime. Avoid: confidence score, cutoff, relevance score

Escalation Trigger: A curated Thai and English phrase list that fires Escalation in the browser before any network call is made. A Corpus artifact, not a model judgement. It is an accelerator, never a path: Escalation is reachable from every surface without it, so a phrase it does not match costs a tap rather than the call. Avoid: keyword, urgency detection, emergency classifier, emergency router

Routing Fixture: The curated set of questions, each paired with one exact expected outcome — a named Source Span, the chooser, or Not Stated — that Routing is verified against. A Corpus artifact. Avoid: eval set, benchmark, test data

Who uses it

Safety Officer: The statutory Thai workplace safety role, จป. Has legal duties around chemical management, and the most demanding information needs of the four roles. Avoid: safety manager, HSE officer, jor por

Supervisor: หัวหน้างาน — the person accountable for a production area and the people working in it. Sits between the Safety Officer's statutory duties and the Handler's point-of-use needs. Avoid: line manager, foreman, team lead

Store Officer: The person responsible for the chemical store — receiving, labelling, storage conditions and stock. Reads storage guidance more than emergency guidance. Avoid: warehouse staff, storekeeper

Handler: Any worker who uses chemicals in the production process. The largest group, and the one at the point of exposure. Avoid: operator, user, employee

Curator: The person who performs Curation. Not one of the four roles above: those are the people the product answers, and the Curator is the person who decides what it may answer with. Their surfaces are a separate internal tool, reachable only where nothing is served, and every irreversible judgement in the product is theirs. One named Curator stands behind each Reconciliation and each Curated Explanation, Translation and Escalation. Avoid: admin, editor, author, reviewer (unqualified), curator workbench

Verification: The Curator's recorded judgement that one page's extracted text matches the page as rendered. A document is verified whole before anything is selected from it, and a span carries one page's verified text. One record per page, and it is not withdrawn. Avoid: validation, proofing, QA, check

Using the product

Identification: Determining which Chemical Record the user means, by any of three peer routes: reading a QR label The Plant has applied, reading the printed container label by camera (CAS Number first, then product name), or manual search. No route is a fallback of another. Avoid: scanning, lookup, detection

PPE: Personal Protective Equipment, recommended per chemical and per item with a stated reason where the SDS supports it — "nitrile gloves" rather than "gloves". Some SDS name no material; that absence is displayed, never filled in. Avoid: protective gear, safety equipment

Spill Response: The set of branches for a release of a specific chemical, each branch an ordered procedure selected by a condition the SDS itself states — commonly spill volume. Order within a branch is semantic. A branch is never chosen on the user's behalf. Avoid: leak handling, incident response, cleanup

First Aid: Immediate care guidance for exposure, structured by exposure route — eye, skin, inhalation, ingestion — following SDS Section 4. Avoid: medical advice, treatment

Escalation: Directing the user out of the app to real help — calling hotline 1669, evacuating, seeking medical attention. One tap from every surface; precedes the procedure in Spill Response, and runs alongside it in First Aid. Avoid: emergency contact, help

Standing Statement: The app-authored sentence that the product retrieves SDS information and does not replace the SDS, site procedure or trained judgment. It carries no Source Span because it makes no claim about any document. Stated on First Run and present on every safety surface. Avoid: disclaimer, terms, legal notice, about text

First Run: The first use of the app on a device, judged by that device's own stored record of having been told. A device whose record cannot be read is on its First Run. Avoid: onboarding, welcome, first launch, install

Anonymous Use: Full use of every safety capability with no account. The default mode, and the only mode any safety capability may require. Avoid: guest mode, unauthenticated

Routing: The Conversational surface resolving a question to Source Spans — one singled out within its curated field, or that field shown whole — to the chooser, or to one of the no-answer states. It decides where to point and never composes Safety-Critical Content, so its output carries the same Source Span it would have carried anywhere else. Avoid: answering, RAG, lookup, semantic search

Query Intent: The structured reading of a question — product name, target SDS Section, exposure route — that Routing obtains from a cloud model when a connection exists, and does without when there is none. The only thing that crosses the network; no Corpus content ever does. Advisory: its terms are added to the user's own and never substituted for them, so a product name it supplies competes with what the user typed rather than replacing it, and still reaches the chooser rather than a record. Avoid: prompt, embedding, context, query expansion, resolved query

Routing Floor: The client-side retrieval over the Corpus held on the device, which Routing always runs and which needs no connection. Query Intent improves what is fed to it; nothing replaces it. Avoid: fallback, cache, offline mode, degraded mode