Writing A Strong TB Laboratory Access Policy For PC3
A tuberculosis laboratory operating at biosafety level 3 needs an access policy that is clear enough for daily use and robust enough for an external assessment. In Australia, this setting is commonly described as physical containment level 3, or PC3. The policy should control who enters, what they are authorised to do, how access is recorded, and what happens when arrangements change.
A useful document does more than state that entry is restricted. It connects facility access with risk assessment, staff competency, respiratory protection, incident management, equipment security, and continual improvement. The GLI Quality Tool approach is particularly helpful because it supports laboratories working through different stages of quality management, including those with limited staffing or regional constraints.
Define The Policy’s Purpose And Scope
Begin by explaining why the policy exists. A TB laboratory policy for biosafety level 3 facility access control should protect workers, patients, visitors, contractors, specimens, and the wider community from exposure or unauthorised handling of Mycobacterium tuberculosis. It should apply to every person who may enter the controlled area, whether they are a scientist, cleaner, engineer, courier, auditor, student, or senior manager.
State which rooms and activities are covered. The scope may include the specimen receipt area, processing rooms, culture or susceptibility testing rooms, autoclave areas, storage spaces, air-handling plant access, and any associated change rooms. If a room is outside the PC3 boundary but still presents a security or contamination risk, identify it as well.
Use plain language and define local terms. Australian staff may refer to the facility as “the PC3,” while a policy may need to distinguish the containment level from a particular laboratory suite. Refer to applicable organisational procedures, state or territory public health requirements, and relevant Australian Standards, including AS/NZS 2243.3 where applicable. The policy should direct users to the current controlled documents rather than reproducing technical requirements that may change.
Use A Risk-Based Authorisation Model
Access should be based on the work a person is approved to perform, not simply their job title. A senior employee may need access to review records but not to handle infectious cultures. A maintenance contractor may enter only under escort and only for a defined task. A visiting microbiologist from Melbourne or Perth should receive the same objective assessment as a local staff member.
Create access categories that are easy to understand. For example, authorised operators may work independently; supervised personnel may enter only with an approved trainer; escorted visitors may enter for a short, documented purpose; and emergency responders may enter under a specific emergency arrangement. The policy should state who approves each category and what evidence is required before access is granted.
Consider the hazards associated with each activity. Opening primary specimens, manipulating cultures, operating a biological safety cabinet, transporting infectious material, and entering plant areas do not carry identical risks. Link the authorisation level to training, competency assessment, health and safety requirements, and the person’s current duties. This avoids the common problem of access remaining active after a staff member changes roles.
Assign Clear Responsibilities
The laboratory director or facility manager should own the policy and ensure that resources, staffing, and security arrangements support it. A PC3 facility manager, biosafety officer, or delegated senior scientist can administer day-to-day access decisions, but the policy must make accountability visible. Avoid vague wording such as “management approval” when a named role can be specified.
Human resources, security, information technology, occupational health, and facilities teams may each control part of the process. The policy should explain how their records connect. For instance, a termination notice from HR should trigger immediate review of swipe-card access, keys, alarm permissions, laboratory information system accounts, and shared passwords.
Supervisors should confirm that personnel are trained, medically advised where required, competent for assigned procedures, and fit to work in the area. Staff should report lost cards, suspected tailgating, damaged doors, alarm faults, and unexpected visitors promptly. In a smaller regional service, one person may hold several roles, so the policy should include an independent review or second-person check for high-risk approvals.
Entry Controls At A Glance
Describe the physical and administrative controls in operational terms. A person should be identifiable, authorised for the relevant zone, and able to demonstrate a legitimate reason for entry. Access devices must not be lent to another person, doors must not be propped open, and unknown individuals should be challenged in a professional manner and reported if they cannot establish their authority.
The policy should explain the entry sequence, including personal protective equipment, hand hygiene, checking alarms or signage, and any required buddy arrangements. It should also cover exit steps such as decontamination, removal of protective clothing, handwashing, and reporting spills or exposure concerns. The details must match the facility’s validated procedures rather than relying on generic instructions.
Controls to specify
- Named approval before independent access
- Photo identification and individual access credentials
- Visitor escort, sign-in, and time-limited permission
- Immediate reporting of lost cards, faults, or suspicious entry
Records to retain
- Current access authorisation and expiry date
- Training and competency evidence
- Visitor, contractor, and maintenance logs
- Door, alarm, incident, and access review records
A swipe-card system is useful, but it is not a complete control. A laboratory in Sydney may have sophisticated electronic monitoring, while a remote service may rely on keys, a sign-in register, and a local security contact. The policy should define the minimum outcome and explain compensating controls where electronic systems are unavailable, including regular reconciliation by an authorised manager.
Manage Visitors, Contractors, And Emergencies
Visitors should be approved before arrival wherever practicable. Record their name, organisation, purpose, host, entry and exit times, areas visited, and any briefing provided. A contractor working on ventilation, refrigeration, alarms, or waste systems may require additional controls because their task can affect containment. The host should remain responsible for the visitor’s conduct while inside the controlled area.
Include arrangements for deliveries and specimen movement. Couriers should not enter the PC3 suite unless there is a documented need. External engineers must know which work can be performed without entering containment and what decontamination or escort arrangements apply. In Australia, state or territory laboratory networks may move specimens between metropolitan centres and regional hospitals, so the policy should distinguish transport-chain controls from facility entry controls.
Emergency access requires careful wording. Fire, medical, security, power, ventilation, or flood events may require rapid entry by people who are not routine PC3 users. List the emergency contact numbers, isolation points, escort expectations where feasible, and post-event reporting requirements. After an emergency, reconcile all entrants, assess exposure or contamination, secure cultures and records, and suspend access if the facility’s containment status is uncertain.
Connect Access With Training And Records
Training should be completed before unsupervised access begins and refreshed at defined intervals. Cover TB hazards, containment principles, entry and exit procedures, PPE, biological safety cabinets, waste, spills, exposure response, security expectations, and reporting lines. A short induction alone is not enough for work involving cultures or high-consequence procedures.
Competency evidence should be specific to the person’s duties. Observe practical behaviours, review documentation, and record the assessor, date, result, and any restrictions. The laboratory can use phase-specific quality checklists to examine whether access control, personnel records, equipment, documentation, and assessment activities are being implemented consistently.
Keep access records controlled and retrievable. The register should show who approved access, the authorised zones, start and review dates, supervision requirements, training status, and suspension or removal decisions. Protect personal information and restrict records to people with a legitimate need to know. Document retention periods should align with organisational policy, accreditation expectations, and applicable Australian privacy obligations.
Handle Suspensions, Incidents, And Corrective Action
The policy should state when access is suspended. Examples include expired competency, a failed respiratory protection fit check where one is required, illness or fitness concerns, a security breach, repeated procedural non-conformance, lost credentials, or a serious incident. Suspension should be proportionate and prompt, with a clear process for reinstatement after the concern has been addressed.
Every access incident needs a documented response. Preserve relevant access logs, interview involved people, assess whether infectious material or confidential information was exposed, and notify the responsible biosafety and management roles. Avoid treating an event as a personal failure before examining system causes such as unclear signage, unreliable door controls, rushed shift handovers, or incomplete contractor induction.
Corrective action should have an owner, due date, effectiveness check, and evidence of closure. If a failed proficiency test reveals weaknesses in supervision, specimen handling, or competency records, the laboratory can use this corrective action guidance to structure the response. Access may need to remain restricted until corrective actions are verified, rather than being restored automatically when retraining is scheduled.
Review The Policy And Keep It Current
Set a formal review interval, such as annually, and trigger an earlier review after a facility alteration, new test method, serious incident, audit finding, security change, or change in legislation or organisational responsibility. A move, refurbishment, ventilation upgrade, or new laboratory information system can alter access risks even when the microbiology work remains the same.
Use evidence from internal audits, access-log reviews, incident reports, visitor records, training completion, and staff feedback. The user instructions can help teams apply the GLI Quality Tool consistently and understand how to use its practical materials within a broader quality management system.
The final approved version should have an owner, version number, approval date, review date, and change history. Withdraw obsolete printed copies and ensure the current policy is available where staff need it. In a busy Australian laboratory, a concise one-page entry summary beside the access point can support the full controlled document without replacing it.
A well-written policy turns PC3 entry from an informal habit into a controlled, auditable process. Review the current facility arrangements against the policy, assign owners to any gaps, and record the corrective actions in the laboratory quality system. Use the GLI Quality Tool materials to support implementation, then brief every authorised person so the policy is applied consistently from the next shift onward.