Food safety on a recipe
Control points inside the steps, and the storage and handling block — what renders on the line and what a manager must sign.
Food safety lives in two different places in a recipe, and the difference is not cosmetic: one is a step a cook must hit, the other is how the product is kept.
Control points, inside the steps
Each step can be marked:
- No control point — the default
- CCP — food safety — a critical control point
- QCP — quality spec — a quality control point
Set the requirement and its target, e.g. Cook to internal temperature at 165°F. Temperatures are entered in °F.
CCP and QCP are not interchangeable
They render the same way but mean different things, and only a CCP pulls in a manager:
| CCP | QCP | |
|---|---|---|
| what it protects | someone’s safety | your standard |
| example | cook to 165°F, hold below 41°F | sauce nappe, 12 pieces per portion |
| manager sign-off | required | not required |
Mark it CCP only when getting it wrong could make someone ill. Marking a quality spec as a CCP is not “extra safe” — it trains your managers to PIN through a keypad several times a shift, and a sign-off that happens reflexively is worth nothing when it matters. Under-marking is dangerous; over-marking is how you get there.
What a cook sees
A control point renders inside its step as a bordered red panel — the words ⚠ CRITICAL CONTROL POINT, the requirement, and the number very large. See What each view shows.
It appears in Heart of House only. A server does not hold the pan.
What it triggers
A recipe with a CCP changes how acknowledgment works: instead of a tap, the line gets a keypad, and a named manager’s PIN is required. See Acknowledging a recipe.
⚠ Add a manager PIN to every location before publishing a CCP recipe. A location with no PINs cannot sign one off at all.
The food safety block
Below the procedure, a block of optional fields — and its own note is the important part: “empty fields don’t render”. An unfilled field costs a cook nothing; it simply does not appear.
| field | what it is for |
|---|---|
| Storage location | where it lives — walk-in, low boy |
| Shelf life (hours) | how long it is good for |
| Storage temp min / max (°F) | the range it must be held in |
| Hot hold ≥ (°F) | service holding, hot |
| Cold hold ≤ (°F) | service holding, cold |
| Reheat to ≥ (°F) | the reheat target |
| Labeling spec | what goes on the label — day-dot + name + use-by |
| Cooling requirements | the cooling curve, e.g. 135→70°F within 2 hrs; 70→41°F within 4 hrs |
| Allergen handling | handling beyond the allergen list — dedicated fryer; glove change before plating |
Fill these for anything held, cooled or reheated
A dish that is cooked and sent needs a CCP on the step. A prep that is made Monday and used Thursday needs this block, because the risk is in what happens between those days, and nothing in the procedure covers it.
Shelf life and labeling spec together are what let a manager walk a walk-in and tell what should be thrown out — which is a routine task Tavorly can either support or be useless for, depending on whether these two fields are filled.
Allergen handling is not the allergen list
Allergens themselves roll up automatically from ingredients. This field is for the handling — shared fryers, glove changes, separate boards. Rolled-up allergens tell a server what is in the dish; this tells a cook how not to put something in it by accident. See The ingredient catalog.
What Tavorly does not do
Tavorly records and distributes your specs and proves they were read. It is not a HACCP plan, a temperature log, or a monitoring system — it does not take readings, alarm on excursions, or store a log of measured temperatures. It carries the spec a cook works to and the attestation that a manager signed it.
Your food-safety plan remains yours. This is how you get it in front of the people executing it, correct and current.
Last checked against the product on August 18, 2026.