Safety Planning and Means Restriction: The Stanley-Brown Protocol
The risk assessment is done. Maria's client sits across from her, passive ideation named out loud for the first time, risk level assigned, session running eleven minutes over. What happens in the next twenty minutes, the co-creation of a Stanley-Brown Safety Planning Intervention and a direct conversation about the medications in the bathroom cabinet, is the part of suicide care with some of the strongest evidence behind it, and it is also the part most often documented as a single line: "safety plan completed." This lesson teaches the workflow for co-creating a Stanley-Brown safety plan in session, using AI to produce the clean typed version afterward, and verifying that every step on the typed page is the client's, not the AI's. It covers lethal-means counseling and how to document it so the chart shows the conversation actually happened. By the end you will have a Typed Stanley-Brown Plan workflow: the six steps in the order the client produced them, a transcription prompt that forbids invention, and a means-restriction documentation block that holds up under review.
What a Safety Plan Is, and What It Replaced
The Stanley-Brown Safety Planning Intervention (SPI), developed by Barbara Stanley and Gregory Brown, is a brief, collaborative intervention in which the clinician and client build a prioritized, written list of coping strategies and sources of support the client can use before or during a suicidal crisis. It replaced the no-suicide contract, the old practice of asking a client to promise not to hurt themselves, which the field abandoned because a promise extracted in an office has no protective force at 2 AM, and because "client contracted for safety" in a chart reads to a reviewer as the clinician outsourcing safety to the client's word. The safety plan works differently: it assumes the crisis will come, and it pre-builds the client's response to it, step by step, in the client's own language, while the client is regulated enough to think.
The controlling analogy for this lesson: a safety plan is a fire escape map drawn by the person who lives in the building. A fire marshal can require that a map exist, can check that it covers every exit, can insist it be posted where it can be found in smoke. But the map only works if the person who will use it drew the route themselves, knows which door sticks, which neighbor is home during the day, which stairwell they would actually take in the dark. A generic evacuation diagram taped to the wall of a stranger's building saves no one. Hold that image through everything that follows, because it explains both why the client must author every step and why AI's role is confined to making the map legible, never to drawing the route.
The evidence base matters for your documentation posture. Safety planning-type interventions have been associated with reductions in suicidal behavior and improvements in treatment engagement in the research literature, which is why the SPI sits inside the Zero Suicide framework's intervention step and why a completed, documented safety plan is among the first things a reviewer looks for after an elevated-risk assessment. The intervention is brief, typically twenty to forty-five minutes, and it is a clinical intervention, not a form. The distinction will carry the whole lesson: the plan is something you do with the client, and the document is the record of what you did.
The Six Steps, In the Order the Client Produced Them
The Stanley-Brown SPI has six steps, and the order is part of the intervention: each step is tried before escalating to the next. Step one: warning signs, the thoughts, images, moods, situations, and behaviors that tell this client a crisis is building. Not "feeling sad," but the client's actual signature: "when I start re-reading his texts," "when I skip dinner and pour the third drink," "when the apartment starts feeling like a place I'm only visiting." Step two: internal coping strategies, things the client can do alone to take their mind off the crisis without contacting anyone: the specific playlist, the shower, the walk to the reservoir, the lifting routine. Step three: people and social settings that provide distraction, not disclosure: the sister who talks about her kids, the coffee shop with the chess players, the Wednesday pickup game. The client is not telling these people about the crisis; their presence is the intervention. Step four: people the client can ask for help, named, with phone numbers, people the client would actually call and actually tell. Step five: professionals and agencies to contact during a crisis: the clinician's number and after-hours protocol, the 988 Suicide and Crisis Lifeline, the nearest emergency department by name and address. Step six: means restriction, making the environment safer, which gets its own section of this lesson because it gets its own scrutiny.
The clinical craft is in the eliciting. A safety plan built by the clinician suggesting items and the client nodding is the stranger's evacuation diagram. The questions sound like: "Walk me back through last Tuesday. What was the first sign, looking back, that the night was going bad?" "Who is someone you could be around, not to talk about this, just to not be alone?" "If you called your sister at midnight, what would you actually say?" Each elicited item gets tested in session: is it specific, is it feasible at 2 AM, would you actually do it? An item the client would not actually use gets replaced now, in the office, not discovered as useless during the crisis.
And here is the documentation principle that AI workflows most often violate: the typed plan must preserve the steps in the order the client produced them, in the client's wording. If the client's third internal coping strategy was "watch the fish tank," the typed plan says "watch the fish tank," not "engage in calming visual activities." The client's language is the route they drew; the paraphrase is the stranger's diagram. When the crisis comes, the plan has to sound like the person reading it.
Every step on a safety plan must be the client's, elicited in session and written in the client's words. AI may type the plan; it may never populate it. A safety plan with even one AI-invented step is a fire escape route through a wall that does not have a door.
Lethal-Means Counseling: The Conversation and Its Documentation
Step six, means restriction, is where safety planning intersects with the strongest practical lever in suicide prevention: time and distance between a person in crisis and the methods they would use. Suicidal crises are often short; method substitution is far from automatic; and reducing access to highly lethal means, firearms above all, changes outcomes. Lethal-means counseling is the collaborative conversation in which the clinician and client (and often a family member) make a concrete plan to reduce access during the period of elevated risk. It is not confiscation, and it is not a lecture. It is problem-solving: who holds the firearm, where, transferred how, for how long, with what trigger for return; where the medications go, who fills the weekly pill organizer, whether the stockpile gets disposed of through a pharmacy take-back.
The conversation starts from the means inquiry you documented in the risk assessment lesson: firearms in the home, medication supplies, any method the client has considered. For firearms, the gold standard is storage away from the home during the risk period, with a named third party, a licensed dealer where state law supports it, or at minimum locked storage with the ammunition separate and the key or combination held by someone else. Know your state's transfer rules before you counsel; several states have specific provisions for temporary firearm transfers in exactly this situation, and getting the logistics wrong stalls the plan. For medications, the working numbers are smaller supplies and slower access: a 7-day supply dispensed where the prescriber will cooperate, the rest held by a family member, the leftover opioids from the 2023 surgery out of the house entirely.
Now the documentation, because this is the conversation most often had and least often charted. The means-restriction block in your note records five things: what means were identified (from the direct inquiry); what specific restriction plan was agreed (who, what, where, by when); who else was involved or will be involved (the brother taking the firearm, the spouse holding the medications, with the client's consent to that contact documented); the client's stated commitment and any ambivalence, recorded as ambivalence; and the follow-up check, the date you will ask whether the transfer actually happened. That last element is the one reviewers almost never find and always want: a plan to move the firearm that is never verified is a documented intention, not a documented intervention. The next session's note says, in one line, "Client confirms firearm transferred to brother's residence 4/12; medications in weekly organizer held by spouse." Now the chart shows the loop closed.
Where AI Enters: After the Session, Below the Judgment
State the boundary for this chapter again, because it governs here with full force: AI does not assess risk, AI does not score anything, AI does not decide. And in this lesson, one more clause: AI does not write safety plan steps. Not as suggestions, not as a starter template the client edits, not as "examples to discuss." The entire mechanism of the SPI is that the client generates the content; a plan seeded with model-generated coping strategies is a different intervention, an unvalidated one, wearing the validated one's name. The temptation is real because the output looks plausible: ask any model for "five internal coping strategies for a suicidal crisis" and you will get five reasonable-sounding items. Reasonable-sounding is the problem. The client who did not produce "go for a run" will not run at 2 AM, and the chart will say a Stanley-Brown intervention occurred when something weaker did.
So where does AI legitimately enter? After the session, in the transcription seat. The in-session artifact is usually handwritten, on the printed SPI form or a notepad, in two people's handwriting, with arrows and cross-outs from the testing process. The client needs a clean, legible, typed copy: one for their phone, one for the fridge, one for the chart. AI converts the clinician's notes or dictation of the handwritten plan into the typed version, preserving step order and the client's exact wording, and formatting it onto the practice's SPI layout with the crisis numbers (988, the local ED, the after-hours line) verified by the clinician. The prompt that does this safely reads, in substance: "You are a transcriptionist. Below is a Stanley-Brown safety plan co-created in session, dictated by me from the handwritten original. Produce a clean typed version. Preserve the six-step structure, the order of items within each step, and the client's exact wording. Do not add, remove, reword, generalize, or improve any item. If any step appears empty or unclear in my dictation, mark it INCOMPLETE for me to resolve; do not fill it."
The second legitimate AI seat is the documentation of the intervention in the progress note: formatting the clinician's shorthand about the safety-planning session, which steps were completed, what the means-restriction agreement was, who was involved, into the note structure, exactly as the previous lesson's formatter prompt does for risk assessment. The third seat is logistics: drafting the client-facing instruction sheet ("keep one copy in your phone notes, one at home; we will review and update this plan at every session while risk is elevated"), which contains no clinical content the clinician did not specify. Three seats, all downstream of the session, all below the judgment line.
The Verification Pass: Proving Every Step Is the Client's
Here is the discipline that separates a defensible AI-assisted safety-planning workflow from a liability: the verification pass, done by the clinician, against the handwritten original, before the typed plan goes anywhere. Lay the in-session artifact next to the AI's typed output and check four things, item by item. One: completeness, every handwritten item appears, none dropped. Models truncate lists; a dropped item in step four is a missing name the client chose, which is a missing rung on the ladder. Two: fidelity, every item in the client's wording, no paraphrase drift. "Watch the fish tank" must not have become "engage in relaxing activities"; "call Denise, not Mom" must not have become "contact family members," which in this client's case inverts the instruction. Three: order, items within each step in the sequence the client produced them, because the client prioritized as they generated, and the order encodes which strategy comes first. Four: no additions, nothing on the typed page that is not on the handwritten page. This is the check most clinicians skip because additions feel unlikely, and it is the check that matters most, because a model given a five-item pattern will sometimes helpfully complete it to six, and that sixth item is an AI-authored clinical intervention sitting in your chart with your signature implying you and the client built it.
Then verify the fixed content separately: the 988 Suicide and Crisis Lifeline number, your practice's after-hours protocol, the emergency department's current name and address. Models mangle phone numbers with total confidence, and a safety plan with a wrong crisis number is worse than no plan, because it spends the client's one moment of reaching out on a dead end. Dial-test the numbers on the plan once; it takes ninety seconds.
The verification pass ends with the client. The typed plan goes back to the client for review, ideally at the next contact: "Read this back to me. Is this still your plan? Is every item still something you would actually do?" That review is itself an intervention, a rehearsal, and it gets one line in the chart: "Typed safety plan reviewed with client 4/15; client confirms accuracy; copy to client phone and chart." Now the record shows a co-created plan, a faithful transcription, and a client who has the map in hand and recognizes the route as their own.
Documenting the Safety-Planning Session in the Chart
The progress note for the safety-planning session has its own skeleton, and it must do more than attach the plan. Section one: the clinical context, linking back to the risk assessment ("following risk assessment of 4/8, risk level moderate, clinician-assigned, safety planning intervention initiated as documented in the disposition"). Section two: the intervention itself, named ("Stanley-Brown Safety Planning Intervention co-created in session, approximately 35 minutes"), with each of the six steps noted as completed and any step the client struggled with described clinically, because the struggle is data ("client initially unable to identify any step-four contact; with exploration, named older sister Denise; client's difficulty identifying support figures noted as treatment target"). Section three: the means-restriction block from earlier in this lesson, with the five elements: means identified, specific plan, third parties and consent, client's stated commitment with ambivalence recorded as ambivalence, and the scheduled verification. Section four: the logistics, where the plan lives (client's phone, fridge, chart), the review cadence (every session while risk remains elevated), and any family member who received a copy with consent. Section five: the clinician's brief assessment of the client's engagement with the process, in observational language: did the client generate items readily, did affect shift during the work, did the client rehearse a step aloud.
Two phrasing disciplines. First, never write "safety plan completed" as the whole entry; that is the three-clause risk note's sibling, and it documents a form, not an intervention. Second, never let the note imply the client is now safe. The safety plan manages risk; it does not extinguish it. The note's closing posture is monitoring: "risk remains moderate; safety plan in place; re-assessment at every session per monitoring plan." The plan is one instrument in the disposition the clinician already assigned, and the documentation should keep that hierarchy visible: assessment first, clinician's risk level, disposition, and the safety plan as an intervention inside that disposition, never a substitute for it.
For pre-licensed clinicians, the supervision line runs through this note too. Carmen can co-create a safety plan with her client; her supervisor should see the plan and the note, and the chart should show that review where the practice's escalation policy requires it. A supervisor who has never looked at how an associate's safety plans are built, or whether an AI tool is quietly seeding them, is supervising the signature and not the work.
The Failure Modes That Reach a Reviewer's Desk
It is worth naming the specific ways this workflow goes wrong, because each one has a distinct fingerprint in the chart. Failure one: the template plan. The chart contains a safety plan whose steps could belong to anyone, "deep breathing, call a friend, go to the ER," with no client-specific content. A reviewer reads it as the form filled out, the intervention not performed. The fix is upstream, in the eliciting; no prompt repairs a plan that was never the client's. Failure two: the AI-seeded plan. The steps are specific but uniform across the practice's charts, the telltale of clinicians asking a model to generate "personalized" coping strategies. Specificity without authorship is camouflage, and chart-to-chart comparison strips it. Failure three: the orphaned plan. A beautiful safety plan, never referenced again, no review at subsequent sessions, no update when the client's circumstances changed, no verification that the firearm transfer happened. The orphaned plan tells a reviewer that the practice treats safety planning as a one-time documentation event, exactly what Zero Suicide exists to prevent. Failure four: the unsigned route, a typed plan that went to the client without the verification pass, carrying a paraphrased step, a dropped name, or a wrong crisis number. This is the failure unique to AI-assisted workflows, and it is fully preventable by the four-check pass against the handwritten original.
Notice that none of these failures is caused by AI, and only one is even enabled by it. The chart-level discipline, client-authored content, means restriction verified, the plan revisited until risk steps down, is the same discipline the intervention has always required. AI changes one thing: the typed plan now arrives fast and clean, which removes the last logistical excuse for the client leaving without a legible copy. Used inside the boundary, AI makes the validated intervention easier to deliver with fidelity. Used outside it, AI quietly replaces the intervention with its costume.
The Applied Problem: The Typed Stanley-Brown Plan, Verified
Your artifact is the Typed Stanley-Brown Plan workflow: the transcription prompt, a completed typed plan produced from a realistic handwritten original, and the means-restriction documentation block, assembled as a set you can run the day a safety-planning session ends. Build it in three steps.
Step one: stage the input. Write out a realistic handwritten-plan dictation, as if reading your in-session notes aloud: "Step one, warning signs: re-reading his texts; skipping dinner, third drink; apartment feels like visiting. Step two, internal coping: fish tank; shower; reservoir walk; lifting. Step three, people and places for distraction: coffee shop chess tables; Wednesday pickup game; sister Denise around her kids. Step four, people to ask for help: Denise 510-555-0142; sponsor Mark 510-555-0177. Step five, professionals: my number and after-hours line; 988; Highland ED, 1411 E 31st St. Step six, means: brother takes the handgun Saturday; meds to weekly organizer, spouse holds the rest." Run the transcription prompt from this lesson against it, with its non-negotiable clauses: preserve order and exact wording, add nothing, reword nothing, mark unclear steps INCOMPLETE.
Step two: run the four-check verification pass on the output, completeness, fidelity, order, no additions, then verify the fixed content: dial-test 988 formatting, confirm the ED name and address, confirm your after-hours line. Deliberately corrupt one test run, tell the model step two had only two items and see whether it pads the list, so you have seen with your own eyes what silent completion looks like before it ever touches a real client's plan.
Step three: write the means-restriction documentation block as a reusable template with the five elements: means identified; specific restriction plan (who, what, where, by when); third parties involved and the client's documented consent to that contact; client's stated commitment with ambivalence recorded as ambivalence; and the scheduled verification date with a blank line for the follow-up confirmation. "Done" looks like this: a typed plan that matches the handwritten original line for line in the client's own words, a transcription prompt you trust because you have watched it refuse to invent, and a means-restriction block that will show a reviewer, in five labeled moves, that the conversation happened, the plan was specific, and the loop was closed.
Key Takeaways
- The Stanley-Brown Safety Planning Intervention is a brief, collaborative clinical intervention, not a form: a prioritized, written crisis response built with the client while they are regulated, which replaced the abandoned no-suicide contract. The document is the record of the intervention, never a substitute for it.
- The six steps run in escalating order: warning signs, internal coping strategies, people and social settings for distraction, people to ask for help, professionals and agencies including 988 and the local ED, and means restriction. The typed plan must preserve the steps in the order the client produced them, in the client's exact wording, because the order encodes priority and the language is what the client will recognize in crisis.
- Every step is the client's, elicited and tested in session. AI never writes, suggests, seeds, or completes safety plan steps; a plan with model-generated content is an unvalidated intervention wearing the validated one's name. AI's legitimate seats are all downstream: transcribing the handwritten plan, formatting the clinician's documentation, and drafting logistics text.
- Lethal-means counseling is collaborative problem-solving about time and distance from method: firearm storage away from the home or locked with ammunition separate and the key held by another, smaller medication supplies with the remainder held by a family member. Document five elements: means identified, the specific plan, third parties with the client's consent, commitment with ambivalence recorded as ambivalence, and the scheduled verification, then close the loop in the chart when the transfer is confirmed.
- The verification pass is the clinician's: typed output against handwritten original, checking completeness, fidelity to the client's wording, order, and above all no additions, then dial-testing the crisis numbers, because models drop items, paraphrase, helpfully complete lists, and mangle phone numbers with total confidence. The plan then goes back to the client for review, which is itself a rehearsal and gets one line in the chart.
- The session note documents the intervention, not the form: context linking to the clinician-assigned risk level, the six steps with clinical observations about the client's process, the means-restriction block, plan logistics and review cadence, and a closing posture of monitoring, never an implication that the client is now safe.
- Your artifact is the Typed Stanley-Brown Plan workflow: a transcription prompt that preserves order and wording and refuses to invent, a verified typed plan produced from a realistic original, and a reusable five-element means-restriction documentation block with the verification line that closes the loop.
Skill.re