THIS EXPLANATION
THE ROOM
ENG·34 Engineering & Technology 7 MIN · 8 STATIONS

Non-bypassable safety interlocks

A Socratic walk-through of non-bypassable safety interlocks — reasoned out one step at a time, not lectured.

abcdefgh
a

The question we started with

THE QUESTION #

Why does a machine that refuses every override protect its operators better than one that trusts them?

A press will not close while its guard is open. Fine. But why does a well-designed machine also refuse the experienced operator who says, truthfully, I know what I am doing and I need it to run just this once?

The refusal looks like an insult to competence, and often it is felt as one. It is also the design choice that safety engineering keeps arriving at, and not because designers think operators are fools. There is a specific reason a machine that cannot be talked round protects people better than one that can, and it is worth reasoning out rather than asserting.

b

Reasoning it through

REASONING #

Start with the case for the override. The operator is skilled, the situation is unusual, the machine's rule is a blunt approximation, and a person with judgement can see when the rule does not apply. That argument is not silly. So why does it fail?

Ask what the operator is actually being asked to decide, and when. It is the middle of a shift, a jam has stopped the line, the supervisor is asking when it will run again, and clearing the jam properly means a full lockout that takes twenty minutes. The choice is not "safety versus recklessness". It is "a certain, immediate, visible cost against a small probability of an injury that has not happened the last hundred times".

Now notice what those hundred times have done to the judgement. Every successful bypass is evidence — weak, but real-feeling — that the bypass is safe. The risk did not go away; it simply did not land. So the operator's estimate drifts downward with each repetition, precisely because nothing bad happened. Does the judgement being applied here get better with experience, or worse?

There is a second force, and it is the one people underweight. If the override exists, then declining to use it becomes a decision the operator has to defend. The supervisor can ask why. The colleague on the next shift did it. The person who insists on twenty minutes of lockout is now the person slowing the line. The existence of the option creates a pressure that would not otherwise exist — which means the override does not merely permit unsafe operation, it manufactures the demand for it.

Now the move that answers the question. What happens if the option is genuinely removed — not discouraged, not logged, not password-protected, but absent? The pressure has nowhere to land. Nobody can ask the operator to bypass the guard, because the operator cannot. The argument ends before it starts, and it ends without the operator having to win it.

That is a commitment device: value obtained not from making a better choice, but from making a choice unavailable in advance, while you are calm and the pressure is hypothetical. The machine's designer, sitting at a desk with no supervisor and no stopped line, has better judgement about this trade-off than the same person would have at three in the morning with the line down — so the design binds the later self to the earlier one's decision. And crucially, it binds everyone's later self at once, which is what removes the social cost of refusing.

Then the honest complication, which the standards themselves confront. If the constraint is painful enough, people defeat it — taping a spare actuator to the guard switch, wedging a magnet against the sensor. ISO 14119, the standard covering interlocking devices associated with guards, is explicit about this: it treats defeat in a reasonably foreseeable manner as a hazard to be designed against, and requires that the design also reduce the motivation to defeat. That second clause is the whole art. A commitment the user has strong reason to escape is not a strong commitment; it is a puzzle with a known solution.

Which sets the real design target. The interlock must be hard to defeat — coded actuators rather than generic ones, guard locking that holds until motion has stopped, monitored contacts that fail safe — and the safe path must be quick enough that nobody wants to. Remove the option and remove the reason for wanting it, in the same design.

c

The analogy

THE ANALOGY #
THE FIGURE

Odysseus had himself tied to the mast before the sirens, and ordered the crew's ears stopped so they could not hear him countermand it. Note what he did not do: he did not resolve to be strong-willed, and he did not leave himself a way to be untied on request. He knew that the version of himself who would be doing the asking was not the version who should be deciding, so he made the request unanswerable in advance.

WHERE IT BREAKS DOWN

Odysseus bound only himself, by his own choice, whereas a machine's interlock binds an operator who never consented and may be more competent than the designer — which is why an interlock earns its authority through the standards and the accident record behind it, and why designing one carelessly is a real imposition rather than a wise self-restraint.

d

Clarifying the model

THE MODEL #

The misconception to correct is that this is about distrusting operators. It is about acknowledging that judgement is made under conditions — time pressure, production targets, fatigue, normalised risk — and that the conditions, not the person, are what shift the decision. Trusting someone's competence and removing their option to gamble under duress are not in conflict.

Second refinement: the value of the interlock is not only that it blocks the unsafe action but that it removes the conversation. A constraint everyone knows is absolute dissolves the ordinary social pressure that would otherwise be applied to a person holding an option they would rather not use.

Third, a real limit: a commitment device can bind the wrong thing. An interlock that stops a machine in a state more dangerous than running it has committed the operator to the wrong action. Hence the rare, deliberately awkward controlled exceptions — an enabling device under a hold-to-run control — designed with the same care as the refusal. The rule is not "never permit motion with a guard open" but "never permit it on the operator's say-so alone".

e

A picture of it

THE PICTURE #
Non-bypassable safety interlocks
Non-bypassable safety interlocks Start at the rounded terminal and take the "no" branch from the first diamond, since that is the interesting case. The second diamond is where the whole argument sits: the left branch is a dead end by design and loops back through clearing the jam, which is the only route the machine offers. The right branch is not a feature -- it is the defeat path the standard requires you to engineer against, and it is the only way to the hazard. Notice the loop: the safe branch returns to the guard test, so the machine keeps asking the same question until the honest answer is yes. {"generator":"[email protected]","source":"../Socrates/.diagram-cache/_src/non-bypassable-safety-interlocks.md","sourceIndex":1,"sourceLine":4,"sourceHash":"d7bc24b3b28c748ec68d7973b308d74f7661aa400a6dec77619ed0bd8590b6e8","diagramType":"flowchart-v2","layoutVariant":"source","repairedDuplicateIds":[],"motion":"entrance-with-reduced-motion-fallback","presentation":"editorial","attempt":1,"viewBox":{"x":0,"y":0,"width":915,"height":951},"qa":{"passed":true,"findings":[]}} yes no by design, none only by defeating theswitch Operator starts a cycle Are all guards closed? Drive is energised Safety relay opens the drivecircuit Is there a way to override? Machine simply will not move Guard fooled with a spareactuator Clear the jam, close the guard Motion with a person in thedanger zone Cycle completes
KINDSsourcedecisionprocessoutcomeriskconnector

How to readStart at the rounded terminal and take the "no" branch from the first diamond, since that is the interesting case. The second diamond is where the whole argument sits: the left branch is a dead end by design and loops back through clearing the jam, which is the only route the machine offers. The right branch is not a feature — it is the defeat path the standard requires you to engineer against, and it is the only way to the hazard. Notice the loop: the safe branch returns to the guard test, so the machine keeps asking the same question until the honest answer is yes.

f

What became clearer

WHAT CLEARED #
WHAT CLEARED

The interlock's strength comes from being unarguable. By removing the option in advance, the designer takes the decision away from the moment when pressure, fatigue and a hundred uneventful bypasses would have distorted it — and, just as importantly, spares the operator from having to defend a refusal nobody can now demand.

g

Where to go next

ONWARD #
  • Guard locking versus simple interlocking, and when a guard must stay shut after the stop command.
  • How designers reduce the motivation to defeat rather than only the ability.
  • Enabling devices and hold-to-run controls — the deliberately awkward exceptions, and why they are shaped that way.
h

Key terms

TERMS #
TermWhat it means
Interlocka device that makes a machine's hazardous motion conditional on a guard being in place.
Commitment devicean arrangement made in advance that removes a future option, chosen because the future decision will be made under worse conditions.
Defeatcircumventing an interlock, typically with a spare actuator or magnet; ISO 14119 treats reasonably foreseeable defeat as a hazard to design against.
Guard lockingholding a guard shut until the machine has actually come to rest, rather than merely stopping it when the guard opens.

Every term the collection defines is gathered in the glossary.

Nearby on the shelf

4