Intervention requires an always-available means of stopping
Aliases: stop intervention · human override · protective stop control
What it is
An always-available intervention control lets an authorised person prevent further consequence at any execution stage. It may be protective stop, software cancel, enabling device, or remote abort, but must match risk and remain reachable when the main interface, focus, or network fails.
Why it happens
Autonomy reduces opportunities to affect action, and intervention loses value near irreversibility. Controls buried in menus or dependent on application state add search and confirmation time that becomes extra travel. Stable independent controls reduce selection steps and bypass some common software failures.
Studying it
Across task phases, posture, workload, and interface faults, detection, reach, activation, physical stop, error, and stopping distance can be measured. Command issue and cessation are distinct. Gloves, one-handed use, disconnection, and multi-person sites matter. Hazardous trials need limited energy or simulation.
Where it stops holding
Universal stop access does not imply universal reset or control authority. De-energising can drop a payload, so each stop needs a defined safe reaction. Preventing accidental activation should not hide the control.
Applying it
- Provide a stable stop from every plausible position and interface, independent of nominal workflow.
- Define effects on drive, brake, load, and communication, distinguishing cancel, protective stop, and emergency stop.
- Fault-inject and measure total time and distance to physical safety, including backups and authority.