X4.02.2Safe post-intervention statedesignresearch

The post-stop state must be safe and unambiguous

Aliases: post-stop state · stop confirmation · safe halted state

What it is

A safe post-intervention state no longer amplifies hazard, controls payload and stored energy, and shows whether the task is cancelled, motion has physically ceased, energy remains, and recovery is required. An on-screen “stopped” label is not a mechanical guarantee.

Why it happens

Stop commands traverse communication, controller, drive, and brake with possible delay or failure. Power removal can release gravity or pneumatic loads; braking retains stored energy. If display reflects command rather than execution, people approach before cessation. Confirmation needs independently measurable physical conditions.

Studying it

Across speed, load, slope, and faults, record command, drive response, zero velocity, brake lock, load stability, and display timing. Human trials test approach and residual-energy understanding. Frozen feedback and desynchronised display matter.

Where it stops holding

Safe states differ: a base brakes, a suspended load may lower, and medical support may need continuity. Clarity means role-relevant action information, not every parameter. Automatic restart usually undermines state certainty.

Applying it

  • Define terminal drive, brake, load, tool, and stored-energy conditions with independent confirmation.
  • Distinguish command received, braking, physical stop, and safe approach.
  • Measure the full stop chain at maximum load and under single faults, verifying entry only after true safety.

Related

  • Same group: X4.02.1 Intervention requires an always-available means of stopping · X4.02.3 The intervention window must be long enough
  • Adjacent: X5.03 Emergency stop · X4.06 Explicit transfer of control authority
  • Search terms: post-stop state · safe state · stop confirmation

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/X4.02.2