The post-stop state must be safe and unambiguous
Aliases: post-stop state · stop confirmation · safe halted state
What it is
A safe post-intervention state no longer amplifies hazard, controls payload and stored energy, and shows whether the task is cancelled, motion has physically ceased, energy remains, and recovery is required. An on-screen “stopped” label is not a mechanical guarantee.
Why it happens
Stop commands traverse communication, controller, drive, and brake with possible delay or failure. Power removal can release gravity or pneumatic loads; braking retains stored energy. If display reflects command rather than execution, people approach before cessation. Confirmation needs independently measurable physical conditions.
Studying it
Across speed, load, slope, and faults, record command, drive response, zero velocity, brake lock, load stability, and display timing. Human trials test approach and residual-energy understanding. Frozen feedback and desynchronised display matter.
Where it stops holding
Safe states differ: a base brakes, a suspended load may lower, and medical support may need continuity. Clarity means role-relevant action information, not every parameter. Automatic restart usually undermines state certainty.
Applying it
- Define terminal drive, brake, load, tool, and stored-energy conditions with independent confirmation.
- Distinguish command received, braking, physical stop, and safe approach.
- Measure the full stop chain at maximum load and under single faults, verifying entry only after true safety.