Y3.03.2Redundant coding beyond colordesign

A critical state must stay identifiable by shape, text, or sound even if color disappears entirely

Aliases: redundant coding beyond color · control-room interface

What it is

Color must never be the only code: critical state has to remain identifiable through at least one of text, shape, icon, position, or sound even when color is completely unavailable. This is redundant coding — a genuinely independent basis for judgment, not the same information decorated twice.

Why it happens

Single-channel color coding fails for more reasons than color-vision deficiency alone. Color is a perceptual channel that degrades under many ordinary conditions: strong ambient glare, grayscale printing or photocopies, and aging or low-quality panels all compress the discriminable range. Even someone with fully typical color vision has far weaker color discrimination in peripheral vision than at fixation — a small icon that relies only on hue, once it falls near the edge of an operator's field of view, has already lost most of its coding value, independent of any color-vision deficiency; this is simply a property of normal peripheral vision. A second channel earns its value precisely when the color channel fails for any of these reasons, because the information can still be recovered through a fully independent path. But redundancy is not free: if the two channels disagree semantically — color implying one severity, text or icon implying another — the operator now has to spend an extra step deciding which channel to trust, a Stroop-like coding conflict introduced at exactly the moment fast judgment matters most. Adding a second channel is not sufficient on its own; the state granularity and direction conveyed by both channels must agree, or the redundant code performs worse than no redundancy at all.

Where it stops holding

Not every ordinary datum needs multichannel coding — applying the redundancy principle uniformly inflates interface density fast enough that the few states that genuinely need redundancy get buried under a field of icons; redundancy should be allocated by consequence, not spread evenly. Dynamic coding (flashing) introduces its own boundary conditions: flash rates must avoid ranges that can trigger photosensitive reactions, and audio-only coding fails outright for hearing-impaired operators or on a noisy plant floor, where sound itself needs a visual backstop.

Applying it

First check whether the state granularity carried by each channel actually agrees — a common failure is text that only says "abnormal" while color distinguishes several severity levels, in which case the text is not providing real redundancy, only a coarser repeat of the same signal. Pair alarms, control authority, interlock state, and irreversible actions with at least one cue that is independent of color and interpretable on its own, and specify explicitly that this cue's granularity must match the color channel. How to check: test recognition accuracy under grayscale display, strong glare, and color-vision-deficiency simulation filters, and include operators with actual color-vision deficiency; separately verify semantic agreement between channels for every state, not just whether a non-color cue exists at all.

Related

  • Same group: Y3.03.1 Sector-defined safety color semantics · Y3.03.3 Safety semantics over brand color
  • Nearby: Y3.12 Low-saturation principle for high-performance graphics · Y8.08 Lighting, glare, and night shifts
  • Search terms: redundant coding · color vision deficiency · Stroop-like coding conflict

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Y3.03.2