An extra deliberate step, like a cover or a dual action, separates a real command from an accidental brush
Aliases: intent-discriminating safeguards · hazardous energy control
What it is
An intent-discriminating safeguard inserts an extra but identifiable step into an operating path — a cover, a latch, a dual action, a key, or a controlled sequence — so that a deliberate operation and an inadvertent one (a collision, a slip, a mistouch) follow different action paths and can be told apart. The idea resembles a forcing function — using physical or procedural structure to force a prerequisite to be met first — but the key point is that not every "one more step" actually blocks an error; whether it does depends on exactly which error mechanism that step targets.
Why it happens
A genuinely effective extra step must match the error mechanism it is meant to intercept: a physical barrier (a cover, a guard) stops pure physical contact errors like a body or tool bumping something; requiring a distinctive, uncommon action (pressing two widely separated buttons simultaneously) targets "adjacent misselection" — a finger landing in the wrong place that is still on some operable control; a sequence check (A must complete before B can trigger) targets "acting before a prerequisite is met." If the extra step is merely clicking "OK" a second time, it introduces no evidence independent of the first click — it only adds time, and once an operator becomes familiar with the interface, the repeated click gets absorbed into an automated action sequence, becoming just as unthinking as the first click. Protection actually decreases as familiarity increases.
Where it stops holding
Adding a step has costs: it lengthens the time needed exactly in the emergency scenarios where speed matters most, it compounds the difficulty of fine motor action already present in gloved work, and it can pose a real obstacle for operators with limited physical capability. A mechanical device also wears, jams, or gets propped open by field staff for convenience — a guard that looks intact but no longer protects is more dangerous than no guard at all, because it manufactures false confidence. An intent-discriminating safeguard solves an intent-recognition problem; it does not substitute for a safety interlock, which blocks a hazardous state regardless of intent — the two have different failure modes and different scopes of application.
Applying it
First classify exactly which error the safeguard is meant to prevent — inadvertent contact, wrong object, wrong sequence, or unauthorized action — before choosing a device type that matches that mechanism, rather than defaulting reflexively to "add a confirmation dialog."
- The reset path must preserve the same intent-discrimination, so removing the safeguard does not immediately allow the exact hazardous action it was meant to prevent.
- How to check: separately measure time to complete the full sequence when acting deliberately, the rate of unintended activation, wear after extended use, and whether field instances exist of the device being propped open to bypass it. Treat the emergency-scenario response time budget as its own verification metric, not an afterthought.
Related
- Same group: Y4.04.2 Consequence-matched safeguard strength · Y4.04.3 Verifiable safeguard state
- Nearby: Y3.05 Inadvertent-operation protection · Y4.07 Emergency reach and inadvertent-activation protection
- Search terms:
Intent-discriminating safeguards·hazardous energy control·safety-critical work