Zhejiang Xinsenzheng Automation Co., Ltd.

Industrial Sensor Manufacturer OEM & Application Support Factory-direct Supply

Restart Interlock and Manual Reset: How to Prevent Unexpected Machine Restart

A restart interlock keeps hazardous operation inhibited after a safeguard or defined safety event is restored. A manual reset deliberately re-arms that safety function. Reset is not start: releasing an emergency stop, closing a guard, clearing a light curtain, restoring power or pressing reset must not by itself create hazardous motion.

Guarded industrial robot cell requiring controlled reset and restart logic
Restart behavior must be designed for the complete guarded cell, not just one button. Photo: Ludovic Delot / Pexels.

What is the difference between restart interlock, manual reset and machine start?

They answer three separate questions: should the hazard remain inhibited, may the safety function become ready again, and may production operation begin?

Restart interlock holds the inhibited state. Manual reset re-arms the safety function. A separate start command requests machine operation.

Closing a door or clearing a protective field restores an input condition; it does not prove the area is empty. A valid reset confirms that the defined reset conditions have been addressed, but reset itself must not launch hazardous motion.

Use this distinction when reviewing a functional specification, control narrative or supplier proposal.
Action or stateIntended functionWhat it does not proveBuyer or validator check
Safeguard restored
Input restored
The guard is closed, emergency-stop actuator is released or protective field is clear.That nobody remains inside, final elements are off or a restart is safe.Confirm that restoration alone leaves hazardous operation inhibited where the safety requirements demand restart interlock.
Restart interlock
State held
Prevents automatic return of hazardous operation after the defined safety event.Energy isolation, safe access for servicing or achievement of a required PL/SIL.Trace every event that should latch the stopped state, including mode and power changes.
Manual reset
Safety re-armed
Uses a deliberate action to allow the safety function to become ready when all required inputs and feedback are valid.A machine start, an empty danger zone or complete removal of stored energy.Test that reset cannot create hazardous motion and cannot be accepted from an unsafe location or state.
Normal start
Run requested
Initiates the intended operating cycle after safety and process permissives are satisfied.Permission to bypass, reset or override a safety function.Keep start functionally separate and test maintained commands, remote commands and power restoration.
Energy isolation
Hazardous energy controlled
Physically prevents transmission or release of hazardous energy for work covered by the applicable procedure.Replacement by a stop button, PLC bit, interlock, safety relay or reset button.Identify every energy source and verify isolation and control of stored or residual energy.

Reset is not lockout/tagout. OSHA 29 CFR 1910.147 explicitly excludes pushbuttons, selector switches and other control-circuit devices from its definition of an energy-isolating device. Jurisdictions and tasks differ, so apply the site procedure and applicable law rather than treating a safety circuit as isolation.

When is manual reset needed instead of automatic reset?

Do not choose the mode from convenience or a relay label. Base it on the access pattern, the possibility of a person remaining exposed, the start logic, the applicable machine standard and the documented risk assessment.

Preliminary decision gate: each recommendation still requires machine-specific engineering and validation.
ConditionRecommendationEvidence requiredStop boundary
A person can enter or remain behind the safeguardUse a deliberate restart strategy; manual reset is normally part of it, but may not be sufficient by itself.Access drawing, occupancy analysis, reset-zone matrix, applicable Type C requirements and validation plan.Do not release the design if a hidden or trapped person could be exposed after reset or start.
Point-of-operation access only, with no space to remain insideAutomatic re-arming may be considered only if the safety requirements permit it and normal start logic cannot cause an unexpected hazard.Risk assessment, safeguard geometry, start-command analysis and power-return test results.Do not select automatic behavior merely to shorten cycle time.
Reset operator cannot see every affected area or one command covers several zonesUse zone-specific authority and additional risk-reduction measures such as presence sensing, controlled access or trapped-key logic as justified.Real layout, sightline review, zone interfaces, sequence narrative and fault tests.Do not allow one reset to re-arm an unseen zone without a validated protective strategy.
Service, cleaning, jam clearing or maintenance requires entryApply the required hazardous-energy control or safe-intervention method; do not rely on reset logic as isolation.Task-based risk assessment, energy-control procedure and verification method.Stop work if energy isolation or the approved alternative cannot be verified.
Deliberate re-arming

Manual reset

A person operates a reset control after the required safety inputs are restored. The safety function can then become ready for a separate start.

Verify: the input cannot be held or bypassed in a way that defeats the intended acknowledgement.

Reset-state change checked

Monitored manual reset

The safety logic requires a valid change of reset state after the safety conditions return. This can detect some stuck, shorted or permanently operated reset conditions.

Verify: active edge, pulse duration, release timing and fault response from the exact controller manual.

Only after justification

Automatic re-arming

The safety output can become ready when its defined input conditions return, without a separate manual reset action.

Verify: whether the supplier means automatic reset, automatic start or both; the terms are not used consistently across products.

Automatic reset is not necessarily automatic restart, but it removes one deliberate barrier. Review maintained run commands, PLC state, drive behavior, operating modes, network commands and power restoration as one system. Product-specific reset timing and edge behavior must come from the exact safety relay or controller manual.

What is the correct reset-and-restart sequence?

The exact logic varies, but a restart-interlock design should make restoration, re-arming and starting distinct and testable states.

  1. Hazardous operation is permitted

    Safety inputs and production permissives are valid for the selected operating mode.

  2. A defined safety event occurs

    A guard opens, an emergency stop is pressed, an ESPE field is interrupted or another safety demand occurs.

  3. The designed safe response occurs

    Safety outputs command the selected contactors, drives, valves, brakes or other final elements.

  4. The initiating condition is restored

    The guard closes, actuator is released or field clears; the restart interlock still holds hazardous operation inhibited.

  5. Reset is deliberately accepted

    The logic checks required inputs, reset transition and feedback, then re-arms without hazardous motion.

  6. A separate start is requested

    Normal operation begins only after all safety and process conditions are satisfied.

Test restoration events separately

Guard closure, E-stop release, protective-field clearing, mode change and power return can follow different software paths. Test each event rather than assuming one successful reset proves them all.

Treat control guards as a documented exception

Some narrowly defined applications may permit guard closure to initiate a cycle. Do not generalize that behavior: it requires explicit support from the applicable machinery requirements, risk assessment and validation.

Power return belongs in the sequence test. A retained PLC bit, maintained start request or remote command must not recreate hazardous operation simply because supply voltage returns.

What must the complete safety chain prove before reset is accepted?

A sensor or relay certificate covers a component and its defined use. The installed restart function depends on the complete path from detection through final elements, feedback, machine state and normal controls.

Safety inputsE-stop, guard, ESPEDetect the defined demand or unsafe condition.
Safety logicRelay or safety controllerEvaluates channels, mode, reset and faults.
Safety outputsOSSD or safety contactsRemove or inhibit permission for the hazard.
Final elementsContactors, drive, valvesCreate the selected machine response.
Machine stateMotion and energyMust meet the documented safe-state criteria.
Feedback path: where the architecture requires it, EDM or another defined feedback mechanism reports whether selected final elements reached the expected state before reset or the next cycle.
Technician checking industrial control cabinet wiring and switching components
Feedback and fault response must be checked against the exact switching architecture. Photo: Shameer Vayalakkad Hydrose / Pexels.

What EDM can and cannot prove

EDM can help the safety logic detect an unexpected state of selected contactors or other final elements. It does not prove that all motion has stopped, pressure is released, gravity is restrained, thermal energy is harmless or another power source is isolated.

  • Identify every final element needed to achieve the safe state.
  • Define the expected feedback state and maximum transition time.
  • Specify how discrepancy faults are indicated, latched and cleared.
  • Test welded, stuck, wrong-state and timing faults included in the validation plan.

What component compliance can support

  • The component's declared function, response time and diagnostic behavior.
  • Its approved connection, reset modes and environmental limits.
  • Performance data used in the safety-related control-system calculation.

What component compliance does not prove

  • The reset position and zone authority are correct for this machine.
  • The complete safety function achieves the required PLr or SIL/CL.
  • Actual stopping time, safe state and fault response meet the specification.
  • The delivered model, firmware and configuration match the evaluated design.

For ESPE interfaces, see the xsz sensor guide to OSSD safety outputs. Two signal wires connected to ordinary PLC inputs do not create a safety-rated logic function.

Where should a manual reset control be installed?

The design should let the person resetting assess the affected danger area, prevent operation from within that safeguarded space, and make the exact reset authority clear. Large or obstructed cells need more than a generic distance rule.

Four placement checks

  1. Outside the safeguarded space: the control cannot be reached or operated from a trapped-person position inside.
  2. Effective observation: guards, tooling, pallets, pits, platforms and material do not hide another person.
  3. Defined zone authority: the control re-arms only the documented zone and linked hazards behave predictably.
  4. Suitable human factors: identity, access, location and indication reduce confusion with start, stop or fault-reset controls.

Do not invent a universal reset-button distance. ISO 13855:2024 includes positioning considerations for safety-related manual control devices relative to safeguarded spaces, but the final solution still depends on the real geometry, reach paths, access pattern and applicable machine requirements.

How should whole-body access, blind areas and multiple zones change the design?

If a person can pass through the safeguard and remain inside after it clears, the input no longer detects that person's presence. Reset location helps, but the wider restart strategy must address occupancy, entrapment and zone interaction.

Illustrative engineering review

Two-door robot cell with a light-curtain loading portal

The proposal uses one HMI reset for both access doors and the loading portal. A fixture blocks part of the cell from the HMI, and a person can stand behind the light curtain after the field clears.

Decision: do not approve yet
  • Define which safeguard events latch each zone and which reset control owns that zone.
  • Provide a layout and sightline review for every reset position.
  • Add risk-assessed occupancy and entrapment measures where observation alone is insufficient.
  • Keep reset separate from robot cycle start and test linked conveyors and remote commands.
  • Submit the safety requirements, logic description, PL/SIL evidence and validation tests before release.

Light-curtain boundary: the protective field can detect passage through it, but it does not by itself detect someone standing behind the field or validate the restart behavior of the machine. The access route, safety logic, reset arrangement, final elements and validation must work as one safety function.

Potential additional measures

Depending on the risk, options can include zone-specific resets, presence sensing, trapped-key systems, controlled-access procedures, escape release, internal emergency-stop devices or pre-start warnings. No single measure is universally sufficient.

Evidence the reviewer should request

Request the scaled layout, access routes, safeguard coverage, reset and start locations, zone-cause-and-effect matrix, safety requirement specification, exact device manuals, software/configuration revision and fault-based validation plan.

Why will a safety relay or controller not reset?

A refused reset is often the correct response to a missing condition or detected fault. Diagnose from the safety requirements, current drawing, device indicators and exact manual—never by casually bridging reset or feedback terminals.

Safe diagnostic directions for common restart-interlock symptoms.
SymptomLikely questionSafe diagnostic directionRelease boundary
Reset button has no effectIs a guard, E-stop channel, OSSD, mode input, supply or feedback condition still invalid?Read device diagnostics and compare every safety input with the current drawing and status table.Do not bypass the missing input to continue commissioning.
Reset works only after button releaseDoes the selected mode act on a falling edge or require a defined pulse?Compare the observed sequence with the exact model and firmware manual.Do not assume another relay family uses the same timing.
EDM fault remainsIs a contactor welded, auxiliary contact wrong, feedback path open or transition too slow?Establish safe conditions, inspect final elements and verify the specified contact type and timing.Do not clear or mask a discrepancy without finding its cause.
System re-arms on power returnIs reset configured for automatic behavior, permanently high or retained in logic?Review cold-start behavior, maintained commands, safety-controller configuration and drive state.Do not release if power return can create unexpected hazardous operation.
Machine moves when reset is pressedAre reset and normal start coupled in wiring, PLC logic or cycle recovery?Stop commissioning, separate the commands and repeat the safety-function validation.This is a release-stopping defect unless an explicitly permitted control-guard function applies.
One zone resets anotherIs reset authority or the safety-network mapping too broad?Define zone ownership, linked hazards, inter-zone handshakes and start permissives.Do not re-arm an unseen or occupied zone.

How should the installed restart function be verified and validated?

Validate against documented safety requirements before handover and after relevant changes. A reset lamp or one successful cycle is not enough evidence.

Minimum test families to include in a machine-specific validation plan.
Test familyPass evidenceStop release when
Every initiating deviceEach guard, E-stop, ESPE and mode demand creates the specified safe response in every relevant mode.Any demand is ignored, delayed beyond the requirement or affects the wrong zone.
Restoration and resetRestoration alone does not restart; reset is accepted only after all required conditions and creates no hazardous motion.Guard closure, field clearing, E-stop release or reset initiates an unintended hazard.
Normal startStart is a distinct action and works only with valid safety and process permissives.A retained, remote or mode-dependent command bypasses the intended sequence.
Reset location and zonesReach, observation, authority, blind areas and linked-zone behavior match the approved layout.A person can reset from inside or re-arm an unseen affected area without adequate measures.
Feedback and faultsSpecified stuck, welded, wrong-state, cross-channel, timing and reset-input faults produce the required response.A single fault can be cleared by reset or remain undetected contrary to the safety requirements.
Power and mode changesLoss and restoration of tested supplies, PLC restart, drive restart and mode transitions cannot create unexpected motion.Any retained state or command re-enables the hazard without the required sequence.
Machine safe stateMeasured stopping time, pressure, gravity restraint and other defined criteria meet the specification.The control output changes but the actual hazard does not reach or maintain the required safe state.
Records and revisionResults identify machine, drawing, software, firmware, device model, tester, date and accepted deviations.The tested configuration cannot be traced to the machine being released.
Safety professional inspecting industrial machinery during validation
Validation must connect safeguard detection, safe response, restart behavior, feedback and actual machine state. Photo: ThisIsEngineering / Pexels.

Revalidate after relevant change. Triggers can include a replaced safety device, new suffix or firmware, logic edit, changed reset location, new guarding, altered tooling, faster motion, different drive parameters, changed stopping time, network modification or a revised access route.

What should an RFQ request for restart interlock and manual reset?

“Include a safety reset button” is not a functional specification. Give the machine builder, integrator or component supplier the access pattern, safe-state requirement, reset authority and evidence obligations.

Machine, hazards and access

  • Machine task, destination market and applicable Type C standard.
  • Hazards and energy sources, including pressure, gravity, heat and inertia.
  • Operating modes, foreseeable interventions and every access route.
  • Whether a person can enter or remain in each danger zone.

Safety function and reset authority

  • Safeguards and required safe response for each machine zone.
  • PLr or SIL/CL, stopping-time data and restart events to control.
  • Requested reset mode, reset locations, sightlines and zone authority.
  • Separate normal start and restrictions on HMI, network or remote reset.

Final elements and component evidence

  • Contactors, drive safety functions, valves, brakes and stored-energy controls.
  • Required EDM or other feedback state, sequence and timing.
  • Exact component model and suffix, manual and datasheet revision.
  • Safety data, response time, reset-mode behavior, diagnostics and firmware.

Acceptance and change records

  • Safety requirements and zone cause-and-effect matrix.
  • Current circuit drawings, PL/SIL calculation and assumptions.
  • Software or configuration backup tied to the released revision.
  • Validation plan, fault tests, measured results and revalidation triggers.

Acceptance principle: every important claim must trace to the exact machine zone, safety function, component model/suffix and tested configuration. A generic brochure or certificate is not the installed-function validation record.

Standards and official guidance checked for this guide

  1. ISO 14118:2017 — prevention of unexpected start-up across electrical, hydraulic, pneumatic, stored-energy and external-influence hazards; the page notes that machine-specific means come from Type C standards or risk assessment.
  2. ISO 13849-1:2023 — methodology for the design and integration of safety-related parts of control systems.
  3. ISO 13849-2:2012 — current published validation procedures, with a replacement draft under development as of this review.
  4. ISO 13850:2015 — functional requirements and design principles for emergency-stop functions.
  5. ISO 14119:2024 — design and selection of interlocking devices associated with guards and measures against foreseeable defeat.
  6. ISO 13855:2024 — positioning of safeguards and safety-related manual control devices relative to safeguarded spaces.
  7. IEC 60204-1:2016+A1:2021 consolidated edition — current consolidated requirements for electrical equipment of machines.
  8. IEC 61496-1:2020 — general ESPE design, construction and test requirements; intended for use with the sensing-technology-specific part.
  9. OSHA 29 CFR 1910.147 — U.S. control-of-hazardous-energy requirements and the control-circuit limitation.
  10. Rockwell Automation Guardmaster Safety Relays user manual — manufacturer example showing that monitored manual and automatic/manual reset edges and timing are product-specific.

Reference boundary: standard titles and scopes do not identify every clause applicable to a particular machine. Purchase the applicable editions, check regional adoptions and amendments, follow the exact certified component manuals, and have the final function validated by competent personnel.

Need to review a safety-sensor application?

Prepare the machine layout, access routes, required safety performance, safeguard positions, stopping data, reset zones and interface details before asking for a component recommendation.

Use the RFQ checklist
Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare