Restart Interlock and Manual Reset: How to Prevent Unexpected Machine Restart
A restart interlock keeps hazardous operation inhibited after a safeguard or defined safety event is restored. A manual reset deliberately re-arms that safety function. Reset is not start: releasing an emergency stop, closing a guard, clearing a light curtain, restoring power or pressing reset must not by itself create hazardous motion.
Guarded robot cellImage unavailable. The article diagrams below still explain reset location and restart logic.
What is the difference between restart interlock, manual reset and machine start?
They answer three separate questions: should the hazard remain inhibited, may the safety function become ready again, and may production operation begin?
Closing a door or clearing a protective field restores an input condition; it does not prove the area is empty. A valid reset confirms that the defined reset conditions have been addressed, but reset itself must not launch hazardous motion.
| Action or state | Intended function | What it does not prove | Buyer or validator check |
|---|---|---|---|
| Safeguard restored Input restored | The guard is closed, emergency-stop actuator is released or protective field is clear. | That nobody remains inside, final elements are off or a restart is safe. | Confirm that restoration alone leaves hazardous operation inhibited where the safety requirements demand restart interlock. |
| Restart interlock State held | Prevents automatic return of hazardous operation after the defined safety event. | Energy isolation, safe access for servicing or achievement of a required PL/SIL. | Trace every event that should latch the stopped state, including mode and power changes. |
| Manual reset Safety re-armed | Uses a deliberate action to allow the safety function to become ready when all required inputs and feedback are valid. | A machine start, an empty danger zone or complete removal of stored energy. | Test that reset cannot create hazardous motion and cannot be accepted from an unsafe location or state. |
| Normal start Run requested | Initiates the intended operating cycle after safety and process permissives are satisfied. | Permission to bypass, reset or override a safety function. | Keep start functionally separate and test maintained commands, remote commands and power restoration. |
| Energy isolation Hazardous energy controlled | Physically prevents transmission or release of hazardous energy for work covered by the applicable procedure. | Replacement by a stop button, PLC bit, interlock, safety relay or reset button. | Identify every energy source and verify isolation and control of stored or residual energy. |
Reset is not lockout/tagout. OSHA 29 CFR 1910.147 explicitly excludes pushbuttons, selector switches and other control-circuit devices from its definition of an energy-isolating device. Jurisdictions and tasks differ, so apply the site procedure and applicable law rather than treating a safety circuit as isolation.
When is manual reset needed instead of automatic reset?
Do not choose the mode from convenience or a relay label. Base it on the access pattern, the possibility of a person remaining exposed, the start logic, the applicable machine standard and the documented risk assessment.
| Condition | Recommendation | Evidence required | Stop boundary |
|---|---|---|---|
| A person can enter or remain behind the safeguard | Use a deliberate restart strategy; manual reset is normally part of it, but may not be sufficient by itself. | Access drawing, occupancy analysis, reset-zone matrix, applicable Type C requirements and validation plan. | Do not release the design if a hidden or trapped person could be exposed after reset or start. |
| Point-of-operation access only, with no space to remain inside | Automatic re-arming may be considered only if the safety requirements permit it and normal start logic cannot cause an unexpected hazard. | Risk assessment, safeguard geometry, start-command analysis and power-return test results. | Do not select automatic behavior merely to shorten cycle time. |
| Reset operator cannot see every affected area or one command covers several zones | Use zone-specific authority and additional risk-reduction measures such as presence sensing, controlled access or trapped-key logic as justified. | Real layout, sightline review, zone interfaces, sequence narrative and fault tests. | Do not allow one reset to re-arm an unseen zone without a validated protective strategy. |
| Service, cleaning, jam clearing or maintenance requires entry | Apply the required hazardous-energy control or safe-intervention method; do not rely on reset logic as isolation. | Task-based risk assessment, energy-control procedure and verification method. | Stop work if energy isolation or the approved alternative cannot be verified. |
Manual reset
A person operates a reset control after the required safety inputs are restored. The safety function can then become ready for a separate start.
Verify: the input cannot be held or bypassed in a way that defeats the intended acknowledgement.
Monitored manual reset
The safety logic requires a valid change of reset state after the safety conditions return. This can detect some stuck, shorted or permanently operated reset conditions.
Verify: active edge, pulse duration, release timing and fault response from the exact controller manual.
Automatic re-arming
The safety output can become ready when its defined input conditions return, without a separate manual reset action.
Verify: whether the supplier means automatic reset, automatic start or both; the terms are not used consistently across products.
Automatic reset is not necessarily automatic restart, but it removes one deliberate barrier. Review maintained run commands, PLC state, drive behavior, operating modes, network commands and power restoration as one system. Product-specific reset timing and edge behavior must come from the exact safety relay or controller manual.
What is the correct reset-and-restart sequence?
The exact logic varies, but a restart-interlock design should make restoration, re-arming and starting distinct and testable states.
- Hazardous operation is permitted
Safety inputs and production permissives are valid for the selected operating mode.
- A defined safety event occurs
A guard opens, an emergency stop is pressed, an ESPE field is interrupted or another safety demand occurs.
- The designed safe response occurs
Safety outputs command the selected contactors, drives, valves, brakes or other final elements.
- The initiating condition is restored
The guard closes, actuator is released or field clears; the restart interlock still holds hazardous operation inhibited.
- Reset is deliberately accepted
The logic checks required inputs, reset transition and feedback, then re-arms without hazardous motion.
- A separate start is requested
Normal operation begins only after all safety and process conditions are satisfied.
Test restoration events separately
Guard closure, E-stop release, protective-field clearing, mode change and power return can follow different software paths. Test each event rather than assuming one successful reset proves them all.
Treat control guards as a documented exception
Some narrowly defined applications may permit guard closure to initiate a cycle. Do not generalize that behavior: it requires explicit support from the applicable machinery requirements, risk assessment and validation.
Power return belongs in the sequence test. A retained PLC bit, maintained start request or remote command must not recreate hazardous operation simply because supply voltage returns.
What must the complete safety chain prove before reset is accepted?
A sensor or relay certificate covers a component and its defined use. The installed restart function depends on the complete path from detection through final elements, feedback, machine state and normal controls.
Final-element feedback reviewVerify the actual contactor, drive or valve state against the documented architecture.
What EDM can and cannot prove
EDM can help the safety logic detect an unexpected state of selected contactors or other final elements. It does not prove that all motion has stopped, pressure is released, gravity is restrained, thermal energy is harmless or another power source is isolated.
- Identify every final element needed to achieve the safe state.
- Define the expected feedback state and maximum transition time.
- Specify how discrepancy faults are indicated, latched and cleared.
- Test welded, stuck, wrong-state and timing faults included in the validation plan.
What component compliance can support
- The component's declared function, response time and diagnostic behavior.
- Its approved connection, reset modes and environmental limits.
- Performance data used in the safety-related control-system calculation.
What component compliance does not prove
- The reset position and zone authority are correct for this machine.
- The complete safety function achieves the required PLr or SIL/CL.
- Actual stopping time, safe state and fault response meet the specification.
- The delivered model, firmware and configuration match the evaluated design.
For ESPE interfaces, see the xsz sensor guide to OSSD safety outputs. Two signal wires connected to ordinary PLC inputs do not create a safety-rated logic function.
Where should a manual reset control be installed?
The design should let the person resetting assess the affected danger area, prevent operation from within that safeguarded space, and make the exact reset authority clear. Large or obstructed cells need more than a generic distance rule.
Four placement checks
- Outside the safeguarded space: the control cannot be reached or operated from a trapped-person position inside.
- Effective observation: guards, tooling, pallets, pits, platforms and material do not hide another person.
- Defined zone authority: the control re-arms only the documented zone and linked hazards behave predictably.
- Suitable human factors: identity, access, location and indication reduce confusion with start, stop or fault-reset controls.
Do not invent a universal reset-button distance. ISO 13855:2024 includes positioning considerations for safety-related manual control devices relative to safeguarded spaces, but the final solution still depends on the real geometry, reach paths, access pattern and applicable machine requirements.
How should whole-body access, blind areas and multiple zones change the design?
If a person can pass through the safeguard and remain inside after it clears, the input no longer detects that person's presence. Reset location helps, but the wider restart strategy must address occupancy, entrapment and zone interaction.
Two-door robot cell with a light-curtain loading portal
The proposal uses one HMI reset for both access doors and the loading portal. A fixture blocks part of the cell from the HMI, and a person can stand behind the light curtain after the field clears.
Decision: do not approve yet- Define which safeguard events latch each zone and which reset control owns that zone.
- Provide a layout and sightline review for every reset position.
- Add risk-assessed occupancy and entrapment measures where observation alone is insufficient.
- Keep reset separate from robot cycle start and test linked conveyors and remote commands.
- Submit the safety requirements, logic description, PL/SIL evidence and validation tests before release.
Light-curtain boundary: the protective field can detect passage through it, but it does not by itself detect someone standing behind the field or validate the restart behavior of the machine. The access route, safety logic, reset arrangement, final elements and validation must work as one safety function.
Potential additional measures
Depending on the risk, options can include zone-specific resets, presence sensing, trapped-key systems, controlled-access procedures, escape release, internal emergency-stop devices or pre-start warnings. No single measure is universally sufficient.
Evidence the reviewer should request
Request the scaled layout, access routes, safeguard coverage, reset and start locations, zone-cause-and-effect matrix, safety requirement specification, exact device manuals, software/configuration revision and fault-based validation plan.
Why will a safety relay or controller not reset?
A refused reset is often the correct response to a missing condition or detected fault. Diagnose from the safety requirements, current drawing, device indicators and exact manual—never by casually bridging reset or feedback terminals.
| Symptom | Likely question | Safe diagnostic direction | Release boundary |
|---|---|---|---|
| Reset button has no effect | Is a guard, E-stop channel, OSSD, mode input, supply or feedback condition still invalid? | Read device diagnostics and compare every safety input with the current drawing and status table. | Do not bypass the missing input to continue commissioning. |
| Reset works only after button release | Does the selected mode act on a falling edge or require a defined pulse? | Compare the observed sequence with the exact model and firmware manual. | Do not assume another relay family uses the same timing. |
| EDM fault remains | Is a contactor welded, auxiliary contact wrong, feedback path open or transition too slow? | Establish safe conditions, inspect final elements and verify the specified contact type and timing. | Do not clear or mask a discrepancy without finding its cause. |
| System re-arms on power return | Is reset configured for automatic behavior, permanently high or retained in logic? | Review cold-start behavior, maintained commands, safety-controller configuration and drive state. | Do not release if power return can create unexpected hazardous operation. |
| Machine moves when reset is pressed | Are reset and normal start coupled in wiring, PLC logic or cycle recovery? | Stop commissioning, separate the commands and repeat the safety-function validation. | This is a release-stopping defect unless an explicitly permitted control-guard function applies. |
| One zone resets another | Is reset authority or the safety-network mapping too broad? | Define zone ownership, linked hazards, inter-zone handshakes and start permissives. | Do not re-arm an unseen or occupied zone. |
How should the installed restart function be verified and validated?
Validate against documented safety requirements before handover and after relevant changes. A reset lamp or one successful cycle is not enough evidence.
| Test family | Pass evidence | Stop release when |
|---|---|---|
| Every initiating device | Each guard, E-stop, ESPE and mode demand creates the specified safe response in every relevant mode. | Any demand is ignored, delayed beyond the requirement or affects the wrong zone. |
| Restoration and reset | Restoration alone does not restart; reset is accepted only after all required conditions and creates no hazardous motion. | Guard closure, field clearing, E-stop release or reset initiates an unintended hazard. |
| Normal start | Start is a distinct action and works only with valid safety and process permissives. | A retained, remote or mode-dependent command bypasses the intended sequence. |
| Reset location and zones | Reach, observation, authority, blind areas and linked-zone behavior match the approved layout. | A person can reset from inside or re-arm an unseen affected area without adequate measures. |
| Feedback and faults | Specified stuck, welded, wrong-state, cross-channel, timing and reset-input faults produce the required response. | A single fault can be cleared by reset or remain undetected contrary to the safety requirements. |
| Power and mode changes | Loss and restoration of tested supplies, PLC restart, drive restart and mode transitions cannot create unexpected motion. | Any retained state or command re-enables the hazard without the required sequence. |
| Machine safe state | Measured stopping time, pressure, gravity restraint and other defined criteria meet the specification. | The control output changes but the actual hazard does not reach or maintain the required safe state. |
| Records and revision | Results identify machine, drawing, software, firmware, device model, tester, date and accepted deviations. | The tested configuration cannot be traced to the machine being released. |
Installed-function validationRecord the machine state, test condition, result and exact configuration.
Revalidate after relevant change. Triggers can include a replaced safety device, new suffix or firmware, logic edit, changed reset location, new guarding, altered tooling, faster motion, different drive parameters, changed stopping time, network modification or a revised access route.
What should an RFQ request for restart interlock and manual reset?
“Include a safety reset button” is not a functional specification. Give the machine builder, integrator or component supplier the access pattern, safe-state requirement, reset authority and evidence obligations.
Machine, hazards and access
- Machine task, destination market and applicable Type C standard.
- Hazards and energy sources, including pressure, gravity, heat and inertia.
- Operating modes, foreseeable interventions and every access route.
- Whether a person can enter or remain in each danger zone.
Safety function and reset authority
- Safeguards and required safe response for each machine zone.
- PLr or SIL/CL, stopping-time data and restart events to control.
- Requested reset mode, reset locations, sightlines and zone authority.
- Separate normal start and restrictions on HMI, network or remote reset.
Final elements and component evidence
- Contactors, drive safety functions, valves, brakes and stored-energy controls.
- Required EDM or other feedback state, sequence and timing.
- Exact component model and suffix, manual and datasheet revision.
- Safety data, response time, reset-mode behavior, diagnostics and firmware.
Acceptance and change records
- Safety requirements and zone cause-and-effect matrix.
- Current circuit drawings, PL/SIL calculation and assumptions.
- Software or configuration backup tied to the released revision.
- Validation plan, fault tests, measured results and revalidation triggers.
Acceptance principle: every important claim must trace to the exact machine zone, safety function, component model/suffix and tested configuration. A generic brochure or certificate is not the installed-function validation record.
Related xsz sensor resources for the next design decision
Standards and official guidance checked for this guide
- ISO 14118:2017 — prevention of unexpected start-up across electrical, hydraulic, pneumatic, stored-energy and external-influence hazards; the page notes that machine-specific means come from Type C standards or risk assessment.
- ISO 13849-1:2023 — methodology for the design and integration of safety-related parts of control systems.
- ISO 13849-2:2012 — current published validation procedures, with a replacement draft under development as of this review.
- ISO 13850:2015 — functional requirements and design principles for emergency-stop functions.
- ISO 14119:2024 — design and selection of interlocking devices associated with guards and measures against foreseeable defeat.
- ISO 13855:2024 — positioning of safeguards and safety-related manual control devices relative to safeguarded spaces.
- IEC 60204-1:2016+A1:2021 consolidated edition — current consolidated requirements for electrical equipment of machines.
- IEC 61496-1:2020 — general ESPE design, construction and test requirements; intended for use with the sensing-technology-specific part.
- OSHA 29 CFR 1910.147 — U.S. control-of-hazardous-energy requirements and the control-circuit limitation.
- Rockwell Automation Guardmaster Safety Relays user manual — manufacturer example showing that monitored manual and automatic/manual reset edges and timing are product-specific.
Reference boundary: standard titles and scopes do not identify every clause applicable to a particular machine. Purchase the applicable editions, check regional adoptions and amendments, follow the exact certified component manuals, and have the final function validated by competent personnel.