Motion and state
Its state is used to practise permissive and trip reasoning; it is not a safety-rated engineering model.
controls · safety model
A safety relay monitors safety devices such as an emergency stop or guard switch and removes hazardous-motion permission through redundant, force-guided outputs. A standard PLC can display status and coordinate normal production, but it must not silently replace the safety function. The important PLC boundary is command versus permission: the controller may request motion only while the independently validated safety circuit reports healthy.
Start with the public scenario; create a free account when you want to save progress.
Explore Safety relay in 3D
Load the interactive model when you are ready to rotate, inspect and operate it. Deferring WebGL keeps the reference page fast.
Its state is used to practise permissive and trip reasoning; it is not a safety-rated engineering model.
Commission it by proving active feedback before accepting enable.
Inject stuck-on, stuck-off states and require the PLC sequence to detect, stop and recover deliberately.
PLC integration guide
Dual input channels allow the relay to detect a single open circuit, contact fault or channel discrepancy. Its output contacts drive safety contactors, safe drive inputs or another validated final element according to the risk assessment. A standard PLC status bit is useful for messages and sequence inhibition, but software, network communications and an ordinary output do not acquire a safety rating because the logic looks redundant.
A manual monitored reset should be accepted only after input channels are healthy, external devices have returned to their expected state and the reset signal makes the required transition. Resetting the relay restores permission; a separate deliberate machine start command should be required. PLC logic should clear stale run requests when safety permission drops so motion cannot resume unexpectedly when the circuit is restored.
External device monitoring reads mechanically linked normally-closed auxiliary contacts from the final contactors. Before reset, those contacts must prove the contactors actually opened. If a power pole or mechanism remains closed, the feedback path prevents reset. The PLC can present a specific EDM fault to maintenance, but the safety relay performs the safety-rated monitoring.
The reference above focuses on PLC integration. The interactive school lesson shows the device, signal or mechanism before you write the control sequence.
Learn the E-stop mechanism and reset principleSignal map
PLC output Enable; PLC input Active feedback
| Signal | PLC direction | Type / range |
|---|---|---|
| Enable enable | output | bool |
| Active feedback active | input | bool |
Field checklist
Fault finding
| Symptom | Check |
|---|---|
| Safety relay will not reset | Check both input channels, reset-edge requirements, feedback-loop state, supply voltage and the device diagnostic code. |
| Relay resets but PLC still shows safety open | Trace the auxiliary status contact, input common, PLC address and any inversion in the standard program. |
| Intermittent channel discrepancy | Inspect simultaneous contact operation, cable damage, loose terminals and test-pulse compatibility. Do not mask it with PLC delay. |
Fault and recovery exercise
Inject stuck-on, stuck-off states and require the PLC sequence to detect, stop and recover deliberately.
Training model only. It does not perform a machinery risk assessment, calculate performance level or SIL, replace a safety PLC, or validate a real safety function.
Plain-English answers
Not for a safety-rated function. Use certified safety hardware and a validated design appropriate to the risk. A standard PLC may consume diagnostic status only.
The architecture can detect certain single faults and disagreement instead of allowing one hidden wiring or contact failure to defeat the stop request.
The safety device checks that reset occurs as a deliberate signal transition under valid conditions rather than accepting a permanently bridged reset input.
Free first success
Open a related browser scenario, run the PLC logic and see the component state respond. Start without installing software or entering a card.
Keep building
controls
Its visible state changes with simulated I/O, making status and diagnosis readable in the scene.
controls
Its visible state changes with simulated I/O, making status and diagnosis readable in the scene.
controls
Its visible state changes with simulated I/O, making status and diagnosis readable in the scene.
Technical reference and worked-example guide
Direct answer
Safety relay guide becomes useful when it connects hazard and required function, safe state, input devices, channel structure, discrepancy, reset type, output contacts, external-device monitoring, fault exclusions and diagnostic interface with hazardous demand through input channels, safety-relay logic, force-guided outputs, final switching devices, energy removal, stop result and reset prerequisites, then proves the declared protective device removes the permitted hazardous action and deliberate reset cannot initiate unexpected movement under normal, boundary, fault and recovery conditions. The objective is a repeatable engineering or learning result, not merely activity inside a page or tool.
This guide is written for automation learners and maintenance technicians studying dual-channel emergency-stop or guard circuits, monitored reset, contactor feedback and diagnostic evidence. The intended result is specific: the reader can trace a basic safety-relay function and explain why diagnostic status or standard PLC logic does not independently prove risk reduction.

System map / 02
Treat these as connected checkpoints. Each checkpoint has an expected state, an observable state and a boundary to the next part of the system. That structure prevents a software indication from being mistaken for physical proof.
hazard and required function, safe state, input devices, channel structure, discrepancy, reset type, output contacts, external-device monitoring, fault exclusions and diagnostic interface. For safety relay inputs, reset, outputs and diagnostic boundaries, record the initial condition, actor, requested change, observable result and stopping condition before selecting a tool or implementation.
hazardous demand through input channels, safety-relay logic, force-guided outputs, final switching devices, energy removal, stop result and reset prerequisites. Separate request, internal state, output or service, physical or user-visible result and independent feedback so each boundary can be inspected.
the declared protective device removes the permitted hazardous action and deliberate reset cannot initiate unexpected movement. Run more than one cycle from a known state and retain the values, timings or artifacts that demonstrate repeatability.
cross fault, welded contactor, channel disagreement, reset held, guard cycling, supply loss, diagnostic-wire fault, restart and maintenance bypass. Choose minimum, maximum, simultaneous, delayed or restart conditions that reveal assumptions hidden by the happy path.
a hazard, input, channel, reset, relay, output, final-device, feedback, stopping, calculation or validation mismatch. Preserve the first symptom, divide the system at a measurable boundary and change one condition only after predicting the result.
the function designed and validated by qualified personnel on target components under the applicable risk-reduction standard and test plan. Restore normal state, remove temporary changes, repeat affected checks and document which claims remain limited to the learning environment.
Procedure / 03
Run the steps in order the first time. Later, the same structure becomes a diagnostic loop: define the expected condition, observe the boundary, interpret the difference and choose one proving action.
Convert hazard and required function, safe state, input devices, channel structure, discrepancy, reset type, output contacts, external-device monitoring, fault exclusions and diagnostic interface into initial conditions, one stimulus and observable pass criteria.
Evidence: Another person can repeat the case without guessing the intended result.
Avoid: Using page completion or an animation as the acceptance criterion.
Document hazardous demand through input channels, safety-relay logic, force-guided outputs, final switching devices, energy removal, stop result and reset prerequisites and name who owns each state or decision.
Evidence: Every request and result has a source, destination and useful inspection point.
Avoid: Using the same value as command, status and independent feedback.
Apply the declared protective device removes the permitted hazardous action and deliberate reset cannot initiate unexpected movement from a clean start and record the expected evidence.
Evidence: Repeated runs produce the same bounded result.
Avoid: Changing several parameters before a baseline exists.
Test cross fault, welded contactor, channel disagreement, reset held, guard cycling, supply loss, diagnostic-wire fault, restart and maintenance bypass without changing the acceptance contract.
Evidence: Limits, timing and restart behavior reach defined states.
Avoid: Testing only one ideal sequence.
Introduce or analyse a hazard, input, channel, reset, relay, output, final-device, feedback, stopping, calculation or validation mismatch and locate the first disagreement.
Evidence: The proving action distinguishes the leading hypotheses.
Avoid: Resetting, forcing or replacing before evidence is retained.
Complete the function designed and validated by qualified personnel on target components under the applicable risk-reduction standard and test plan and repeat the affected regression cases.
Evidence: Reference use is complete when inputs, assumptions, units or initial conditions are recorded and the result is independently checked at a useful boundary.
Avoid: Treating an acknowledged message or one successful rerun as handover.
Diagnostic matrix / 04
The table is a reasoning aid, not a parts-replacement chart. Preserve the initial symptom, inspect the named boundary and use the interpretation to choose the next controlled test. Site safety procedures and equipment manuals remain authoritative.
| Observed symptom | Inspect | Interpretation | Next proving action |
|---|---|---|---|
| The expected result is unclear | Requirement, initial state, actor, stimulus, units and pass condition | The technician, programmer and reviewer may be solving different versions of the task. | Rewrite one observable acceptance case before continuing. |
| Internal state changes but the outcome does not | Request, final owner, output or service boundary and independent feedback | A software or interface indication proves intent at one layer, not the complete outcome. | Trace the first boundary after the changing state. |
| Normal case passes but an edge case fails | Limits, timing, simultaneous events, reset and restart assumptions | The implementation contains a hidden assumption exposed by the changed condition. | Add the failed boundary as a permanent regression case. |
| The failure disappears after reset | Original symptom, histories, diagnostics, timestamps and active cause | Reset changed evidence or state without proving the initiating cause. | Reproduce under a controlled condition and preserve pre/post-event data. |
| Simulator and target disagree | Model boundary, software version, task timing, I/O behavior, data types and configuration | A learning model and the intended target do not share one of the recorded assumptions. | Reduce the case and verify against current target documentation. |
| The result cannot be explained | Prediction, observation, proving action, alternative hypotheses and limitations | Activity occurred but the evidence is not yet transferable or reviewable. | Have the learner defend the signal path and repeat a changed case. |
Product evidence / 05
The page connects definitions and worked examples to runnable tools, explicit assumptions and repeatable checks so a formula or pattern can be challenged.
This guide cannot select architecture, calculate achieved performance, validate a safety function, authorize bypasses or replace risk assessment, manufacturer instructions and qualified engineering.
Commissioning notebook / 06
Use these as written briefs rather than click-through instructions. For every case, state the expected condition before acting, retain the first useful observation and explain why the final result proves the requirement. A different program or component choice can still be correct when it produces the same bounded behavior and evidence.
Case 01
predict → observe → prove
Engineering context. hazard and required function, safe state, input devices, channel structure, discrepancy, reset type, output contacts, external-device monitoring, fault exclusions and diagnostic interface. For safety relay inputs, reset, outputs and diagnostic boundaries, record the initial condition, actor, requested change, observable result and stopping condition before selecting a tool or implementation. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.
Controlled setup. Use the “Write the acceptance case” stage of the workflow: convert hazard and required function, safe state, input devices, channel structure, discrepancy, reset type, output contacts, external-device monitoring, fault exclusions and diagnostic interface into initial conditions, one stimulus and observable pass criteria. The acceptance record should show this result: another person can repeat the case without guessing the intended result. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.
Fault challenge. Introduce or analyse “The expected result is unclear” as one bounded deviation. Inspect requirement, initial state, actor, stimulus, units and pass condition The working interpretation is that the technician, programmer and reviewer may be solving different versions of the task. The next proving action is to rewrite one observable acceptance case before continuing. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.
Review and recovery. The most common trap here is using page completion or an animation as the acceptance criterion. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.
Explain it aloud: What does a safety relay do? A defensible short answer is: It evaluates compatible safety inputs and controls safety-related outputs with defined fault response, diagnostics and reset behavior.
Case 02
predict → observe → prove
Engineering context. hazardous demand through input channels, safety-relay logic, force-guided outputs, final switching devices, energy removal, stop result and reset prerequisites. Separate request, internal state, output or service, physical or user-visible result and independent feedback so each boundary can be inspected. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.
Controlled setup. Use the “Build the map” stage of the workflow: document hazardous demand through input channels, safety-relay logic, force-guided outputs, final switching devices, energy removal, stop result and reset prerequisites and name who owns each state or decision. The acceptance record should show this result: every request and result has a source, destination and useful inspection point. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.
Fault challenge. Introduce or analyse “Internal state changes but the outcome does not” as one bounded deviation. Inspect request, final owner, output or service boundary and independent feedback The working interpretation is that a software or interface indication proves intent at one layer, not the complete outcome. The next proving action is to trace the first boundary after the changing state. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.
Review and recovery. The most common trap here is using the same value as command, status and independent feedback. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.
Explain it aloud: Can a normal PLC replace a safety relay? A defensible short answer is: Not by default. The required safety function and performance determine the suitable architecture, components and validation process.
Case 03
predict → observe → prove
Engineering context. the declared protective device removes the permitted hazardous action and deliberate reset cannot initiate unexpected movement. Run more than one cycle from a known state and retain the values, timings or artifacts that demonstrate repeatability. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.
Controlled setup. Use the “Run the baseline” stage of the workflow: apply the declared protective device removes the permitted hazardous action and deliberate reset cannot initiate unexpected movement from a clean start and record the expected evidence. The acceptance record should show this result: repeated runs produce the same bounded result. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.
Fault challenge. Introduce or analyse “Normal case passes but an edge case fails” as one bounded deviation. Inspect limits, timing, simultaneous events, reset and restart assumptions The working interpretation is that the implementation contains a hidden assumption exposed by the changed condition. The next proving action is to add the failed boundary as a permanent regression case. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.
Review and recovery. The most common trap here is changing several parameters before a baseline exists. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.
Explain it aloud: What should I learn first about safety relay inputs, reset, outputs and diagnostic boundaries? A defensible short answer is: Start with the operating contract and evidence path: hazard and required function, safe state, input devices, channel structure, discrepancy, reset type, output contacts, external-device monitoring, fault exclusions and diagnostic interface, followed by hazardous demand through input channels, safety-relay logic, force-guided outputs, final switching devices, energy removal, stop result and reset prerequisites. Add advanced features only after the baseline is predictable.
Case 04
predict → observe → prove
Engineering context. cross fault, welded contactor, channel disagreement, reset held, guard cycling, supply loss, diagnostic-wire fault, restart and maintenance bypass. Choose minimum, maximum, simultaneous, delayed or restart conditions that reveal assumptions hidden by the happy path. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.
Controlled setup. Use the “Challenge assumptions” stage of the workflow: test cross fault, welded contactor, channel disagreement, reset held, guard cycling, supply loss, diagnostic-wire fault, restart and maintenance bypass without changing the acceptance contract. The acceptance record should show this result: limits, timing and restart behavior reach defined states. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.
Fault challenge. Introduce or analyse “The failure disappears after reset” as one bounded deviation. Inspect original symptom, histories, diagnostics, timestamps and active cause The working interpretation is that reset changed evidence or state without proving the initiating cause. The next proving action is to reproduce under a controlled condition and preserve pre/post-event data. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.
Review and recovery. The most common trap here is testing only one ideal sequence. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.
Explain it aloud: How do I practise safety relay inputs, reset, outputs and diagnostic boundaries effectively? A defensible short answer is: Use short cases with known initial conditions, a written prediction, one action and an observable result. Then alter a boundary or fault and explain why the evidence changed.
Case 05
predict → observe → prove
Engineering context. a hazard, input, channel, reset, relay, output, final-device, feedback, stopping, calculation or validation mismatch. Preserve the first symptom, divide the system at a measurable boundary and change one condition only after predicting the result. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.
Controlled setup. Use the “Isolate one failure” stage of the workflow: introduce or analyse a hazard, input, channel, reset, relay, output, final-device, feedback, stopping, calculation or validation mismatch and locate the first disagreement. The acceptance record should show this result: the proving action distinguishes the leading hypotheses. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.
Fault challenge. Introduce or analyse “Simulator and target disagree” as one bounded deviation. Inspect model boundary, software version, task timing, I/O behavior, data types and configuration The working interpretation is that a learning model and the intended target do not share one of the recorded assumptions. The next proving action is to reduce the case and verify against current target documentation. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.
Review and recovery. The most common trap here is resetting, forcing or replacing before evidence is retained. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.
Explain it aloud: What counts as proof of competence? A defensible short answer is: A repeatable artifact or system result plus an explanation of the signal path is stronger than time spent, screenshots or a copied answer. Physical competence requires separate supervised evidence.
Case 06
predict → observe → prove
Engineering context. the function designed and validated by qualified personnel on target components under the applicable risk-reduction standard and test plan. Restore normal state, remove temporary changes, repeat affected checks and document which claims remain limited to the learning environment. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.
Controlled setup. Use the “Close the evidence loop” stage of the workflow: complete the function designed and validated by qualified personnel on target components under the applicable risk-reduction standard and test plan and repeat the affected regression cases. The acceptance record should show this result: reference use is complete when inputs, assumptions, units or initial conditions are recorded and the result is independently checked at a useful boundary. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.
Fault challenge. Introduce or analyse “The result cannot be explained” as one bounded deviation. Inspect prediction, observation, proving action, alternative hypotheses and limitations The working interpretation is that activity occurred but the evidence is not yet transferable or reviewable. The next proving action is to have the learner defend the signal path and repeat a changed case. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.
Review and recovery. The most common trap here is treating an acknowledged message or one successful rerun as handover. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.
Explain it aloud: Why test faults and restart behavior? A defensible short answer is: Because a hazard, input, channel, reset, relay, output, final-device, feedback, stopping, calculation or validation mismatch or cross fault, welded contactor, channel disagreement, reset held, guard cycling, supply loss, diagnostic-wire fault, restart and maintenance bypass can expose assumptions that never appear during ideal startup and steady operation.
Answer surface / 07
These concise answers define the operating, training and product boundaries most often missed in broad summaries. The full workflow and diagnostic table above provide the evidence behind them.
It evaluates compatible safety inputs and controls safety-related outputs with defined fault response, diagnostics and reset behavior.
Not by default. The required safety function and performance determine the suitable architecture, components and validation process.
Start with the operating contract and evidence path: hazard and required function, safe state, input devices, channel structure, discrepancy, reset type, output contacts, external-device monitoring, fault exclusions and diagnostic interface, followed by hazardous demand through input channels, safety-relay logic, force-guided outputs, final switching devices, energy removal, stop result and reset prerequisites. Add advanced features only after the baseline is predictable.
Use short cases with known initial conditions, a written prediction, one action and an observable result. Then alter a boundary or fault and explain why the evidence changed.
A repeatable artifact or system result plus an explanation of the signal path is stronger than time spent, screenshots or a copied answer. Physical competence requires separate supervised evidence.
Because a hazard, input, channel, reset, relay, output, final-device, feedback, stopping, calculation or validation mismatch or cross fault, welded contactor, channel disagreement, reset held, guard cycling, supply loss, diagnostic-wire fault, restart and maintenance bypass can expose assumptions that never appear during ideal startup and steady operation.
No. It can build concepts and diagnostic reasoning. Exact firmware, I/O electrical behavior, networking, safety and commissioning require current official tools, documentation and target equipment.
Keep the requirement, initial state, program or configuration, observed values, fault hypothesis, proving action, recovery result and a concise limitations statement.
Continue the signal path / 08