
62
9M02-8978-A002-EN
Version 14
Safe-E-
Stop™
User Guide
Appendix VII: Safety Manual for Safe-E-Stop
Functions
The Safe-E-Stop product has been designed to provide a wireless Emergency Stop function. Since it is a
wireless system, any loss of communication between the Machine Safety Device (MSD) and any of the
linked Personal Safety Devices (PSDs) will result in the machine stopping.
A safety function must be fully automatic hence there is one safety function in the system; this is the
communication loss function. This function is controlled by the MSD, it ensures that if communication with
one of the linked PSDs is lost for more than 2 seconds, the MSD will open all of its safety relays. This
safety function has a safety performance level of SIL3 according to IEC61508:2010, vol 1-7.
The Emergency Stop function is implemented between any linked PSD and the MSD. The Emergency
Stop function is not fully automatic because the initiating event occurs when an operator presses the
emergency stop switch. The design of the system from this point to the opening of the E-Stop safety
relays of the MSD has been designed to the Systematic Capability of 3 as per IEC61508:2010, vol 1-7.
Once the E-Stop event is triggered, the Stop function has a safety performance level of SIL3 according to
IEC61508:2010 vol 1-7.
Failure Modes
PSD
Any failure of the PSD will lead to the PSD transitioning into a Safe State. In Safe State, the PSD will
terminate all wireless communications; the MSD will as a consequence detect a communication loss and
open all the safety relays (E-Stop and COMM LOSS), this will bring the machine to a safe state. The
display on the PSD will show ERROR 1 and the Error LED will flash.
MSD
Any failure of the MSD will lead to the MSD transitioning into a Safe State. In Safe State, the MSD will
open all safety relays and stop all wireless communication with the PSDs. The display on the MSD will
show ERROR 1 and the Error LED will flash.
Operational Constraints
The PSD is a personal safety device; it is the responsibility of the operator/user to verify that the PSD is
linked. In an environment where multiple systems are in use, the operators need to be trained to verify
that the correct PSD is in use for the machine being used. Several methods are suggested to help the
operator select the right PSD; clear identification of the machine under control that corresponds with the
configuration labels on the PSD side labels can be used. A color code can also be used such as the
colored logo label option or the different colored PSD option. Finally, by connecting a PLC using the
Ethernet/IP interface, the PLC could provide some indication of each PSD that is connected and by using
the green button on the PSD the PLC could also provide a visual or audible indication that it is in fact
acting on the intended machine.