Hello everyone. Machine we shipped six months ago, a small polishing spindle in an enclosure. Compact GuardLogix 1769-L30ERMS, TLS3-GD2 solenoid lock on the door, spindle on a PF525 with STO off the safety outputs.
Customer rang this morning. Operator hits Stop, the lock lets go about a second later and the spindle's still turning. With a heavy polishing wheel it takes eight seconds or so to run down. Nobody got hurt, but somebody opened that door onto a spinning wheel.
I'll own the logic. Stop drops the STO, a timer in the safety task runs 1000 ms, then the lock output releases. I took the 1000 ms off the bench, where the ramp had it stopped inside a second with a small wheel, and I checked nothing else.
They're asking for a faster brake. Any thoughts on what that release should really be waiting on?
Trend it before anything else. Spindle speed from Stop to zero, heaviest wheel, no load, worn belt if it has one. And to be clear, right now the lock is waiting on a timer off the Stop command, not on anything that knows the spindle stopped?
Timer, off the Stop command. Nothing that knows the speed. On STO the drive coasts, so the ramp means nothing, I can see that now. I think the bench number was the ramp and never the coast.
What does the risk assessment say about access while the spindle is rotating? That decides whether a validated time delay is acceptable at all, or whether you need safe speed monitoring. Ask the customer's safety person for that page. One thing to do tomorrow: measure the coast with the heaviest wheel they actually run, not the one you shipped.
Two ways to do this properly, and neither one is a timer off Stop.
Standstill from a safe speed monitor: encoder or a safety rated speed input into the safety controller, or a drive that gives you safe standstill, and the lock only lets go when that says zero. Best answer, costs hardware.
Time delay: allowed if the risk assessment allows it, but the delay is measured, not guessed. Worst case coast, heaviest wheel, no load, worn belt, plus a margin the safety engineer sets, and it lives in the safety task and gets documented. Your 1000 ms is a bench ramp number, it was never the coast time. On an L30ERMS with no safety encoder, the timed route is probably what you'll do this month.
Measured it with the customer's big wheel on, no load, belt as found. 11 s, worst of five. So my 1000 ms was out by a factor of ten. Trend screenshot attached for the file.
And the timer lives in the safety task, not the standard one.
Changed it. The lock output now waits on a safety task timer started when the STO drops, preset set by the customer's safety engineer comfortably over the 11 s, documented against the measured coast. Safety task re-signed, tested with the big wheel ten times, door stays shut until it's stopped.
So the release was tied to the Stop command through a bench timer and had nothing to do with standstill. Now it's a validated delay in the safety task off the measured worst case coast.
Customer still wants it faster, so a safe speed monitor goes on the quote for the next machine. The brake idea I've left alone. Thanks mattr and mikko.
Coast time with the heaviest wheel goes in the validation file, not the bench number.