Restart authorization is the deliberate, evidence-based decision that a stopped system can be safely returned to service. In a modern warehouse, restarting a conveyor, sorter, or automated storage and retrieval machine may appear routine, but it is one of the highest-risk moments in the operational cycle. Personnel may still be inside maintenance zones, guards may be improperly seated, sensors may be misaligned, and control logic may retain latent faults. This article examines the inspection points and early warning signs that should inform any restart decision. It is written for warehouse operators, maintenance engineers, and controls teams who need a structured way to think about safe intervention, access control, and disciplined recovery. The content is educational and general; it does not replace site procedures, OEM documentation, lockout requirements, or competent engineering judgment.
The Operating Context of Restart Authorization #
A system stop is rarely a single event. It can be a planned shutdown for maintenance, a fault-triggered halt, a power loss, a product jam, an operator-initiated stop, or an emergency stop. Each of these creates a distinct restart context. The authorization process must account for how the stop occurred, how long the system was inactive, and what actions were taken during the downtime. It must also account for what may have changed: a servicer who has finished work, a part that has been replaced, a guard that has been removed, or a sensor that has been cleaned.
Restart authorization is not the same as pushing a green button. It is a structured decision gate. The person authorizing the restart must have confidence in several facts: all personnel are clear of hazard zones, all physical safeguards are restored and functional, all energy sources are controlled and then properly re-applied, and the control system is in a known, stable state. The decision must be based on documented evidence, not on the assumption that because the stop was routine, the condition is unchanged.
Warehouse environments add particular complexity. Multiple contractors may work on the same line. Shift changes can interrupt a maintenance task. Product overflow in a buffer lane can conceal a hazard. Mobile equipment such as reach trucks and pallet jacks may enter and leave zones that are momentarily clear. A disciplined restart authorization process is therefore a human factors control as much as a technical one. It formalizes communication between operations, maintenance, and controls teams so that no one authorizes a restart with incomplete information.
Defining the Restart Boundary #
Before inspecting anything, the team must know exactly what is being restarted. A “restart” may apply to a single motor, a zone of conveyors, an entire sorter, or a full storage and retrieval aisle. The boundary is not simply what the PLC sees; it is the physical space affected by the machinery. The person authorizing the restart must know which guard doors interlock with which zones, which emergency stop circuits feed which contactors, and which personnel access points fall within the risk perimeter.
Boundary definition has two parts. The first is the equipment boundary: the machines, drives, ancillaries, and control systems that will be returned to service. The second is the personnel boundary: the physical areas in which a restart could create a hazard for someone who is not yet clear of the machine. In many warehouse incidents, the two boundaries do not match. An operator may clear a four-meter conveyor section, but the controls team starts a downstream pump that feeds product into that section from a hidden transfer. Defining the restart boundary before inspection is a simple but critical step in preventing such mismatches.
The boundary should be recorded. It can be noted on a whiteboard, a work order, or a handheld checklist. The record should name the equipment, the controlling panel, the zones affected, and any personnel who have accessed the area. That record is the basis for the restart conversation. If the boundary was changed during the work, it must be communicated and agreed upon again before restart.
Component Interactions in the Restart Chain #
Restart authorization requires a mental model of how the components interact. A warehouse automation system is a chain of interdependent elements. Electrical power feeds the distribution board. The board feeds drives and contactors. The contactors control motors. The motors move belts and rollers. Sensors report position, presence, and speed. The PLC reads the sensors, executes logic, and sends commands. Safety relays and light curtains sit between the hard-wired safety circuit and the control logic. Any single component can affect the entire chain, but the failure mode is not always visible at the point of failure.
Consider a simple example: a pressure switch on a pneumatic system. If the pressure switch has drifted out of calibration, it may report normal pressure even when the pneumatic actuator cannot deliver enough force to move a diverter. The PLC sees “pressure OK” and allows the restart. The diverter moves halfway. A downstream package collides with the partially moved diverter, causing a jam. The jam trips a fault, the system stops again, and the team is left chasing a mechanical problem that was actually a calibration problem.
Another interaction is between the safety circuit and the control logic. A safety relay that is manually reset allows power to return to the machine’s control circuit, but the PLC may still be in an event-log state that prevents normal operation. The operator restarts the machine, sees no motion, and assumes a second fault has occurred. In reality, the PLC required a specific sequence of acknowledgment. Understanding these interaction layers helps the inspection team know where to look when a restart appears to be blocked despite all physical checks appearing normal.
Primary Inspection Points #
The physical inspection should follow a consistent sequence. While sites vary, the following inspection points are broadly applicable.
Personnel and Access Control #
Confirm that all personnel have exited the hazard zone. This is not simply a visual check. The inspection must verify that no one is inside a guard enclosure, beneath a lift, in a pit, or in a servicing aisle. If multiple teams were involved, each team leader must confirm that their people are out and their tools are removed. The presence of a portable work light, a tool roll, or a ladder in a hazard zone is evidence that a task may still be in progress.
Lockout and Tagout Verification #
Each energy isolation point must be verified in its correct position. A locked-off breaker, valve, or plug is not proof that the energy is isolated; the verification step involves attempting to start the system or testing for zero energy in the expected method prescribed by site procedures. The physical lock and tag are reminders, not validation devices. The person authorizing restart must check that no locks remain on isolation points, unless the restart is part of a deliberate re-energization sequence in which locks are removed step by step.
Guards and Interlocks #
All fixed and movable guards must be in position and secured. Interlock switches must be correctly aligned and the actuating cams must be free of wear. A guard that appears closed but does not depress the interlock actuator will not satisfy the safety circuit. Conversely, a guard that is forced closed with a damaged hinge may allow the interlock to align intermittently. Inspect the hinge and the latch, not only the switch.
Emergency Stop Devices #
E-stop buttons, pull cords, and foot switches should be in the released position. The inspection should confirm that each E-stop is not latched, and that resetting them is done deliberately. If multiple E-stops were pressed during an incident, all should be released before any restart is attempted. The reset action should be coordinated, because some safety circuits require all E-stops to be reset before the safety relay will re-energize, whereas others require a specific sequence.
Presence-Sensing Devices #
Light curtains, safety laser scanners, and area scanners must be clean, aligned, and free of obstructions. A thin layer of plastic wrap or dust on a light curtain emitter can cause intermittent blocking. A scanner mounted at an angle may have a reduced detection zone without any visible damage. Verify beam alignment indicators and perform the walk-through test that the site procedure defines. If the device has an automatic test cycle, confirm that it completed successfully.
Material and Product Flow Paths #
Inspect the conveyor deck, chutes, and transfer areas for leftover product, packing material, broken pallet boards, or tools. A partially elevated pallet in a transfer station can cause a restart jam. A stray strap or film hanging from a load can wrap around a drive roller. The inspection should look through the entire path, not just the zone where the stop occurred.
Drive and Motor Condition #
For directly visible motors and gearboxes, check for signs of recent overheating, unusual noise, or oil leakage. A warm motor that has just been stopped is not necessarily a fault, but a motor that is hot to the touch when the system was idle for an extended time may indicate a stuck contactor or an energized brake. A gearbox that is weeping oil may have lost enough lubricant to create a risk on restart.
Control Panel Status and Fault Logs #
Open the control panel only if authorized and in compliance with site electrical safety rules. Look at the PLC input/output status, drive fault indications, and safety relay status indicators. Note any alarms that are active. The fault log should be reviewed by a competent person who can distinguish between historical events and current conditions. The absence of a displayed fault does not mean the system is healthy; some faults clear automatically when power is cycled, leaving no clue that the underlying condition remains.
Early Warning Signs and Observable Symptoms #
It is tempting to judge the condition of a warehouse system only at the moment of restart. A more reliable approach is to treat the restart inspection as an opportunity to identify early warning signs that predict future problems. The table below lists common observable symptoms and the interpretation that a competent team should consider.
| Symptom | Potential Condition | Recommended Check | Action Boundary |
|---|---|---|---|
| Intermittent sensor dropout | Debris, moisture, or degraded emitter/receiver | Clean lenses, check alignment, inspect cable for chafing | Do not restart until the sensor indicates stable, repeatable output |
| Unusual motor sound on manual jog | Bearing wear, coupling misalignment, or abnormal load | Listen with a mechanics stethoscope, measure vibration if available | Stop the jog, escalate to maintenance, do not authorize full restart |
| E-stop button does not reset smoothly | Dirt ingress, broken latch mechanism, or damaged actuator | Operate the button through its full travel; inspect the latch | Replace the device before restart authorization |
| Guard interlock indicator flickers | Misalignment or loose mounting bracket | Check bracket bolts, verify actuator alignment with feeler gauge if available | Realign and secure before restart; replace bracket if deformed |
| Conveyor belt drifts to one side | Idler wear or belt tension imbalance | Visually observe belt tracking over several revolutions | Track the belt or escalate; drifting can cause edge damage and jam |
| Pneumatic pressure drops quickly after isolation | Leak in cylinder or hose, or open drain valve | Listen for hissing, feel for air flow, check the lubricator/drain | Repair leak before restart; low pressure can cause partial motion |
| PLC fault log shows repeated, unexplained resets | Loose wiring, failing power supply, or internal heat issue | Check terminal tightness, panel cooling, and 24V supply levels | Do not authorize restart until the root cause is identified |
| Product accumulation in a buffer lane | Downstream sensor failure or timing misadjustment | Manually confirm sensor state with a test piece | Correct the sensor or timing logic before restarting the lane |
The table is not an exhaustive checklist, nor does it replace manufacturer fault codes. It is a guide to the kind of evidence that should slow down the restart. If any symptom appears marginal, the conservative decision is to investigate further. A restart authorization that is delayed by one hour is cheaper than a restart authorization that leads to a secondary incident.
Evidence Collection and Documentation #
A restart authorization is more defensible when it is based on recorded evidence. The evidence does not need to be elaborate, but it should be sufficient to show that the inspection was performed and the conditions were acceptable. A simple log should include the following elements: the equipment or zone being restarted, the date and time, the reason for the original stop, the name of the person performing the inspection, the name of the person authorizing the restart, the key checks performed, and any discrepancies found and resolved.
Photographs are useful evidence. A picture of a cleared conveyor path, a properly seated guard, or a clean sensor face can resolve a dispute later, especially if there is an incident after the restart. Photographs should not be used as a substitute for inspecting the physical condition, but they are a good addition to the written log. On systems with a safety PLC or a data recorder, the event log should be exported or note the relevant event sequence before the log is overwritten.
It is also important to document the communication chain. If a maintenance technician found a broken tension spring and replaced it, the person authorizing the restart needs to know that the replacement was done correctly and that the new part is the right type. Verbal communication is often incomplete. A written handover note on the work order, or a direct phone call with a specific handover file, is preferable to relying on memory.
Common Interpretation Errors #
Several interpretation errors recur in restart decisions. Recognizing them can prevent a hasty authorization.
The first error is treating “all indications show ready” as proof of safety. Many control systems are designed to show a ready state when the safety circuit is closed and all sensors are in their normal positions. But a safety circuit being closed does not mean a guard is mechanically sound; it only means the switch is actuated. A stuck interlock actuator can produce a ready state while the guard is barely hanging. The ready lamp should be treated as one input, not as a certification.
The second error is ignoring the difference between a cleared fault and a corrected fault. A fault that clears when a jammed product is removed is cleared. A fault that clears on its own without any corrective action is suspicious. If the PLC logs show a sensor error that disappeared without human intervention, and the sensor is known to be sensitive to dust or condensation, the restart inspection should include a deliberate verification of that sensor.
The third error is assuming that because a stop was short, the system is unchanged. A five-minute stop caused by a power dip can leave drives in an unexpected state. A short stop during shift change may result in unfinished work if a colleague was in the middle of adjusting a sensor. The duration of the stop does not determine the depth of the inspection.
The fourth error is accepting a verbal confirmation without a physical verification. A technician may say that all guards are back in place, but the technician may have only looked at the guards near the work area, not the entire line. The restart authorizer is accountable for the decision; reliance on incomplete confirmation is a common root cause of incidents.
Maintenance Implications #
Restart inspections reveal more than whether a machine is safe to run. They also reveal the health of the machine. A machine that requires a lengthy inspection before every restart is a machine that is telling the team something about its condition. For example, if a light curtain needs its lenses cleaned every time the machine is stopped, the cleaning is a symptom of a broader issue: perhaps the machine is installed in a dusty area without adequate guarding, or perhaps there is a source of fine debris nearby that should be addressed.
Intermittent warning signs found during a restart inspection should be transferred to the maintenance plan. If a conveyor belt is tracking slightly to the right and the restart inspection catches it, the correction may be straightforward, but the underlying cause—worn idler, uneven tension, or a bent frame—should be recorded for a scheduled maintenance task. Restart inspections are therefore a complementary data source to periodic maintenance schedules. They are not a replacement for them.
Maintenance teams should also be aware that a restart is a stress test. Starting a motor under load draws higher current. A slightly dry bearing may be undetectable at low speed but cause a thermal trip within seconds of full-speed operation. If a restart is followed by an immediate fault, the maintenance team should look for conditions that only appear under load: bearing wear, coupling misalignment, unbalanced product loads, or a conveyor that is carrying more weight than it was designed for.
Decision Boundaries and Escalation #
Not every discrepancy found during an inspection can be resolved on the spot. The decision boundary is the line between a condition that is safe to proceed with and a condition that requires escalation. The boundary should be defined by site procedures, but in general it follows a simple rule: any condition that could create an unexpected movement, a fall, an entrapment, or a release of stored energy is a stop-and-escalate condition. Any condition that only affects efficiency, such as a slightly dirty barcode sensor that is still reading correctly, may be noted and addressed after the restart, provided it does not affect safety.
Another decision boundary involves the authority to restart. The person authorizing the restart must be clearly identified. In many sites, the control systems engineer or the shift maintenance lead has the authority, while an operator does not. The boundary should be respected even if the responsible person is not immediately available. Waiting for the correct authority is part of a disciplined recovery process.
Escalation should occur when there is uncertainty. If the inspection team cannot agree on whether a guard is properly aligned, or if a fault code is not in the standard diagnostic table, the decision should be escalated to a more experienced engineer or to the OEM support line. Using the OEM documentation is preferable to guessing. If a suspected fault could affect the safety function, the restart should not occur.
It is also important to define the boundary for re-stop. If an inspection starts and then finds a condition that requires additional maintenance, the equipment should be returned to a locked-out state before any further work. A restart authorization that is partially completed should not leave the system in a state where some energy is applied and some guards are removed. The process is binary: either the system is fully safe to restart, or it is not ready and remains isolated.
Key Takeaways #
- Restart authorization is a decision gate based on documented evidence, not a simple action of pressing a reset button or a run button.
- Define the equipment and personnel boundaries before inspecting; a restart must cover the entire affected zone, not just the visible fault area.
- Inspect personnel access, lockout state, guards, interlocks, E-stops, presence-sensing devices, flow paths, and drive condition in a consistent sequence.
- Use observable symptoms such as intermittent sensor dropout, flickering interlock indicators, and unusual motor sounds as early warning signs of underlying conditions.
- Collect and record evidence, including photos, fault log excerpts, and handover notes, so that the restart decision is traceable and accountable.
- Avoid common interpretation errors: do not confuse a ready status with physical safety, a cleared fault with a corrected fault, or a short stop with a negligible event.
- Route recurring findings from restart inspections into the periodic maintenance plan; a restart inspection is a real opportunity to detect wear and drift.
- Escalate when there is uncertainty or when a condition could lead to unexpected movement, entrapment, or energy release; do not bypass safety devices to force a restart. Site procedures, lockout requirements, OEM documentation, and competent engineering judgment always take priority over this general guidance.