Robot safety scanners are among the most information-rich components on an automated mobile robot or robotic handling cell. They provide a safety-rated protective field, a configurable warning field, and a stream of diagnostic and status data. For warehouse operators, maintenance engineers, and controls teams, the challenge is not always detecting a fault: it is interpreting the data signals correctly and deciding whether a scanner is genuinely degraded, whether the environment is confusing it, or whether a wiring or configuration issue exists elsewhere. This article explains how safety scanner signals behave in practice, how condition monitoring data should be read, and where the decision boundary lies between routine maintenance, component replacement, and escalation to the original equipment manufacturer (OEM) or competent site engineering.
Operating Context: Where the Scanner Sits in the System #
Safety scanners are used in two broad roles. On automated guided vehicles (AGVs) and autonomous mobile robots (AMRs), a scanner at the leading edge creates fields that change with travel direction and speed. In a robotic handling cell, a stationary scanner protects access zones around a robot arm. In both cases the scanner is not a standalone stop button; it is one input to a safety logic system.
The scanner continuously sends two safety-related output signals, typically a redundant pair. It also sends non-safety status outputs, warning zone outputs, and—on most modern units—a serial or Ethernet diagnostic connection. Understanding which signal belongs to which path is the first step in interpreting a fault. A generic OSSD pair, once switched off, must be ignored by the control system until a deliberate reset is performed. Warning zone outputs, by contrast, are informational and can be used for deceleration, path planning, or annunciation. They are not safety-rated.
Field Sets and Speed Dependence #
Most mobile robots do not use a single fixed protective field. The scanner stores several field sets, and the vehicle controller selects one based on speed and direction. At low speed the protective field can be shorter; at higher speed it must reach further to give the braking system enough time. The speed information can arrive via discrete input wires or via a safety-rated fieldbus message. If the speed signal is bad, the scanner may select the wrong field set: too short a field at high speed creates a dangerous condition, and too long a field at low speed causes nuisance stops. This interaction is a common source of confusion, because the scanner itself often records the field set that was active at the moment of a trip.
Data Signals Produced by a Safety Scanner #
An engineering team cannot interpret scanner data without first naming the signals correctly. The following list covers the signal groups found on typical industrial safety laser scanners, without claiming to match any particular vendor:
- OSSD pair (OSSD1, OSSD2): The two safety-rated output signal switching devices. Both must switch together. They are continuously test-pulsed so the downstream safety controller can detect shorts between channels, to +24 V, or to 0 V.
- Warning zone output: A conventional digital output that becomes active when an object enters the configured warning field. It is not part of the safety function.
- Contamination / range reserve output: A diagnostic signal indicating that the measured reflectivity or measurement range is degrading.
- Status and error codes: Provided via a local display, blink pattern, or diagnostic protocol.
- Safety-related fieldbus telegrams: When the scanner is integrated into a safety fieldbus, the OSSD state is transmitted as cyclically redundant data. The diagnostic channel often shares the same physical cable but must be treated as a separate data path.
- Event log / data recorder: Internal storage of field violations, I/O changes, and internal faults, typically readable through configuration software.
Each signal has a different interpretation window. The OSSD pair is the only signal that actively stops a robot. The other signals provide context, pre-warning, and historical evidence.
From Raw Signal to Control Decision #
When the protective field is interrupted, the scanner turns off its OSSD pair. A safety relay or safety PLC sees that transition, opens the contactors or removes the run-permission from the drive, and brings the machine to a controlled stop. On an AMR, the vehicle controller also receives a non-safety request to stop, but the safety-rated stop is independent of the navigation software.
The reset behavior matters. Some systems use automatic restart when the field clears; others require manual confirmation. The scanner itself may not know which restart mode is configured. A technician who cycles power should remember that the downstream safety logic may require a separate reset sequence before the robot moves again.
Test pulses deserve practical attention. Safety outputs are periodically switched off for microseconds while the OSSD output is energized. A downstream safety controller watches for those pulses. If a cable has a short circuit, the pulses propagate unpredictably and the safety controller reports a cross-channel fault. The scanner may look healthy on its diagnostic display because the laser and measurement engine are fine. The root cause is often mechanical damage to a cable, a crushed connector, or incorrect wiring.
Condition Monitoring Basics #
Modern scanners give maintenance teams a rich picture of long-term health. The key monitored parameters are:
- Reflection quality or measurement reserve: How much reflected light the scanner receives from objects at the boundary of the protective field. A low reserve means the window may be dirty or the target surface is poorly reflective.
- Window contamination level: A diagnostic value that increases as dirt builds up on the front window. It is a trend signal; a single reading matters less than a shift over days.
- Internal temperature: Faults at ambient temperature above or below a normal operating band can point to a failing heater, blocked ventilation, or an imminent internal fault.
- Alignment integrity: Especially on fixed installations, the mounting position relative to the floor or guarding is part of the safety function. Vibration or impact can tilt the scanner by a fraction of a degree and change the effective field shape.
- Operating hours and laser runtime: Useful for planning preventive replacement in harsh environments, even when no fault has been recorded.
Condition monitoring is not a substitute for regular functional testing. It does, however, turn a “random” stop into a predictable pattern. A scanner that reports increasing contamination after every cleaning cycle has a different failure mode than one whose contamination is stable but whose mounting has loosened.
Observable Symptoms and Likely Causes #
Warehouse teams see a small set of recurring symptoms. The value of a structured approach is in avoiding immediate blame on the scanner itself.
- Nuisance stops in one specific aisle: Usually environment-related, not scanner degradation. Reflective surfaces, floor markings, hanging film wrap strips, or a new metal rack at grazing angle can interrupt the protective field.
- Frequent contamination alarms: The scanner is probably in a dusty or misty environment, or the cleaning procedure is incorrect. A persistent alarm after a correct cleaning points at the window itself.
- Asymmetric OSSD behavior: When only one channel disconnects or both channels disagree, suspect wiring or output driver electronics.
- Startup faults that clear after a power cycle: These can be internal self-test issues or a downstream safety relay that has latched. Power cycling may reset a fault, but it also erases the event context unless logs are read first.
- Communication drops without stops: A fault in the diagnostic path only. The safety path remains on, which is why the robot keeps running. This separation is useful: an Ethernet drop is not by itself a safety-related event.
Practical Diagnostic Table #
The table below is a starting point for structured fault finding. It is deliberately generic; the OEM documentation and local site procedures always take priority.
| Symptom | Signal behavior | Likely cause | First check |
|---|---|---|---|
| Random stop in one location with no visible object | Both OSSD channels switch off simultaneously; event log records a protective field violation | Reflective surface or floor seam creating a false echo in the protective field | Review scanner diagnostic contour image/reflection map at that map coordinate |
| One OSSD channel toggles, the other stays on | Asymmetric signal; downstream safety controller reports channel or cross-fault | Damaged cable at a flex point, loose connector, short to 0 V or +24 V | Inspect cable strain relief, connector torque, and test continuity |
| Scanner fails to start; error blink code continuously repeats | OSSD pair remains off after power-up | Contaminated window, severe misalignment, or internal initialization fault after interrupted power | Clean window per OEM method; verify mounting; reboot; if repeated, treat as internal fault |
| Warning output fires often but no stop occurs | Warning output toggles repeatedly; OSSD pair remains on | Warning field set too large, or transient reflections within the warning zone only | Compare warning event timestamps with vehicle path; inspect field configuration |
| Diagnostic software loses connection, but robot continues | OSSD remains on; ping fails or packet loss on diagnostic channel | IP conflict, damaged cable, bad switch port, or RF interference | Check IP address, replace patch cable, test switch port |
| Scanner reports reduced range immediately after cleaning | Contamination level looks normal, but measurement reserve is low | Aging window coating, internal optical drift, or permanent film on the glass | Run any available reference check; plan replacement if no offset adjustment is authorized |
| One AMR on a fleet stops more often than identical units | OSSD stops occur at valid objects that other robots ignore | Mounting height or tilt differs from the other units; bracket fatigue after impact | Measure scanner height and angle against the OEM specification |
Use the table as a hypothesis generator, not as a final diagnosis. Before replacing a scanner, confirm the interpretation with the scanner’s own event log and with the safety controller’s diagnostic history.
Collecting Evidence: Logs, Timing, and Context #
Fault finding becomes faster when the evidence is aligned in time. A scanner stop event that occurred at 14:32:17 is hard to explain if the only tool used is the scanner’s internal log. Good practice is to compare three sources:
- AMR or cell controller log: shows the exact path, speed, and message sequence before the stop.
- Safety controller log: records OSSD state transitions, reset requests, and cross-fault messages.
- Scanner diagnostic log: records the active field set, contamination reading, and the nature of the field violation.
When all three timestamps agree, the picture becomes clearer. A stop that appears in all logs as a true protective field violation at a known map coordinate points to the environment. A stop that appears only in the safety controller, with the scanner reporting normal operation, points to a wiring or logic problem. A stop that appears in the scanner log with a simultaneous contamination spike suggests the window was obscured at that moment—for example, by someone walking past with a load that disturbed a hanging strip.
Environmental context matters as much as electrical context. A scanner may behave differently when the morning sun comes through a roller door, when condensation forms on the floor, or when a new line of monorails passes close to the protective field. Take photographs and note lighting, floor dryness, and nearby moving equipment at the time of each event. Over a week of logging, patterns emerge that a single snapshot cannot reveal.
Common Interpretation Errors #
Several interpretation mistakes recur in warehouse maintenance teams, and they are worth naming explicitly.
- Treating the warning zone output as a safety channel. A warning zone is advisory. It can be used to slow a robot, but slowing a robot on a warning zone alone is not a protective measure. If a warning zone output is used to trigger a stop, the stop is not safety-rated and the system design must not rely on it for personnel protection.
- Assuming the OSSD pair is energized whenever the scan is visible on the diagnostic display. The diagnostic display can remain active during a stop. The OSSD
Related Pearl Gateway Guides #