Safety scanners are optoelectronic protective devices that use pulsed infrared light to detect objects and personnel entering predefined areas around moving machinery. On autonomous mobile robots (AMRs), automated handling cells, and mixed-traffic warehouse floors, these scanners are frequently the primary means of reducing the risk of collision between a machine and a person. Selecting the correct scanner, configuring its fields, and defining its application boundaries requires more than a reading of the brochure. A scanner that is oversized, undersized, or installed at an improper height can create nuisance trips, hidden blind spots, or a false sense of coverage. This article discusses the technical criteria that influence scanner selection, the physical and functional boundaries that govern their use, and the practical diagnostics that help maintenance teams distinguish a genuine safety demand from a configuration or contamination problem.
The Role of Safety Scanners in Mobile Robot Systems #
A safety scanner is typically one component in a layered control architecture. In a typical AMR, the scanner connects to a safety interface, which may be a safety-rated PLC, a safety relay module, or a drive-integrated safety controller. The scanner emits signals, often called OSSD outputs, that switch between an ON and OFF state based on whether an object is detected inside a configured protective field. When the scanner detects an intrusion, the safety chain responds by commanding a safe stop, a reduced speed, or a warning signal, depending on how the system is designed.
The scanner does not manage navigation. The robot’s navigation LiDAR or vision system builds maps, localizes the vehicle, and plans paths. The safety scanner is the last non-contact layer of protection, acting independently of the navigation system. This separation is intentional. If the navigation system reports the wrong position, the scanner still monitors the immediate vicinity and can stop the robot before it strikes an object. The same principle applies in handling cells: the scanner protects access points and overlapping zones, while the cell controller coordinates motion sequences. Maintenance teams must understand this separation because a failure to stop is often misattributed to the scanner when the real fault lies in the interface wiring, the safety controller, or the drive’s safe torque off circuit.
Charging stations introduce another interaction. When an AMR docks, the scanner must continue to protect personnel approaching the connector area while tolerating the structure of the charging station itself. Blanking zones, which mask stationary fixtures, are common. If the station shifts by a few millimeters, the scanner may either see the station and request a stop or fail to see a person in the gap. The scanner does not know that charging is in progress; it only knows the field configuration that is currently active. The fleet management system and the charger controller decide when it is safe to energize the contacts. This division of responsibility is a core concept for anyone maintaining these systems.
Operational Principles and Field Anatomy #
Safety scanners work by emitting short pulses of infrared light and measuring the time required for the reflection to return. The scanner rotates a mirror or uses a solid-state array to sweep a scan plane, typically across a horizontal arc of 180 to 275 degrees. Each pulse produces a point in a two-dimensional polar map around the scanner. The controller compares these points against one or more configured polygons, which are the protective fields.
Two field types are used in most applications. The protective field, sometimes called the safety zone, initiates a safe stop when a sufficiently large object enters it. The warning field, located further outward, initiates a non-safety response such as reduced speed, audible alarm, or a signal to the traffic controller. The two fields are configured as pairs, and multiple pairs can be stored in the device. The active pair is selected by discrete inputs, allowing the robot to use a wide, slow-speed field in open aisles and a narrow, high-speed field on straight sections. This zone switching is a normal operational feature, not a safety override, because each field pair is individually validated during commissioning.
Two parameters govern detection performance: resolution and response time. Resolution refers to the minimum object size that reliably triggers a response. A scanner with higher angular resolution can detect a thin object such as a fork tine earlier, but only if the object remains in the scan plane. Response time is the interval between the scanner detecting an object and the OSSD output changing state. The total stopping distance of the vehicle, which includes controller processing, drive braking, and any sliding distance, must fit within the distance from the field boundary to the nearest hazardous part of the machine. This calculation is the core of every valid safety scanner installation, and it is usually documented in the OEM’s safety validation.
Core Selection Criteria #
Selecting a scanner begins with a hazard analysis, not with a brand preference. The following criteria are generally applicable across all modern devices.
Object Reflectivity and Detection Capability #
Scanners rely on reflected light. Dark clothing, matte black plastic, and glossy painted surfaces return different amounts of energy. A scanner certified for a certain protective field size under laboratory conditions may lose range in a dusty warehouse with low-reflective pallets. The correct selection is based on the lowest reflectivity object that must be detected, which is usually a human leg or body. If the risk assessment identifies other hazards, such as protruding steel edges, the scanner may need to detect narrower objects, which reduces the achievable field size. Always verify the selected device’s detection capability against the least reflective material present in the work zone, and never rely on the maximum range specification alone.
Field Range and Angular Coverage #
The scanner must see far enough ahead to allow the vehicle to stop without changing the interaction with other vehicles. This distance is a function of speed, response time, and degradation factors such as worn tires or wet floors. The angular opening must cover the vehicle’s width plus margins for curved paths and swiveling loads. A scanner that covers 190 degrees may be adequate for a unit that always moves forward, while a robot that rotates in place may require 270 degrees of coverage or additional side-mounted scanners. The mounting height determines which body parts are detected. A high mount protects the torso but may miss a child or a low obstacle; a low mount protects legs but can be blinded by floor pallets and rack legs.
Risk Reduction and Interface Architecture #
The scanner must have enough safety outputs and inputs to handle the required control scheme. A simple stop function needs one pair of OSSD outputs. A speed reduction scheme needs additional protected outputs or communication over a safety-rated bus. Some scanners support multiple independent fields, while others support only a single field pair with a fixed warning zone. The number of zone-switching inputs must match the number of distinct operating conditions, which are determined by the risk assessment. Choosing a device with unused capability is acceptable, but choosing one with insufficient inputs forces compromises during commissioning.
Environmental Factors #
Dust, humidity, and ambient lighting affect scanner performance. Optical windows accumulate grease, dust, and water film. Scanners with internal heaters are preferable for refrigerated warehouses because condensation changes reflection. Strong sunlight shining directly into the window can saturate the receiver and cause faults. External shielding, correct mounting orientation, and regular cleaning schedules mitigate these issues. The selection process should include a review of seasonal conditions, not just the current warehouse state.
Application Boundary 1: Dynamic Fleet Traffic vs Fixed Hazard Points #
In a mixed fleet, multiple AMRs and forklifts share aisles. Each robot’s scanner protects the space immediately around that robot. The scanner cannot see around corners, through racking, or beyond the maximum configured field. Therefore, intersections are controlled by a higher-level traffic system or by rule-based right-of-way logic. The boundary of scanner responsibility ends where the robot’s actual footprint and projected path no longer align with the protective field geometry.
A common misunderstanding is that a scanner with a large range can replace a traffic management system. It cannot. The scanner detects objects present at the moment of scanning. It does not predict that a vehicle approaching from behind a rack will enter the aisle in two seconds. The traffic controller coordinates reservations, while the scanner handles the immediate reaction. When a vehicle is stopped at an intersection, the scanner still detects a person stepping in front of it, which the traffic controller cannot do. These two functions have different boundaries, and both are necessary.
Fixed hazard points, such as charging stations, conveyors, and lift gates, often require both a stationary scanner and a vehicle-mounted scanner. The stationary scanner protects the entrance to the hazard, while the vehicle scanner protects the moving load. The two systems must be interlocked so that the vehicle cannot enter the guarded area while the stationary scanner has an active field violation. Site engineers must mark these boundaries explicitly in the functional specification, or the commissioning team may leave an unguarded route that neither system covers completely.
Application Boundary 2: Speed Control and Zone Switching #
Zone switching is the most flexible feature of modern safety scanners, and it is also the most frequently misinterpreted. Consider a robot that travels at 1.8 m/s in open aisles and 0.6 m/s near workstations. The scanner can be configured with two field pairs. Pair A has a large protective field that brings the robot to a stop from 1.8 m/s within the available sight distance. Pair B has a smaller protective field and a far warning field that triggers a demand for 0.6 m/s. The navigation controller selects the appropriate field pair based on the vehicle speed and location.
The critical boundary here is that the scanner does not decide the speed. The scanner only reports whether an object is inside the active protection field. The drive system must be capable of responding to the demand. If the drive fails to reach the lower speed, the near protective field in Pair B may not be large enough to stop the robot in time. For this reason, speed-controlled applications should be monitored by an independent speed check function, or the distance between the warning field and the protective field must be calculated using the maximum achievable speed, not the commanded speed. A robot that is commanded to slow down but does not actually slow down is a latent hazard, and the scanner alone cannot detect it.
Application boundary decisions also affect start-up and restart. After the scanner has caused a stop, the robot often requires a manual reset at a safe location. Some configurations permit automatic restart if the field is clear after a short delay. The boundary is determined by the risk assessment, not by convenience. If any possibility exists that a person was struck and is lying in the warning field, automatic restart must not be enabled. This decision belongs to the site’s engineering review.
Application Boundary 3: Handling Cells and Collaborative Workspaces #
Fixed scanners are commonly mounted at the entry points of robotic handling cells, where they supplement interlock gates and light curtains. The scanner detects a person entering the protective area and sends a stop demand to the cell controller. A mobile scanner mounted on a robot can protect the front of the cell’s moving platform, but it cannot see behind columns or under the platform. These blind areas must be covered by other devices or marked as inaccessible.
In collaborative applications, a scanner may be used to reduce the robot speed when a person approaches, allowing the robot to continue working at a safe speed. The boundary is that the scanner detects only in its plane. If a person reaches over a barrier and places a hand in the robot’s work envelope above the scan plane, the scanner will not see it. Additional devices, such as two-dimensional light curtains or safety mats, may be required. The OEM should provide a documented risk assessment for the specific application, and the site must not add speed reduction zones without revalidating the full system.
Handling cells also involve recovery. When a scanner has stopped the robot, maintenance staff often need to enter the cell to remove a jammed product. The scanner cannot simply be disabled while the robot is reset. Safe recovery must use a controlled mode with reduced speed and torque, or the robot must be brought to a known safe state using the manufacturer’s procedures. Generic advice to “move the robot manually with a teach pendant” is dangerous unless the integrator has confirmed that the safety chain is still active in that mode.
Observable Symptoms and Troubleshooting #
Operators and maintenance staff see symptoms, not causes. The table below lists common symptoms, probable underlying causes, evidence to collect, and the first check that should be performed. The table is diagnostic guidance only; any fault must be handled according to OEM instructions and site lockout procedures.
| Symptom | Likely Cause | Evidence to Collect | Initial Check |
|---|---|---|---|
| Field intrusion fault with no visible object in the area | Reflective surface, dirt on the optical window, or conflicting light from another scanner | Fault timestamp, scanner status log, photograph of the field area, cleaning history | Inspect the window for smudges or scratches; look for new reflective signage or polish on the floor |
| Frequent speed reductions in a specific aisle | Warning field overshoots the aisle, or rack edge reflectivity is near the threshold | Field configuration, aisle width measurement, vehicle position at the time of the event | Review the configured field geometry against an accurate CAD drawing of the aisle |
| Stop triggered at the charging station during docking | Mechanical misalignment, scanner mount shift, or charging contact arcing interference | Docking offset measurement, scanner alignment fixture results, power supply voltage trend | Verify the scanner mounting bolts and the docking alignment pins; check the window for residue |
| Scanner does not complete startup self-test | Internal fault, low supply voltage, or severe window contamination | Fault code, supply voltage at the moment of failure, ambient temperature | Measure the supply voltage at the scanner connector under load; cycle power after cooling |
| Safe stop activates only when the robot carries a specific load | The load changes the robot’s vibration mode, causing the scanner mount to flex | Load mass, vibration measurement during travel, mount bracket inspection | Retorque the mount bracket and inspect for cracks or compliance |
Evidence collection should follow a standard sequence. Record the fault code, the time, the robot position, the active field pair, and the ambient conditions. Use the scanner’s configuration software to export the log and the field geometry. This data is valuable for the OEM or integrator because it converts a vague complaint into a reproducible event. Do not immediately alter field size or sensitivity; changing the configuration without understanding the root cause can create a delayed hazard.
Common Interpretation Errors #
Several interpretation errors recur across warehouse maintenance teams and integrators alike. Recognizing these errors reduces unnecessary downtime and prevents dangerous modifications.
- Treating the warning field as a safety field. The warning field is not rated for stop
Related Pearl Gateway Guides #