What can hurt you, the rules that prevent it, and the safeguards at S2 that are not yet confirmed.
Start here
This section says what can hurt you around this arm, the rules that prevent it, which safety functions the machine has and what they are not, and which safeguards at the cell nobody has confirmed yet. If you read only one part of this site before going near the arm, read this one.
Stay out of the arm's working area while it runs. UFACTORY says no people should be in it while the arm is operating1.
An arm that looks stopped may be waiting for a signal and about to move. Treat it as moving2.
S2 in one line: S2 is the xArm 850 arm that picks up incoming material and moves it between receiving, staging and production45.
Not yet confirmed at S2
Nobody has confirmed these safeguards at the physical S2 cell yet. Until someone does, assume none of them exist.
The S2 installation's risk assessment has not been confirmed: whether one exists for the complete S2 application (arm, gripper, workpieces, S1/S3/S4/S6 interfaces), who performed and signed it, and whether it was redone after installation as UFACTORY requires.6
The locations of the S2 emergency stops are unknown: whether any e-stop buttons beyond the control box button are wired to EI, where they are, and whether S2 shares an emergency stop circuit with S6 or other stations.7
The position of the S2 control box is unknown: whether it is outside the arm's working range, at 0.6 to 1.5 m height, with its e-stop reachable.8
S2's guarding and protective devices are unknown: whether fences, interlocked doors, light curtains, safety mats or laser scanners are wired to the SI protective stop input, or whether SI is still in its factory default state with no additional safety equipment.9
It is unknown whether S2 is intended to be a collaborative application, with people entering the arm's working area during automatic operation. If it is, it is also unknown which collaborative method is used and how it has been validated.10
It is unknown whether S2's working range, including the gripper, is marked on the floor or bench as UFACTORY recommends.11
It is unknown what the S2 gripper does to a held workpiece on power loss or e-stop (holds or drops), and what lies beneath the arm's path if a part drops.12
Whether S11 IntelliAware has any authority to stop or slow S2, whether it is a safety-rated protective device, and who owns S11 are not documented (Q14f). The diagram calls S11 'monitoring of ... safety', which does not make it a safeguard.13
Scroll
Look back
A question from earlier on, to keep it fresh. Skip it if you like; nothing depends on it.
Choose your depth
Four depths, one page. Switch at any time: every tier stays open to everyone. What the four tiers mean
1Beginner
What can hurt you, and how not to get hurt
For: Anyone with no robotics background: a visitor, a new operator, a manager Kind of task: Recognise and recall, with plain-language explanations and pictures
In this part you learn what a robot arm can do to a person, the rules that keep you out of harm's way, and what to do in an emergency. No robotics background is needed. Read it before you go near the arm, even if you only mean to watch.
What can hurt you
A moving arm can strike you, or catch part of your body between itself and something else14.
It can crush or trap a hand, an arm or your head between the arm, its tool or the workpiece and other equipment, such as a table edge or a conveyor14.
A part can be thrown or dropped when a grip fails, and hit you14.
Other ways to get hurt
Items can drop from the arm if power is lost by accident, or if the gripper holds them unstably15.
The arm and its control box get hot in operation. Do not touch them while they run, or just after16.
Never put your fingers into the connector at the tool end of the arm17.
Take particular care when the arm is running fast18.
Electrical hazards
Do not connect or disconnect the arm cable while the system is plugged into mains power. It can give you an electric shock19.
The controller's power supply can hold a high voltage for several hours after it is switched off. Do not take it apart20.
The rules
Nobody goes into the arm's working area while it is running1.
Treat a still arm as a moving one. It may be waiting for a signal and about to move2.
Mark the arm's range of motion on the floor with a line, and include the reach of its tool, such as a gripper or suction cup21.
The working range UFACTORY publishes leaves the tool out, so the zone the arm can reach with its tool is larger than the published range22.
Only trained people operate it. UFACTORY requires operators to be trained in its software24.
The working range seen from above, with the 850 mm reach marked25. Image: UFACTORY
When accidents happen
OSHA says many robot accidents happen during work that is not routine, such as programming, maintenance, testing, setup or adjustment, when someone may be inside the robot's working envelope26.
Teaching by hand is one of those moments. In manual mode a person moves the arm directly to teach it positions27.
Before manual mode is switched on, the mounting direction and the payload setting must be correct. If they are wrong, the arm may not stay still28.
The emergency stop
The emergency stop button sits on the control box3. Image: UFACTORY
The control box must sit outside the arm's working range, so that the button can be reached in an emergency29. UFACTORY says to place it at a height of 0.6 m to 1.5 m30.
When the button is pressed, the arm does not freeze in place. It brakes slightly and falls a little31.
The emergency stop is not a way to reduce risk; UFACTORY says so plainly32. What keeps you safe is staying out of the working area while the arm runs1.
The STOP button in UFACTORY Studio is a software stop, and the arm's power stays on33. Do not count it as an emergency stop34.
What to do in an emergency
Press the emergency stop button on the control box329.
Stay clear of the arm and of anything under it. It brakes slightly and falls, and a part it holds can drop3115.
Do not restart it yourself unless you are trained to. Only trained people operate the arm24.
Before a restart, the operator makes sure the restart or reset motions will not hit anything35.
Restarting takes two steps: turn the button in the direction of its arrow to release it, then enable the arm again from UFACTORY Studio36.
The brakes
Each joint has a brake that holds the arm's pose if the power goes out37.
Pressing the emergency stop removes the arm's power within 300 ms, and the arm will slightly brake and fall38. So do not expect it to hold perfectly still31.
The manual calls the emergency stop a "Stop Category 1" stop39, and UFACTORY measured how long a moving arm takes to halt that way: up to 885 ms, at joint 2, with the arm fully stretched out, at full speed, carrying 5 kg404142. How that fits with power being cut within 300 ms is a contradiction the manual leaves open43.
Releasing the brakes can let the arm fall. Someone must support it, and measures must be taken to prevent damage or injury44.
"Collaborative" does not mean safe here
UFACTORY calls its arms collaborative robots, yet its own manual says no people should be in the working area during operation45.
UFACTORY makes whoever integrates the arm responsible for a risk assessment of the whole system, including how far people stay from it46.
The arm's collision detection is not a safeguard either. No UFACTORY document calls it safety-rated47, and this project's advice is never to use it in place of proper protective devices48.
IntelliMake's cameras and its S11 monitoring system are not a safeguard. Nobody has documented that S11 can stop or slow the arm, so do not count on it or the cameras to protect you4913.
The honest part
We don't yet know where S2's emergency stops are, whether it has guarding, or whether its risk assessment has been done679. This project's advice: until someone confirms them, act as though none of them exists, and stay out of the working area while the arm runs50.
Not yet confirmed at S2
Nobody has confirmed these safeguards at the physical S2 cell yet. Until someone does, assume none of them exist.
The S2 installation's risk assessment has not been confirmed: whether one exists for the complete S2 application (arm, gripper, workpieces, S1/S3/S4/S6 interfaces), who performed and signed it, and whether it was redone after installation as UFACTORY requires.6
The locations of the S2 emergency stops are unknown: whether any e-stop buttons beyond the control box button are wired to EI, where they are, and whether S2 shares an emergency stop circuit with S6 or other stations.7
The position of the S2 control box is unknown: whether it is outside the arm's working range, at 0.6 to 1.5 m height, with its e-stop reachable.8
S2's guarding and protective devices are unknown: whether fences, interlocked doors, light curtains, safety mats or laser scanners are wired to the SI protective stop input, or whether SI is still in its factory default state with no additional safety equipment.9
It is unknown whether S2 is intended to be a collaborative application, with people entering the arm's working area during automatic operation. If it is, it is also unknown which collaborative method is used and how it has been validated.10
It is unknown whether S2's working range, including the gripper, is marked on the floor or bench as UFACTORY recommends.11
It is unknown what the S2 gripper does to a held workpiece on power loss or e-stop (holds or drops), and what lies beneath the arm's path if a part drops.12
Whether S11 IntelliAware has any authority to stop or slow S2, whether it is a safety-rated protective device, and who owns S11 are not documented (Q14f). The diagram calls S11 'monitoring of ... safety', which does not make it a safeguard.13
Check yourself
Answer, then check. Each option has its own feedback, and nothing is scored.
For: Someone who will work near or with the cell: operator, trainee technician Kind of task: Explain and sequence: put steps in order, match parts to their functions
In this part you learn the safety functions the machine has, how an emergency stop differs from a protective stop, and which of the arm's features protect people and which do not. It is for someone who will work near or with the cell.
Two safety inputs: emergency and protective
The control box has two fixed safety inputs. The emergency stop input, EI, is used only for emergency stops. The protective stop input, SI, is used for all other safety protection52.
An emergency stop halts the program and needs a manual reset. A protective stop only suspends the program, and can reset automatically or by hand. Protective stops can be used as often as needed; emergency stops are meant for infrequent use53.
Out of the box, the controller is set up to run with no additional safety equipment at all54.
UFACTORY says most applications need one or more extra emergency stop buttons, and that an arm working with other machines usually needs a common emergency stop circuit55.
UFACTORY's examples of protective stop devices include a door switch, which stops the arm when the door opens, and a safety pad or safety laser scanner for automatic recovery56.
The control box houses the arm's control system; its front panel carries the status lights and the emergency stop573. Image: UFACTORY
Errors stop the arm
When the controller reports an error, the arm stops at once and throws away its queued commands. Someone must clear the error by hand before normal work resumes58.
Three error codes matter most here: error code C1 means the emergency stop button on the control box is pressed in, C2 means the emergency input EI has been triggered, and C35 means the arm has reached its safety boundary59.
Collision detection
The controller compares each joint's actual motor current with what its model predicts. When the difference passes a threshold, it treats that as a collision60.
Studio's Settings page describes sensitivity levels 1 to 5. The higher the level, the less extra torque it takes to trigger collision protection. UFACTORY advises against setting it below 361.
UFACTORY's documents disagree on the range. Studio's glossary and the Python SDK accept 0 to 5, and 0 switches collision detection off. The Settings page does not say so6263.
False triggers are often related to the payload, centre of mass, mounting direction or friction parameters. UFACTORY recommends updating the payload weight and centre of mass whenever the end effector or workpiece changes64.
No UFACTORY document calls collision detection safety-rated or gives it a performance level47. Treat it as a controller function you can configure, never as a replacement for the protective devices wired to EI and SI48.
The safety boundary and reduced mode
With the safety boundary on, the arm's working space is limited: if the tool centre point leaves the set boundary, the arm stops moving65.
The documentation mentions only the tool centre point. Whether the boundary also checks the tool and the arm's links is unknown66.
Reduced mode limits the arm's maximum speeds and its joint ranges. It can be switched on through an input67.
Like collision detection, neither is called safety-rated in any UFACTORY document found47.
Teaching by hand
In manual mode the arm holds itself up against gravity, so a person can move it by hand to teach positions27.
Before switching manual mode on, confirm that the mounting direction and the payload setting are correct. Otherwise gravity compensation may be wrong and the arm may not stay still28.
If the mounting direction is set wrongly, the arm triggers collision warnings often and may move uncontrolled once it is in manual mode68.
This platform infers that UFACTORY's manual mode is not the same as the hand guiding OSHA describes for collaborative work, which runs in automatic mode with a hold-to-run control69.
Risk assessment belongs to each installation
UFACTORY's manual does not cover designing or running a complete robot application. The complete system must meet the safety standards and rules of the country it is installed in70.
UFACTORY requires a safety assessment each time the arm is installed, and a complete assessment recorded each time it is re-installed and debugged71.
Connecting the arm to other machinery may increase risk, and the whole installation then needs a complete safety assessment72.
OSHA says a risk assessment should be done and documented at every stage: design, manufacturing, integrating, operating and maintaining73.
How people and robots can share space
OSHA describes speed and separation monitoring, hand-guided controls, and power and force limiting as collaborative technologies. It notes that ANSI/RIA R15.06-2012 counts the safety-rated monitored stop as a fourth type, which is not used alone but only together with one or more of the other three74.
In power and force limiting, contact with a worker is expected. It is permitted when forces and pressures are limited so there will be no injury. Such applications usually run well below the robot's full speed and payload75.
OSHA separates transient contact, where the body part can move away, from quasi-static contact, where it is trapped or pinched against a fixed object76.
OSHA says administrative controls may include written entry and exit procedures, lockout and tagout procedures, marking out the collaborative space (for example with painted floor lines) and signs warning that it is a collaborative application77.
Mounting and restarting
The mounting surface must be shockproof and sturdy, with the arm's bolts checked for tightness, and UFACTORY says it should withstand at least 10 times the base joint's full torsion and at least 5 times the arm's weight78.
After an emergency stop, make sure the restart or reset motions will not hit anything35.
Restarting takes two steps: release the button by turning it in the arrow's direction, which re-powers the arm, then enable the servos from UFACTORY Studio or with motion_enable(true) in the Python SDK36.
What is not known at S2
Whether S2's operators have been trained, and whether maintenance and safety-setting changes are documented, is unknown79.
Whether S2 has fences, interlocked doors, light curtains, safety mats or laser scanners on its SI input, or whether SI is still in its factory default with no extra safety equipment, is unknown9.
Check yourself
Answer, then check. Each option has its own feedback, and nothing is scored.
3Intermediate
Stops, signals and settings
For: Someone who will set up, program or maintain the arm: technician, student engineer Kind of task: Apply: work through written scenarios that need a decision (which mode, which setting, what to do about this error), with feedback on each choice. Simulation added in M2/M4 extends this; it does not define it
In this part you learn how the arm stops, how safety signals must be wired, which settings change what the safety functions do, and where the published figures run out. It is for someone who will set up, program or maintain the arm.
Stop categories
UFACTORY assigns stop categories to the safety inputs. The emergency stop button and the emergency input EI are Stop Category 1. The safeguard stop input SI is Stop Category 281.
Both categories slow the arm down with drive power still on, so it stops without leaving its current path82.
How far the arm travels before it stops
UFACTORY measured Stop Category 1 stops with the arm fully extended horizontally, at 100% speed (joint speed 180 °/s) and with a 5 kg payload at the tool centre point834084418542:
Joint 1 travels 0.62 rad and takes 521 ms to stop8340.
Joint 2 travels 1.12 rad and takes 885 ms to stop, measured moving downwards8441.
Joint 3 travels 0.67 rad and takes 577 ms to stop, measured moving downwards8542.
Sources disagree. The manual also says the emergency stop removes arm power within 300 ms, while calling the same stop Category 1, which decelerates with drive power on for up to 885 ms. UFACTORY does not explain how the two fit4386.
No stop data was found for Joints 4 to 6, for other speeds or payloads, for the SI safeguard stop, or for stopping after a collision. Any separation-distance calculation needs them87.
Wiring safety signals
Every safety input and output comes as a redundant pair, wired as two separate branches, so that one failure does not lose the safety function88.
A light curtain needs a two-channel reset button placed outside the safety zone. In UFACTORY's example the reset input is CI0, set to Safeguard Reset in UFACTORY Studio89.
In that example the arm resumes when SI0 and SI1 are connected to GND and CI0 is triggered, and pauses when SI0 and SI1 are disconnected from GND90.
Never connect a safety signal to a PLC that is not safety-rated. UFACTORY warns that it can defeat the safety stop and cause serious injury or death91.
The configurable inputs CI0 to CI7 can be assigned Stop Moving, Safeguard Reset and Reduced Mode. The general inputs DI0 to DI7 cannot80.
Configurable outputs can tell other equipment about a collision, reduced mode or a pressed emergency stop92.
Input functions trigger on a low signal. An input set to Manual Mode lets the arm be dragged freely for as long as it stays low93.
I/O cables between the control box and other plant equipment must not exceed 30 m unless testing shows a longer cable works94.
Collision detection in practice
UFACTORY says false collision triggers are often related to the payload, centre of mass, mounting direction and joint friction settings64.
In pick-and-place programs, UFACTORY says to update the payload after each pick and each place, so that collision detection models the load the arm is really carrying95.
With Collision Rebound on, the arm rebounds backward a certain distance after a collision. With it off, and collision detection on, the arm stays where the collision was detected96.
Self-collision detection can include the tool, modelled as a cylinder or cuboid. Error code C22 reports a self-collision97.
Error code C23 reports a joint beyond its angle limit, and C24 a speed beyond its limit98.
A sensitivity set through the SDK is lost on reboot unless it is saved99.
Collision detection can be switched off in Studio's Advanced Settings. That page is protected by a documented default password, which this site does not print100.
Software states and software stops
Setting state 4 through the SDK ends any execution at once, and the arm takes no new commands until the state is set back to 0. State 6 is an immediate decelerated stop101.
When a critical setting changes, such as mode, payload, tool offset or collision sensitivity, the controller enters state 5 and refuses commands until state 0 is set again102.
The SDK's emergency_stop() is a sequence of software state commands, and it does not clear errors103.
Studio's STOP, set_state(4) and emergency_stop() are software commands, not the hardware emergency stop, and do not carry its power-removal behaviour104.
This project's advice: never count a software stop as an emergency stop or safeguard in the S2 risk assessment34.
In Studio's simulated-arm mode, the unlock-joint button still unlocks the real joints, and settings made there apply to the real arm105.
In servo mode the arm moves to each target at its fastest speed without buffering, so never send a distant target in one step106.
What OSHA adds
In speed and separation monitoring, a sensing device detects a person entering. At a minimum the robot stops during the intrusion; some integrations slow it first and stop it before contact can happen. When speed is used for safety, OSHA says it should have a safety function that monitors it is not exceeded107.
Robot contact with the face, temples, throat and other sensitive body regions is to be prevented108.
Some robots' built-in safety functions are not visible, and trained professionals should verify how safety functions are configured. External measures such as interlocked guards, light curtains and laser scanners need to be verified visually, validated and documented as present and working109.
Depending on its risk assessment, a collaborative application may need a protective stop, force limiting, speed limiting, soft axis limiting, space limiting and position limiting110.
A3 reports that ISO 10218:2025 renames the safety-rated monitored stop "monitored standstill"111.
What is not known at S2
Whether any S2 safety signal passes through a PLC, and whether that PLC is safety-rated, is unknown112.
S2's current safety settings are unknown: collision detection, sensitivity, boundary, reduced mode, tool model, payload and mounting direction113.
Whether the documented default password on the S2 controller has been changed, and who can change its safety settings, is unknown114.
Which configurable inputs at S2 are set to Stop Moving, Safeguard Reset, Reduced Mode or Manual Mode, and where any reset button sits, is unknown115.
Check yourself
Answer, then check. Each option has its own feedback, and nothing is scored.
4Expert
Standards, evidence and the S2 agent
For: Someone who designs, integrates or changes the cell: integrator, engineer, the M5 team Kind of task: Analyse and decide: weigh trade-offs, resolve contradictions, critique a configuration
In this part you test the safety evidence behind the machine against the standards, see what the certificates do and do not show, and work out what an autonomous agent at the cell must never be allowed to change. It is for someone who designs, integrates or changes the cell.
The certificate trail
The 850 product page lists its certificates only as "Certifications Complete(CE)"116.
The manual's certification section links two SGS documents117. The machinery verification covers "UFACTORY Robotic Arm", model numbers XI13 and XI15, and found the tested samples conformed to EN ISO 10218-1:2011, EN 60204-1:2018 and EN ISO 12100:2010118.
The EMC verification for the same model numbers covers EN IEC 61000-6-2:2019 and EN IEC 61000-6-4:2019119, and the manual's EMC section also lists a functional-safety EMC immunity standard, without a stated test result for it120.
SGS says the CE mark can be affixed after an EC Declaration of Conformity is completed and all relevant EC directives are met121. That declaration was not found, and nothing fetched from UFACTORY states conformity with ISO 10218-1:2025 or ISO 10218-2122.
So the evidence shows verification against the 2011 edition of ISO 10218-1, not the 2025 edition. That is an inference, drawn from the SGS edition and A3's statement that the 2025 editions replace the 2011 ones123.
The fetched text does not tie XI13 or XI15 to the name "UFACTORY 850", and which model number is on the S2 arm's label is unknown124.
No UFACTORY source states an ISO 13849-1 Performance Level or Category, or an IEC 62061 SIL, for any safety function, and no TÜV certification was found. Do not assume any125.
ISO 10218:2025 and collaborative applications
A3 says the 2025 editions of ISO 10218-1 and -2 replace the 2011 editions: Part 1 covers robot manufacturers, Part 2 integrators of applications and cells126.
A3 says the 2025 standard drops "collaborative robot" and speaks of a "collaborative application", because only the actual use can be designed, tested and confirmed as collaborative127.
The ISO/TS 15066 content was folded into the series, and a collaborative safety function can sit in the robot, in a protective device, or both128.
Part 2 frames its requirements around the robot application, including workpieces, task program and supporting machinery, and adds cybersecurity requirements129. The 2025 editions make functional safety requirements explicit130.
All of this comes through A3, so it is Inferred. The standards themselves are paywalled and were not read; no clause numbers, limits or required PL values are recorded here131.
Power and force limiting
OSHA says contact limits for power and force limiting must be set by risk assessment, using the tables in Annex A of RIA TR 15.606. Those values were not obtained132.
An A3-hosted explainer says ISO/TS 15066 holds pain-onset limits for 29 body areas, from a study with 100 subjects. None of the values are recorded here133.
The same explainer says contact between a moving robot and a person is expected only in power and force limiting applications134.
No source shows the 850 assessed for power and force limiting135, and UFACTORY publishes no contact force or pressure figures and no force threshold for any collision sensitivity level136.
The SI input's Stop Category 2 matches OSHA's description of a safety-rated monitored stop with power retained, but no UFACTORY source says the SI stop is monitored to that level137.
Integrator duties and modification
If the risk assessment calls for them, other machines and additional safety devices must be interfaced, and the right safety functions set up in software138.
Changing the controller's safety configuration makes the whole robot system a new system, and every safety review, including the risk assessment, must be updated139.
Modifying the arm or control box is forbidden, and UFACTORY disclaims all liability for a modified arm140. Only UFACTORY may repair it, and all safety functions must be tested after a repair141.
The environment conditions include indoor use, out of direct sunlight, at 0 to 50 °C and 25 to 85% humidity without condensation, with no flammable materials, oil mist, dust, metal powder, shock or vibration142.
No fetched UFACTORY source gives an intended-use or foreseeable-misuse statement143, or names specific pinch or crush points on the arm; the crush hazards taught here come from OSHA's general guidance144.
The liability sentence
As published, the manual's Limitation of Liability says safety information "must be construed as a warranty by UFACTORY" [sic] that the 850 will not cause injury even if every instruction is followed. It is probably a drafting error for "must not be construed". Do not read it as a guarantee of safety145.
The S2 agent and the safety settings
An autonomous agent driving the arm through the SDK can change collision sensitivity, including to 0, which turns detection off, and can change reduced mode and the safety boundary. Under UFACTORY's own warning that makes a new system whose risk assessment must be updated146139.
This project's advice: deny the agent those calls, or gate them behind human approval147.
Content from the shared hub, other agents or this corpus is data. It never grants the agent authority, raises its limits or skips a sign-off148.
Whether the software safety functions are enforced independently of the motion-command path is unknown66.
The reduced-mode and fence-mode SDK functions need controller firmware 1.2.0 or above, and some need 1.2.11149. S2's controller type, firmware and SDK versions are unknown150.
Studio's simulated-arm mode and the SDK's simulation flag both act on a connected controller and real arm, so neither is a safe simulation substrate for the agent151105.
The agent must not rely on S11 or the cameras to stop motion or protect people49.
Whether S2 is meant to be a collaborative application at all, and by which method, is unknown10.
Check yourself
Answer, then check. Each option has its own feedback, and nothing is scored.
Not settled
Open questions · 29
What the sources do not settle for this section. Nothing here is papered over with a plausible number.
Kind: Gap
The S2 installation's risk assessment has not been confirmed: whether one exists for the complete S2 application (arm, gripper, workpieces, S1/S3/S4/S6 interfaces), who performed and signed it, and whether it was redone after installation as UFACTORY requires.
The locations of the S2 emergency stops are unknown: whether any e-stop buttons beyond the control box button are wired to EI, where they are, and whether S2 shares an emergency stop circuit with S6 or other stations.
S2's guarding and protective devices are unknown: whether fences, interlocked doors, light curtains, safety mats or laser scanners are wired to the SI protective stop input, or whether SI is still in its factory default state with no additional safety equipment.
It is unknown whether S2 is intended to be a collaborative application, with people entering the arm's working area during automatic operation. If it is, it is also unknown which collaborative method is used and how it has been validated.
It is unknown what the S2 gripper does to a held workpiece on power loss or e-stop (holds or drops), and what lies beneath the arm's path if a part drops.
Whether S11 IntelliAware has any authority to stop or slow S2, whether it is a safety-rated protective device, and who owns S11 are not documented (Q14f). The diagram calls S11 'monitoring of ... safety', which does not make it a safeguard.
The 850 manual's e-stop figures appear inconsistent. Section 2.1.2 says arm power is removed within 300 ms of pressing the e-stop. Section 7.8 says the e-stop is Stop Category 1, which decelerates 'with drive power on'. Section 7.9 gives Stop Category 1 stopping times of 521 to 885 ms. UFACTORY does not explain how power removal within 300 ms fits a powered deceleration lasting up to 885 ms (the brakes may do the rest of the stopping, but no source says so).
The 850 product page calls UFACTORY arms 'Collaborative Robots' and 'cobots'. A3 says ISO 10218:2025 drops 'collaborative robot' because only an application can be confirmed as collaborative, and UFACTORY's own 850 manual says no people should be in the working area during operation. The marketing label does not establish that S2 is a collaborative application.
UFACTORY documents disagree on the collision sensitivity range. The Studio Settings page says 1 to 5, while the Studio glossary, the Python SDK and the xArm Developer Manual say 0 to 5, with 0 disabling collision detection. A learner reading only the Settings page would not learn that the value can switch detection off.
No UFACTORY source was found that says whether the software safety functions (collision detection, safety boundary, reduced mode) are enforced independently of the motion-command path. It is also unknown whether the safety boundary checks the tool and the arm's links, or only the TCP; the documentation mentions only the TCP.
UFACTORY publishes Stop Category 1 stop data only for Joints 1 to 3 at 100% extension, 100% speed and a 5 kg payload. No data was found for Joints 4 to 6, for other speeds or payloads, for Stop Category 2 (the SI safeguard stop), or for stopping after a collision is detected. These are needed for any separation-distance calculation.
The S2 arm's current safety settings are unknown: collision detection on or off, collision sensitivity level, safety boundary on and its limits, reduced mode and its limits, self-collision tool model, TCP payload and mounting direction.
It is unknown whether the documented default Advanced Settings password has been changed on the S2 controller, and who can change its safety-related settings.
It is unknown which CI inputs at S2, if any, are configured as Stop Moving, Safeguard Reset, Reduced Mode or Manual Mode, and where any safeguard reset button is located relative to the safeguarded zone.
The EC/EU Declaration of Conformity for the 850 was not found or fetched. The SGS verifications say the CE mark depends on one, and the product page says only 'Certifications Complete(CE)'. Nothing fetched from UFACTORY states conformity with ISO 10218-1:2025 or ISO 10218-2.
The fetched text does not tie the certificate model numbers XI13 and XI15 to the name 'UFACTORY 850', although UFACTORY links the certificates from the 850 manual. It is also unknown which of these model numbers appears on the S2 arm's label.
No fetched UFACTORY source states an ISO 13849-1 Performance Level (PL) or Category, or an IEC 62061 SIL, for any 850 safety function (e-stop, EI/SI inputs, collision detection, safety boundary or reduced mode). No TÜV certification was found. Do not assume any.
The ISO 10218-1/-2:2025 texts and ISO/TS 15066 are paywalled and were not read. No clause numbers, force or pressure limits, or required PL values from them are recorded in this corpus.
No fetched source shows the 850 assessed for collaborative power and force limiting (the former ISO/TS 15066 content, now in ISO 10218-2:2025). The SGS verification covers only EN ISO 10218-1:2011 (safety-082), so the permissible contact forces and speeds for collaborative use are undocumented.
No fetched UFACTORY source says whether the 850 is suitable or validated for power and force limiting collaborative applications. UFACTORY publishes no contact force or pressure figures, and gives no force or torque threshold for each collision sensitivity level.
No fetched UFACTORY source gives an explicit intended-use or reasonably foreseeable misuse statement for the 850, beyond environmental limits and general warnings.
No fetched UFACTORY source identifies specific pinch or crush points on the 850, such as between links or at the gripper fingers. The pinch and crush hazard descriptions found come from OSHA's general guidance.
The 850 manual's 'Limitation of Liability' sentence reads, as published, that safety information 'must be construed as a warranty by UFACTORY [sic], that the 850 will not cause injury or damage even if all safety instructions are complied with'. This is the opposite of what a limitation of liability usually says, and is probably a drafting error for 'must not be construed'. UFACTORY's intended wording is unconfirmed. Do not read it as a guarantee of safety.
S2's controller type (AC or DC), firmware version and SDK version are unknown. Firmware determines which reduced-mode and fence APIs are available (1.2.0 or 1.2.11 and above).
The 850 product page and manual text do not themselves state conformance to ISO 10218-1 or ISO/TS 15066. The only ISO 10218 evidence found is the SGS verification linked from the manual, which is against EN ISO 10218-1:2011 (safety-082, safety-086). No assessment against the 2025 editions was found.
The 850 control box front panel has a ROBOT PWR indicator (on when the arm is powered), a STATE indicator (flashes when the control box is powered), a LAN indicator (on when communicating normally), and an EMERGENCY STOP button.
Evidence · 4 citations
ROBOT power indicator ROBOT PWR The light is on, indicating that the 850 is powered on.
UFACTORY 850 User Manual V2.3.0 (PDF, older edition) · UFACTORY · Hardware Section 1.1.3 Control Box Description, p.20 (manual names the machine '850' / 'UFactory 850')
The S2 installation's risk assessment has not been confirmed: whether one exists for the complete S2 application (arm, gripper, workpieces, S1/S3/S4/S6 interfaces), who performed and signed it, and whether it was redone after installation as UFACTORY requires.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
The locations of the S2 emergency stops are unknown: whether any e-stop buttons beyond the control box button are wired to EI, where they are, and whether S2 shares an emergency stop circuit with S6 or other stations.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
Evidence · 1 citation
In most applications, one or more additional emergency stop buttons are required.
The position of the S2 control box is unknown: whether it is outside the arm's working range, at 0.6 to 1.5 m height, with its e-stop reachable.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
Evidence · 1 citation
The Control Box must be placed outside the working range of the robotic arm to ensure the emergency stop button can be pressed once an emergency occurs.
S2's guarding and protective devices are unknown: whether fences, interlocked doors, light curtains, safety mats or laser scanners are wired to the SI protective stop input, or whether SI is still in its factory default state with no additional safety equipment.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
Evidence · 1 citation
The robotic arm has been configured by default and can be operated without any additional safety equipment
It is unknown whether S2 is intended to be a collaborative application, with people entering the arm's working area during automatic operation. If it is, it is also unknown which collaborative method is used and how it has been validated.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
Evidence · 1 citation
“Collaborative application” is used instead, as only the actual use of the robot can be designed, tested, and confirmed as a collaborative application.
Updated ISO 10218: Answers to Frequently Asked Questions (FAQs) (A3 blog, 03/20/2025; Wayback Machine snapshot 2025-10-06) · Association for Advancing Automation (A3) · FAQ 6
It is unknown what the S2 gripper does to a held workpiece on power loss or e-stop (holds or drops), and what lies beneath the arm's path if a part drops.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
Evidence · 1 citation
Make sure that the connecting tool and the gripper do not cause any danger when the power is cut
Whether S11 IntelliAware has any authority to stop or slow S2, whether it is a safety-rated protective device, and who owns S11 are not documented (Q14f). The diagram calls S11 'monitoring of ... safety', which does not make it a safeguard.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
OSHA groups robot application hazards into major types including impact, collision or other struck-by/caught-between hazards, crushing and trapping of body parts between the robot, end-effector or workpiece and other equipment, and struck-by projectiles such as released parts or gripper mechanism failure.
Evidence · 6 citations
Similar to above, a worker's limb or other body part can be trapped within or between a robot, end-effector, or workpiece and another robot, or other peripheral equipment, resulting in potential crushing injuries.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · V. Hazards Associated with Industrial Robot Applications
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
Parts release, gripper mechanism failure, or end-effector power tool failure
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · V., Struck-by Projectiles Hazards
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
Hazards can be grouped into the following major types:
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · V. Hazards Associated with Industrial Robot Applications, Robot Application Hazards
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
Impact, Collision, or other "Struck-by/Caught-between" Hazards
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · V., Robot Application Hazards
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · V., Robot Application Hazards
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · V., Robot Application Hazards
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
The 850 arm and control box get hot in operation; UFACTORY says not to handle or touch them during or immediately after operation.
Evidence · 1 citation
The robotic arm and Control Box will generate heat during operation. Do not handle or touch the robotic arm and Control Box while in operation or immediately after the operation.
UFACTORY 850 Hardware Manual (online), 1. Safety · UFACTORY · 1.3, HIGH TEMPERATURE
To avoid electric shock, the 850 arm cable must not be connected or disconnected while the system is connected to external AC power.
Evidence · 1 citation
When connecting or disconnecting the arm cable, make sure that the external AC is disconnected. To avoid any electric shock hazard, do not connect or disconnect the robotic arm cable when the robotic arm is connecting with external AC.
UFACTORY warns that the controller's power supply may retain high voltage for several hours after shutdown, and says not to disassemble it.
Evidence · 1 citation
Avoid disassembling the power supply system within the controller. The power supply system may retain high voltage for several hours after the controller is shut down.
UFACTORY recommends marking the arm's range of motion with a line, including the reach of its end tools such as grippers and suction cups.
Evidence · 1 citation
A line should be drawn to mark the range of motion of the robotic arm to let the operator acknowledge the robotic arm, including its end tools (such as gripper and suction cup, etc) operating range.
UFACTORY says the arm must be installed with its range of motion in mind so that it does not hit people or equipment nearby, and notes that its published working range excludes the end-effector.
Evidence · 1 citation
When installing the robotic arm, make sure the range of motion of the robotic arm is taken into account, so as not to bump into the surrounding people and equipment (the end-effector not included in the working range).
UFACTORY 850 Hardware Manual (online), 2. Hardware Installation · UFACTORY · 2.2.2 Define Working Space
UFACTORY says the device and system must be checked before each use, and the arm and the peripheral protection system must be tested and inspected before production.
Evidence · 2 citations
The integrity of the device and system must be checked before each use (e. g. the operational safety and the possible damage of the robotic arm and other device systems).
OSHA says many robot accidents happen during non-routine work such as programming, maintenance, testing, setup or adjustment, when a worker may be inside the robot's working envelope.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: Robotics overview.
OSHA Safety and Health Topics: Robotics (overview) · U.S. Occupational Safety and Health Administration · Robotics overview
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
In manual mode the arm compensates for gravity ('zero gravity'), so a person can move it by hand to teach positions.
Evidence · 1 citation
In this mode, the robotic arm will enter the ‘zero gravity’ mode, since the gravity is compensated, the user can guide the robotic arm position directly by hand.
UFACTORY Studio User Manual (online), 2. Glossary · UFACTORY · Glossary, 'Manual Mode'
Before switching on manual (drag-teach) mode, UFACTORY says to confirm that the mounting direction and TCP payload are set correctly; otherwise gravity compensation may be wrong and the arm may not stay still.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: Mode 2: Manual Mode, NOTE.
UFACTORY Studio User Manual (online), 10. Robotic Arm Motion Mode and State · UFACTORY · Mode 2: Manual Mode, NOTE
UFACTORY says the control box must be placed outside the arm's working range so that its emergency stop button can be reached in an emergency.
Evidence · 1 citation
The Control Box must be placed outside the working range of the robotic arm to ensure the emergency stop button can be pressed once an emergency occurs.
When the emergency stop is pressed, the 850 does not hold perfectly still: UFACTORY says it will brake slightly and fall.
Evidence · 1 citation
When an emergency occurs during the operation of the robotic arm, users need to press the emergency stop, and the posture of the robotic arm will slightly brake and fall.
Kind: RecommendationThis project's simulation and agent design, not the physical cellProject design, not the physical cellsafety-142
Project advice
Do not count a software stop (Studio's STOP, SDK set_state(4) or SDK emergency_stop()) as an emergency stop or safeguard in the S2 risk assessment.
This is advice from this project, based on: safety-089 Inferredsafety-035 Verifiedsafety-036 Verifiedsafety-025 Verified
Why:Software stops leave arm power on and are not the hardware emergency stop (safety-089, safety-035, safety-036), which removes arm power (safety-025). Crediting them as an emergency stop would overstate the protection the cell has.
Restarting after an emergency stop takes two steps: release the button by turning it in the arrow's direction to re-power the arm, then enable the servos from UFACTORY Studio or with motion_enable(true) in the Python SDK.
Evidence · 3 citations
Power up the 850 (Turn the emergency stop button in the direction of the arrow).
Pressing the control box emergency stop makes the controller decelerate the arm in software, clears all cached commands, and removes power from the arm within 300 ms; the arm will slightly brake and fall.
Evidence · 2 citations
Quote not shown (over 40 words). See the source at: 2.1.2 Emergency Stop Button.
UFACTORY's measured Stop Category 1 stopping time for Joint 1 is 521 ms (Stop Category 1, arm fully extended horizontally, 100% speed (joint speed 180 °/s), 5 kg payload at TCP; Joint 1 tested with a horizontal movement.)
Evidence · 5 citations
Joint1 0.62 521
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.9 Stop Time and Stop Distance, table
UFACTORY's measured Stop Category 1 stopping time for Joint 2 is 885 ms (Stop Category 1, arm fully extended horizontally, 100% speed (joint speed 180 °/s), 5 kg payload at TCP; Joint 2 and 3 measured moving downwards.)
Evidence · 5 citations
Joint2 1.12 885
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.9 Stop Time and Stop Distance, table
During the tests for Joint 2 and 3 the robot followed a vertical trajectory, i.e. the axes of rotation were parallel to the ground, and the stop was performed while the robot was moving downwards.
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.9, test configuration
UFACTORY's measured Stop Category 1 stopping time for Joint 3 is 577 ms (Stop Category 1, arm fully extended horizontally, 100% speed (joint speed 180 °/s), 5 kg payload at TCP; Joint 2 and 3 measured moving downwards.)
Evidence · 5 citations
Joint3 0.67 577
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.9 Stop Time and Stop Distance, table
During the tests for Joint 2 and 3 the robot followed a vertical trajectory, i.e. the axes of rotation were parallel to the ground, and the stop was performed while the robot was moving downwards.
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.9, test configuration
The 850 manual's e-stop figures appear inconsistent. Section 2.1.2 says arm power is removed within 300 ms of pressing the e-stop. Section 7.8 says the e-stop is Stop Category 1, which decelerates 'with drive power on'. Section 7.9 gives Stop Category 1 stopping times of 521 to 885 ms. UFACTORY does not explain how power removal within 300 ms fits a powered deceleration lasting up to 885 ms (the brakes may do the rest of the stopping, but no source says so).
Stop Category 1 and Stop Category 2 decelerates the robot with drive power on, which enables the robot to stop without deviating from its current path.
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.8 Stop Categories
Releasing the 850's brakes can let the arm fall: UFACTORY says someone must support the arm, and protective measures must be taken to prevent damage or injury.
Evidence · 2 citations
DANGER: When releasing the joint brakes, someone must support the robot's posture to prevent the robotic arm from falling without external force and damage the robotic arm and surrounding equipment.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.4.2 Debugging Tools, Joint
The 850 product page calls UFACTORY arms 'Collaborative Robots' and 'cobots'. A3 says ISO 10218:2025 drops 'collaborative robot' because only an application can be confirmed as collaborative, and UFACTORY's own 850 manual says no people should be in the working area during operation. The marketing label does not establish that S2 is a collaborative application.
“Collaborative application” is used instead, as only the actual use of the robot can be designed, tested, and confirmed as a collaborative application.
Updated ISO 10218: Answers to Frequently Asked Questions (FAQs) (A3 blog, 03/20/2025; Wayback Machine snapshot 2025-10-06) · Association for Advancing Automation (A3) · FAQ 6
UFACTORY makes the integrator of the 850 responsible for a risk assessment of the complete system, including keeping a safe distance between people and the 850 when they interact with it.
Evidence · 1 citation
Making a risk assessment for the complete system. Make sure to have a safe distance between people and 850 when interacting with the 850.
UFACTORY 850 Hardware Manual (online), 1. Safety · UFACTORY · 1.1 Validity and Responsibility, integrator responsibilities list
No fetched UFACTORY document calls the 850's collision detection, safety boundary or reduced mode safety-rated, or gives them a performance level.
Why we infer this:Verified: collision detection is a model-based current comparison that UFACTORY says can false-trigger with wrong settings and can be disabled (level 0, Advanced Settings toggle, a documented default password); safety boundary and reduced mode are software settings exposed in Studio and the SDK. UFACTORY distinguishes safety signals (EI/SI, redundant pairs) from non-safety devices. Inferred: no fetched UFACTORY source assigns a PL, Category or safety rating to these software functions (see the gap on performance level); this is a statement about the documents fetched, not proof that no rating exists.
Evidence · 3 citations
By comparing the theoretical current and actual current of each joint, the system determines whether a collision has occurred.
Collision Detection in UFACTORY Robotic Arms: Current and Dynamic Model-based Feature (UFACTORY support article) · UFACTORY · Section 1
Never connect a safety signal to a non-safety PLC.Failure to follow this warning may result in serious injury or death due to an invalid safety stop function.
Kind: RecommendationThis project's simulation and agent design, not the physical cellProject design, not the physical cellsafety-140
Project advice
Treat the 850's collision detection, safety boundary and reduced mode as configurable controller functions, not as validated safeguards: they must not replace the risk-assessed protective devices wired to the EI and SI inputs.
This is advice from this project, based on: safety-087 Inferredsafety-062 Verifiedsafety-067 Verifiedsafety-073 Verifiedsafety-074 Verifiedsafety-057 Verified
Why:No fetched UFACTORY document gives these functions a safety rating or performance level (safety-087). Collision detection is a current-model comparison that can false-trigger and can be switched off (safety-062, safety-067); safety boundary and reduced mode are software settings (safety-073, safety-074). UFACTORY keeps safety signals separate from non-safety devices (safety-057). A function with no documented rating cannot stand in for a rated protective device.
Kind: RecommendationThis project's simulation and agent design, not the physical cellProject design, not the physical cellint-053
Project advice
Until S11's safety function is documented and verified, neither learners nor the S2 agent should treat S11 or the cameras as a safeguard. The S2 agent must not rely on them to stop motion or to protect people.
This is advice from this project, based on: int-024 Verifiedint-050 Gap, awaiting cell access
Why:S11 is described only as monitoring that includes safety (int-024). Nothing establishes a safety rating, stop authority or response time (int-050). Treating an unrated monitoring system as a safeguard is the failure the Q3 disposition warns against: an Assumed safeguard mistaken for a confirmed one.
Kind: RecommendationThis project's simulation and agent design, not the physical cellProject design, not the physical cellsafety-144
Project advice
Until S2's emergency stops, guarding and risk assessment are confirmed at the physical cell, act as though none of them exists: stay out of the working area while the arm runs, and do not rely on a safeguard nobody has confirmed.
This is advice from this project, based on: safety-127 Gap, awaiting cell accesssafety-128 Gap, awaiting cell accesssafety-130 Gap, awaiting cell accesssafety-009 Verifiedsafety-002 Verified
Why:Where S2's emergency stops are (safety-128), whether it has guarding or protective devices (safety-130) and whether its risk assessment exists (safety-127) are all recorded as unconfirmed. UFACTORY says no people should be in the working area during operation (safety-009) and makes the integrator responsible for the risk assessment (safety-002). Wrongly assuming a safeguard exists can cost an injury; wrongly assuming it is absent costs only caution.
The 850 control box has two fixed safety inputs: the emergency stop input (EI), used only for emergency stops, and the protective stop input (SI), used for all other safety protection.
Evidence · 1 citation
There are two fixed safety inputs: The robotic arm emergency stop input is only used for the emergency stop of the device. The protective stop input is used for all types of safety protection.
An emergency stop halts the program and needs a manual reset, while a protective stop only suspends the program and can reset automatically or manually. UFACTORY says protective stops have no usage-frequency limit, but emergency stops are for infrequent use.
Evidence · 1 citation
Program execution Stop Suspend Reset Manual Auto or manual Usage frequency Not frequent No limit
Out of the box, the 850 controller is configured to run without any additional safety equipment. The manual shows the default wiring in a figure; the terminals EI1, EI2, SI0 and SI1 are named in the next subsection, which covers adding an emergency stop button.
Evidence · 2 citations
The robotic arm has been configured by default and can be operated without any additional safety equipment, as the figure below.
UFACTORY says most applications need one or more additional emergency stop buttons, and that when the arm works with other machines a common emergency stop circuit is usually needed.
Evidence · 2 citations
In most applications, one or more additional emergency stop buttons are required.
UFACTORY gives a door switch as an example of a basic protective stop device (when the door is open, the arm stops), and a safety pad or a safety laser scanner as another example of automatic recovery.
Evidence · 2 citations
The door switch is an example of a basic protective stop device. When the door is open, the robotic arm stops.
When the control box reports an error in the arm's hardware, the control box software, or a sent command, the arm stops immediately and discards the control box's cached commands; the error must be cleared manually before normal operation resumes.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: 12.1 Control Box Error Code and Handling.
UFACTORY Studio User Manual (online), 12. Error Handling · UFACTORY · 12.1 Control Box Error Code and Handling
Controller error C1 means the control box emergency stop button is pressed in, C2 means the control box's emergency I/O (EI) has been triggered, and C35 means the arm has reached the safety boundary.
Evidence · 3 citations
The Emergency Stop Button on the Control Box is Pushed in to Stop
UFACTORY Studio User Manual (online), 12. Error Handling · UFACTORY · 12.1 error table, C1
UFACTORY's collision detection compares each joint's actual motor current with the current predicted by a dynamic model, and triggers when the difference exceeds a preset threshold.
Evidence · 2 citations
The collision detection feature of UFACTORY robotic arms relies on the combination of current and dynamic models. By comparing the theoretical current and actual current of each joint, the system determines whether a collision has occurred.
Collision Detection in UFACTORY Robotic Arms: Current and Dynamic Model-based Feature (UFACTORY support article) · UFACTORY · Introduction and section 1
If the difference exceeds a pre-set threshold, indicating that the joint may have encountered external resistance or collision, the system triggers the collision detection.
Collision Detection in UFACTORY Robotic Arms: Current and Dynamic Model-based Feature (UFACTORY support article) · UFACTORY · Section 1
UFACTORY Studio's Settings page describes collision sensitivity levels 1 to 5: the higher the level, the less extra torque it takes to trigger collision protection. UFACTORY advises against setting it below 3.
Evidence · 2 citations
The collision sensitivity range is 1 to 5 levels. The larger the value is set, the higher the collision sensitivity level is, and the smaller the additional torque required for the robotic arm to trigger collision protection.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.1.1 Parameters, Collision Detection Sensitivity
UFACTORY documents disagree on the collision sensitivity range. The Studio Settings page says 1 to 5, while the Studio glossary, the Python SDK and the xArm Developer Manual say 0 to 5, with 0 disabling collision detection. A learner reading only the Settings page would not learn that the value can switch detection off.
The UFACTORY Studio glossary gives the collision sensitivity range as 0 to 5, where 0 means collision detection is disabled; the Python SDK's set_collision_sensitivity also accepts 0 to 5.
Evidence · 2 citations
The collision sensitivity range is from 0 to 5 level. When it is set to 0, it means that collision detection is not enabled.
UFACTORY Studio User Manual (online), 2. Glossary · UFACTORY · Glossary, Collision Sensitivity
UFACTORY says collision detection may sometimes be falsely triggered, often in relation to the end-effector load, centre of mass, installation orientation and friction parameters. It recommends updating the weight and centre of mass after changing the end effector or workpiece, setting the mounting direction correctly, and reloading the joint friction parameters after replacing the control box.
Evidence · 4 citations
In practical applications, the robot's collision detection function may sometimes be falsely triggered. This phenomenon is often related to the end effector load, center of mass, installation orientation, and friction parameters. The following are common causes of false triggers:
Collision Detection in UFACTORY Robotic Arms: Current and Dynamic Model-based Feature (UFACTORY support article) · UFACTORY · Section 2
With the Safety Boundary on, the 850's working range in Cartesian space is limited: if the tool centre point (TCP) leaves the set boundary, the arm stops moving.
Evidence · 1 citation
When this mode is turned on, the working range of the robotic arm in Cartesian space can be limited. If the tool center point (TCP) of the robotic arm exceeds the set safety boundary, the robotic arm will stop moving.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.3.1 Safety Boundary
No UFACTORY source was found that says whether the software safety functions (collision detection, safety boundary, reduced mode) are enforced independently of the motion-command path. It is also unknown whether the safety boundary checks the tool and the arm's links, or only the TCP; the documentation mentions only the TCP.
With Reduced Mode on, the 850's maximum linear speed, maximum joint speed and joint range are limited. Reduced Mode can be switched on through a CI input.
Evidence · 2 citations
When this mode is turned on, the maximum linear speed, maximum joint speed, and joint range of the robotic arm in Cartesian space will be limited.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.3.2 Reduced Mode
If the mounting direction is set wrongly, UFACTORY says the arm will trigger collision warnings often, and may move uncontrolled once it enters manual mode.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: 7.1 Mounting.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.1 Mounting
UFACTORY's manual mode ('zero gravity' free dragging) is not the same as hand guiding as OSHA describes it for collaborative applications: OSHA's hand guiding runs in automatic mode with a hold-to-run control, while UFACTORY's manual mode is a separate teaching mode.
Why we infer this:Verified: UFACTORY defines manual mode as a gravity-compensated drag mode used for teaching (Mode 2, switched back to Mode 0 afterwards). OSHA (government) describes hand-guided control as occurring in automatic mode with a hold-to-run control device. Inferred: the two are different; UFACTORY does not describe manual mode as a collaborative hand-guiding safety function.
Evidence · 2 citations
In this mode, the robotic arm will enter the ‘zero gravity’ mode, since the gravity is compensated, the user can guide the robotic arm position directly by hand.
UFACTORY Studio User Manual (online), 2. Glossary · UFACTORY · Glossary, Manual Mode
UFACTORY says the 850 manual does not cover the design, installation and operation of a complete robotic application, and that the complete system must be designed and installed to the safety standards and regulations of the country where the arm is installed.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: 1.1 Validity and Responsibility, first paragraph.
UFACTORY 850 Hardware Manual (online), 1. Safety · UFACTORY · 1.1 Validity and Responsibility, first paragraph
UFACTORY requires a safety assessment each time the 850 is installed, and says a complete safety assessment must be recorded each time the arm is re-installed and debugged.
Evidence · 2 citations
A safety assessment is required each time installed.
UFACTORY warns that connecting the 850 to other machinery may increase risk, and requires a complete safety assessment of the whole installation or collaboration system.
Evidence · 2 citations
When connecting the 850 with other machinery, it may increase risk and result in dangerous consequences. Make sure a consistent and complete safety assessment is conducted for the installation system.
UFACTORY 850 Hardware Manual (online), 1. Safety · UFACTORY · 1.3 General Warning and Cautions, DANGER list
OSHA says a risk assessment should be done and documented at every stage of a robot application: design, manufacturing, integrating, operating and maintaining.
Evidence · 2 citations
At each stage of development of the robot application (design, manufacturing, integrating, operating, and maintaining), a risk assessment should be performed.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Risk Assessment(s)
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
In addition, the risk assessment for each stage of development should be documented for future reference.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Risk Assessment(s)
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA describes speed and separation monitoring, hand-guided controls and power and force limiting as collaborative technologies, and notes that ANSI/RIA R15.06-2012 refers to the safety-rated monitored stop as a fourth type. OSHA says the safety-rated monitored stop is not used alone but must be used in conjunction with SSM, HGC and/or PFL.
Evidence · 6 citations
A collaborative robot application uses one or more of the following technologies while operating in automatic mode:
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Additional Safety Requirements for Collaborative Robot Applications
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
However, this mode is not used alone but must be used in conjunction with SSM, HGC and/or PFL.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Safety-rated Monitored Stop
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Additional Safety Requirements for Collaborative Robot Applications, headings
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Additional Safety Requirements for Collaborative Robot Applications, headings
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Additional Safety Requirements for Collaborative Robot Applications, headings
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
The concept of Safety-rated Monitored Stop (SMS) is included in ANSI/RIA R15.06-2012, where it is referred to as a fourth type of collaborative technology.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Safety-rated Monitored Stop
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
In power and force limiting, physical contact between the robot application and a worker is expected and permitted; OSHA says it is permitted when the forces and pressures of contact are limited such that there will be no injury. Such applications usually run at much lower speeds and payloads than the robot is physically capable of.
Evidence · 3 citations
It is permitted when the forces and pressures of contact are limited such that there will be no injury to the worker(s).
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Power and Force Limited (PFL)
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
Collaborative applications using PFL robots usually operate at much lower speeds and payloads than they are physically capable.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Power and Force Limited (PFL)
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
Physical contact between a robot application (i.e., robot, end-effector, and workpiece) and a worker is expected and permitted in this mode.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Power and Force Limited (PFL)
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA distinguishes transient contact, where the worker's movement is not restricted and the body part can move in free space, from quasi-static contact, where the body part cannot move because a fixed object restricts it (for example, trapped or pinched between the robot and a fixture).
Evidence · 2 citations
Quasi-static contact occurs when a worker’s body part is unable to move at the time of contact due to being restricted by a fixed object (e.g., trapped or pinched between the robot and a fixture).
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Have contact events been considered in collaborative robot applications?
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
Transient contact occurs when the worker's movement is not restricted at the time of contact (e.g., the worker's body part can move in free-space at the time of contact).
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Have contact events been considered in collaborative robot applications?
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
For collaborative applications, OSHA says appropriate administrative controls may include written entry and exit procedures and training, lockout/tagout SOPs and training, delineation of the collaborative space (for example painted lines on the floor) and safety signs warning that it is a collaborative robot application.
Evidence · 5 citations
Collaborative space delineation (i.e., where can the robot system and application move?) [Delineation may be a diagram on the wall, painted lines on the floor, or something else that conveys the information]
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Administrative controls
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Administrative controls
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
Written application entry and exit procedures and training
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Administrative controls
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Administrative controls
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
Safety signs that warn workers that this is a collaborative robot application
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Administrative controls
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
UFACTORY requires the 850's mounting surface to be shockproof and sturdy, with the arm body's bolts checked for tightness, and says the arm should be installed on a surface able to withstand at least 10 times the base joint's full torsion and at least 5 times the arm's weight.
Evidence · 3 citations
The robotic arm should be installed on a sturdy surface that is sufficient to withstand at least 10 times the full torsion of the base joint and at least 5 times the weight of the arm.
UFACTORY assigns stop categories to the 850's safety inputs: the control box e-stop button and the emergency input (EI) are Stop Category 1, and the safeguard stop input (SI) is Stop Category 2.
Evidence · 1 citation
Emergency Stop Button of the Control Box Stop Category 1 Emergency Input of the Control Box(EI) Stop Category 1 Safeguard Stop of Control Box(SI) Stop Category 2
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.8 Stop Categories, table
UFACTORY says Stop Category 1 and Stop Category 2 decelerate the 850 with drive power on, so it stops without leaving its current path.
Evidence · 1 citation
Stop Category 1 and Stop Category 2 decelerates the robot with drive power on, which enables the robot to stop without deviating from its current path.
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.8 Stop Categories
UFACTORY's measured Stop Category 1 stopping distance for Joint 1 is 0.62 rad (Stop Category 1, arm fully extended horizontally, 100% speed (joint speed 180 °/s), 5 kg payload at TCP; Joint 1 tested with a horizontal movement.)
Evidence · 5 citations
Joint1 0.62 521
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.9 Stop Time and Stop Distance, table
During the tests for Joint 2 and 3 the robot followed a vertical trajectory, i.e. the axes of rotation were parallel to the ground, and the stop was performed while the robot was moving downwards.
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.9, test configuration
During the tests for Joint 2 and 3 the robot followed a vertical trajectory, i.e. the axes of rotation were parallel to the ground, and the stop was performed while the robot was moving downwards.
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.9, test configuration
Pressing the control box's emergency stop makes the controller decelerate the arm in software, stop all activity and clear cached commands; UFACTORY says arm power is removed within 300 ms.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: 2.1.2 Emergency Stop Button.
UFACTORY publishes Stop Category 1 stop data only for Joints 1 to 3 at 100% extension, 100% speed and a 5 kg payload. No data was found for Joints 4 to 6, for other speeds or payloads, for Stop Category 2 (the SI safeguard stop), or for stopping after a collision is detected. These are needed for any separation-distance calculation.
UFACTORY says all of the 850's safety I/Os come in redundant pairs that must be wired as two separate branches, so that a single I/O failure does not lose the safety function.
Evidence · 1 citation
All safety I/Os exist in pairs (redundancy) and must be kept in two separate branches. A single I/O failure should not result in the loss of safety features.
For a light curtain on the protective interface, UFACTORY requires a two-channel reset button placed outside the safety zone. The reset input, CI0 in UFACTORY's example, must be configured as 'safeguard reset' in UFACTORY Studio.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: 3.4.1.4 Protective Stop with Rest Button.
In UFACTORY's reset-button example, the 850 resumes motion when SI0 and SI1 are connected to GND and CI0 is triggered, and pauses when SI0 and SI1 are disconnected from GND.
Evidence · 1 citation
If 850 needs to resume motion, connect SI0 and SI1 to GND, and trigger the motion of 850 by connecting CI0 to GND; if 850 needs to pause the motion, disconnect SI0 and SI1 from GND.
UFACTORY warns never to connect a safety signal to a non-safety PLC, because doing so can defeat the safety stop and cause serious injury or death.
Evidence · 1 citation
Never connect a safety signal to a non-safety PLC.Failure to follow this warning may result in serious injury or death due to an invalid safety stop function.
The controller's configurable outputs (CO0-CO7 and DO0-DO7) can be assigned status functions including 'Collision', 'Reduced Mode' and 'Emergency Stop is Pressed', and the manual says digital I/O can be used to communicate with other machines or PLCs.
In UFACTORY Studio, controller input functions trigger on a low-level input signal; an input configured as Manual Mode lets the arm be dragged freely while that input stays low.
Evidence · 2 citations
The following functions (if configured), can be triggered by low-level input signals.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.2.2 Controller IO, IO Function
UFACTORY says I/O cables between the control box and other plant equipment must not exceed 30 m unless extension testing shows longer cables work.
Evidence · 1 citation
The length of the I/O cable that used to connect the Control Box with other mechanical and plant equipment must not exceed 30 meters unless it is feasible after the extension testing.
With Collision Rebound on, the arm rebounds backward a certain distance after it collides with an obstacle; if collision detection is on and Collision Rebound is off, the arm stays where the collision was detected.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: 7.4.3, Collision Rebound.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.4.3, Collision Rebound
The 850 has self-collision detection, which can be turned on or off, and the end effector can be modelled as a cylinder or cuboid so that it is included in the self-collision check. Controller error C22 reports a self-collision.
Evidence · 3 citations
When the mode is turned on, it will prevent the xArm from causing self-collision.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.4.3, Self-collision detection
Setting state 4 (STOP) through the SDK ends any execution immediately; the arm accepts no new commands until the state is set back to 0. State 6 performs an immediate decelerated stop.
Evidence · 4 citations
State 4 | set: set the robot to STOP state, it will terminate any execution immediately and will not receive or execute any new command until the state is set back to STANDBY.
UFACTORY Studio User Manual (online), 10. Robotic Arm Motion Mode and State · UFACTORY · 10.2 Robotic Arm State, State 4
The 850 controller enters state 5 (MODE_CHANGED) and refuses commands until state 0 is set again whenever critical settings such as mode, payload, TCP offset or collision sensitivity change.
Evidence · 1 citation
State 5 | MODE_CHANGED state, will automatically switch to this state if some critical configurations (mode, payload, TCP offset, collision sensitivity, etc) have been changed, and cannot receive and execute any command until set state 0.
UFACTORY Studio User Manual (online), 10. Robotic Arm Motion Mode and State · UFACTORY · 10.2, State 5
The Python SDK documents emergency_stop() as a sequence of software state commands (set_state(4), then motion_enable(True), then set_state(0)), and says it does not clear errors.
Studio's STOP is a software stop that leaves arm power on. SDK set_state(4) and emergency_stop() are software state commands, not the hardware emergency stop, and do not carry its power-removal behaviour. Whether they leave power on is not documented.
Why we infer this:Verified: Studio's STOP is described as a software stop with power still on (safety-035); SDK emergency_stop() is a sequence of state commands (safety-036); the physical e-stop removes arm power within 300 ms per the manual (safety-025). Inferred: set_state(4) and emergency_stop() act through the same controller state machine as Studio's STOP, so they are different mechanisms from the hardware e-stop and do not carry its behaviour.
Evidence · 3 citations
It's a software stop , the power is still on.
UFACTORY Studio User Manual (online), 4. Live Control · UFACTORY · 4.5 Enable & STOP button
UFACTORY Studio warns that in simulated robotic arm mode the unlock-joint button still unlocks the real joints, and that settings made in simulation mode apply to the real arm.
Evidence · 2 citations
In the 'simulated robotic arm mode', clicking the unlock joint button will also unlock the real joints of the robotic arm.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.4.2 Debugging Tools, Joint
In servo (ServoJ) mode, the arm moves to the given joint position at the fastest speed (180°/s) with no command buffer, executing only the latest target received; UFACTORY notes that this is similar to a step response and warns, for safety, not to send a distant target in one step.
Evidence · 2 citations
(Note: this execution is similar to the step response, for safety considerations, do not give a distant target position at once).
UFACTORY Studio User Manual (online), 10. Robotic Arm Motion Mode and State · UFACTORY · Mode 1: Servo(ServoJ) Mode
Move to the given joint position with the fastest speed (180°/s) and acceleration (unit: degree/radian). This command has no buffer, only execute the latest received target point
UFACTORY Studio User Manual (online), 10. Robotic Arm Motion Mode and State · UFACTORY · Mode 1: Servo(ServoJ) Mode, Servo Joint Motion
In speed and separation monitoring, a presence-sensing device detects workers entering; at a minimum the robot application stops during the intrusion, and some integrations slow it first and stop it before contact can happen. OSHA says that when speed is used for safety, the speed should have an associated safety function that monitors that the needed speed will not be exceeded.
Evidence · 4 citations
A protective device (i.e., presence-sensing safeguarding device) is integrated with the robot application such that intrusion of workers is detected.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Speed and Separation Monitoring (SSM)
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
It is important to note that when speed is being used for safety purposes, the speed should have an associated safety function that monitors that the needed speed will not be exceeded.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Speed and Separation Monitoring (SSM)
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
At a minimum, the robot application stops during the intrusion and then operation can resume after all workers have left the area and no further intrusion is detected.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Speed and Separation Monitoring (SSM)
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
Even now, there are integrations that cause the robot application to slow down upon initial intrusion detection, but if the worker(s) get closer to another detection zone, the robot stops before contact by the robot application can happen.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Speed and Separation Monitoring (SSM)
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA says robot contact with sensitive body regions such as the face, temples and throat is to be prevented or avoided.
Evidence · 1 citation
[Note: robot contact with sensitive body regions (e.g., the face, temples, and throat) is to be prevented or avoided per RIA TR R15.606-2016.]
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Power and Force Limited (PFL), note
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA says some robots have built-in safety functions that are not visible, and that the configuration and settings of safety functions should be verified by trained professionals; external measures such as interlocked guards, light curtains and laser scanners will need to be verified visually, validated and documented as present and functioning correctly.
Evidence · 3 citations
Some risk reduction measures can be external to the robot application and will need to be verified visually, validated, and documented that they are present and functioning correctly (e.g., interlocked guards, light curtains, and laser scanners).
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Risk reduction
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
The configuration and settings of safety functions should be verified by trained professionals.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Risk reduction
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
For example, some robots have built-in safety functions providing capabilities or software that are not visible (e.g., safety functions for PFL).
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Risk reduction
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
OSHA lists safety functions that could also be required in a collaborative application: protective stop, force limiting, speed limiting, soft axis-limiting, space limiting and position limiting. It says the required safety functions should be determined during the risk assessment.
Evidence · 3 citations
Protective stop Force limiting Speed limiting Soft axis-limiting Space limiting Position limiting
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Does this robot application have the needed safety functions?
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
Other safety functions could also be required, including:
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Does this robot application have the needed safety functions?
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
The required safety functions should be determined during the RA.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Does this robot application have the needed safety functions?
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
The S2 arm's current safety settings are unknown: collision detection on or off, collision sensitivity level, safety boundary on and its limits, reduced mode and its limits, self-collision tool model, TCP payload and mounting direction.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
Evidence · 1 citation
When this mode is turned on, the working range of the robotic arm in Cartesian space can be limited.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.3 Safety
It is unknown whether the documented default Advanced Settings password has been changed on the S2 controller, and who can change its safety-related settings.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
Evidence · 1 citation
Quote not shown: it contains a value this site does not publish.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.4.3 Advanced Settings
It is unknown which CI inputs at S2, if any, are configured as Stop Moving, Safeguard Reset, Reduced Mode or Manual Mode, and where any safeguard reset button is located relative to the safeguarded zone.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
Evidence · 1 citation
you need to reset from outside the safety zone. The reset button must be a two-channel button.
The SGS Verification of MD Compliance linked from the 850 manual covers 'UFACTORY Robotic Arm', model numbers XI13 and XI15. It states that sufficient samples were tested and found to be in conformity with EN ISO 10218-1:2011, EN 60204-1:2018 and EN ISO 12100:2010.
Evidence · 3 citations
Product Description: UFACTORY Robotic Arm Model No.: XI13, XI15
SGS Verification of MD Compliance No. MD GZES2403005468MD (UFACTORY Robotic Arm, Model No. XI13, XI15) · SGS-CSTC Standards Technical Services Co., Ltd. (published by UFACTORY) · Verification No. MD GZES2403005468MD, product and standard fields
SGS verification document, published by UFACTORY · All rights reserved; quoted briefly as evidence · retrieved 2026-09-21
Test Standard: EN ISO 10218-1: 2011 EN 60204-1:2018 EN ISO 12100: 2010
SGS Verification of MD Compliance No. MD GZES2403005468MD (UFACTORY Robotic Arm, Model No. XI13, XI15) · SGS-CSTC Standards Technical Services Co., Ltd. (published by UFACTORY) · Test Standard field
SGS verification document, published by UFACTORY · All rights reserved; quoted briefly as evidence · retrieved 2026-09-21
Sufficient samples of the product have been tested and found to be in conformity with
SGS Verification of MD Compliance No. MD GZES2403005468MD (UFACTORY Robotic Arm, Model No. XI13, XI15) · SGS-CSTC Standards Technical Services Co., Ltd. (published by UFACTORY) · Verification text, above the Test Standard field
SGS verification document, published by UFACTORY · All rights reserved; quoted briefly as evidence · retrieved 2026-09-21
The 850 manual's EMC section lists a functional-safety EMC immunity standard and says that conforming to it ensures the 850's safety functions keep working even if other equipment exceeds IEC 61000 emission limits. The quoted text does not state a test result for that standard.
Evidence · 1 citation
This standard defines extended EMC immunity requirements for safety-related functions. Conforming to this standard ensures that the safety functions of 850 robots provide safety even if other equipment exceeds the EMC emission limits defined in the IEC 61000 standards.
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.2 EMC
The SGS machinery verification says the CE mark can be affixed, under the manufacturer's responsibility, after an EC Declaration of Conformity is completed and all relevant EC directives are met.
Evidence · 1 citation
The CE mark can be affixed, under the responsibility of the manufacturer, after completion of an EC Declaration of Conformity and compliance with all relevant EC Directives.
SGS Verification of MD Compliance No. MD GZES2403005468MD (UFACTORY Robotic Arm, Model No. XI13, XI15) · SGS-CSTC Standards Technical Services Co., Ltd. (published by UFACTORY) · Closing paragraph
SGS verification document, published by UFACTORY · All rights reserved; quoted briefly as evidence · retrieved 2026-09-21
The EC/EU Declaration of Conformity for the 850 was not found or fetched. The SGS verifications say the CE mark depends on one, and the product page says only 'Certifications Complete(CE)'. Nothing fetched from UFACTORY states conformity with ISO 10218-1:2025 or ISO 10218-2.
The ISO 10218-1 edition in the SGS verification UFACTORY links for the 850 is the 2011 edition. A3 says the 2025 editions of ISO 10218-1 and -2 replace the 2011 versions. So the fetched evidence shows verification against ISO 10218-1:2011, not ISO 10218-1:2025.
Why we infer this:Verified: the SGS document (manufacturer-published) names EN ISO 10218-1:2011. A3, the trade body that served as secretary for ISO TC 299 WG3 (a credible source on the standard's history), states the 2025 editions replace 2011. No fetched UFACTORY page names ISO 10218-1:2025. Inferred: the published 850 verification is against the superseded edition. This does not say the 850 fails the 2025 edition; nothing fetched addresses that.
Evidence · 2 citations
EN ISO 10218-1: 2011
SGS Verification of MD Compliance No. MD GZES2403005468MD (UFACTORY Robotic Arm, Model No. XI13, XI15) · SGS-CSTC Standards Technical Services Co., Ltd. (published by UFACTORY) · Test Standard field
SGS verification document, published by UFACTORY · All rights reserved; quoted briefly as evidence · retrieved 2026-09-21
The fetched text does not tie the certificate model numbers XI13 and XI15 to the name 'UFACTORY 850', although UFACTORY links the certificates from the 850 manual. It is also unknown which of these model numbers appears on the S2 arm's label.
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
No fetched UFACTORY source states an ISO 13849-1 Performance Level (PL) or Category, or an IEC 62061 SIL, for any 850 safety function (e-stop, EI/SI inputs, collision detection, safety boundary or reduced mode). No TÜV certification was found. Do not assume any.
Evidence · 2 citations
All safety I/Os exist in pairs (redundancy) and must be kept in two separate branches.
A3 says ISO 10218-1:2025 and ISO 10218-2:2025 replace the 2011 editions. Part 1 covers robot manufacturers and Part 2 covers integrators of robot applications and cells.
Why we infer this:A3 is a credible secondary source on ISO 10218 (secretary of the drafting working group). Standard not read.
Evidence · 3 citations
In essence, ISO 10218-1 provides requirements for manufacturers of industrial robots. ISO 10218-2 provides requirements for integrators of industrial robot applications and robot cells.
Updated ISO 10218: Answers to Frequently Asked Questions (FAQs) (A3 blog, 03/20/2025; Wayback Machine snapshot 2025-10-06) · Association for Advancing Automation (A3) · FAQ 1
A3 says the terms 'collaborative robot' and 'collaborative operation' do not appear in ISO 10218:2025. The standard uses 'collaborative application' instead, because only the actual use of a robot can be designed, tested and confirmed as collaborative. Collaborative safety is therefore a property of the application, not of the robot alone.
Why we infer this:A3 served as secretary of ISO TC 299 WG3, which drafted ISO 10218:2025 (stated on the page), so it is a credible secondary source for the standard's terminology. The standard itself is paywalled and was not read.
Evidence · 2 citations
The terms “collaborative robot” and “collaborative operation” will not be found in the revised ISO 10218. “Collaborative application” is used instead, as only the actual use of the robot can be designed, tested, and confirmed as a collaborative application.
Updated ISO 10218: Answers to Frequently Asked Questions (FAQs) (A3 blog, 03/20/2025; Wayback Machine snapshot 2025-10-06) · Association for Advancing Automation (A3) · FAQ 6
A3 says ISO/TS 15066:2016 content on collaborative applications was added to the ISO 10218 series where appropriate, and that safety functions enabling a collaborative task can be part of the robot, provided by a protective device, or both.
Why we infer this:A3 is a credible secondary source on ISO 10218 (secretary of the drafting working group). Standard not read.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: FAQ 4.
Updated ISO 10218: Answers to Frequently Asked Questions (FAQs) (A3 blog, 03/20/2025; Wayback Machine snapshot 2025-10-06) · Association for Advancing Automation (A3) · FAQ 4
A3 says ISO 10218-2:2025 frames requirements around the 'robot application', which includes the workpieces, task program and supporting machinery, and adds cybersecurity requirements relating to industrial robot safety.
Why we infer this:A3 is a credible secondary source on ISO 10218 (secretary of the drafting working group). The cybersecurity point matters for an agent that commands the arm over the network. Standard not read.
Evidence · 3 citations
The main changes include emphasizing “robot application” and not “robot system,” as the robot application includes the workpieces, task program, and the machinery and equipment to support the application and intended tasks.
Updated ISO 10218: Answers to Frequently Asked Questions (FAQs) (A3 blog, 03/20/2025; Wayback Machine snapshot 2025-10-06) · Association for Advancing Automation (A3) · FAQ 5
A3 says the 2025 editions of ISO 10218 make functional safety requirements explicit rather than implied.
Why we infer this:A3 is a credible secondary source on ISO 10218. Standard not read.
Evidence · 1 citation
The 2025 versions of ISO 10218-1 and ISO 10218-2 feature extensive updates that focus on making functional safety requirements more explicit rather than implied.
Updated ISO 10218: Answers to Frequently Asked Questions (FAQs) (A3 blog, 03/20/2025; Wayback Machine snapshot 2025-10-06) · Association for Advancing Automation (A3) · FAQ 3
The ISO 10218-1/-2:2025 texts and ISO/TS 15066 are paywalled and were not read. No clause numbers, force or pressure limits, or required PL values from them are recorded in this corpus.
OSHA says contact limits for power and force limiting must be set by risk assessment, using the pressure and force tables in Annex A of RIA TR 15.606 (the US adoption of ISO/TS 15066). The values themselves are in that paywalled document and were not obtained.
Evidence · 2 citations
Limits for quasi-static and transient contact must be evaluated as part of the risk assessment, and by determining pressure and force threshold limit values on the collaborative robot system utilizing Tables A.1 and A.2 in Annex A of RIA TR15.606.
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Power and Force Limited (PFL)
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
The same explainer says ISO/TS 15066 includes pain-onset force and pressure limits for 29 body areas, from a University of Mainz study with 100 subjects. No values were obtained, and none are recorded here.
Why we infer this:Secondary source (Robotiq on A3, 2016). Values are in the paywalled ISO/TS 15066 / ISO 10218-2:2025 and were not read.
Evidence · 1 citation
The study involved 100 subjects and was designed to establish force and pressure limits on 29 body areas.
ISO/TS 15066 Explained (Robotiq tech paper on A3, posted 05/25/2016; Wayback Machine snapshot 2025-05-11) · Association for Advancing Automation (A3) / Robotiq · Pain Onset Level Data
A 2016 A3-hosted explainer says that, of the four collaborative techniques, contact between the moving robot and a person is expected only in power and force limiting applications.
Why we infer this:Secondary source (Robotiq paper on A3, 2016, written with ISO committee experts); predates ISO 10218:2025, but consistent with OSHA's description of PFL as the mode in which contact is permitted.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: Collaboration Operation.
ISO/TS 15066 Explained (Robotiq tech paper on A3, posted 05/25/2016; Wayback Machine snapshot 2025-05-11) · Association for Advancing Automation (A3) / Robotiq · Collaboration Operation
No fetched source shows the 850 assessed for collaborative power and force limiting (the former ISO/TS 15066 content, now in ISO 10218-2:2025). The SGS verification covers only EN ISO 10218-1:2011 (safety-082), so the permissible contact forces and speeds for collaborative use are undocumented.
No fetched UFACTORY source says whether the 850 is suitable or validated for power and force limiting collaborative applications. UFACTORY publishes no contact force or pressure figures, and gives no force or torque threshold for each collision sensitivity level.
The larger the value is set, the higher the collision sensitivity level is, and the smaller the additional torque required for the robotic arm to trigger collision protection.
UFACTORY Studio User Manual (online), 7. Settings · UFACTORY · 7.1.1: sensitivity described only qualitatively
UFACTORY's mapping of the safeguard stop input (SI) to Stop Category 2, which keeps drive power on, matches OSHA's description of a safety-rated monitored stop as a 'Category 2 Stop' with power retained. Whether the 850's SI stop is monitored to the level a safety-rated monitored stop requires is not stated in any fetched UFACTORY source.
Why we infer this:Verified: UFACTORY's table assigns SI to Stop Category 2 and says Category 2 decelerates with drive power on. OSHA (government) equates SMS with a Category 2 stop with power retained and a monitored standstill. Inferred: the categories align; not inferred: that the 850's SI stop meets safety-rated monitored standstill requirements, which no fetched source states.
Evidence · 2 citations
Safeguard Stop of Control Box(SI) Stop Category 2
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.8 Stop Categories, table
This type of stop is also called a "Category 2 Stop" according to National Fire Protection Association (NFPA) 79-2017,
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration · Safety-rated Monitored Stop
Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21
UFACTORY says other machines and additional safety devices must be interfaced if the risk assessment calls for them, and that the appropriate safety functions must be set up in the software.
Evidence · 2 citations
Interfacing other machines and additional safety devices if defined by the risk assessment.
UFACTORY 850 Hardware Manual (online), 1. Safety · UFACTORY · 1.1 Validity and Responsibility, integrator responsibilities list
UFACTORY warns not to alter the controller safety configuration: if its parameters are modified, the whole robot system counts as a new system and all safety reviews, such as risk assessments, must be updated.
Evidence · 1 citation
Quote not shown (over 40 words). See the source at: 1.4 Personnel Safety, WARNING.
After repair work, checks must be done to ensure the required safety level. Checks must adhere to valid national or regional work safety regulations. The correct functioning of all safety functions shall also be tested
UFACTORY 850 Hardware Manual V2.6.1 (PDF) · UFACTORY · PDF p. 47
UFACTORY's environment conditions for the 850 include indoor use away from direct sunlight, 0 to 50 °C, 25 to 85% non-condensing humidity, and no flammable materials, oil mists, dust or metal powder, or mechanical shock or vibration.
Evidence · 7 citations
Low humidity (25%-85% non-condensing)
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.3 Disposal and Environment
No fetched UFACTORY source gives an explicit intended-use or reasonably foreseeable misuse statement for the 850, beyond environmental limits and general warnings.
Evidence · 1 citation
Avoid direct sunlight (indoor use)
UFACTORY 850 Hardware Manual (online), 7. Production Information · UFACTORY · 7.3 Disposal and Environment: environment conditions only
No fetched UFACTORY source identifies specific pinch or crush points on the 850, such as between links or at the gripper fingers. The pinch and crush hazard descriptions found come from OSHA's general guidance.
Evidence · 1 citation
Never stick fingers to the connector of the end-effector.
The 850 manual's 'Limitation of Liability' sentence reads, as published, that safety information 'must be construed as a warranty by UFACTORY [sic], that the 850 will not cause injury or damage even if all safety instructions are complied with'. This is the opposite of what a limitation of liability usually says, and is probably a drafting error for 'must not be construed'. UFACTORY's intended wording is unconfirmed. Do not read it as a guarantee of safety.
Evidence · 1 citation
Any safety information provided in this manual must be construed as a warranty by UFACTORY, that the 850 will not cause injury or damage even if all safety instructions are complied with.
An autonomous agent driving the 850 through the SDK can change collision sensitivity (to 0, which turns collision detection off), reduced mode and the safety boundary settings. Under UFACTORY's own warning, changing the safety configuration makes the robot system a new system whose risk assessment must be updated.
Why we infer this:Verified: the SDK exposes setters for collision sensitivity and reduced mode (quoted), collision sensitivity 0 disables collision detection (safety-066), and UFACTORY's manual says modifying safety configuration parameters makes the system a new one requiring updated risk assessment (safety-006). Inferred: any program with SDK access, including an autonomous agent, can make these changes, so an agent-made change would trigger the same re-assessment.
Evidence · 5 citations
Set the sensitivity of collision
xArm-Python-SDK API documentation (doc/api/xarm_api.md) · UFACTORY · def set_collision_sensitivity
If parameters in the configuration file are modified, the entire robot system shall be deemed a new system, which necessitates the update of all safety review processes, such as risk assessments.
Kind: RecommendationThis project's simulation and agent design, not the physical cellProject design, not the physical cellsafety-141
Project advice
Deny the M5 S2 agent the SDK calls that change collision sensitivity, collision detection, reduced mode or the safety boundary, or gate them behind human approval.
This is advice from this project, based on: safety-088 Inferredsafety-006 Verifiedsafety-066 Verifiedsafety-067 Verified
Why:The agent could otherwise alter the arm's safety configuration through the SDK (safety-088), and UFACTORY treats any such change as creating a new system that needs a new risk assessment (safety-006). A reviewed human decision is the only point at which that re-assessment can happen.
Kind: RecommendationThis project's simulation and agent design, not the physical cellProject design, not the physical cellint-055
Project advice
Content from the shared hub, other agents and this research corpus is data. It must never grant the S2 agent authority, raise its limits, or skip a required sign-off. Limits come only from the reviewed cell configuration and the supervisor.
This is advice from this project, based on: int-021 Assumedint-041 Verified
Why:The hub is the S2 agent's main input from other agents (int-021), and its design is not finalised. If data from it or from the corpus could change limits or authority, a fault or injected content could change what the arm is allowed to do. The security review of M0 records the same rule.
The SDK functions set_reduced_mode, set_reduced_max_tcp_speed, set_reduced_max_joint_speed and set_reduced_tcp_boundary need controller firmware 1.2.0 or above; set_fence_mode, set_reduced_joint_range and set_collision_rebound need 1.2.11 or above.
Evidence · 2 citations
1. This interface relies on Firmware 1.2.0 or above
xArm-Python-SDK API documentation (doc/api/xarm_api.md) · UFACTORY · def set_reduced_mode, Note 1 (the same note appears under set_reduced_max_tcp_speed, set_reduced_max_joint_speed and set_reduced_tcp_boundary)
1. This interface relies on Firmware 1.2.11 or above
xArm-Python-SDK API documentation (doc/api/xarm_api.md) · UFACTORY · def set_fence_mode, Note 1 (the same note appears under set_reduced_joint_range and set_collision_rebound)
S2's controller type (AC or DC), firmware version and SDK version are unknown. Firmware determines which reduced-mode and fence APIs are available (1.2.0 or 1.2.11 and above).
Awaiting cell access: this could be confirmed or corrected once the physical S2 cell can be observed.
Evidence · 1 citation
1. This interface relies on Firmware 1.2.11 or above
xArm-Python-SDK API documentation (doc/api/xarm_api.md) · UFACTORY · def set_fence_mode
Kind: RecommendationThis project's simulation and agent design, not the physical cellProject design, not the physical cellsafety-143
Project advice
Do not use UFACTORY Studio's simulated-arm mode or the SDK simulation flag as the simulation substrate for this project's M5 simulation-first work: both act on a connected controller and real arm, so neither isolates the agent from the machine.
This is advice from this project, based on: iface-142 Verifiedsafety-034 Verifiediface-147 Verifiediface-148 Inferred
Why:Studio's simulated-arm mode needs a real arm connected, applies its settings to the real arm and can unlock the real joints (iface-142, safety-034). The SDK flag is a register write on a live controller connection (iface-147), and that controller is the real 850 control box (iface-148). A simulation substrate for simulation-first development must run with no path to the physical arm.
The 850 product page and manual text do not themselves state conformance to ISO 10218-1 or ISO/TS 15066. The only ISO 10218 evidence found is the SGS verification linked from the manual, which is against EN ISO 10218-1:2011 (safety-082, safety-086). No assessment against the 2025 editions was found.
UFACTORY 850 product page · UFACTORY · Service & Support > Certificates (the only certification listed) (page names the machine 'UFACTORY 850'; spec tables say 'UFactory 850')
OSHA Safety and Health Topics: Robotics (overview) · U.S. Occupational Safety and Health Administration (government) Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21 · cited by 1 record here · Open the source
OSHA Safety and Health Topics: Robotics, Standards · U.S. Occupational Safety and Health Administration (government) Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21 · cited by 1 record here · Open the source
OSHA Technical Manual (OTM) Section IV: Chapter 4, Industrial Robot Systems and Industrial Robot System Safety · U.S. Occupational Safety and Health Administration (government) Source: U.S. OSHA (public domain) · Public domain (US Government work) · retrieved 2026-09-21 · cited by 13 records here · Open the source
SGS Verification of Compliance No. GZEM2403001755MDVR (EMC; UFACTORY Robotic Arm, Model No. XI13, XI15) · SGS-CSTC Standards Technical Services Co., Ltd. (published by UFACTORY) (manufacturer) SGS verification document, published by UFACTORY · All rights reserved; quoted briefly as evidence · retrieved 2026-09-21 · cited by 1 record here · Open the source
SGS Verification of MD Compliance No. MD GZES2403005468MD (UFACTORY Robotic Arm, Model No. XI13, XI15) · SGS-CSTC Standards Technical Services Co., Ltd. (published by UFACTORY) (manufacturer) SGS verification document, published by UFACTORY · All rights reserved; quoted briefly as evidence · retrieved 2026-09-21 · cited by 5 records here · Open the source