4 Safety

4.1 Overview of Safety Features

The Thor robot includes many safety features for operating in hybrid and industrial applications. The exact implementation of these features will depend upon the application and risk assessment. The final performance level of the system will depend on the integration and must be calculated by the integrator.

Thor has parameters for the below settings that can be fully customized for the end application and allow for integration with a wide variety of industrial safety components.

4.1.1 Response Time

Thor responds to safety events within the tolerances in the below chart:

Safety Input Event Worst Case Detection Time Worst Case Power Off Time Worst Case Response Time
Internal Emergency Stop 50ms 600ms 600ms
External Emergency Stop 50ms 600ms 600ms
External Safety IO Slow Speed Input 50ms N/A 600ms
External Safety IO Emergency Stop 50ms 600ms 600ms
Tablet or Browser E-Stop 1000ms* 1600ms* 1600ms*

*Network Latency Dependent

Safety Output Event Worst Case Response Time
Robot E-Stop 50ms

4.2 Safety Settings

WARNING – Safety Parameters Shall Match the Operating Scenario and the Presence of Persons

All safety-related parameters – speed and slow-speed limits, safety-input assignments, auto-reset behavior, collision-detection thresholds, and payload mass – are safety-critical and shall be configured per the integrator’s ISO 10218-2 risk assessment for the actual operating scenario.

Parameters validated for one scenario – for example automatic or person-excluded (“outside the cage”) operation – shall not be used when a person can be inside the safeguarded space. Parameters safe for an excluded person are not safe for a present person.

After any change, the affected safety functions shall be re-verified before returning to production (settings apply only on “Apply”). Access shall be restricted by PIN/role to authorized personnel.

Using parameters that do not match the actual presence of persons may delay or prevent the safety reaction and expose personnel to hazardous motion

Safety Settings can be accessed by tapping the robot menu, then Settings > Safety.

Accessing Safety Settings

Settings are locked by default; click the “Unlock” button and re-enter the robot PIN to make the settings here editable.

Safety settings do not take effect until you tap “Apply Settings.”

4.2.1 Speed Limits

4.2.1.1 How Limits Work

Thor has several levels of limits; the robot is always gated to the lowest of all of these:

All of these settings are described below.

4.2.1.2 Editing Global Limits

The first tab of safety settings allows setting limits on the speed and acceleration of both the tooltip and the joints of the robot.

4.2.1.2.1 Using Factory Presets

By default, you will be presented with the choice of several presets.

The “default” (middle) setting restricts the robot to a tooltip speed of 0.75m/s at full speed or 0.5m/s at slow speed, which is safe for most hybrid settings. Note that an unguarded or partially guarded hybrid setting requires the use of peripheral safety devices, such as area scanners or light curtains, wherever hard guarding is not used. Several other speed restriction settings are available; if there are factors that may require more caution (such as the robot’s payload or end effectors), it may be desirable to select a more conservative setting.

Remember that many factors can affect whether a given speed is safe. Before putting the robot into production, you should always conduct a full safety assessment per ISO 10218-2 to determine the proper values for these settings and any other mitigations required.

Safety Setting Presets

To review the values set for these factory presets, you can scroll down.

4.2.1.2.2 Custom Limits

To edit these limits, switch off “Use Factory Preset”; the limits should then become editable:

Editing custom limits in Safety Settings

The following can be customized, both for when the robot operates at its full speed and in a “slow” mode that can be triggered via Safety I/O settings:

4.2.2 Speed Modifier % Slider

The robot can be slowed down from its maximum as needed inside the robot menu.

This is useful for trying out a routine before putting it into production.

Setting this slider only applies a cap to the maximum limits that would otherwise be set in Safety Settings; movements that were already slower than that are not affected.

Modifying the global speed


4.2.3 Customizing Speed Limits For A Step

When editing a “Move” step, the “Motion Speed” shows the speed of this specific step. This is useful to notice for delicate movements or when required for safety. To change the speed, tap the “Edit Motion Limits” icon.

Step-specific setting

By tapping “Edit Motion Limits”, several options are available. The motion can be restricted to percentage of the maximum (as with the global speed modifier in the robot menu), or to a new set of custom limits.

Note that these limits apply whether the robot is operating at full speed or at any “slow” speed mode defined in safety settings. The robot will always apply the lowest of all limits in effect. It is also not possible to set torque limits on a per-step basis.

Editing speed limits applied to an individual step

4.3 Safety I/O

WARNING — Required Safeguarding Shall Use the Safety-Rated Inputs

Any safeguarding device required by the risk assessment shall be wired to the safety-rated inputs and assigned a safety function on this screen. Standard (non-safety) digital I/O described in §3.9 shall not be used for safeguarding. Connect each safeguarding device as a dual-channel pair and confirm correct stop / slow-speed response before operation.

Omitting or mis-wiring required safeguarding may expose personnel to hazardous robot motion.

In the safety Settings there are two tabs for I/O, Safety Inputs and Safety Outputs. Safety inputs allow you to tie in devices such as area scanners and key switches to discrete inputs onto your control box. Safety outputs allows the robot to indicate safety-critical elements of its status over discrete outputs to other devices like PLCs and other moving equipment that should stop when the robot does.

4.3.1 Configuring Safety Inputs

WARNING — Safety-Input, Slow-Speed and Auto-Reset Settings Are Safety Critical

Each safeguarding device shall be assigned the correct safety function (Emergency Stop / Pause / Slow Speed), wired dual-channel, and verified to trigger before operation.

The “Slow Speed” set shall be a speed/force determined safe by the risk assessment for the closest credible human proximity — not a default. Auto-Reset shall be configured so the robot cannot resume or speed up while a person may remain inside; re-enabling shall require a deliberate reset from outside the space.

Incorrect input, slow-speed, or auto-reset configuration may allow hazardous motion while a person is exposed.

The sixteen 24V inputs on the control box are all safety-rated and can be used in pairs. Safety devices are connected in pairs to eliminate the possibility of a stray signal keeping the robot operating while actually in an unsafe condition. Therefore, if either of the paired inputs is below 24V, it will be treated as a “low” signal.

Safety Input Settings

The following options are available:

4.3.2 Configuring Safety Outputs

Additionally, the sixteen outputs on the control box are all safety-rated and are also used in pairs to eliminate the possibility of a stray signal keeping the robot operating while actually in an unsafe condition.

Safety Output Settings

The following options are available:

4.4 Collisions & Protective Stops

When the robot is running a routine and encounters a collision, it will stop. The routine can be re-started with the “Play” button in the top toolbar. Every time a collision occurs, it will also log the time and force measured, which can be reviewed in the Notification (bell) section.

Collisions are detected with two methods: 1) by monitoring the current coming out of the joint motor to measure torque and find discrepancies, 2) by monitoring an IMU (accelerometer) inside each joint.

4.4.1 Adjusting Collision Sensitivity

WARNING — Collision Thresholds Affect Protective Force Limiting

Collision-detection thresholds shall be set and validated per the risk assessment and shall not exceed the values validated for collaborative / power-and-force-limited operation. Over-relaxed thresholds can allow injurious contact forces before the robot stops.

Depending on the environment and safety requirements, it may be desirable to change the sensitivity of collision detection. This can be done in the “Collisions” section of Safety IO.

This allows adjusting the thresholds used for both methods: the torque shock threshold (in newton-meters) and the acceleration threshold used by the IMU (in m/s²).


Collision sensitivity settings

4.5 Setting the Robot’s Payload Mass

WARNING — Payload Mass Shall Be Configured Accurately

The configured payload mass shall include the end-effector and shall match the actual payload. An inaccurate payload degrades collision sensing and balance and can contribute to unexpected motion.

The robot’s knowledge of its payload mass affects its ability to balance and sense collisions. It’s important for overall safety to configure the payload as part of setting up a robot cell with Thor.

There are two ways to set the payload:

  1. By adding a Set Payload step to a routine
  2. By setting the payload parameter within an Actuate Gripper step. This is useful for situations where the payload changes as a result of the gripper.

The payload mass entered should account not only for the mass of the payload itself but also that of any attached end effectors. The spec sheet for the end effector should include this information.

Set Payload Step to a Routine  Set Payload Parameter in Actuate Gripper step

4.6 Implementing Safeguarding Devices

WARNING — Safeguarding Devices Shall Be Connected to the Safety-Rated I/O

The Thor is partially completed machinery. Where the integrator’s risk assessment (per ISO 10218-2 / ISO/TS 15066) identifies the need for safeguarding — for example, during high-speed or non-collaborative operation, or whenever the robot can exceed the collaborative speed and force limits — the required safeguarding devices (such as light curtains, laser area scanners, or interlocked guard gates) shall be connected to the Thor control box safety-rated inputs and configured as Safety Inputs (see §4.3).

Safeguarding devices shall be selected, positioned, and wired in accordance with the risk assessment, ISO 13855 (positioning relative to approach speed), and ISO 13849-1. Each device shall be connected as a dual-channel pair to the safety-rated inputs and verified to trigger the assigned safety function (Emergency Stop, Protective Stop / Pause, or Slow Speed) before the cell is placed into production.

Failure to connect and validate the required safeguarding devices may leave personnel exposed to crushing, impact, and trapping hazards and can result in serious injury or death.

Every safety scanner has a unquie implimentation method. Please consult the manufacturer’s guide for an in-depth procedure on how to install the device. Below is a generic wiring diagram intended to aid with installing a safety scanner.

Generic Safety Scanner Wiring

4.7 3-Position Enabling Deadman Switch

WARNING — Operating-Mode Discipline

During automatic operation, persons shall be excluded from the safeguarded space (interlocked guarding / presence detection → protective stop). Programming or teaching near the robot shall be performed in reduced-speed manual mode with the 3-position enabling device held in the centre position.

Allowing persons in the envelope during automatic operation, or teaching at full speed, can cause serious injury.

The 3-position enabling Deadman switch is a safety device used to control robot motion during manual or teach operations. It ensures that the robot can only move when the operator is intentionally and safely holding the switch in the correct position.

The switch has three distinct positions:

  1. Released (Position 1) When the switch is not pressed, robot motion is disabled. This prevents unintended movement when the operator is not actively engaged.

  2. Enabled (Position 2) When the switch is pressed to its middle, neutral position, robot motion is permitted. This is the only position in which manual movement (including ‘Tap to Recover’) or teaching is allowed.

  3. Fully Depressed (Position 3) If the switch is squeezed beyond the enabled position—such as during a startle or panic reaction—robot motion is immediately stopped.

This design provides fail-safe behavior in both loss-of-contact and panic scenarios. Releasing or over-pressing the switch causes a stop, reducing the risk of injury during close-proximity operation.

The 3-position enabling Deadman switch is intended for use only during manual modes (e.g., teach, maintenance, jogging, unbraking, etc) and must be continuously held in the enabled position for robot motion to occur.

4.7.1 Pendant Connection Locations

The electrical connections for the pendant are located on the bottom edge of the tablet and control box, as shown in the connection images.

4.7.1.1 M12 Connection

4.7.1.2 USB-C Direct Connect