Quick answer
Collaborative ≠ skip safety: force limiting / speed control is a design capability—not a substitute for a written cell risk assessment and risk reduction
Standards frame: ISO 10218-1/2 (industrial robot safety requirements) + ISO/TS 15066 (collaborative application supplement, including power-and-force limiting discussion)
Write before quote: work-zone boundary, speed / person strategy, e-stop and reset ownership, tool DI / DO and who wires valves
EOAT change = reassess: spilma notes tooling changes mass, inertia, and contact geometry—especially for PFL
Same-page links: tool path and I/O → End-effector guide; zoning with layout → Workcell layout guide
Week three of install: the arm is bolted down. Gripper feedback finds no spare PLC points; line e-stop topology disagrees with the arm cabinet; EHS asks for a risk review. The fight is not “is the cobot dangerous?” It is that safety and I/O were never written into the purchase scope. Below: collaborative vs standards language, zones / e-stop / tool I/O, EOAT reassessment, a pre-buy checklist table, and a 5 DI + 2 DO gap example you can paste into an RFQ.
Collaborative does not mean you can skip safety
Collaborative robotic arms often need less fencing, but “collaborative” describes the ability to share a workspace under assessed conditions—not a liability waiver. ISO 10218 covers robot and cell integration safety requirements (commonly Part 1 for the robot, Part 2 for integration / application); ISO/TS 15066 supplements collaborative operation (including power-and-force limiting discussion). Both still assume documented risk analysis and reduction—see spilma’s 10218 / 15066 guide. Buyer and integrator notes (EVS, AMD, Ocean Player in deployment and payload contexts) also tie safety assumptions to speed, load, and tooling: overload or a sharper fingertip can invalidate stopping-distance and contact-pressure pictures in your assessment.
This page helps you define scope before you quote. It does not replace formal assessment, certification, or local law. Naming a standard in a slide deck does not make the cell compliant.
How to judge the scope is RFQ-ready
When people may enter the envelope—and what the arm does then—is written as executable sentences, not the words “collaborative mode”
E-stop and reset ownership names a role; “we’ll see later” is not enough
The tool signal list has point counts and voltage that match spare PLC points or an explicit add-on module line
EOAT-change reassessment triggers sit in a contract attachment
Top-view layout language matches safety zoning words, with a comparison / advisor link for cabinet I/O across models
Miss any item and week-three arguments usually return.
Zones, e-stop, and tool I/O (what to write before quote)
| Topic | What to write before quote | Enough when… |
|---|---|---|
| Work-zone boundary | Floor mark / curtain / scanner / “fixed station + trained not to enter”; whether hands enter on changeover | A third party can draw when people may enter |
| Speed and person distance | Transfer speed when clear vs reduced speed or hold when someone is near | Both modes have written triggers |
| E-stop and reset | Button locations, main contactor behavior, line interlock, who may restart | E-stop reachable; reset ownership is not verbal |
| Tool I/O | Grip feedback, vacuum OK, vision OK, conveyor interlock—DI / DO count and voltage | Points are line items—not “standard open/close” |
| Responsibility split | Standard cabinet points vs PLC changes; who supplies and wires valves / harnesses | Main quote vs extras are clear |
| EOAT change | Who triggers reassessment and what is delivered | Same page as the End-effector guide |
Zoning words must match the top view—if layout draws a walkway but the safety scope says “full isolation,” the RFQ fails on contact → Workcell layout guide.
Worked example: I/O gap (5 DI + 2 DO vs quote 2 points)
Quote attachment: “standard gripper open / close, 2 points.” Floor signal list:
| Signal | Type | Purpose |
|---|---|---|
| Grip seated | DI | Confirm positive hold before lift |
| Vacuum OK | DI | Allow leave pick only after seal |
| Vent complete | DI | Place without cup stick |
| Vision NG | DI | Divert / stop on fail |
| Conveyor permit | DI | Interlock against box collision |
| Open / close (or suck / vent) commands | DO ×2 | Drive valve or gripper |
Total: 5 inputs + 2 outputs. No spare PLC points; adding a module takes about two weeks and eats the commissioning window. If the vacuum generator is integrator-supplied and the harness was never in the main quote, week-three arguments escalate into contract language. Listing counts, voltage, and valve ownership in the RFQ is cheaper than adding modules after delivery.
EOAT changes require reassessment
Heavier, longer, or sharper tools—or different contact area and tip material—change effective mass, inertia, and PFL pressure pictures. spilma lists skipping EOAT reassessment as a common non-conformity. Switching vacuum to grip (or the reverse) also changes drop interlocks and I/O counts—when the path changes, revisit:
Tool path and TCP mass → End-effector guide · Payload guide
Open/close or build/vent time → Cycle time guide
Envelope and human paths → Workcell layout guide
Fingertip safety is not “higher clamp force is better.” In a shared zone, contact geometry and force-limit strategy belong in the scope file. Public EOAT discussions (Olympus, Robotiq, and similar) often bind grasp method to application constraints—write compliance materials and interlocks into the same page.
Pre-buy one-page scope checklist
| Check item | Yes / No / Notes |
|---|---|
| Do people enter the envelope in normal run? How often? | |
| Who does changeover / loading? Zone hold needed? | |
| How is reset done after e-stop? Who authorizes? Line e-stop interlocked? | |
| Tool-signal list (DI / DO) and voltage | |
| Who supplies and wires valves / vacuum generators? | |
| Who builds PLC / MES interface, and when is it due? | |
| Who triggers reassessment when EOAT changes? What is delivered? | |
| What the main quote includes vs fencing / certification / civil work | |
| Do layout top view and safety zoning use the same words? | |
| Has the comparison table checked cabinet I/O? → Side-by-Side Comparison |
If the application and shared-station path are still open, narrow the model with Product Advisor, then fill the table into the same RFQ pack.
Safety ↔ EOAT cross-check
| Cross question | Symptom when it fails | Fix |
|---|---|---|
| Sharp tips / clamp force not in assessment | EHS stop or PFL trips | Tool geometry in scope; change triggers review |
| Vacuum drop with no interlock | Motion continues after drop | Vacuum OK as DI, motion interlocked |
| I/O quoted as “standard 2 points” | Module add in commissioning week | Signal table as lines (see example) |
| Cup / tip swap without integrator notice | Old assessment invalid | Contract states change triggers |
Published evidence bands (safety scope)
| Band | How to use it | Source |
|---|---|---|
| ISO 10218-1/2 | Robot and integration safety frame | iso.org |
| ISO/TS 15066 | Collaborative operation supplement (incl. PFL) | iso.org |
| EOAT change → reassess | Mass / inertia / contact geometry shift | spilma |
| Layout and risk before bolts | Plan before install | Ocean Player integrate guide |
| Load / speed assumptions | Overload can break safety and takt assumptions | EVS · AMD · Ocean Player payload |



