How to scope cobot safety and I/O before purchase: ISO 10218 / TS 15066

Cobot safety and I/O scope before purchase: collaborative ≠ skip safety; define zones, e-stop, and tool I/O under ISO 10218 and ISO/TS 15066; EOAT changes require reassessment. Collaborative robotic arm pre-buy checklist.

Roooll cobot safety and I/O guide: scope ISO 10218 / TS 15066 zones, e-stop, and tool signals before you buy

Quick answer

Collaborative ≠ skip safety: force limiting / speed control is a design capability—not a substitute for a written cell risk assessment and risk reduction

Standards frame: ISO 10218-1/2 (industrial robot safety requirements) + ISO/TS 15066 (collaborative application supplement, including power-and-force limiting discussion)

Write before quote: work-zone boundary, speed / person strategy, e-stop and reset ownership, tool DI / DO and who wires valves

EOAT change = reassess: spilma notes tooling changes mass, inertia, and contact geometry—especially for PFL

Same-page links: tool path and I/O → End-effector guide; zoning with layout → Workcell layout guide

Week three of install: the arm is bolted down. Gripper feedback finds no spare PLC points; line e-stop topology disagrees with the arm cabinet; EHS asks for a risk review. The fight is not “is the cobot dangerous?” It is that safety and I/O were never written into the purchase scope. Below: collaborative vs standards language, zones / e-stop / tool I/O, EOAT reassessment, a pre-buy checklist table, and a 5 DI + 2 DO gap example you can paste into an RFQ.

Collaborative does not mean you can skip safety

Collaborative robotic arms often need less fencing, but “collaborative” describes the ability to share a workspace under assessed conditions—not a liability waiver. ISO 10218 covers robot and cell integration safety requirements (commonly Part 1 for the robot, Part 2 for integration / application); ISO/TS 15066 supplements collaborative operation (including power-and-force limiting discussion). Both still assume documented risk analysis and reduction—see spilma’s 10218 / 15066 guide. Buyer and integrator notes (EVS, AMD, Ocean Player in deployment and payload contexts) also tie safety assumptions to speed, load, and tooling: overload or a sharper fingertip can invalidate stopping-distance and contact-pressure pictures in your assessment.

This page helps you define scope before you quote. It does not replace formal assessment, certification, or local law. Naming a standard in a slide deck does not make the cell compliant.

How to judge the scope is RFQ-ready

When people may enter the envelope—and what the arm does then—is written as executable sentences, not the words “collaborative mode”

E-stop and reset ownership names a role; “we’ll see later” is not enough

The tool signal list has point counts and voltage that match spare PLC points or an explicit add-on module line

EOAT-change reassessment triggers sit in a contract attachment

Top-view layout language matches safety zoning words, with a comparison / advisor link for cabinet I/O across models

Miss any item and week-three arguments usually return.

Zones, e-stop, and tool I/O (what to write before quote)

TopicWhat to write before quoteEnough when…
Work-zone boundaryFloor mark / curtain / scanner / “fixed station + trained not to enter”; whether hands enter on changeoverA third party can draw when people may enter
Speed and person distanceTransfer speed when clear vs reduced speed or hold when someone is nearBoth modes have written triggers
E-stop and resetButton locations, main contactor behavior, line interlock, who may restartE-stop reachable; reset ownership is not verbal
Tool I/OGrip feedback, vacuum OK, vision OK, conveyor interlock—DI / DO count and voltagePoints are line items—not “standard open/close”
Responsibility splitStandard cabinet points vs PLC changes; who supplies and wires valves / harnessesMain quote vs extras are clear
EOAT changeWho triggers reassessment and what is deliveredSame page as the End-effector guide

Zoning words must match the top view—if layout draws a walkway but the safety scope says “full isolation,” the RFQ fails on contact → Workcell layout guide.

Worked example: I/O gap (5 DI + 2 DO vs quote 2 points)

Quote attachment: “standard gripper open / close, 2 points.” Floor signal list:

SignalTypePurpose
Grip seatedDIConfirm positive hold before lift
Vacuum OKDIAllow leave pick only after seal
Vent completeDIPlace without cup stick
Vision NGDIDivert / stop on fail
Conveyor permitDIInterlock against box collision
Open / close (or suck / vent) commandsDO ×2Drive valve or gripper

Total: 5 inputs + 2 outputs. No spare PLC points; adding a module takes about two weeks and eats the commissioning window. If the vacuum generator is integrator-supplied and the harness was never in the main quote, week-three arguments escalate into contract language. Listing counts, voltage, and valve ownership in the RFQ is cheaper than adding modules after delivery.

EOAT changes require reassessment

Heavier, longer, or sharper tools—or different contact area and tip material—change effective mass, inertia, and PFL pressure pictures. spilma lists skipping EOAT reassessment as a common non-conformity. Switching vacuum to grip (or the reverse) also changes drop interlocks and I/O counts—when the path changes, revisit:

Tool path and TCP mass → End-effector guide · Payload guide

Open/close or build/vent time → Cycle time guide

Envelope and human paths → Workcell layout guide

Fingertip safety is not “higher clamp force is better.” In a shared zone, contact geometry and force-limit strategy belong in the scope file. Public EOAT discussions (Olympus, Robotiq, and similar) often bind grasp method to application constraints—write compliance materials and interlocks into the same page.

Pre-buy one-page scope checklist

Check itemYes / No / Notes
Do people enter the envelope in normal run? How often?
Who does changeover / loading? Zone hold needed?
How is reset done after e-stop? Who authorizes? Line e-stop interlocked?
Tool-signal list (DI / DO) and voltage
Who supplies and wires valves / vacuum generators?
Who builds PLC / MES interface, and when is it due?
Who triggers reassessment when EOAT changes? What is delivered?
What the main quote includes vs fencing / certification / civil work
Do layout top view and safety zoning use the same words?
Has the comparison table checked cabinet I/O? → Side-by-Side Comparison

If the application and shared-station path are still open, narrow the model with Product Advisor, then fill the table into the same RFQ pack.

Safety ↔ EOAT cross-check

Cross questionSymptom when it failsFix
Sharp tips / clamp force not in assessmentEHS stop or PFL tripsTool geometry in scope; change triggers review
Vacuum drop with no interlockMotion continues after dropVacuum OK as DI, motion interlocked
I/O quoted as “standard 2 points”Module add in commissioning weekSignal table as lines (see example)
Cup / tip swap without integrator noticeOld assessment invalidContract states change triggers

Published evidence bands (safety scope)

BandHow to use itSource
ISO 10218-1/2Robot and integration safety frameiso.org
ISO/TS 15066Collaborative operation supplement (incl. PFL)iso.org
EOAT change → reassessMass / inertia / contact geometry shiftspilma
Layout and risk before boltsPlan before installOcean Player integrate guide
Load / speed assumptionsOverload can break safety and takt assumptionsEVS · AMD · Ocean Player payload

Common questions

If it is labeled collaborative, do we still need fencing?
Maybe. Speed, payload, EOAT sharpness, and interaction mode decide measures—the assessment decides, not the brochure. Human paths on the layout and zoning in the assessment must use the same words.
Does ISO/TS 15066 replace ISO 10218?
No. 15066 supplements collaborative operation; the cell still sits in the 10218 integration frame. RFQ attachments should name both and state who delivers the assessment package.
Is I/O included in the arm price by default?
Standard point counts follow the configuration sheet; extras, valves, and PLC changes are often separate lines—list them in the RFQ and check cabinet options in Side-by-Side Comparison.
Who owns the risk assessment?
Usually the integrator / employer side under local rules. Buyers at least provide task, people, and zoning inputs and write deliverables into the contract. Missing inputs leave the scope blank.
Do we reassess if we only change cup faces?
If contact area, hardness, sharp edges, or tool mass change materially, trigger at least a documented review—“looks similar” is not an exemption. spilma stresses the effect of the change, not the invoice amount of the spare.
Who may reset after e-stop?
Write it into scope: button locations, key / permission needs, line e-stop interlock, and whether tool state (grip / vacuum) must be confirmed before restart. “Anyone on the line knows” does not belong in a contract.
Does buying a cobot with power-and-force limiting mean automatic compliance?
No. PFL is one collaborative strategy option; it still depends on correct tooling, speed, contact assumptions, and verification. Change EOAT or raise speed and the old verification may no longer hold.

Next steps

End effector and vacuum I/O: End-effector guide

Compare cabinet and I/O across tiers: Side-by-Side Comparison

Application and shared-station path: Product Advisor

Layout and human paths: Workcell layout guide

TCP mass and rated headroom: Payload guide

Open/close time and interlock beats: Cycle time guide

Electrical drawings or station video: Contact us

Share article

New possibilities for your next cobot deployment.

Explore new ways to move your decision forward—with clarity, confidence, and less second-guessing. You don't need every detail settled before you loop in procurement or engineering. When the guides have pointed the way, the paths below help you take the next step together.