Operating mode and access permission

PITmode

Selecting an operating mode changes which safety functions are active — which makes the selection itself a safety-relevant act. PITmode combines functionally safe operating mode selection with access permission, so the mode a machine will accept depends on who is asking.

Functionally safe mode selectionAccess permission controlSafety and Security in one systemPITreader RFID permissionsUp to PL d
PL dStated for the system
RFIDTransponder keys
I.A.M.Identification and Access Management
Safe operating mode selection at a machine using the Pilz PITmode system
PITmodeOperating mode selection with access permission
SafeFunctionally safe mode selection
PermissionTied to the individual
PL dStated for the system
PreventsIncorrect operation and manipulation
Why it is specified

PITmode addresses

The manufacturer states these devices enable functionally safe operating mode selection and the control of access permissions on plant and machinery, so that incorrect operation and manipulation are prevented.

Mode selection made safe

Functionally safe operating mode selection, rather than a key switch whose position is simply read.

Permission and mode together

Safety and Security functions in one system, combining mode selection with access permission control.

Prevents manipulation

The manufacturer states incorrect operation and manipulation are prevented, protecting human and machine.

Scales to the requirement

Options range from a simple enable and user authentication to a complex permission matrix with company-specific coding.

Applications

PITmode is used

The requirement usually appears where setup mode reduces protection, and that mode is being used more widely than intended.

Safe operating mode selection on a machine using Pilz access management
Mode discipline

Setup mode kept for setup

Where setup mode reduces protection to allow adjustment, the ability to select it is limited to people permitted to work that way.

ConfirmConfirm the modes and who may select each.
Technician working inside a machine under an authorised operating mode
Authorised work

Maintenance and adjustment

Maintenance work that requires a permissive mode, granted only to staff trained and authorised for that task.

ConfirmConfirm roles and the permission matrix.
Operator presenting a Pilz RFID transponder key at a machine
Identification

Permission by transponder key

PITreader provides the authentication layer, with transponder keys available in freely writable versions and with fixed, stored coding.

ConfirmConfirm key type and coding requirement.
Technical data

Selection parameters that matter

PITmode is specified as a system of hardware and software components. These are its defining characteristics.

Access permission decides whether a mode may be selected. The mode-dependent safety functions themselves must still be specified and validated for the machine.
FunctionOperating mode selection and access permission system
ScopeEnables functionally safe operating mode selection and the control of access permissions on plant and machinery
PurposeIncorrect operation and manipulation are prevented, protecting human and machine
PortfolioOffered under Identification and Access Management (I.A.M.), combining Safety and Security functions in one system
ComponentsVarious hardware and software components for a one-stop Safety and Security solution
AuthenticationPITreader implements access permissions, from a simple enable and user authentication to a complex permission matrix and company-specific coding
DeploymentPITreader is flexible as a standalone device or used in conjunction with a controller
KeysTransponder keys with RFID technology, available in freely writable versions and with fixed, stored coding
CapabilityPL d is stated for the system within the access management range
Selecting a mode safely is not the same as the mode being safe. Which safety functions remain active in each mode, and the performance level each must achieve, follow from the machine risk assessment.
Models

System configuration

The system is defined by the modes required, the permission model and how deeply it integrates with the controller.

Modes

Operating mode selection

The number and nature of the modes the machine offers, and what each permits.

Selection
Functionally safe
Level
PL d stated
Permissions

Simple to complex

From a simple enable and user authentication through to a complex permission matrix.

Simple
Enable
Complex
Permission matrix
Coding

Company-specific

Company-specific coding is available where keys must be restricted to one organisation.

Keys
Writable or fixed
Coding
Company-specific
Integration

Standalone or with a controller

PITreader is flexible as a standalone device or used with a controller.

Standalone
Yes
Controller
Manufacturer controller
Accessories

Keys, readers and controller integration

The hardware count is small; the permission model and the mode definition carry the project.

Credentials

RFID transponder keys

Available in freely writable versions and with fixed, stored coding, issued per person against the permission model.

ConfirmConfirm key type, quantity and coding.
Authentication

PITreader

Implements the access permission function, standalone or in conjunction with a controller.

Typical pairingPITreader with PITmode.
Evaluation

Safety controller

Mode-dependent safety functions are implemented in the safety controller, which the mode selection informs.

Typical pairingPNOZmulti 2 configurable controller.
Before quotation

Application review

Define the modes and the permission model before the hardware. Both are organisational decisions before they are technical ones.

Modes

  • Which operating modes exist and what each permits
  • Which safety functions change between modes
  • Required performance level for mode selection
  • How modes are indicated to the operator

People and permissions

  • Which roles exist and what each may do
  • Whether a simple enable or a permission matrix is required
  • Whether company-specific coding is needed
  • How keys are issued, changed and revoked

Machine integration

  • Existing safety controller and spare capacity
  • Whether PITreader will be standalone or controller-connected
  • Number of machines and selection points
  • Existing mode selector arrangement being replaced

Records and administration

  • Whether mode changes must be recorded
  • Who administers permissions, and from where
  • Network and certificate arrangements
  • Behaviour expected if the network is unavailable
Related technologies

PITmode sits in the architecture

Permission and mode selection form a layer above the safety function. They determine what may be requested; the safety controller determines what the machine actually does in that mode.

PITreader for authentication
PITgatebox for commands at the gate
PNOZmulti 2 for mode-dependent functions
Guard devices at the access points
Enabling device for setup work
Mode-dependent functions validated separately
Authorised maintenance work inside a machine under a selected operating mode