Access permission system

PITreader

Machine safety assumes the person at the controls is trained for the task in hand. PITreader replaces that assumption with an RFID transponder key tied to an individual, so what someone may do is defined by stored permissions rather than by who happens to be holding a shared key.

RFID transponder keyIdentification and Access ManagementPermissions per roleIntegrates with PNOZmulti 2Standalone or in a control architecture
RFIDTransponder key
PL dStated within the I.A.M. range
SIL CL 2Stated within the I.A.M. range
Pilz control and signal devices including access management products
PITreaderShown within the safety control and signal device range
IdentifyWho is at the machine
PermitWhat they may do
RevokeWithout collecting hardware
IntegrateWith safety control architecture
Why it is specified

Authentication changes

The gain is administrative as much as technical: permissions become a record that can be changed centrally rather than a key that circulates.

Identity, not possession

An RFID transponder key identifies the individual operator rather than merely unlocking a function.

Permissions per role

What a person may do is defined by stored permissions, which can be issued and withdrawn centrally.

Part of a Safety and Security concept

The manufacturer positions Identification and Access Management as covering both safety and security aspects together.

Works within the control architecture

Used standalone or with supported safety control architectures, including as an input to PNOZmulti 2.

Applications

PITreader is used

The typical trigger is an audit finding, an incident, or a persistent habit of using a shared key to reach a mode that should be restricted.

Operator presenting a Pilz PITreader RFID transponder key at a machine
Shift operation

Authorised machine operation

The machine accepts commands only from a person whose stored permissions cover the task, replacing the shared key kept in a drawer.

ConfirmConfirm roles and the permission model.
Technician working inside a machine following authorised guard access
Maintenance

Controlled machine entry

Entry for cleaning, clearing a blockage or maintenance, where the guard should release only for staff trained for that task.

ConfirmConfirm which roles may enter, and when.
Safe operating mode selection at a machine using Pilz access management
Operating modes

Restricted mode selection

Where setup mode reduces protection to allow adjustment, the ability to select it is limited to people permitted to work that way.

ConfirmConfirm the modes and who may select each.
Technical data

Selection parameters that matter

publishes PITreader within the Identification and Access Management portfolio. Device-level specifications should be confirmed against the current product documentation before quotation.

A dedicated PITreader product page was not resolvable at the time of writing; the statements below are taken from the access management and related product pages.
FunctionRFID-based authentication for machine access and permissions
PortfolioPart of the Identification and Access Management (I.A.M.) range
CredentialRFID transponder key issued to an individual
Permission modelStored permissions determine what the holder may do
CapabilityPL d and SIL CL 2 are stated within the access management range
UseStandalone, or with supported safety control architectures
Gate integrationIntegrated into PITgatebox variants to activate the pushbutton unit
Mode integrationUsed with PITmode for access permission and operating-mode selection
Controller inputAccess permission PITreader is listed among the devices connectable to PNOZmulti 2 base units
Authentication establishes who may act. It is not itself the machine safety function, and the required performance level for any mode-dependent safety function must be established separately.
Models

PITreader deployment

The reader is rarely bought alone. It is normally specified as part of a gate, mode-selection or controller arrangement.

Standalone

Reader at the machine

Used on its own to establish identity and permission at an operator station.

Credential
RFID key
Scope
Per machine
With PITgatebox

Gate activation

Integrated into PITgatebox variants so gate commands are accepted only after successful authentication.

Unit
PITgatebox
Check
Permission
With PITmode

Operating-mode selection

Combined with PITmode so access permission and functionally safe mode selection work together.

System
PITmode
Level
PL d stated
With PNOZmulti 2

Controller input

Access permission via PITreader is listed among the devices connectable to PNOZmulti 2 base units.

Controller
PNOZmulti 2
Role
Permission input
Accessories

Keys, permissions and administration

Most of the work in an access-management project is the permission model, not the hardware count.

Credentials

RFID transponder keys

Keys are issued per person and carry the permissions that determine what the holder may do at the machine.

ConfirmConfirm the number of holders and how keys are issued.
Gate operation

PITgatebox

The pushbutton unit that accepts the operator command once the permission has been checked.

Typical pairingPITgatebox with PITreader.
Mode control

PITmode

Where the permission must also govern which operating mode the machine will accept.

Typical pairingPITmode operating mode selection.
Before quotation

Application review

Define the permission model before the hardware. The number of readers follows from where identity actually has to be established.

People and permissions

  • Which roles exist and what each may do
  • How permissions are issued, changed and revoked
  • Who administers the system, and from where
  • Whether contractors and temporary staff are included

Machine and modes

  • Which operating modes exist and what each permits
  • Which safety functions change between modes
  • Existing safety controller and spare capacity
  • Whether mode selection must be functionally safe

Points of use

  • Where identity must be established — operator station, gate, or both
  • Number of readers required
  • Mounting position, reach and visibility
  • Existing guard devices at those points

Records and IT

  • Whether entry and mode changes must be recorded
  • Where records are held and who reviews them
  • Network and certificate arrangements
  • Expected behaviour if the network is unavailable
Related technologies

PITreader sits in the architecture

Identity and permission form a layer above the safety function. They decide whether an action is allowed to be requested; the safety controller still decides whether the machine may move.

PITgatebox for commands at the gate
PITmode for safe mode selection
PNOZmulti 2 as permission input
PSENmlock or PSENslock 2 at the guard
Safety controller performs the safety function
Records and administration defined separately
Safe operating mode selection using Pilz identification and access management