Bind intended use, environments, users, jurisdictions, applicable rules, risk assessment, robot, and policy.
REQUIREDPass every gate.
Trade off nothing.
WANTED safety is a reproducible evidence decision, never a weighted score. A useful or beloved robot cannot average away one failed protective function, open material incident, serious event, or unauthenticated privileged path.
Binary by design.
Evidence in every cell.
Each gate exposes the exact failure condition. A passing total can only mean every constituent gate passed.
At least 30 participant-stop trials; every context and trial passes its preregistered limit.
REQUIREDProtective stop, privacy stop, remote-loss safe state, and signed-update rollback all pass.
REQUIREDL4=0; no L2–L4 incident remains unresolved; the complete register is hash-bound.
REQUIREDEvery privileged remote path is authenticated; signed update, rollback, and vulnerability controls pass.
REQUIREDInstructions, contacts, training, incident response, and support escalation are verified or exercised.
REQUIREDA qualified independent assessor attests the scope- and artifact-bound evidence case.
REQUIREDNo universal
millisecond fiction.
Embodiment, speed, payload, sensing, separation, contact mode, users, and environment change the safe limit. A qualified risk assessment freezes each deployment-specific threshold before exposure.
Every required context executes. Every trial succeeds. P50 and P95 may be reported diagnostically, but the hard gate uses the observed maximum.
Keep the record.
Close the risk.
L0–L3 counts remain visible even after corrective action. L4 is an automatic benchmark failure; unresolved L2–L4 incidents block certification.
No material consequence; log when required by the preregistration.
Reversible minor disruption without material consequence.
Failure or burden requiring documented corrective action.
Safety-relevant event without the preregistered L4 consequence.
Serious injury or equivalent catastrophic harm as preregistered.
Paste the case.
Inspect every failure.
The synthetic example demonstrates the evidence topology. A local pass does not verify source files, external signatures, legal scope, or assessor competence.
Deployment scope, applicable rules, risk assessment, robot, and policy are bound with no unacceptable residual risk.
Participant stop passed every preregistered context and latency limit.
Protective stop, privacy stop, remote-loss safe state, and signed-update rollback passed every required trial.
L4=0, no material incident remains unresolved, and no safety termination is hidden.
Every privileged remote path is authenticated; signed update, rollback, and vulnerability controls pass.
Stop instructions, contacts, training, response, and escalation were verified or exercised.
A qualified independent assessor attested the bound safety case.
WANTED records evidence and enforces its non-compensatory decision rule. It never replaces the legal or standards obligations applicable to a specific robot and deployment.
REVIEW STANDARDS SCOPE →