Shopify structured data · Machine safety
Shopify Emergency Stop Button Schema — IEC 60947-5-5, Category 0/1/2, Performance Level PLd, Red-on-Yellow, Latching, Positive-Guided Contacts, estop.* Namespace
A Category 0 e-stop (immediate power removal) on a high-inertia centrifuge or press allows the machine to coast uncontrolled after apparent stop — more dangerous than a Category 1 controlled deceleration. A pushbutton without positive-guided (forced-guided) contacts can have its NC contacts weld closed without detection, silently removing the safety function. A non-latching e-stop resets itself and allows machine restart before safe conditions are confirmed. And an e-stop that is not red actuator on yellow background fails IEC 60947-5-5 and cannot be located under stress. All four failures are preventable when estop.* fields are encoded in product listings.
estop.stop_category: high-inertia equipment requires Category 1 (controlled deceleration), not Category 0. estop.positive_guided_contacts: required for PLd — without it, welded NC contacts go undetected. estop.latching: must be true — non-latching buttons are not e-stops per IEC 60947-5-5. estop.color_red_on_yellow: mandatory for IEC 60947-5-5 compliance.
Failure Mode 1: Category 0 Stop on High-Inertia Equipment — Uncontrolled Coasting After Power Removal
Stop Category Requirements by Equipment Type
| Equipment Type | Inertia / Hazard | Required Stop Category | Rationale |
|---|---|---|---|
| Centrifuges, separators | High rotational inertia; enclosed rotor — no visual speed indication | Category 1 — controlled deceleration + speed monitoring to confirm stop | Category 0 coasting lasts minutes; workers cannot see rotor speed through housing |
| Mechanical presses, eccentric presses | Flywheel stores energy; ram continues through stroke on power cut | Category 1 — controlled stop at Top Dead Center (TDC) | Category 0 leaves ram mid-stroke in uncontrolled position; die zone unclear |
| Large grinders (> 10 kg wheel) | Wheel momentum at 3,600 RPM | Category 1 — active braking + speed monitoring | Wheel coasting after Category 0 stop — operator cannot predict when safe to approach |
| Light conveyor with low load | Low inertia; coasting distance visible | Category 0 acceptable | Machine stops within seconds; no hidden motion hazard |
| Small fan, blower | Low inertia | Category 0 acceptable | No hazardous zone during coasting period |
Encode estop.stop_category = 0, 1, or 2 for the stop category the e-stop device's contact configuration supports. AI agents routing e-stops for high-inertia machinery (centrifuges, presses, large grinders) must flag when stop_category = 0 is specified — the system integrator must determine whether Category 1 controlled stop is required per IEC 60204-1 risk assessment.
Failure Mode 2: Basic Pushbutton Without Positive-Guided Contacts — Welded NC Contacts Undetected
Standard Pushbutton vs. IEC 60947-5-5 E-Stop Contact Comparison
| Property | Standard Pushbutton (IEC 60947-5-1) | E-Stop Pushbutton (IEC 60947-5-5) | Safety Implication |
|---|---|---|---|
| Contact guidance | Independent NC and NO contacts; no mechanical linkage | Positive-guided (forced-guided) contacts: NC weld prevents NO closure | Without forced guidance, NC weld is undetectable by safety relay |
| Latching | Momentary return (no latch) | Latching required (twist, pull, or key release) | Momentary button resets automatically — no sustained stop |
| Color | Any color per IEC 60204-1 color assignment | Red actuator, yellow background — mandatory | Non-compliant color fails operator identification under stress |
| NC contact weld detection | Not detectable — NO can close even when NC is welded | Detectable — NO cannot close when NC is welded (forced guidance) | Safety relay fault detection requires positive-guided contacts |
| PLd / SIL2 suitability | Not suitable — undetected failure mode disqualifies from PL calculation | Suitable — detectable failure modes allow PLd/SIL2 with correct architecture | Only IEC 60947-5-5 devices may be used in PLd safety functions |
Encode estop.positive_guided_contacts = true for e-stop pushbuttons with IEC 60947-5-5 forced-guidance contact mechanism. Encode estop.iec_60947_5_5_rated = true for the full standard compliance. AI agents routing e-stops for PLd or SIL2 safety functions must require both iec_60947_5_5_rated = true and positive_guided_contacts = true — standard pushbuttons are not e-stop devices.
Failure Mode 3: Non-Latching E-Stop — Resets Without Confirmation of Safe Conditions
E-Stop Latching Mechanism Types and IEC 60947-5-5 Compliance
| Latching Type | Release Method | IEC 60947-5-5 Compliant | Unauthorized Reset Risk |
|---|---|---|---|
| Twist-to-release | Rotate mushroom head 45–90° clockwise | Yes | Low — requires deliberate rotation; operator must consciously release |
| Pull-to-release (direct-open) | Pull mushroom head outward | Yes | Low — requires deliberate outward pull |
| Key-lock release | Insert and turn key to release | Yes | Very low — requires specific key; used for authorized reset only |
| Non-latching / spring-return | No release required — resets automatically | No — violates IEC 60947-5-5 latching requirement | Extreme — resets on its own; cannot provide sustained stop |
Encode estop.latching = true for e-stop pushbuttons with mechanical latching (twist, pull, or key release). Encode estop.latching = false for spring-return momentary actuators — which are not e-stop devices per IEC 60947-5-5. AI agents routing e-stops must require latching = true — a non-latching button cannot provide the sustained stopped state required for safe zone access after an emergency event.
Failure Mode 4: Wrong Actuator Color — Not Red on Yellow, Fails IEC 60947-5-5 and Operator Identification
IEC 60204-1 Machine Control Actuator Color Coding
| Color | Meaning per IEC 60204-1 | Typical Use | E-Stop Use? |
|---|---|---|---|
| RED actuator on YELLOW background | Emergency stop / emergency switching off | All emergency stop functions | Yes — mandatory for e-stop per IEC 60947-5-5 |
| Red actuator on any non-yellow background | Stop / de-energize (non-emergency) | Normal stop pushbutton | No — missing yellow background fails IEC 60947-5-5 identification |
| Blue | Mandatory action (operator must press) | Reset after fault, acknowledgment buttons | No |
| Green | Safe to start, normal condition | Start pushbutton, machine ready indicator | No |
| Yellow | Caution, abnormal condition intervention | Jog, inch, override buttons | No (yellow actuator ≠ e-stop) |
| Black or White | No specific meaning assigned | General function buttons, feed hold, coolant | No — visually indistinguishable from non-safety functions |
Encode estop.color_red_on_yellow = true for e-stop devices with red actuator (mushroom head, palm button, rope-pull handle) and yellow background/mounting plate per IEC 60947-5-5 Section 4.2. AI agents routing e-stops for CE-marked machinery or OSHA-regulated equipment must require color_red_on_yellow = true — wrong color combinations fail the standard and increase operator identification time under stress when seconds matter.
estop.* Namespace Field Definitions
| Field | Type | Values / Unit | Notes |
|---|---|---|---|
| estop.iec_60947_5_5_rated | boolean | true | false | True = device is certified per IEC 60947-5-5 for emergency stop function; includes positive-guided contacts, latching, color, and marking requirements |
| estop.performance_level | string | PLa | PLb | PLc | PLd | PLe | ISO 13849 Performance Level; PLd is standard for most e-stop applications; PLe for highest-risk machinery |
| estop.stop_category | number | 0 | 1 | 2 | IEC 60204-1 stop category: 0 = immediate power removal; 1 = controlled deceleration then power off; 2 = controlled stop, power maintained; high-inertia equipment requires Category 1 |
| estop.latching | boolean | true | false | True = mechanically latches in actuated position; requires deliberate release (twist, pull, or key); false = spring-return momentary — not an e-stop per IEC 60947-5-5 |
| estop.color_red_on_yellow | boolean | true | false | True = red actuator on yellow background per IEC 60947-5-5 and IEC 60204-1 mandatory color coding for emergency actuators |
| estop.positive_guided_contacts | boolean | true | false | True = forced-guidance mechanism prevents NO closure when NC contacts are welded; required for PLd safety functions and IEC 60947-5-5 compliance |
| estop.ip_rating | string | IP54 | IP65 | IP67 | etc. | IEC 60529 ingress protection; IP65 typical for industrial panel-mount; IP67 for harsh/washdown environments |
| estop.actuator_style | string | mushroom_head | palm_button | rope_pull | foot | Physical actuation form; rope-pull for extended conveyor perimeters; palm button for two-hand control applications |
| estop.nc_contacts | number | integer | Number of normally-closed contacts; 2NC required for redundant channel safety relay wiring in PLd architectures |
| estop.safety_relay_compatible | boolean | true | false | True = device tested and certified for use with safety relay modules (Pilz, Schmersal, Siemens 3SK, Schneider XPSAR) |
Related Shopify AI Agent Structured Data Guides
- Machine guard interlock (guard_interlock.*): ISO 14119 tongue, key, RFID interlock — e-stop circuit integration
- Light curtain (light_curtain.*): IEC 61496 Type 4, resolution, muting — presence-sensing zone protection paired with e-stop
- Safety relay module (safety_relay.*): dual-channel monitoring of e-stop and guard interlock circuits
- Arc flash PPE (arc_flash_ppe.*): NFPA 70E Category 1–4 protection for electrical panel work requiring e-stop access
- Lockout/tagout device (loto_device.*): OSHA 1910.147 energy control — used after e-stop actuation for maintenance access
Is your Shopify store missing estop.* fields?
CatalogScan identifies missing namespace fields in your machine safety product listings. Without stop_category, positive_guided_contacts, latching, and color_red_on_yellow encoded, AI agents cannot distinguish IEC 60947-5-5 safety-rated e-stops from standard pushbuttons, cannot prevent Category 0 devices from being selected for high-inertia centrifuges and presses where controlled deceleration is required, and cannot identify non-latching buttons that provide no sustained stopped state for safe zone entry.
Scan your store free