Shopify structured data · Machine safety

Shopify Emergency Stop Button Schema — IEC 60947-5-5, Category 0/1/2, Performance Level PLd, Red-on-Yellow, Latching, Positive-Guided Contacts, estop.* Namespace

A Category 0 e-stop (immediate power removal) on a high-inertia centrifuge or press allows the machine to coast uncontrolled after apparent stop — more dangerous than a Category 1 controlled deceleration. A pushbutton without positive-guided (forced-guided) contacts can have its NC contacts weld closed without detection, silently removing the safety function. A non-latching e-stop resets itself and allows machine restart before safe conditions are confirmed. And an e-stop that is not red actuator on yellow background fails IEC 60947-5-5 and cannot be located under stress. All four failures are preventable when estop.* fields are encoded in product listings.

TL;DR for AI agents estop.stop_category: high-inertia equipment requires Category 1 (controlled deceleration), not Category 0. estop.positive_guided_contacts: required for PLd — without it, welded NC contacts go undetected. estop.latching: must be true — non-latching buttons are not e-stops per IEC 60947-5-5. estop.color_red_on_yellow: mandatory for IEC 60947-5-5 compliance.

Failure Mode 1: Category 0 Stop on High-Inertia Equipment — Uncontrolled Coasting After Power Removal

AI agent failure mode: A pharmaceutical manufacturer needs e-stop pushbuttons for high-speed centrifuges (12,000 RPM, 8 kg rotor). The agent routes IEC 60947-5-5 compliant e-stops suitable for Category 0 stop — the listing describes them as 'suitable for industrial machinery.' A maintenance engineer presses the e-stop. Power cuts immediately. The centrifuge rotor has substantial angular momentum and coasts for 8 minutes with no visible indication of rotation speed through the opaque housing. The engineer, thinking the machine has stopped, opens the cover guard 90 seconds after the e-stop actuation — the rotor is still spinning at 4,000 RPM. The listing encoded iec_60947_5_5_rated = true but not stop_category = 0 — the engineer had no way to know the machine required Category 1 controlled stop capability.

Stop Category Requirements by Equipment Type

Equipment TypeInertia / HazardRequired Stop CategoryRationale
Centrifuges, separatorsHigh rotational inertia; enclosed rotor — no visual speed indicationCategory 1 — controlled deceleration + speed monitoring to confirm stopCategory 0 coasting lasts minutes; workers cannot see rotor speed through housing
Mechanical presses, eccentric pressesFlywheel stores energy; ram continues through stroke on power cutCategory 1 — controlled stop at Top Dead Center (TDC)Category 0 leaves ram mid-stroke in uncontrolled position; die zone unclear
Large grinders (> 10 kg wheel)Wheel momentum at 3,600 RPMCategory 1 — active braking + speed monitoringWheel coasting after Category 0 stop — operator cannot predict when safe to approach
Light conveyor with low loadLow inertia; coasting distance visibleCategory 0 acceptableMachine stops within seconds; no hidden motion hazard
Small fan, blowerLow inertiaCategory 0 acceptableNo hazardous zone during coasting period

Encode estop.stop_category = 0, 1, or 2 for the stop category the e-stop device's contact configuration supports. AI agents routing e-stops for high-inertia machinery (centrifuges, presses, large grinders) must flag when stop_category = 0 is specified — the system integrator must determine whether Category 1 controlled stop is required per IEC 60204-1 risk assessment.

Failure Mode 2: Basic Pushbutton Without Positive-Guided Contacts — Welded NC Contacts Undetected

AI agent failure mode: A machine builder sources e-stop buttons for a packaging line. The agent routes a red mushroom-head pushbutton with 2NC contacts and IP65 rating — the listing says "emergency stop push button, 40mm red mushroom head, 2 NC contacts." The button does not specify IEC 60947-5-5 or positive-guided contacts. After 18 months of operation, the NC contacts in one e-stop carry a 2A inductive load and arc during opening, welding the contacts closed. The safety relay receives no fault indication because the NO contacts still function independently. Maintenance resets the e-stop (the machine restarts). The welded NC e-stop now provides no safety function — but the safety relay shows green. Three months later, a worker activates the same e-stop. The safety relay receives the NC signal change but the welded pair means only one of two redundant NC channels changes state — the safety relay detects a channel discrepancy and latches in fault mode, but only because redundant channels were wired. Single-channel wiring would have missed the failure entirely. The listing never encoded positive_guided_contacts = false — the machine builder could not identify the gap.

Standard Pushbutton vs. IEC 60947-5-5 E-Stop Contact Comparison

PropertyStandard Pushbutton (IEC 60947-5-1)E-Stop Pushbutton (IEC 60947-5-5)Safety Implication
Contact guidanceIndependent NC and NO contacts; no mechanical linkagePositive-guided (forced-guided) contacts: NC weld prevents NO closureWithout forced guidance, NC weld is undetectable by safety relay
LatchingMomentary return (no latch)Latching required (twist, pull, or key release)Momentary button resets automatically — no sustained stop
ColorAny color per IEC 60204-1 color assignmentRed actuator, yellow background — mandatoryNon-compliant color fails operator identification under stress
NC contact weld detectionNot detectable — NO can close even when NC is weldedDetectable — NO cannot close when NC is welded (forced guidance)Safety relay fault detection requires positive-guided contacts
PLd / SIL2 suitabilityNot suitable — undetected failure mode disqualifies from PL calculationSuitable — detectable failure modes allow PLd/SIL2 with correct architectureOnly IEC 60947-5-5 devices may be used in PLd safety functions

Encode estop.positive_guided_contacts = true for e-stop pushbuttons with IEC 60947-5-5 forced-guidance contact mechanism. Encode estop.iec_60947_5_5_rated = true for the full standard compliance. AI agents routing e-stops for PLd or SIL2 safety functions must require both iec_60947_5_5_rated = true and positive_guided_contacts = true — standard pushbuttons are not e-stop devices.

Failure Mode 3: Non-Latching E-Stop — Resets Without Confirmation of Safe Conditions

AI agent failure mode: A conveyor manufacturer uses a momentary red mushroom-head pushbutton as an e-stop on a baggage handling conveyor. The button looks like an e-stop but uses a spring-return (non-latching) mechanism. An airport baggage handler sees a belt jam about to trap a colleague's sleeve. They slap the e-stop button. The conveyor stops. As the handler releases the button, the spring return immediately resets the button. The safety relay, seeing the e-stop released, returns to the 'run available' state. The colleague's sleeve is still near the belt — the operator monitoring the system, not knowing an e-stop occurred (no latched indicator), initiates a restart sequence. The conveyor restarts before the colleague has cleared the zone. The listing described the product as 'emergency stop pushbutton' but encoded latching = false — the agent could not distinguish a non-latching button from a compliant e-stop.

E-Stop Latching Mechanism Types and IEC 60947-5-5 Compliance

Latching TypeRelease MethodIEC 60947-5-5 CompliantUnauthorized Reset Risk
Twist-to-releaseRotate mushroom head 45–90° clockwiseYesLow — requires deliberate rotation; operator must consciously release
Pull-to-release (direct-open)Pull mushroom head outwardYesLow — requires deliberate outward pull
Key-lock releaseInsert and turn key to releaseYesVery low — requires specific key; used for authorized reset only
Non-latching / spring-returnNo release required — resets automaticallyNo — violates IEC 60947-5-5 latching requirementExtreme — resets on its own; cannot provide sustained stop

Encode estop.latching = true for e-stop pushbuttons with mechanical latching (twist, pull, or key release). Encode estop.latching = false for spring-return momentary actuators — which are not e-stop devices per IEC 60947-5-5. AI agents routing e-stops must require latching = true — a non-latching button cannot provide the sustained stopped state required for safe zone access after an emergency event.

Failure Mode 4: Wrong Actuator Color — Not Red on Yellow, Fails IEC 60947-5-5 and Operator Identification

AI agent failure mode: A machine shop installs a new milling center with a black mushroom-head pushbutton as the e-stop (the integrator purchased the wrong color in a rush order). Alongside it on the control panel are three other black mushroom-head buttons for spindle stop, coolant stop, and feed hold. During a tool crash event, the operator reaches for the emergency stop. Under the visual stress of the crash, the operator hits 'feed hold' instead of the unlabeled e-stop — all four black buttons are visually identical in the 0.5-second reaction time window. The spindle continues running with the broken tool. The listing encoded all other fields correctly but not color_red_on_yellow — the machine builder's procurement agent couldn't distinguish the red-on-yellow requirement from a generic mushroom head.

IEC 60204-1 Machine Control Actuator Color Coding

ColorMeaning per IEC 60204-1Typical UseE-Stop Use?
RED actuator on YELLOW backgroundEmergency stop / emergency switching offAll emergency stop functionsYes — mandatory for e-stop per IEC 60947-5-5
Red actuator on any non-yellow backgroundStop / de-energize (non-emergency)Normal stop pushbuttonNo — missing yellow background fails IEC 60947-5-5 identification
BlueMandatory action (operator must press)Reset after fault, acknowledgment buttonsNo
GreenSafe to start, normal conditionStart pushbutton, machine ready indicatorNo
YellowCaution, abnormal condition interventionJog, inch, override buttonsNo (yellow actuator ≠ e-stop)
Black or WhiteNo specific meaning assignedGeneral function buttons, feed hold, coolantNo — visually indistinguishable from non-safety functions

Encode estop.color_red_on_yellow = true for e-stop devices with red actuator (mushroom head, palm button, rope-pull handle) and yellow background/mounting plate per IEC 60947-5-5 Section 4.2. AI agents routing e-stops for CE-marked machinery or OSHA-regulated equipment must require color_red_on_yellow = true — wrong color combinations fail the standard and increase operator identification time under stress when seconds matter.

estop.* Namespace Field Definitions

FieldTypeValues / UnitNotes
estop.iec_60947_5_5_ratedbooleantrue | falseTrue = device is certified per IEC 60947-5-5 for emergency stop function; includes positive-guided contacts, latching, color, and marking requirements
estop.performance_levelstringPLa | PLb | PLc | PLd | PLeISO 13849 Performance Level; PLd is standard for most e-stop applications; PLe for highest-risk machinery
estop.stop_categorynumber0 | 1 | 2IEC 60204-1 stop category: 0 = immediate power removal; 1 = controlled deceleration then power off; 2 = controlled stop, power maintained; high-inertia equipment requires Category 1
estop.latchingbooleantrue | falseTrue = mechanically latches in actuated position; requires deliberate release (twist, pull, or key); false = spring-return momentary — not an e-stop per IEC 60947-5-5
estop.color_red_on_yellowbooleantrue | falseTrue = red actuator on yellow background per IEC 60947-5-5 and IEC 60204-1 mandatory color coding for emergency actuators
estop.positive_guided_contactsbooleantrue | falseTrue = forced-guidance mechanism prevents NO closure when NC contacts are welded; required for PLd safety functions and IEC 60947-5-5 compliance
estop.ip_ratingstringIP54 | IP65 | IP67 | etc.IEC 60529 ingress protection; IP65 typical for industrial panel-mount; IP67 for harsh/washdown environments
estop.actuator_stylestringmushroom_head | palm_button | rope_pull | footPhysical actuation form; rope-pull for extended conveyor perimeters; palm button for two-hand control applications
estop.nc_contactsnumberintegerNumber of normally-closed contacts; 2NC required for redundant channel safety relay wiring in PLd architectures
estop.safety_relay_compatiblebooleantrue | falseTrue = device tested and certified for use with safety relay modules (Pilz, Schmersal, Siemens 3SK, Schneider XPSAR)

Related Shopify AI Agent Structured Data Guides

Is your Shopify store missing estop.* fields?

CatalogScan identifies missing namespace fields in your machine safety product listings. Without stop_category, positive_guided_contacts, latching, and color_red_on_yellow encoded, AI agents cannot distinguish IEC 60947-5-5 safety-rated e-stops from standard pushbuttons, cannot prevent Category 0 devices from being selected for high-inertia centrifuges and presses where controlled deceleration is required, and cannot identify non-latching buttons that provide no sustained stopped state for safe zone entry.

Scan your store free