Fault & Incident Playbook
Robot Fault and Incident Handling Procedures · v1.1 · Author: Nicholas Ng
Critical Faults
Robot is not controllable from the C2 console or poses a safety risk. Auto-stops and reports a fault + error message.
failToEstopFail to E-Stop
Emergency stop command or mechanism fails to activate when triggered.
Ground-level recovery
- Attempt manual assisted control via wireless joystick (line-of-sight).
- Technical Support: Manual clear after fault-free E-stop test.
failToLowerMastFail to Lower Mast
Obstruction or failure during mast lowering.
Ground-level recovery
- Attempt manual assisted control via wireless joystick (line-of-sight).
- Technical Support: Manual clear after fault-free test.
failToMoveFail to Move
Robot is unable to move autonomously or respond to teleoperation commands.
Ground-level recovery
- Attempt manual assisted control via wireless joystick (line-of-sight).
- Technical Support: Manual clear after robot mobility restored and verified.
navigationErrorNavigation Error
Localization or path planning failure preventing safe autonomous navigation.
C2 Operator
- Teleoperate to designated charging station.
- Send a charging task.
- Escalate to ground recovery if unresolved.
Ground-level recovery
- Attempt manual assisted control via wireless joystick (line-of-sight).
- Robot: Auto-cleared after successful re-localisation when charging.
If robot does not auto-clear
- Technical Support: Manual clear after fault-free test.
sensorFailureSensor Failure
One or more critical sensors not functioning.
Ground-level recovery
- Robot halts due to sensor failure — attempt manual assisted control via wireless joystick under line-of-sight.
- Use a dedicated recovery mode with safety functions disabled.
- Technical Support: Manual clear after fault-free test.
cpuOverloadCPU Overload
Sustained high CPU utilization affecting performance but without thermal risk.
C2 Operator
- Stop patrol task; send a new task for the robot to go charge.
- Inform Technical Support.
- If the situation worsens it will trigger cpuOverheat — refer to that fault.
- Robot: Auto-cleared when CPU stabilises.
cpuOverheatCPU Overheat
CPU temperature exceeds safe operating limits, indicating cooling failure, airflow obstruction, or environmental risk.
Ground-level recovery
- Power down the robot and manually move it to a safe location.
- Technical Support: Manual clear after physical inspection and confirmed thermal stability under load.
motorFaultMotor Fault
Motor controller reports a hardware or safety-related fault.
Ground-level recovery
- Power down the robot and manually move it to a safe location.
- Technical Support: Manual clear after fault-free test.
unexpectedRebootUnexpected Reboot
Robot experiences an unexpected reboot or shutdown during operation.
Ground-level recovery
- Attempt manual assisted control via wireless joystick (line-of-sight).
- Technical Support: Manual clear after stability confirmation.
Non-critical Faults
Robot remains controllable from the C2 console. No immediate on-site recovery required; Technical Support is informed.
failToChargeFail to Charge
Charging unsuccessful or charge rate stagnating.
C2 Operator
- Stop / retry the docking task.
- Teleoperate to a safe location.
- Inform Technical Support for follow-up.
- Robot: Auto-cleared after stable charging resumes.
batteryFaultBattery Fault
Battery health or protection circuitry reports a hardware-level issue without immediate safety risk.
C2 Operator
- Limit operation.
- Teleoperate to a safe location.
- Inform Technical Support for follow-up.
- Technical Support: Manual clear after battery health check.
failToDockFail to Dock
Robot fails to align with or physically connect to the charging dock.
C2 Operator
- Retry the docking task.
- Robot: Auto-cleared after successful dock.
failToLiftMastFail to Lift Mast
Mast extension is obstructed or fails, affecting task execution but not base mobility.
C2 Operator
- Abort task.
- Teleoperate to a safe location.
- Inform Technical Support.
- Technical Support: Manual clear after fault-free test.
cameraFaultCamera Fault
Camera stream unavailable or capture failure affecting surveillance or teleconference only.
C2 Operator
- Inform Technical Support.
- Technical Support: Manual clear after fault-free test.
nvrFaultNVR Fault
NVR offline, recording stopped, or storage unavailable.
C2 Operator
- Stop operation.
- Inform Technical Support.
- Technical Support: Manual clear after storage or service recovery.
displayFaultDisplay Fault
One or more onboard displays not functioning.
C2 Operator
- Inform Technical Support.
- Technical Support: Manual clear after display recovery.
speakerFaultSpeaker Fault
Audio output unavailable.
C2 Operator
- Continue operation.
- Inform Technical Support.
- Technical Support: Manual clear after speaker test.
BlinkerFaultBlinker Fault
Blinkers not functioning.
C2 Operator
- Continue operation.
- Inform Technical Support.
- Technical Support: Manual clear after functional check.
cordonLightFaultCordon Light Fault
Cordon lights not functioning.
C2 Operator
- Continue operation.
- Inform Technical Support.
- Technical Support: Manual clear after light recovery.
headLightFaultHead Light Fault
Head lights not functioning.
C2 Operator
- Continue operation.
- Inform Technical Support.
- Technical Support: Manual clear after light recovery.
Incidents
Safety or security events caused by external interaction. Robot auto-stops; operator acknowledgement is mandatory.
eStopActivatedE-Stop Activated
Emergency stop triggered (e.g. button press).
Initial response
- C2 Operator answers the teleconference call (triggered by the robot when the e-stop button was pressed).
- Ground-level staff inspect the robot and surrounding area.
If accidental activation
- Reset the physical E-stop and inform C2 Operator to resume operation.
If non-benign trigger
- Enforce stop authority and treat the robot as unsafe until recovery is completed.
- Escalate to Technical Support for inspection and follow-up actions.
Accidental activation
- Physical E-stop reset completed.
- C2 Operator manual acknowledgement and resume operation.
Non-benign trigger
- Ground-level verification confirms safe operating condition.
- C2 Operator manual acknowledgement required.
CollisionCollision
Physical impact detected (e.g. bumper hit).
Initial response
- Ground-level staff inspect the robot after impact.
Classification
- Minor contact — no visible damage, misalignment, abnormal behaviour, or new faults.
- Major impact — visible damage, misalignment, abnormal behaviour, or any associated fault or incident.
If minor contact
- Inform C2 Operator to resume operation.
If major impact
- Enforce recovery and treat the robot as unsafe until recovery is completed.
- Escalate to Technical Support for inspection and follow-up actions.
Minor contact
- Ground-level verification completed.
- C2 Operator manual acknowledgement and resume operation.
Major impact
- Recovery and required hardware servicing are completed.
- C2 Operator manual acknowledgement required.
TamperingTampering
Suspicious motion or force suggesting interference.
Initial response
- Ground-level staff assess the robot and surrounding area for signs of interference.
Classification
- Minor interference — accidental contact with no damage, abnormal behaviour, or new faults.
- Major interference — forced or repeated interaction, visible damage, abnormal behaviour, or any associated fault or incident.
If minor interference
- Ground-level staff inform C2 Operator to resume operation.
If major interference
- Ground-level staff enforce recovery and treat the robot as unsafe until recovery is completed.
- Escalate to Technical Support for inspection and follow-up actions.
Minor interference
- Ground-level verification completed.
- C2 Operator manual acknowledgement and resume operation.
Major interference
- Recovery completed and ground-level verification confirms safe operating condition.
- C2 Operator manual acknowledgement required.
IntrusionIntrusion
Forced or unauthorized access detected.
Ground-Level Staff
- Secure the robot and surrounding area.
- Prevent further interaction and do not resume operation.
- Observe and report any signs of intrusion.
C2 Operator
- Acknowledge the incident and keep the robot stopped.
- Escalate to Technical Support and site security.
- Preserve logs and recordings.
Technical Support
- Inspect hardware and software for compromise.
- Perform required recovery or reimaging.
- Approve redeployment only after integrity is confirmed.
- Technical Support completes integrity verification and security clearance is granted.
- C2 Operator manual acknowledgement required.
fallDetectedFall Detected
Robot has tipped over or fallen.
Ground-Level Staff
- Secure the area and physically recover the robot to an upright position.
- Do not resume operation.
C2 Operator
- Acknowledge the incident and keep the robot stopped.
- Escalate to Technical Support.
Technical Support
- Inspect mechanical, sensor, and structural integrity.
- Perform required servicing and validation.
- Physical recovery is completed and Technical Support confirms safe operating condition.
- C2 Operator manual acknowledgement required.