Robot product development path · Gate 05

Safety case, controlled release & field learning

Assemble a claim–argument–evidence case, release only within approved boundaries and keep evidence current as hardware, software and operations change.

Decision this gate must answerIs there sufficient, configuration-specific evidence for accountable people to approve a bounded release—and to stop it when conditions change?

Inputs

Controlled information to bring in

  1. 01

    Closed and open requirements with linked evidence

  2. 02

    Hazard analysis, cybersecurity assessment and human-oversight plan

  3. 03

    As-built configuration, verified software and release notes

  4. 04

    Operating, maintenance, incident, rollback and retirement procedures

Outputs

Artefacts that must be reviewable

  1. 01

    Configuration-specific safety and assurance case

  2. 02

    Approved operating envelope, training and authorisation records

  3. 03

    Staged-release, monitoring, incident and rollback controls

  4. 04

    Change-impact and periodic reassessment schedule

Core work packages

Every workstream leaves traceable evidence.

01

Make claims explicit

State the exact system, configuration, task, environment, people and period covered by each safety or performance claim.

02

Control autonomy and fallback

Define authority, mode awareness, supervision load, intervention timing, safe state, degraded operation and recovery from uncertain perception or planning.

03

Release in stages

Use guarded trials, limited users, bounded sites and explicit exit criteria before wider operation; never let a pilot label hide exposure.

04

Learn from operation

Capture interventions, near misses, incidents, repairs, model drift, environment changes and operator feedback; reassess after material change.

Gate review

Every answer should carry evidence, not only ‘yes’ or ‘no’.

  1. 01

    Does the release decision identify exact configuration, site, users and expiry?

  2. 02

    Can operators recognise mode, limits and uncertainty in time to act?

  3. 03

    Have fallback, stop and recovery been tested under realistic faults?

  4. 04

    Are software, model, parameter and hardware changes subject to impact review?

  5. 05

    Will field evidence trigger containment, correction and case updates?

This page can support

  • 01A transparent bounded-release decision
  • 02Continuous evidence after launch
  • 03Accountable change, incident and rollback governance

This page cannot replace

  • 01Certification or regulatory approval
  • 02Product liability, legal or clinical advice
  • 03A qualified accountable person making the actual release decision