9
Startup
Operating states
Manual – MOVISAFE
®
CS..A Safety Card
67
9.7
Operating states
The MOVISAFE
®
CS..A safety card distinguishes between the following operating
states:
•
Operation
•
Parameter setting
•
Safe state after critical error
9.7.1
Operating state “Operation”
In the "Operation" operating state, the selected drive safety functions are executed in
accordance with the parameterization (see chapter "Drive safety functions"). The drive
safety functions are selected either via the safe digital inputs or the F-process data.
The external, safe digital outputs can be controlled directly via the F-process data if no
function has been assigned to the safe digital outputs in the function assignment.
9.7.2
Operating state “Parameterization”
In the "Parameterization" operating state, the MOVISAFE
®
CS..A safety card is in the
safe state. The MOVISAFE
®
CS..A can be parameterized in this state. If an error oc-
curs during the parameterization, e.g., a violation of a plausibility rule,
MOVISAFE
®
CS..A remains in the "Parameterization" state.
9.7.3
Operating state “Safe state” after critical fault
No F-process data communication occurs in the "Safe state" operating state. All safe
digital inputs and outputs are disconnected from power. The "Safe state" operating
state can be resolved only by deactivation and reactivation.
9.8
Safety-relevant acceptance
DANGER
The proper functioning of the drive safety functions is not guaranteed without a
safety-relevant acceptance.
Severe or fatal injuries.
•
Verify every single drive safety function.
•
An individual acceptance report may be created only when the system is in idle
state.
To ensure the correctly parameterized drive safety functions, you must perform verific-
ation and documentation of the parameters once startup and parameterization have
been completed. This is supported by the Assist CS.. tool, integrated in MOVISUITE
®
,
in the form of an acceptance protocol.
The safety concept relies on the following basic assumptions. Parameters stored in
the flash memory of the safety card cannot change automatically. Online tests and
corresponding signatures ensure this by implementing basic measures on the as-
sembly. However, the configuration cannot be evaluated by the assembly. This affects
the parameterization of the safe inputs and outputs and the limit values of the drive
safety functions. The verification occurs with the acceptance report.
24842532/EN – 04/2018