Safety¶
Four rails, every surface.
| rail | where | what |
|---|---|---|
| clamp | Robot.act |
every real write bounded by the row's max_step; the receipt says clamped=True |
| consent | tools/, CLI, dashboard |
mode="sim" and dry_run=True by default; real motion needs confirm=True; strands HITL wraps hardware motion |
| e-stop | Mesh.estop |
emergency_stop(reason) publishes to every peer and latches a lockout; resume(code) requires STRANDS_MESH_OVERRIDE_CODE |
| audit | mesh.audit |
append-only JSONL, signed sequence chain, verify detects a removed or altered record |
from strands_robots import Robot
from strands_robots.mesh import Mesh
with Robot("so101", mode="sim") as arm, Mesh(arm, "arm-a") as mesh:
mesh.estop.emergency_stop("operator: person in the cell") # every peer latches; act() refuses ESTOP_LATCHED
mesh.estop.resume("...") # refused unless the code matches STRANDS_MESH_OVERRIDE_CODE
Also true everywhere: is_connected() asks the wire and is never cached; close() turns
torque off and releases the port on every exit path; one writer per arm (Robot holds a
Lease, a second owner gets LeaseHeldError naming the holder); every refusal names the
bad value, the cause and the remedy.