Nothing we build touches the control path

There is a line in every factory that separates systems which observe from systems which act. On one side sit reporting, planning and analysis. On the other sit controllers, interlocks, guarding and emergency stops — equipment that can move something heavy and hurt somebody.

MESCATOR is on the observing side, permanently. Not as a first-release limitation, and not as something that changes when the product matures.

Why the line exists

Machinery that can cause harm is governed by requirements that apply to the whole safety function: hazard analysis, defined performance levels, validation, and change control that means a modification requires reassessment rather than a release note.

Business software is built and updated on entirely different assumptions. Frequent releases, rapid fixes, features that evolve with what customers ask for. Those assumptions are correct for a planning system and disqualifying for anything inside a safety function.

A system that could write a setpoint to a machine would be inside that function. All of its obligations would then apply to a product that ships on a Thursday because a customer needed a report change, and no amount of care in the release process makes that arrangement sound.

The specific promises

No writes to controllers. Signals are read. No setpoints, no commands, no parameter changes, no recipe downloads. The integration is one-directional by design rather than by configuration.

No safety functions. Interlocks, light curtains, guarding and emergency stop remain entirely within the systems certified for them. Nothing here participates in stopping a machine.

No control logic. Cycle behaviour belongs to the equipment and its supplier, who assessed it and who is answerable for it.

Advice, not action. Rescheduling, holds, reorders and alerts are prepared for a person. The person knows what the floor looks like right now, and that information does not exist in any system.

What we do instead of writing

Everything useful, as it turns out. Reading gives you the actual throughput, the real changeover cost, the stoppage patterns, the quality signals and the genealogy. That is enough to plan honestly, promise realistically and answer a recall question in minutes.

The remaining step — someone deciding and acting — is the part where a human being is genuinely better, because they can see the bench, the pallet in the wrong place and the operator who is about to finish a shift.

Why say it this loudly

Because this boundary is being blurred commercially. Products described as autonomous manufacturing or self-optimising lines are frequently either doing something much narrower than the language suggests, or genuinely writing to equipment without being clear about which obligations they have taken on.

A manufacturer evaluating any of this should ask one question: does it write to a machine, and if so, what is the safety case and who signed it. The answer here is that it does not, which means the question does not arise — and that is a better position for a planning system than any capability we could add by crossing the line.