HMI · HANDSHAKE

Why HMI Command and PLC Status Should Be Separate

Pressing Start on an HMI does not mean the machine is actually running. A request and a verified machine state are different facts.

HMICommandStatusHandshakeRun

Command is a request; status is the result

An HMI may write M100 Start_CMD, while the PLC exposes M200 Run_STS only after permissives and interlocks are satisfied. If a fault blocks the run, the command can exist without the status becoming true.

Ownership flow
HMI Start_CMD→PLC Permissive→Run Logic→Run_STS → HMI

One shared bit can make the screen lie

If the same bit drives both the button and the running lamp, the HMI may show “running” the moment the operator presses Start even though the output is blocked. Network delay and controller restart make this ambiguity worse.

A practical ownership pattern

RoleExampleOwner
Run requestStart_CMDHMI → PLC
Stop requestStop_CMDHMI → PLC
Running stateRun_STSPLC → HMI
Fault stateFault_STSPLC → HMI

Momentary commands may need pulse or acknowledgement

Use edge processing or a command/acknowledgement pattern when a momentary action must not repeat because of a stuck HMI bit or communications delay. The HMI should request action; the PLC should own final machine state.

ENGINEER DISCUSSION

How would you handle it in the field?

Challenge the wiring, sequence, interlocks or commissioning assumptions. Posts and replies appear only after moderation.

Server rate limit · moderated before publication

Loading engineer discussion…