事故常发生在变更时刻
编程、维护、测试、调试、路线变更、模型升级和人工 override,是企业最需要证据的环节。
01 · Problem
Demo 阶段只要机器人能动;生产阶段必须回答:谁批准了这个技能?它能控制哪些传感器、执行器、ROS/DDS topic?远程接管是谁批准的?事故后如何证明版本、命令、传感器状态、人工接管、停机和回滚?
编程、维护、测试、调试、路线变更、模型升级和人工 override,是企业最需要证据的环节。
一个技能到底能读哪些传感器、写哪些 topic、控制哪些执行器、在哪些区域运行,经常留在文档里。
客户需要知道谁接入、为什么接入、允许哪些命令、持续多久、是否录像、能否紧急撤销。
数据集、评测、HIL、replay、QNN profile、机器人 profile 和 rollback 目标没有绑定成一个 release record。
事故后需要证明版本、权限、传感器状态、命令、停机、人工接管和恢复动作。
02 · Current Alternatives Fail
SafetyOps 不替代 Safety PLC,不替代认证实验室,也不替代 Formant、InOrbit、Foxglove 或 OT security 工具。它把 release gate、command authorization、SBOM/VEX、incident replay 和客户审计包连接起来。
认证安全控制器保护机器和产线,但不记录 AI model lineage、dataset、QNN profile、skill approval 或 remote-assist session。
风险评估材料能支撑交付,但部署后跟不上模型更新、OTA、site config、漏洞处置和 incident replay。
Formant、InOrbit、Viam 和 OEM clouds 管 fleet,但不是以 release gate、权限和 standards evidence 为核心。
Foxglove、MCAP、ROS bag 很适合调试,但还需要 approval、permission、rollback、chain-of-custody 和客户摘要。
OT security、SBOM、AI governance 能回答一部分风险问题,但不回答 learned policy 是否应该移动 actuator。
03 · Solution
每个技能上线前必须声明 permissions、ODD、model evidence、Qualcomm edge profile、SBOM/VEX、approvals、canary scope 和 rollback target。运行时,边缘 agent 做 command admission、boundary monitoring、incident capture 和 rollback proof。
技能声明 sensors、actuators、ROS/DDS allow-deny、ODD、risk level 和 rollback target。
绑定 dataset hash、eval split、HIL clips、replay regressions、SBOM/VEX 和 AI Hub/QNN profile。
safety owner、fleet admin、site owner 对 remote assist、canary scope 和 rollout gate 签名。
边缘 safety-agent 阻止 raw command、越界速度、禁区、传感器失效、延迟异常和未授权远程动作。
事件进入 MCAP ring buffer、access evidence、incident ledger、rollback record 和 LeRobot/HIL 数据队列。
No cloud in the safety loop. SafetyOps 支持证据、策略、监测和有限 command admission;认证安全功能仍属于机器人 OEM / integrator 的本体安全架构。
04 · Why Now
机器人已经进入客户现场,skill 更新越来越快,EU Machinery Regulation、EU CRA、ISO 10218:2025、NIST OT/Zero Trust、IEC 62443 和中国 GB/漏洞规则都在把软件更新、远程接入、网络安全和证据留存推入采购语言。
05 · Product
SafetyOps 不做认证机构。它交付的是 safety-case workflow:让 robot OEM、SI 和企业客户把每次 robot/model/skill/remote-assist change 变成可追踪、可审批、可回滚、可导出的证据包。
06 · Product API/Evidence
所有 release 都绑定 skill manifest、dataset hash、edge profile、approvals、remote-access policy、runtime command decision、SBOM/VEX、incident ledger 和 audit pack。ROS policy 是软件 guardrail,不是 Safety PLC。
skill_id、risk_level、sensors、actuators、ROS allow/deny、ODD、rollback target。
dataset_hash、success_rate、intervention_rate、replay regressions、approvals、decision。
AI Hub job、target device、QNN runtime、latency p95、memory、compute units、fallback status。
operator、MFA、device posture、allowed commands、expiry、approver、session recording pointer。
firmware、container、ROS packages、edge agent、operator app 的组件清单和 exploitability status。
buyer pack、judge pack、insurer pack、standards map、claim boundaries、data lane summary。
POST /v1/robots/{id}/commands:authorize 用 robot state、operator scope、ODD 和 runtime policy 决定 allow / deny。
GET /v1/robots/{id}/cyber-posture 返回 firmware、containers、cert age、open CVEs、VEX status 和 remote access state。
POST /v1/incidents/{id}/evidence-pack 导出 timeline、logs、SBOM/VEX snapshot、access sessions、hashes 和 custody。
07 · Market & Business Model
第一批买家是正在从 demo 走向付费 pilot 的机器人 OEM、RaaS operators、系统集成商和企业自动化团队。SafetyOps 帮他们减少 release review 时间、降低 warranty/SLA 争议、生成 insurer-ready evidence,并让客户验收更快。
CTO、VP Safety、VP Product、customer success,需要证明每次技能更新、远程接管和事故复盘。
EHS、automation engineering、OT security、legal/risk、procurement 需要责任链和验收证据。
人民币 50k-150k / site-year + 50-200 / robot / month,强调 GB/T readiness、数据驻留和私有化。
$25k-$100k / site-year + $20-$100 / robot / month;formal release pack 和 insurer/RaaS API 另收费。
08 · Competition & Moat
FORT、3Laws、Veo、NVIDIA Halos、Formant、InOrbit、Foxglove、Viam、Safety PLC vendors、AI governance 和 SBOM vendors 都解决一层。SafetyOps 的 wedge 是 robot skill release gate、remote-assist responsibility chain 和 cross-OEM safety event schema。
跨 OEM 记录 skill、ODD、command、policy denial、QNN profile、incident、rollback 和 warranty evidence。
dock assist、pick、carry、clean、patrol、elevator、charging 等技能沉淀权限和安全包络模板。
operator identity、MFA、command scope、session recording、break-glass、vendor access 和 revocation 形成责任链。
版本、地点、触发、停机、人工接管和恢复形成 underwriting / claims 可读的风险图谱。
09 · Why Qualcomm
SafetyOps 把 Qualcomm edge 从推理目标升级成 physical AI release target:每个模型都有 AI Hub/QNN profile、runtime artifact、latency/memory、numeric delta、fallback status、rollback 和 incident evidence。
AI Hub / QAIRT / QNN profile 进入 release gate,不再只说 TOPS 或 demo FPS。
Dragonwing target 记录 camera health、frame age、thermal、power、network、QoS 和 sensor confidence。
device identity、secure boot、OTA、key management 和 signed logs 支撑 edge evidence custody。
release manifest 绑定 previous-known-good,事故时一键停用和回滚。
DragonWorks、EdgeRuntimeBench、SkillCertKit、SkillDock、EdgeFleet 串成完整 Qualcomm edge AI lifecycle。
10 · Demo & Ask
比赛 demo 可以用桌面 AMR/机械臂模拟器:上传新技能,缺少 human-proximity eval 被挡住;补上 HIL/replay/QNN/SBOM/VEX 后只允许 canary;运行时 raw /cmd_vel 被拒绝;人进入 keepout zone 触发停机、replay、回滚和 audit pack。
技能卡显示 sensors、actuators、ROS allow/deny、ODD、risk、rollback target 和 missing evidence。
JIT remote-assist session 显示 operator、MFA、command scope、TTL、approver 和 recording pointer。
发布门禁读取 dataset hash、replay pass、HIL clips、AI Hub/QNN latency、memory、fallback status。
canary 部署后,unsafe raw command 被拒绝;keepout 或 QoS 事件触发 slow/stop 和 incident ledger。
打开 MCAP replay,失败片段进入 LeRobot/HIL 队列,一键回滚并导出 judge-audit-pack.zip。
我们的申请:请 Qualcomm 提供 RB3/QCS/IQ target guidance、AI Hub/QNN office hours、device identity / secure lifecycle 建议和 1-2 个 OEM/SI 试点引荐。我们交付一个从技能提交、边缘评测、远程接管、运行时拦截、事故回放到审计包导出的 Qualcomm-first reference demo。
SafetyOps 不声称 certifies robots,不保证 safety,不替代 safety PLC、E-stop、scanner、STO、risk assessment、notified body、TÜV/UL/Intertek 或法律合规审查。它卖的是 audit-ready release evidence:让每个机器人技能在上线前后都有权限、边界、评测、远程接管记录、运行时证据、回滚和审计包。