The strongest evidence in a plant-floor injury has a short half-life. Guard position, lockout devices, residual pressure, controller state and alarm history are all real for a few hours and then, in the ordinary course of getting a line running again, they are gone. Nobody destroys them maliciously. They are destroyed by production pressure, by the work of making an area safe, and by the reasonable instinct to fix what broke. Knowing which records decay, and how quickly, is what makes the first shift recoverable.
The first shift decides what the case can prove
A serious incident starts several processes that do not begin at the same time. An internal investigation starts immediately. A regulatory inspection may open within days. A civil matter, a subrogation claim or a product-liability action against the equipment builder may not begin for a year. What is collected for the first is what the last will live with.
That asymmetry is the argument for treating the machine as an exhibit from the outset, even where nobody yet expects a dispute.
As-found, before the area is made safe
Making a scene safe and preserving it are usually compatible, but only if photography comes first. The sequence worth insisting on is overall views placing the machine in its surroundings, then the guard and its mounting, the control panel with every selector legible, each lockout device in place with its tag readable, and the workpiece still in the machine.
Scale references, and a recorded photographer, date and time, foreclose an entire category of later argument. Where scanning or photogrammetry is available, capturing the cell before anything moves gives every later analyst the same starting geometry.
What a controller actually retains
A programmable controller is a state machine, not a recorder. Absent deliberate logging it holds current values, which is precisely what a restart overwrites. Retentive memory survives a power cycle; non-retentive memory does not. Fault and diagnostic buffers in the processor and in safety modules are typically finite and circular, so continued running rolls the incident out of them.
The consequence is counter-intuitive and is the most frequently lost evidence in this field: a machine cycled a few dozen times may retain nothing about the incident while appearing entirely healthy.
Historians, alarms and operator actions
Where a process historian, alarm server or HMI is present the record is richer, but it decays too. Historians run finite retention windows and often apply compression or deadbands that discard values judged uninteresting. HMI operator-action logs, where enabled, capture mode changes, overrides and setpoint edits, and are frequently the most informative single file in the incident.
All of it depends on time synchronisation. Controllers, historians, badge readers and camera systems drift apart, and a sequence assembled from unsynchronised clocks can invert cause and effect. Record each system's clock offset at collection.
Energy isolation exactly as found
Which isolation devices were applied, by whom, and in what position is the core of any lockout question, and it is undone by the first person who clears the machine. Photograph locks and tags in place before removal, record the name on each tag, and note disconnect and valve positions, block placement, and any gauge reading.
Residual energy is part of that state. Accumulator pressure, a raised platen, suspended tooling, a wound spring, a loaded conveyor take-up — all evidence what still held energy, and all routinely released during recovery without a note being made.
The guard, its fasteners, and the tool marks
Where a guard is missing or displaced, the mounting carries the history. Thread condition, paint witness lines, corrosion patterns and tool marks distinguish a guard removed long ago from one displaced in the event itself. Collect the fasteners and do not reinstall them.
The same applies to interlock hardware. Whatever condition it is in, preserve it in that condition — in place where possible, bagged and labelled where not.
Downloading the program is not preserving it
Control-system evidence includes the logic, not only the data. What matters is the program running at the time: the online version including undocumented edits, the forced input and output table, safety configuration parameters, and whether the running program matches the archived one. Uploading before any maintenance change, and recording checksums or safety signatures, fixes that state.
Forces deserve their own attention. A forced input holding a safeguard in a permissive state is the software equivalent of a jumper, and it vanishes the moment somebody loads a clean program.
Restarting without erasing
Production has to resume, and a position that it must not is neither realistic nor necessary. The workable sequence: photograph as found; collect controller, safety-module and historian data before any cycling or download; preserve the guard and isolation hardware; record clock offsets; then obtain a documented release. That is hours of delay, not weeks.
Where a regulator has placed a hold, or an amputation makes third-party litigation likely, extending that to a coordinated inspection with the other interested parties invited avoids the charge of a one-sided examination.
Where the record is contested
Expect challenges that the data was pulled after the machine had been run, that timestamps came from unsynchronised clocks, that the program examined was not the program running, and that the as-found condition had already been altered before the first photograph.
Each is answered by chain of custody and contemporaneous notes: who collected what, when, and from which device. An analyst who can state plainly what was disturbed before arrival is more credible than one claiming a pristine scene.
This article is general technical orientation, not a failure analysis, an engineering opinion, or advice on any specific matter. Determining the cause of a particular incident requires hands-on examination by a credentialed expert.