My machined-plastic-puck transfer completes uninterrupted runs, but a stop between pick, place and advance can leave the saved pocket inconsistent with the trays. What evidence should my recovery design require before it chooses the next action? This is still a workshop test station, not normal production.
Write down the source, hand and destination possibilities at each interruption boundary. Start with the saved information you actually have, not what you hoped each command accomplished.
That boundary is exactly where my current design would repeat the pocket. It saves only the next index. No source or destination tray identity, and no recorded uncertain state.
Then the old saved index cannot support automatic recovery. A revised record needs tray identity and action context, with an explicit hold when physical occupancy cannot be reconciled.
My draft now has a held transfer with the two tray identities and relevant pockets. It does not decide placement succeeded from the release command. I still need to define who reconciles the physical state.
The offline review also found a tray swap that left a plausible pocket number. With an unrecognised destination tray, the revised draft holds the transfer rather than matching only the index.
Can the person reviewing the hold see which tray was expected and which is presently identified? That would help them report a mismatch without inviting them to choose a convenient tray name.