Getting machines to stop being dangerous is the easy part. Bringing them back safely is where people screw up.
I've spent more years than I care to count watching technicians try to bypass safety interlocks with paperclips and zip ties. It happens on every line, in every industry, whether it's a packaging machine at a food plant or a stamping press in an auto parts shop. The manual reset is one of those requirements that seems simple on paper until someone's deadline is breathing down their neck and the safety circuit won't acknowledge a clear condition. A manual reset on a machine safety system means exactly what it sounds like. A person has to physically go to a designated location and operate a control device to restore the safety circuit after a fault or guard breach. It doesn't reset itself. It doesn't come back online when the timer runs out. Someone has to turn a key, press a button, or flip a switch at the reset station, and that action has to be deliberate and intentional. That's the whole point. The relevant standards are ISO 13850 for emergency stop device requirements, ISO 13849-1 for the performance levels of safety-related parts of control systems, and IEC 62061 which overlaps significantly. In North America you'll also run into ANSI B11.19 and OSHA 29 CFR 1910.212. None of these say "just make sure there's a big red button somewhere." They specify category, performance level, and fault tolerance requirements that determine how the reset circuit has to be designed.
Here's how a basic manual reset circuit actually works. You have a safety relay or a safety PLC monitoring the state of every interlock, light curtain, two-hand control, and emergency stop on the machine. When any of those devices triggers a fault condition, the safety relay drops its output contacts and locks them open. The machine can't run. The lockout is maintained even if the fault condition clears, because that's the whole idea. A qualified person then walks to the reset station, verifies the hazard is actually cleared, and actuates the reset device. The safety relay checks that the reset command is valid, re-energizes its output contacts, and initiates a new safety monitoring cycle. If everything is still good, the machine is allowed to start through the normal start sequence. The reset device itself has to meet specific criteria. ISO 13850 says it needs to be protected against unintentional actuation, which is why keyed resets and guard-key interlocks are so common. The reset button or key switch should only be accessible from a safe location where the operator can see the machine area before resetting. That's not a suggestion. That's the standard. I ran into a problem last year on a robotic weld cell where the manufacturer's manual reset instructions were written for a different safety relay model than what had been installed during a retrofit. The old relay required a momentary contact closure to reset. The new one required a sustained key turn held for two seconds. The documentation didn't mention the change. The electrician followed the manual, hit the reset, watched nothing happen, and then tried holding the button longer, thinking he was just doing it wrong. It didn't work. The safety circuit had a self-diagnostic loop that detected the incorrect reset pulse duration and logged a fault code instead of resetting. We pulled the error log from the safety PLC, saw diagnostic code 0x4A, and figured it out in about ten minutes. The workaround was straightforward once we knew what we were looking for: we temporarily jumpered the timing resistor on the relay to accept the shorter pulse, but only after we confirmed the rest of the safety chain was intact and documented the modification as a one-time troubleshooting measure. Don't make that your permanent solution. Replace the relay with the correct model. The whole thing cost us about forty-five minutes of downtime instead of the four hours it would have taken if we'd kept guessing.
One thing beginners consistently miss is the difference between a reset and a restart. A manual reset clears the safety fault state. It does not start the machine. After a successful reset, you still need to initiate a normal start sequence. The machine should never resume operation automatically after a safety fault, regardless of how fast the reset circuit responds. I've seen this confusion cause incidents where operators treated a cleared fault as a green light and walked up to a machine that was still cycling through its startup routine, assuming it was stationary. Another nuance that doesn't get enough attention is reset blocking. Some machines have multiple fault conditions that can occur simultaneously, or a downstream fault that should prevent reset even after an upstream fault is cleared. A properly designed safety circuit will use blocking logic so that resetting one zone doesn't invalidate the lockout on another. If your safety relay doesn't support this and you're running a multi-zone machine, you need a safety PLC or a safety controller with explicit zone management. A single safety relay with external gating logic can approximate this, but you're adding complexity and potential failure points for something the right controller handles internally. The category of the safety circuit matters enormously here. Category 0 is an uncontrolled stop, meaning power is cut immediately to the actuator. Category 1 is a controlled stop where power is maintained long enough to bring the machine to a complete stop and then removed. Category 2 maintains power during the stop but removes it afterward. The reset requirement interacts differently with each category. On a Category 0 stop, the manual reset is the only thing bringing the system back. On a Category 1 or 2 stop, there's already a controlled sequencing happening, and the manual reset is more of a confirmation step. Getting this wrong means either unnecessary downtime or a safety gap.
Get the Full Details

If you're writing manual reset procedures for your own equipment, don't just tell people to "press the reset button." Document the exact location of the reset device, the sequence of verification steps that must happen before actuation, the expected response of the safety indicator lights, and what to do if the reset doesn't clear the fault within the specified time window. Include the fault code lookup table if your safety controller uses them. Make it usable by someone who hasn't worked on that specific machine in six months. The version of the procedure your maintenance team reads at 2 AM on a Saturday is the only version that matters. There are legitimate cases where manual reset isn't appropriate. If the hazard is something like a chemical release or a fire condition where the environment itself could be unsafe for a person to approach, an automatic reset after environmental conditions normalize is actually the safer choice. But that requires a completely different safety architecture with environmental monitoring interlocks, and it's not something you bolt onto an existing manual-reset design. If you're considering it, you're redesigning the safety system from scratch. Don't try to fake it with a timer and a contactor. The biggest bottleneck in practice isn't the reset circuit itself. It's the administrative side. People skip the verification step, they reset from the wrong location, they prop open guard switches, they ignore fault histories because the machine looks fine. The manual reset instructions are only as good as the culture around them. A perfectly designed Category 3 PLd safety circuit means nothing if the operator treats the reset button like a continue button on a microwave.
If your current setup relies on a simple emergency stop loop with a manual reset that was designed five years ago, it probably doesn't meet current performance level requirements. ISO 13849-1 introduced performance levels that older machines weren't designed for. You might be operating below the required PL for the hazard you're protecting against. A safety function assessment will tell you where you stand. It's not a fun exercise, but it's faster than an incident report.