Unmanned night operation in a factory is not a headcount promise. It is an operating claim: the line can detect an abnormality, contain its effects, choose a safe recovery path, and preserve evidence without sending a person into exposure. This guide turns that claim into practical RFP, FAT, SAT, and production-handover gates for factories in Thailand.
Define unmanned night operation by abnormal-event capability
“Unmanned” means different things to different functions. Management may hear labor savings, engineering may hear automatic cycle time, and EHS may hear an uncontrolled facility. Resolve that ambiguity before requesting quotations.
In this guide, unmanned operation means normal production without a continuously present person, within an approved envelope of products, equipment states, materials, utilities, and time. It does not include cleaning, tooling changes, jam clearing, adjustment, inspection inside a safeguarded space, repair, or maintenance. Those servicing activities require a separate mode, energy isolation, verification of a safe condition, and trained personnel.
Use four verbs as the acceptance test:
| Capability | Design question | Typical acceptance evidence |
|---|---|---|
| Detect | Can hazards, quality drift, starvation, utility loss, and communication failure be found early enough? | Diagnostic tests, sensor coverage, alarm history |
| Contain | Can the event be kept from spreading to people, equipment, WIP, or adjacent processes? | Stop sequence, isolation action, quarantine logic |
| Recover | Is there a bounded path for automatic retry, remote assessment, or on-site repair? | State model, authority matrix, restart checklist |
| Evidence | Can the plant reconstruct what happened and decide product disposition? | Event timeline, audit trail, lot links, validated backups |
A line that runs only until something goes wrong is not 24-hour manufacturing automation. Approval must be based on abnormal-event capability, not a statement that a shift can be removed.
Set the operating boundary and prohibited activities first
Separate unattended production from servicing and maintenance
No person being present during an automatic cycle does not mean nobody will ever touch the machine. Cleaning, lubrication, replenishment, setup, troubleshooting, and preventive maintenance remain. The RFP should separate automatic production, attended production, safe hold, isolation, maintenance, validation, and restart modes. It should state who can select each mode and which safeguards must be proven before a transition.
U.S. OSHA 29 CFR 1910.147 is a useful reference for hazardous-energy control during servicing, but it is a United States regulation, not Thai law. A Thailand facility must establish applicable Thai legal duties, permits, insurer requirements, and corporate rules with qualified local advisers. Referencing an overseas standard does not by itself establish local compliance.
Limit products, recipes, material states, and duration
Avoid the vague sentence “the line is suitable for unmanned operation.” State the approved part numbers, signed recipes, raw-material conditions, packaging, maximum unattended duration, starting inventory, maintenance status, and required building services. New products and temporary parameters should remain attended until their differences are validated.
| Boundary | Allowed example | Return to attended mode when… |
|---|---|---|
| Product and recipe | Released part number and signed recipe | Trial lot, temporary correction, unsigned change |
| Material | Identified lot, enough stock plus margin | Substitute, unknown balance, label mismatch |
| Equipment | Maintenance current, no unresolved warning | Bypass active, degraded sensor, overdue work |
| Utilities | Power, air, cooling, ventilation, fire systems healthy | Threshold approached or partial service loss |
| Access | Safeguarded area confirmed empty | Cleaning, setup, or service is in progress |
| Time | Within a validated unattended window | Maximum duration exceeded or handover incomplete |
Rework risk assessment for a shift with no local observer
ISO 12100:2010 provides a methodology for machinery risk assessment and risk reduction. ISO’s page says the edition was confirmed current in 2022 and also shows that it is under revision. The value is not the standard number on a purchase order; it is applying hazard identification, risk estimation, inherently safe design, protective measures, and information for use to the actual unattended use case.
During an attended shift, an operator may notice noise, smell, vibration, leakage, heat, or WIP disorder. That informal detection layer disappears at night. “The operator will notice it” cannot remain a credited control. The project must either implement equivalent detection and a safe response or exclude that condition from the unattended envelope.
Do not confuse production logic with safety functions
ISO 13849-1:2023 provides a methodology for designing and integrating safety-related parts of control systems. The required performance is derived from the risk reduction needed; this article cannot prescribe one Performance Level for every application. Emergency stop, gate interlocking, safe speed, safe torque off, or pressure release must be specified and validated as safety functions where the risk assessment requires them, not merely as bits in the standard PLC.
For robot cells, ISO 10218-2:2025 addresses integration, commissioning, operation, and maintenance of industrial robot applications and cells. A compliant robot does not make an integrated cell safe by itself. Tooling, fixtures, conveyors, fences, access points, and upstream/downstream equipment create system-level hazards.
| Scenario | Loss or hazard | Detection | Automatic containment | Before a person enters |
|---|---|---|---|---|
| Jammed workpiece | Unexpected motion, damage | Torque, position, cycle timeout | Stop, secure energy, prohibit repeated retry | Isolate, verify stored energy, use jam procedure |
| Robot grip failure | Drop, collision, mixed quality | Grip switch, vision, weight | Stop cell, route to reject if safe | Confirm cell state and object location |
| Leak or overheating | Fire, release, damage | Leak, temperature, smoke, flow balance | Isolate supply, stop zone, coordinate protection | EHS release and medium-specific response |
| Sensor failure | Missed hazard or false good | Open-wire, plausibility, comparison | Fail safe and quarantine product | Replace and function-test |
| Network or server loss | Lost control or records | Heartbeat and time-sync monitoring | Local bounded control or defined stop | Verify data integrity and known state |

Build the RFP as layered readiness gates
Treating unmanned operation as a single equipment feature makes proposals impossible to compare. Structure the RFP as gates. A higher layer never compensates for failure of a foundational one.
Gate 1 — safety and local compliance
Require the machine/cell risk assessment, safety requirements specification, validation plan, safeguarding, isolation points, fire/environment interfaces, and a responsibility matrix for Thailand compliance. Put formal reviews by plant EHS, engineering, maintenance, and qualified advisers into the commercial schedule.
Gate 2 — process and quality stability
Preventing escape is more important than avoiding a stop. Define critical quality characteristics, measurement availability, recipe governance, golden samples, rework rules, traceability, and the affected window around an abnormality. The quarantine must extend back to the last demonstrated good point, not merely start at the alarm timestamp.
Gate 3 — reliability and supply continuity
Test wear items, lubrication, tool life, replenishment, reject-bin capacity, air, cooling, extraction, ventilation, and power quality beyond the intended unattended window. Look for clustered micro-stops, intermittent sensors, and empty/full boundary behavior, not only average uptime.
Gate 4 — control, alarms, and recovery
Do not make every signal a red alarm. Classify what can auto-recover, what permits remote assessment, what requires on-site isolation, and what must trigger immediate escalation. Align alarm class with the state model and authority matrix.
Gate 5 — OT security, backups, and evidence
NIST SP 800-82 Rev.3 recognizes OT’s performance, reliability, and safety constraints. Adapt security to those constraints. Define assets, communication paths, identities, remote access, logging, change control, backups, and recovery in terms of their effect on safe and reliable production.
Gate 6 — people and accountability
Name who receives an alarm, acknowledges it, decides whether to dispatch, expands quarantine, authorizes restart, and reviews the night shift. “Call engineering” is not a control if the number, language, authority, and travel time are undefined.
| RFP deliverable | Supplier responsibility | Factory responsibility | Acceptance evidence |
|---|---|---|---|
| Risk and safety requirements | Identify equipment hazards and proposed controls | Confirm actual use, local duties, constraints | Review record and disposition of open risks |
| Cause/effect and state model | Document logic and event response | Operations, quality, maintenance approve outcomes | Simulation and FAT records |
| Alarm register | Tags, cause, consequence, priority, response | Define roster and response objectives | Injected tests and load test |
| Backup and recovery | Procedures for PLC/HMI/robot/PC | Storage, access, recovery approval | Restore to clean or spare hardware |
| Quality containment | Identify and hold affected output | Set disposition authority and criteria | Simulated upset with lot trace |
| Training and handover | Diagnostic and maintenance material | Verify competence on every shift | Practical assessment records |
Rationalize alarms to produce action, not notifications
IEC 62682:2022 covers management of alarm systems presented through control systems and HMIs, and applies to continuous, batch, and discrete processes. The ISA-18.2 series describes an alarm-management lifecycle; ISA-TR18.2.3-2024 addresses basic alarm design.
Forwarding every alert to a phone is not an unmanned-operation design. It buries important events and creates unnecessary dispatches. Every alarm needs a defined cause, consequence, available response time, assigned action, priority, suppression condition, and closure rule.
| Alarm-field | Question | Weak statement | Useful direction |
|---|---|---|---|
| Consequence | What occurs if no action is taken? | “Abnormal” | Product temperature limit may be reached in ten minutes |
| Priority | What is affected and how soon? | Everything is High | Classify by consequence and available response time |
| Action | What should the receiver do? | “Please check” | Review trend, command allowed stop, notify Quality |
| Response | When is a decision due? | ASAP | Acknowledge in 5 min; dispatch decision in 15 min |
| Suppression | In which states is it not meaningful? | Always enabled | Engineered suppression during planned cleaning |
| Closure | What proves resolution? | Press Reset | Cause cleared, safe state confirmed, quality window set |
FAT should include alarm-flood scenarios. If low plant air produces 50 actuator alarms, the system should identify the root event and organize consequential alarms without hiding relevant evidence. Suppression must be designed, approved, state-dependent, and logged.

Agree stop, containment, and restart as a state machine
“Stop” can mean a production stop, controlled process stop, safety stop, emergency stop, utility isolation, cyber isolation, or quality hold. Define explicit states, transition guards, authority, timeouts, and evidence.
A practical model includes RUN, DETECT, CONTAIN, SAFE HOLD, REMOTE ASSESS, ON-SITE ISOLATION, VALIDATE, RESTART, and QUARANTINE REVIEW. DETECT checks signal plausibility. CONTAIN prevents propagation. SAFE HOLD blocks automatic restart. REMOTE ASSESS exposes only approved information and operations. ON-SITE ISOLATION begins the servicing workflow. VALIDATE proves safety, process, quality, and data before RESTART. QUARANTINE REVIEW is owned by Quality, not by the restart button.
Bound automatic retries
Automatic retry can improve availability, but repeated attempts can enlarge damage or mix suspect product. Permit it only when risk cannot increase, a transient cause can be distinguished, attempts and elapsed time are limited, and every attempt is logged. Repeated gripping, recurrent overcurrent reset, or replay of stale commands after reconnection should default to a hold unless explicitly justified.
| Event class | First action | Remote authority | Automatic restart | Product disposition |
|---|---|---|---|---|
| Minor, demonstrated transient | One bounded retry | Observe and acknowledge | Allowed within validated limits | Auto-inspect affected cycle |
| Unknown quality impact | Stop and establish affected window | View trends; enlarge hold | Prohibited | Hold from last good point |
| Safety, fire, environment | Safe stop and required escalation | No remote restart | Prohibited | Review surrounding output |
| Suspected cyber compromise | Segment communication, reach known state | Incident-response path only | Prohibited | Hold until data integrity is proven |
| Material or utility shortage | Controlled stop and protect WIP | Assess stability and ETA | Only after stable restoration | Decide using dwell/time/temperature rules |
Put boundaries around remote access
NIST SP 1800-45, finalized in June 2026, demonstrates secure remote-access practices for water and wastewater systems. It is not a factory-specific mandate, but its cross-sector lessons are relevant: combine identity assurance, trusted endpoints, least privilege, session control, monitoring, logs, and rapid revocation.
A VPN alone is insufficient. Avoid shared vendor IDs, permanent tunnels, direct PLC routing, and unrecorded configuration changes. Consider a broker or jump host, MFA, time-bound approval, session recording, and read-only initial privilege.
| Remote action | Night responder | Maintenance lead | Supplier | Conditions |
|---|---|---|---|---|
| View dashboard | Yes | Yes | Only when approved | Named ID, MFA, log |
| Acknowledge/comment | Yes | Yes | Normally no | Response procedure and synchronized time |
| Normal stop | Conditional | Yes | Normally no | Consequences pre-assessed |
| Reset or restart | Only named low-risk events | With approval | Supervised session only | State checklist and, where required, dual approval |
| PLC/HMI change | No | Under change control | Time-bound and supervised | Backup, diff, rollback, FAT/SAT |
| Safety bypass/change | No | Formal safety change only | Never alone | Reassessment, validation, local isolation |
Seeing a camera feed is not proof that the site is safe. Cameras have blind spots and may not reveal odor, slight vibration, floor leakage, or stored material. Define conditions requiring physical inspection so production pressure cannot erode the boundary.
Accept OT backups through restore tests
NIST’s OT security publications list includes the OT Backup Quick Start Guide, SP 1339, released in June 2026. Backups support recovery from ransomware, but also from PLC replacement, HMI storage failure, recipe error, robot replacement, and configuration loss.
A project file in a folder is not a recovery capability. Link firmware, licenses, communications, certificates, recipes, historian databases, accounts, calibration, robot frames, and network-device configurations to an asset register and dependency map.
| Asset | Capture point | Protection | Restore acceptance |
|---|---|---|---|
| PLC and safety PLC | After approved change and periodically | Separated offline/immutable generations | Load to spare/test CPU and explain I/O differences |
| HMI/SCADA/industrial PC | After change, before OS work, periodically | Image, settings, licenses | Boot spare/VM and verify communications/screens |
| Robot and motion | After teaching or parameter change | Versioned and tied to machine serial | Restore in test or controlled outage |
| Recipe, quality, history DB | Automated to required RPO | Encrypted, integrity checked, separate failure domain | Sample restore with lot/timeline consistency |
| Switch, firewall, remote gateway | After approved change | Secrets separated; configuration diffs | Restore spare and test paths/deny rules |
RPO and RTO affect product decisions. If 30 minutes of history can be lost, that output needs a defensible quarantine rule. If recovery needs eight hours, SAFE HOLD and a morning handover may be safer than improvised remote restart.
Include materials, utilities, fire, and environment
An automated cell still stops when material runs out, air pressure falls, cooling is lost, or reject capacity fills. Extend scope beyond the cell to every service needed through the unattended window.
For materials, assess quantity sensing, usage variance, misfeed, wrong loading, splice points, empty-container flow, scrap collection, and label verification. Define where WIP stops, how dwell and temperature limits continue to be monitored, and what is discarded after restoration.
For utilities, set separate warning and trip thresholds for power, UPS, compressed air, cooling water, steam/gas where used, dust extraction, ventilation, HVAC, network, and time synchronization. SAT should test partial loss, gradual degradation, and upstream/downstream mismatch.
Fire detection, suppression, smoke management, emergency notification, drainage, bunding, and spill response must align with plant EHS, building systems, permits, and local emergency arrangements. Production shutdown must not disable protective functions; protective activation must place production in an appropriate safe state.
Accumulate evidence through FAT, SAT, and handover
FAT: inject failures, not only good cycles
Inject open-wire and stuck sensors, communication delay, clock offset, empty/full states, air and cooling loss, vision uncertainty, robot grip failure, database loss, and remote-session interruption. Where physical injection would be unsafe, use simulation or signal injection and record the limitation.
| FAT test | Pass condition | Evidence |
|---|---|---|
| Sensor failure | Diagnosed in required time, safe response, no false-good output | I/O log, video, event timeline |
| Alarm flood | Root event visible; critical notification not buried | Alarm summary and receiver record |
| Communication loss | Local logic reaches defined state; no duplicate command | PLC/network logs and state trace |
| Power recovery | No unauthorized automatic start; recipe/time/WIP consistent | Startup checklist and audit log |
| Backup restoration | Clean/spare environment runs; all differences explained | Restore record, hash, approval |
| Quality containment | Affected output traced from last good point and blocked | Lot query, hold status, MES record |
SAT: test the actual Thailand factory environment
Verify power quality, latency, temperature/humidity, dust, lighting, material variation, local-language alarms, shift structure, building protection, and upper-level interfaces. Do not accept only while supplier engineers are standing beside the line. The plant team must receive, decide, contain, and hand over an event themselves.
A continuous run should cover product mix, declining inventory, planned fault injection, shift handover, remote duty, quarantine, and morning review—not only a headline number of hours without stopping. Duration is a risk-based project decision, not a universal legal threshold.
Production handover: distinguish technical completion from operating readiness
A working machine is not ready for unmanned production if rosters, spares, restores, escalation, disposition, or change control are incomplete. Maintain separate technical and operating punch lists. Keep attended operation until every item that can invalidate an unmanned claim is closed.

Use a 30/60/90-day staged validation
The following is illustrative, not a market norm or mandatory timeline. Adapt it to process risk, product, competence, legal review, and available evidence.
| Period | Operating scope | Accountable owner | Example go condition |
|---|---|---|---|
| Days 0–30 | Fault validation under attended operation | Engineering, EHS, Quality | Safety validation complete; state tests pass; no critical open item |
| Days 31–60 | Short unattended windows with nearby response | Production, Maintenance, IT/OT | Alarm response, quarantine, restore, and handover meet targets |
| Days 61–90 | Limited products through night operation | Plant manager and function heads | Repeatable across shifts; dispatch logic works; no critical escape |
| After day 90 | Expand envelope through change control | Change board | Difference assessment before every product/time extension |
Make shift handover part of the control loop
Before release, review unresolved alarms, bypasses, maintenance due dates, inventory, holds, recipe, utility/weather concerns, responder coverage, communication, and backups. In the morning, review micro-stops, retries, disconnects, manual operations, remote sessions, quarantines, and sensor diagnostics—not only production quantity.
| Handover area | Before unattended release | Morning review |
|---|---|---|
| Safety/equipment | No bypass; guards healthy; maintenance current | Stops, safety demand, diagnostics |
| Quality | Released recipe; inspection available; hold capacity | Deviations, retest, hold range, disposition |
| Material/logistics | Quantity, labels, empty/reject capacity | Starvation warning, jam, scrap, inventory variance |
| OT/data | Time, storage, network, backup healthy | Disconnects, remote operations, changes, missing data |
| Organization | Roster confirmed; call tested; access route known | Response time, decision quality, assigned improvement |
Decide go/no-go with gates and metrics
A scorecard can expose disagreement, but it must never average away a critical hazard. The following is illustrative. Unvalidated safety functions, unresolved local compliance, unapproved fire/environment interfaces, failed quarantine, untested restoration, or no accountable responder are automatic no-go conditions.
| Domain | Illustrative weight | Measure | Mandatory gate |
|---|---|---|---|
| Safety/compliance | 25 | Open risks, function tests, isolation procedure | No unresolved critical item |
| Quality/traceability | 20 | Last-good point, containment, inspection availability | No path for suspect escape |
| Reliability/supply | 15 | Stops, material margin, utility response | Containment through unattended window |
| Alarms/recovery | 15 | Response, nuisance, retry, safe-hold success | No missed critical alarm |
| OT/backup | 15 | Access, logs, restore, approved changes | Successful restore test |
| People/handover | 10 | Competence, calls, response, review | Every shift demonstrated competence |
Define denominator and observation window for every metric. Useful candidates include response to high-priority alarms, nuisance ratio, bounded retries, successful SAFE HOLD transitions, completeness of quarantine, approved remote sessions, successful restore exercises, and completed morning reviews.
An illustrative, plant-specific economic frame is:
Annual value = avoidable night-shift cost + recoverable production capacity − added maintenance − duty coverage − connectivity/security − expected downtime and scrap loss.
This is not a market statistic. Document assumptions, sensitivities, downside cases, and owners. Labor savings alone ignore dispatch, spares, restore capability, cybersecurity, and quality-hold costs.
Thailand BOI reported 1,300 approved applications worth THB 1.31 trillion in the first half of 2026, including THB 17.2 billion for projects improving productivity through machinery, digital systems, and automation. This is context for Thailand’s investment environment, not proof of ROI for any unmanned line. Eligibility and benefits require project-specific confirmation.
Questions to put into an automation RFP
- Which abnormalities do operators currently detect through sound, smell, sight, or touch, and what replaces that detection?
- From which risk assessment are safety functions derived, and who validates them?
- How is the last good point established, and can affected output be automatically held?
- What occurs to equipment and WIP during material, reject-capacity, air, cooling, or extraction loss?
- Which events permit automatic retry, how often, for how long, and when is it prohibited?
- Who can view, stop, reset, restart, and change remotely, and is every session recorded?
- How quickly can PLCs, HMIs, robots, industrial PCs, recipes, and network settings be restored—and where is the restore evidence?
- Who owns escalation for fire, spill, ventilation loss, or suspected cyber compromise?
- Which failures are physically injected at FAT/SAT and which are simulated?
- Who decides continuation at days 30, 60, and 90, using which metrics?
Before issuing an RFP, review the common failure risks in Thailand automation projects. If controller age and backups are uncertain, use the Thailand PLC replacement and retrofit guide to establish a baseline. Applications that mix people and robots also benefit from the collaborative robot implementation guide.
Frequently asked questions
Can an unmanned night-operation factory truly have zero workers?
The defined production area may operate without a continuously present operator, but maintenance, cleaning, preparation, quality disposition, and emergency response remain. Bound the claim by product, time, and equipment state. Define conditions for dispatch and a safe hold when no one should restart remotely.
Which failures should a 24-hour automation project test first?
Let risk assessment set priority. Common candidates include power, network, air and cooling loss; starvation; jams; sensor failure; unavailable quality inspection; fire or leak; and interrupted remote access. Test detection, containment, evidence, and recovery—not only endurance during normal cycles.
What is the minimum preparation for factory automation under a labor shortage?
Standardize the process, inventory OT assets, characterize hazards and quality risks, collect stop-reason data, define materials/utilities, and appoint accountable owners. Automating unstable work can reproduce variation faster. Identify every abnormal cue currently supplied by a person.
Can the business case for labor-saving equipment use labor cost alone?
No. Include capacity, yield, downtime, added maintenance, spares, responder coverage, connectivity, cybersecurity, quality quarantine, and training. The formula in this article is illustrative, not an industry average. Test several availability and scrap scenarios without reducing safety or quality gates.
Does remote PLC reset eliminate night dispatch?
No. A remote screen may not show leakage, odor, dropped material, or the state inside a guard. Pre-authorize only defined low-risk events, limit retries, require evidence and logs, and dispatch for safety, fire, environmental, unknown quality, and cyber conditions.
Is U.S. OSHA lockout/tagout law directly applicable in Thailand?
OSHA 29 CFR 1910.147 is U.S. law, not Thai law. It can inform hazardous-energy thinking, but the facility must confirm Thai legal duties, permits, insurer conditions, and corporate standards locally, then document machine-specific isolation and restoration.
Conclusion: acceptance is proven when abnormal events occur
The value of unmanned night operation is not the absence of a person; it is expanding productive time without sacrificing safety, quality, or control. Write the operating boundary and accountability into the RFP, inject faults at FAT, test actual factory conditions at SAT, and validate in staged production gates. Approve only when detection, containment, recovery, and evidence remain effective—and keep servicing work in a separate isolated mode.
TOMAS TECH can help factories in Thailand assess readiness, translate operating risks into RFP/FAT/SAT criteria, and define responsibilities across PLC, robot, MES, maintenance, quality, and OT security. Early concepts and single-line pilots are welcome through our contact page.
Research / Sources
- ISO 12100:2010 — machinery risk assessment and risk reduction
- ISO 13849-1:2023 — safety-related parts of control systems
- ISO 10218-2:2025 — industrial robot applications and cells
- NIST SP 800-82 Rev. 3 — Guide to Operational Technology Security
- NIST SP 1800-45 — secure remote access for water and wastewater systems
- NIST Operational Technology Security Publications
- IEC 62682:2022 — management of alarm systems
- ISA-18 Series — alarm management
- U.S. OSHA 29 CFR 1910.147 — hazardous-energy control (U.S. regulation, not Thai law)
- Thailand BOI — first-half 2026 investment-promotion approvals