Where 1.5 was about the methods, version 1.6 is about the deliverable: what the client actually receives, and what happens to it afterwards. ErgoSphere Viewer ships as a free companion application. It opens the sealed .ergview package, shows the issued report page for page exactly as it prints, carries the Word document inside it, and turns the analysis back into something you can interrogate: live task hierarchies, live bowties, live networks, and a Results surface that presents the figures of an assessment one at a time instead of flattening them onto A4. Then it closes the loop. A recipient can highlight a passage on the page and comment on it the way they would in Word, save a new file, and send it back; the issued deliverable stays byte identical forever, and the review travels as an append-only chain that ErgoSphere reads, anchors, answers and returns. Behind that sits a new fourth top-level module, Deliverables, which is where reports are marked ready, composed into packages, issued with a manifest, superseded, reissued and reviewed. The HF Programme stream lands the assurance document set a client actually contracts for, including a first-class HF Analysis Report with simultaneously valid audience variants, an HF User Requirements Register, and the bound figure token, which makes a number quoted in prose a reference to the analysis rather than a typed digit somebody has to remember to change. Joining it is ErgoDelta, a new tool that places two or more states of the same system side by side and counts what actually moves between them. ErgoDesign gains a posable manikin you drag by the hand, contact highlighting, and a first-person Eye View with a MIL-STD-1472H visual field overlay. ErgoSense can now import an Xsens .mvn recording as a linked take, so motion capture no longer has to be live. The registers scale to thousands of rows, gain a Role Register with task allocation and DIF analysis, and every one of them now knows which project it belongs to. Your existing projects open unchanged.
ErgoSphere Viewer is a separate, free Windows application that opens the .ergview package an ErgoSphere practitioner issues. It needs no account and no connection: the file opens on the recipient's own machine and nothing leaves it. The package is sealed and tamper evident, and the Viewer says so plainly on a Sign-off panel that states what the file does and does not prove - which parts verified against the seal, which were deliberately omitted and which were not, and who issued it. The point of the format is that a human factors analysis is a structure, a graph and a time series, and printing all three onto A4 throws most of it away. The Viewer gives it back. More about the Viewer →
The document screen shows the real pages, laid out exactly as they will print, rather than text on a grey background. The recipient reads the deliverable in the form it was issued in, and can take the .docx away with them: the Word file travels inside the package, so a client who wants their own copy does not have to ask for one. Print was retired in favour of Save DOCX, because a document authored as a Word deliverable should be handed over as one.
Every diagram in the platform built on a graph now reaches the deliverable as a graph. Bowties, FRAM function networks, social and information networks, AcciMap layers, CWA abstraction hierarchies and decision ladders, ErgoTrace, and EAST's three linked networks all render live in the Viewer: zoom them, pan them, hover a node, drag one aside to see what sits behind it. The analyst's own arrangement is preserved, so the reader sees the diagram the practitioner composed rather than a re-run of a layout engine. The data is not editable and nothing is saved back; it is a viewer, deliberately, from end to end.
The hierarchical task analysis reaches the Viewer as a real hierarchy rather than a flat image: expand and collapse to any depth, and read plans, notes and operator steps in place instead of scrolling a numbered list across fourteen pages. It carries the same risk mode and the same node icons the tool itself draws, so a reader can see which steps carry assessments and which carry risk, on the diagram, the way the analyst sees them.
The document screen splits into Report and Results. Results is the figures of an assessment, interrogated one at a time: banded score tiles, dials, charts read against the numbers behind them, and the derivation of a score rather than only its value. It is deliberately styled as an instrument bay, so it reads immediately as something to inspect rather than something to change. An at-a-glance overview reads as a dashboard, in the way the platform's own results pages do. HTA, RULA, REBA and ErgoBow lead the rollout, with REBA brought to full parity with RULA in the deliverable.
The Issues Register, the Task Register and the HF User Requirements Register now appear inside the deliverable, presented the way ErgoSphere's own register pages present them: summary cards at the top, the full list below, full window width, and one place in the navigation. Each exports to CSV, so a client can lift a register straight into their own systems without asking for a re-issue. Assurance holds only assurance documents, so a register no longer appears twice under two different headings.
An Evidence screen groups the package's contents by method, in the order the manifest records them, so a reader can see what the assessment was built from. The seal was extended to cover the manifest's own content as well as the documents and parts it lists, closing the gap where a package's description of itself sat outside the thing that proved it. Every assessment in a package is now individually addressable, which is what makes a comment able to point at one.
The Viewer's reading path treats every package as untrusted input, because in the field it is: a file arrives by email from someone else's machine. Three hardening gaps on that path were closed, and the reader refuses malformed, oversized or self-contradicting packages rather than trying to make sense of them. On the accessibility side, an unnamed interactive control is now a compile error rather than something a code review has to catch, so every control in the application announces itself to a screen reader by construction.
A recipient of a .ergview can record a review against it: their name, position and organisation, general comments, comments anchored to specific findings or assessments, and who they are forwarding it to. Saving produces a new file. The issued deliverable itself remains sealed and byte identical forever. The review is an append-only chain, and every entry hashes its own content, the previous entry's hash, and the sealed digest of the file it was made on, so a chain that has been edited, spliced or attached to a different deliverable reads as broken rather than as valid. A reviewer can pass the file to the next reviewer and the chain simply grows.
Select text anywhere on the paginated page view and it marks immediately; a Comment control becomes available, and the comment is typed in a small popup beside the passage. The mark and its comment travel with the returned file and reopen against the exact words they were made on: the anchor is validated against the sealed page bytes before it is drawn, so a comment either lands on precisely the passage it was written on or reports that it could not be placed. It never lands on the wrong sentence. Nothing is inserted into or moved within the sealed page to make this work.
ErgoSphere opens a returned .ergview, validates the chain, matches it by sealed digest to the package it issued, and imports each comment into the project against the report and passage it was made on. The practitioner resolves or declines each one with a note. A review imported in error can be withdrawn, and the returned file is retained rather than reduced to a digest, so the marked page can be reconstructed later.
A returned comment can be read in place: the practitioner sees the sealed page with the reviewer's mark on it without leaving the application, and answers it there. Every anchored comment now carries a stable identity of its own, which is what lets a later entry reference one precisely, so a reply is bound to the comment it answers rather than to the entry that happened to contain it. Replies return to the reviewer, and a comment can be formally closed or accepted, which is the last leg of the loop the format was designed for.
Deliverables joins Project Management, Assurance and Method Tools as a fourth top-level module. It holds a register of every report the project can produce, with the state each one is actually in: draft, ready, issued, superseded. It is project scoped, so it travels inside the project file with everything else, and the word "Reports" now belongs to exactly one place in the application. Project Management's Reports tab becomes Summary; Assurance's becomes Extracts.
Marking a report ready records a digest of what was marked, so the platform can later tell you the report has moved on since. The quality check that runs at that moment is deliberately advisory: it lists what is outstanding, such as remaining placeholders, uncommitted narrative or unrendered figures, and lets the practitioner mark ready anyway, because a practitioner may have reviewed seeded content and be satisfied with it and the gate cannot know that. A report that cannot build at all still blocks, because with no digest there is nothing for the mark to stand against.
Ready reports are composed into a package, issued as a single .ergview with a manifest of what it contains, and filed into the Document Registry under their own Client Deliverables category, as distinct entries rather than as revisions of one project row. Issuing a later revision supersedes the earlier one and says so. The selection is explicit: every register that can travel, including the Issues Register, is shown as a selectable row rather than silently included.
An issued report can be revised, re-marked and reissued, which the first cut of the module could not do: issuing a report locked it out of the very loop it was meant to enter. Issued packages are retained inside the project file, so a practitioner who has lost the file they sent can recover it from the project rather than rebuilding a deliverable that is supposed to be immutable and hoping the bytes match.
A rail, defence, energy or healthcare client contracts for an integration plan, a requirements register, an issues register, an analysis report and a closeout, all traceable to a standard and all consistent with each other. This stream is about making the methods already in the platform add up to a defensible programme, rather than adding more methods. It was measured against a real, issued seven-document assurance pack produced entirely in Word: where ErgoSphere could not produce something equivalent, that counted as a gap and the gap was closed.
The HFUR arrives as a project-level register: identifier, requirement, end user group, source, verification method, verification stage and status, with requirements grouped by prefix and users classified primary, secondary or tertiary. Its power is in the source column, which points inside an analysis rather than at a document name, so a requirement can cite the exact task step and error mode that produced it. The Issues Register was extended to match, so an issue can cross-reference a requirement and both can name where they came from.
The HF Analysis Report becomes a first-class document rather than something assembled by hand. Its skeleton is seeded from the analyses actually present, of any tool type and any number, rather than from an assumed shape. It supports what real assurance work needs and few document systems offer: two renderings of the same analysis for two audiences, both controlled deliverables at the same revision. While authoring, the practitioner sees at every moment which audiences receive the text under the cursor, and can declare a section withheld from one audience or replaced for it. It exports to Word and marks ready on the Deliverables register like any other document.
This is the feature the whole stream exists for. When a practitioner writes a counted measure into narrative prose, it is inserted as a token bound to the analysis that produced it, not typed as a digit. Change the underlying fact once and every figure in every document moves with it, or the pack visibly refuses to seal. The argument for it is not theoretical: in the reference pack, one corrected fact forced hand edits across six controlled documents at the same revision, and one paragraph of authored prose still carried the superseded numbers after the correction had reached every table and every finding in the same document, written by the practitioner who knew the correction intimately. That is the failure mode this removes.
A new system does not simply remove work. It moves it, reshapes it, and creates work that did not exist before. ErgoDelta places two or more states of the same system side by side, from current working through any interim stages to the target, and counts what actually moves between them. It compares states rather than documents: a step carries a link to the step it came from, so the correspondence holds even after both sides have been edited, and each difference is classified as unchanged, modified, new, removed or folded. Error modes are tracked across the change, so you can see which are removed, which are introduced, and which keep their score but lose the recovery path that used to catch them. It invents no analysis of its own; everything it displays already exists in the linked task and error analyses.
An assessment row previously had no link back to the tool document behind it, with the title as its only connection. That caused two visible defects: renaming a document created a duplicate row, and a comparison could not be certain it was comparing the right two things. Assessments now carry a durable link to their source document, which is the foundation the correspondence, the figure token and the analysis report all stand on.
The platform carried two overlapping end-of-phase report generators. They are consolidated into one, presented as the Human Factors Assurance Report, built on the stronger engine and carrying the lifecycle stage dimension and the sub-claim argument structure the retiring one introduced. The EHFA and HFIP wizards were uplifted against a real issued document set, with every new field optional, so an assessment that uses none of them still finalises and reads exactly as it did before. The wizard hero headers were replaced with the platform's own ribbon, so the assurance surfaces now look and behave like the rest of the application.
The Assurance Register could add standards, which populate clauses, but there was no way to author a project-level requirement: the Custom tab promised sections and clauses you could add later, then offered no way to add them. Requirements authoring closes that, so a project can carry its own requirements alongside the ones a standard brings.
Every assurance narrative seeds a Method section describing the analyses it cites, and those descriptions were uneven. A Method section that gives five sentences for one method and one for another reads unfinished in a document a client receives. Every card a report can cite now answers the same four questions in plain prose: what the method is and what question it answers, what it produces, what it assumes or requires, and its principal limitation, stated plainly.
A practitioner can place their own photographs and figures into report narrative, with captions, and they reach the preview, the Word document and the sealed package identically. Images are normalised on import, respecting EXIF orientation, and fitted to the page with the page's own orientation taken into account, so a portrait photograph on a landscape page behaves the way a person expects rather than the way a fixed height cap dictates. Images that have been imported but not yet placed are reported rather than silently forgotten.
References to figures, tables and sections update themselves when the document changes. Heading numbers are derived at render time and never stored, so they cannot drift out of step with the document they describe, and a section suppressed for one audience does not leave a hole in the sequence for the next. This closed a real defect found in the field: an issued plan whose contents page read 2, 3, 4, 6, 7. Where a heading is demoted, any inherited number is cleared, because in a compliance document a missing number is a far better failure than a wrong one.
The narrative editor gains spell checking, and paste that keeps its formatting instead of flattening it. A navigation pane shows the document's outline and scrolls to any heading, which also repaired a defect where a section led by a figure token lost its anchor and could not be scrolled to at all. A practitioner-placed page break lets an author decide where a page ends, and clipping is made visible rather than discovered after issue.
Report previews are now served rather than embedded whole, which removes a hard ceiling that a long report with images was already close to reaching. The same change lifted the ceiling on the .ergview build, so large deliverables build and preview reliably rather than degrading as the document grows.
Two surfaces were dropping authored prose on the way out: the sealed package, and the compiled closeout, the second of which described the loss in its own preamble as a deliberate gap. Both now carry the narrative the practitioner wrote, and where a section was genuinely left unfilled the practitioner is told before they send it rather than after.
A Role Register arrives, where a role is a position such as "Signaller" or "Still Operator" and never a person. Tasks and roles are then joined: a task can be held by several roles and a role can hold many tasks, with the reason recorded, edited from a panel on either register's rows. Difficulty and frequency are added to that allocation, which closes the DIF triple against AS 7470 clause 9.8(a)(i) since importance already existed as the screening band, and produces a training priority finding from it.
Every register page previously realised every row and rebuilt the whole list on each keystroke of a search. The Task Register stopped being interactive at roughly two hundred rows and was unusable near a thousand, and clients are building registers with thousands. The lists now virtualise, search is debounced, and deep links still highlight the right row despite it. Two registers whose rows were constructed in code rather than from a template were rewritten so they can virtualise at all.
Each project carries a visible-register set, so a project with no major accident hazards is not made to carry a MAH tab. The strip shows what the project actually uses and nothing else.
The overview told you what existed and what had happened. It did not tell you that anything was wrong. It has been rebuilt around a coverage matrix that shows where the registers disagree with each other or leave something unaddressed, with everything that was occupying space without earning it demoted.
The hazard and task registers reused an identifier after a deletion, so two entries in successive revisions of a client-visible register could both carry MAH-003. Both now issue from a persisted counter that never goes backwards. Projects already in the field are checked on open and any duplicate is reported rather than silently renumbered, because renumbering a register a client has already read is its own kind of damage.
Deleting a Site silently left six kinds of record pointing at something that no longer existed, with nothing to repair or report it. The consequence is now shown at the moment of deletion, and projects already carrying dangling references are swept and reported when they open.
A whole class of defect is closed here rather than a single instance. Twenty-nine services filtered what they saved by a project identifier they never stamped when the data was loaded, so rows created before the boundary existed could be dropped on save and block the save outright. Every one of them now stamps on load, a guard test over the whole estate keeps the class closed, and the same fix was carried through the read path. The HF Programme registers gained a project boundary at the same time, which matters because a compliance document should never be assembled from a source that does not know which project it is describing.
The five registers now import CSV through one path with one behaviour rather than five variations on the theme, and the Task Register and HF User Requirements Register were brought to header parity with the rest of the family.
The manikin stops being a fixed bind-pose mesh. Grab its hand, foot, pelvis, chest or head and drag; the figure follows through inverse kinematics, and the posture is saved on the document. Handles persist between interactions, joints can be locked to an axis, hands gain a rotate mode for wrist flexion and forearm rotation, and the gizmos operate in the joint's own local frame, so a downstream joint no longer drags in a strange plane after an upstream one has moved. It is the demonstration tool for the AS 7470:2024 clauses on climbability, foreseeable misuse, safe access and maintainer body positions. The output is a picture and a narrative, deliberately never a score.
A posed posture may be designated an assessed posture: a postulated posture evaluated as a design input in the same way a percentile is, which is a hypothesis about a person and never a claim about one. Every output carries that label, along with the posture's name, its origin and its authoring percentile, on every surface it appears on. The wall between this and measured assessment is absolute and stays absolute: nothing here touches the measured scoring path, and no output implies a real person was observed.
When a body part touches or collides with workstation geometry, that segment highlights red instead of the selection colour, and stays red while deselected for as long as the contact holds. It is contact detection and display, not contact solving: the pose is not pushed back, so what you see is the truth about the posture you posed rather than a solver's opinion of it. Testing is per vertex rather than sampled, light fittings are included because a pendant is a solid object, and contacts are recomputed at report build time rather than stored.
A fourth point of view puts the camera at the manikin's eye point and keeps it there. An overlay draws the visual field as a clear centre, a pastel amber ring and a pastel red ring, with a legend explaining what each means and what the standard says, and flat compasses showing neck pitch and yaw. Click and drag rotates the head within standard neck limits, and the head keeps that position when you return to the 3D view. The normal line of sight sits below screen centre because that is where MIL-STD-1472H puts it, and it stays there. A visual field overlay that does not state which standard it came from is decorative; one that does is defensible in a submission.
ErgoDesign computed a percentile-derived eye height and then never wrote it anywhere another component could read, so every consumer, including the ErgoGlare bridge and ErgoDesign's own report, read a constant instead. The computed eye point is now the value that is stored, carried and reported. A related defect was found and fixed with it: the selected percentile and work posture had no writer at all, so a saved design silently reopened with the user's selection lost. Documents produced before the fix cannot be recomputed, because the percentile they were authored at was never persisted, so they honestly display as not computed rather than being defaulted to a plausible guess.
Population data moves from hardcoded tables to a registry with stated provenance. The estimated legacy ladder is deleted, and the default becomes a genuine data entry: the anthropometric database MIL-STD-1472H itself designates, drawn from ANSUR II, with every percentile ladder reproduced from the source rather than transcribed. Three tables inside the application had been disagreeing with each other about the same measurement by as much as 125 mm; there is now one source, and it is named on the surfaces that use it. A Findings page consolidates what the design assessment produces, including per-posture eye reference points.
Motion capture no longer has to be live. An existing Xsens .mvn recording can be imported into ErgoSense as a take, played back, trimmed to a persisted range, and scored like any other. The import is fast and light: the longest recording in the acceptance corpus, nearly 327 MB and almost eleven minutes long, imports whole in under half a second, and a six-minute recording costs about three megabytes inside the project file. Every take carries its provenance, so a report can state that the posture came from an imported recording and name the file it came from. Frames are materialised on demand and decimation is peak preserving, so the extremes that drive a posture score are never the samples that get thrown away.
Recordings do not all run at the same rate, and the file format declares no rate anywhere. Recordings made at 100 Hz and 240 Hz were being replayed at "1x" in slow motion against an assumed 60 Hz, and their durations read wrong on screen. The rate is now measured from the recording's own timestamps when the file is opened, decimation is derived from it, and durations are truthful. A recording outside a credible band is refused rather than given a default.
The on-screen figure carried a permanent forward hunch and a wrist that did not follow pronation, both from how the skeleton was retargeted rather than from the capture data. The hunch was roughly nineteen degrees of thoracic pitch and about fifty millimetres of forward shoulder shift, on every take. Both are corrected. Both are render-only changes: no score, no stored data and no derivation moved, and live capture and imported replay share the one path, so the fix covers both.
A dedicated stream re-derived RULA and REBA against the original published papers, read at high resolution from the scanned tables rather than taken from any secondary source. The through-line is worth stating plainly, because it is the reason the work was needed: every defect it found had survived because a check compared two copies of our own estate against each other instead of reaching the paper. A guide written from the code cannot catch the code. Sample assessments that plant their scores as literals cannot catch a scorer. Every assertion in this stream now tests against the paper's own rows.
Both methods had their neck scales corrected to their papers. Four cells of REBA's Table C were wrong and are fixed. REBA's load and force input becomes the published three weight bands plus a shock flag, with three duplicate mappings deleted and four separate pickers unified behind one. RULA's force scale is restored to the published four-row scale, its component maxima corrected so a leg score of 2 out of a real maximum of 2 no longer reads "Low", and the force computation is now performed once, by the calculator, rather than in three places that disagreed and made the report's own tables fail to add up.
In ErgoLens, per-frame RULA and REBA scoring were discarding the analyst's own selections at the scorer even though the tool was faithfully persisting them. Both are fixed. Eight invented posture allowances with no basis in either paper were removed from the scoring path, REBA's trunk extension and compound modifiers were corrected, and RULA was deliberately left alone where its paper genuinely differs from REBA's, rather than being made to match for the sake of consistency.
RULA's wrist twist control was writing to a property the scorer did not read. It now points at the property the calculation uses, the orphaned field is retired in place with a migration for existing documents, and the guard that should have caught it was rewritten so the property name is data rather than a literal that can silently go stale.
A missing value that scores well is a more dangerous defect than a wrong value, because nothing about it looks wrong. This release establishes a platform-wide convention and writes it down: an aggregate with no populated inputs refuses to produce a result rather than scoring one, a report gate tests whether a result is current rather than merely non-null, and whether zero is meaningful on a given scale is decided per instrument rather than assumed. Zero barriers on a bowtie, zero workload ratings and a computed value of 0.00 are three different questions and are treated as three different questions.
SUS was substituting a neutral 3 for an unanswered item, which produces a plausible score from an incomplete questionnaire. SHERPA carried a sentinel value that read as a real rating on some surfaces. Both are fixed on every path, classic and extended, with new tests behind each.
Two independent constants were found printing as percentile-specific values in a single tool during a single unrelated audit. That prompted one question, asked across the entire platform: does any surface state or imply that a value was computed when it is actually a fixed default, a field initialiser, or a lookup that never matches? Two systematic sweeps were run and ranked. They were run with planted findings, so a sweep that failed to find what was deliberately put in front of it had its clean bill discarded and its territory re-swept, because an unmeasured silence is not evidence of absence. Columns that described nothing, because no control had ever written to them, were removed rather than labelled.
Settings gains a User Profile block supplying the identity that appears at the top of every issued deliverable, with no operating-system default. A sealed document should say who issued it because a person told it, not because it read a Windows account name.
The theme set is now Charlie and Classic. The third light theme is retired, a saved preference for it is remapped on next launch, and the machinery that existed only because two opposite-polarity light themes shared one slot can be collapsed. The internal style showcase became the single living style guide, covering every control type the application uses on every surface it uses them on, so no default-styled element can hide anywhere in the product.
Machine-facing values in the project file were being written using whatever culture the machine happened to be set to. Dates, identifiers, keys and comparisons are now pinned, with a fixture that proves a project saved on one locale opens correctly on another, and enumerated values parse strictly rather than accepting whatever they are handed.
The Applicability tab rebuilt the whole page on every interaction and realised every requirement in the register. The list is virtualised, standards collapse by default, clause expanders load lazily, and the page now opens in a few hundred milliseconds and stays responsive on a large register.
The remaining PDF template export is retired. Every report in the platform now goes out through one route: the block renderer that drives the preview, the Word document and the sealed package, so those three can no longer disagree about what a report contains.
Every change in this release is additive or migrated. Projects saved by 1.5 and earlier open in 1.6 and keep their data. Where a record needed a new field, a migration supplies it on open and the project is upgraded when you next save. Where a value cannot honestly be reconstructed, such as an eye point authored before the percentile was persisted, the platform says so rather than inventing a plausible number.
Nothing in the review round trip can alter an issued .ergview. A review always produces a new file, and the sealed region of the original is never rewritten. Re-exporting the same assessment produces the same bytes, which is what makes a digest a meaningful piece of evidence rather than a formality.
Projects carrying rows without a project stamp, duplicate register identifiers, or references to a deleted site are repaired or reported when they open, at an informational severity rather than as a warning dialog on every launch. The project tells you what it found once, and the fix persists the next time you save.