← Release Notes / Version 1.6.1.0
Version 1.6.1.0
4 September 2026 Direction Change

This is the most consequential release we have published, and almost none of it is a new feature. The method set is closed at fifty-three tools. From here the engineering effort goes into proving what is already in the platform rather than adding to it, through the dossier programme: every method read back against the paper or the standard it comes from, line by line, with every departure written down and every correction built. Nine methods were re-read this cycle. Most of what that reading found was agreement between the tool and its source, and where it found a departure the departure was closed: HE-HAZOP gained two published steps the worksheet had no field for, SART's two in-project surfaces were reconciled onto a single figure, and a compliance score computed over a register with nothing applicable in it now reads as absent rather than as zero. Every one of those was found by our own reading rather than in the field, which is what a programme like this is for. Bug fixes and user requests keep their place at the front of the queue, and they always will. Alongside that, ErgoSphere Viewer has entered its final stage before public release and is now with a small invited group of users: every one of the fifty-three tools draws its own findings board inside the deliverable, the navigation was rebuilt around the three questions a recipient actually arrives with, a printed figure on the report sheet opens live where it sits, and the HTA reaches the reader as a tree they can search, click and interrogate rather than as fourteen pages of numbered list. ErgoGlare completes its move onto the shared editor shell across twenty-six work packages, indoors and out, and ErgoDesign gains an animation timeline, an X-ray view of the figure through the workstation, and dimensions that live in the scene rather than on one pane's overlay. Your existing projects open unchanged.

A Change of Direction
  • Fifty-Three Tools, and No More New Ones

    Since launch the platform has grown by adding methods: forty-three at 1.4, fifty-two at 1.5, then ErgoDelta alongside the deliverable format and the free reader at 1.6. That phase is over. The catalogue is closed at fifty-three, the thirty-seven published methods and the sixteen ErgoSphere Originals, and the release that would once have carried three new tools carries none. The reason is short enough to say in a sentence: a method with a user interface and no evidence behind it is an opinion that looks like an answer, and a client who signs a human factors report is entitled to more than that. Everything that would have gone into tool fifty-four goes into proving tools one to fifty-three instead.

  • What Replaces It: The Dossier ProgrammeFocus

    Each method in the platform is read back against its own published source, clause by clause and table by table, by someone holding the paper open beside the running tool. Where the implementation matches the source it is recorded as matching, and where it departs the departure is written down with its reason, whether that is a deliberate design choice or a defect to be fixed. The output is a verification and validation dossier per method, released to clients on request under a non-disclosure agreement. That programme is now the roadmap. How the verification work is run →

  • Bug Fixes and User Requests Still Come First

    Nothing about the change of focus pushes a defect or a request to the back of the queue. A crash reported by a user is still fixed before anything else in the day, and a request from someone using the platform in anger still outranks the programme. Several of the fixes in this release started as exactly that: a note made while walking the running application, raised as its own piece of work rather than folded into something else, so it can be pointed at afterwards. We would rather say this plainly than imply otherwise: ErgoSphere is under active development, the walk-throughs and the dossier reads are still turning up things worth fixing, and both will keep doing so. That is the point of running them.

The Dossier Programme: Methods Corrected Against Their Sources
  • Nine Methods Read, and What the Reading Found

    The corrections below are the exceptions rather than the summary. Nine methods were read back against their sources this cycle, most of each one matched what its source asks for, and the departures that did turn up are listed here individually because a programme that only published its clean results would not be worth running. Two of them change a figure, and both are narrow and stated: the compliance score moves only where a register had no applicable clauses in it, which is an unassessed register rather than a poor one, and SART's assessment-register figure moves onto the banded value the tool's own HTA nodes were already carrying. Existing documents are deliberately not re-flagged, because blanking a result a client already holds on the strength of an assumption is the larger harm, and the migration says so in as many words. Every change carries the source passage that decided it, so any figure the platform has ever published can be explained rather than only defended.

  • HE-HAZOP: Two of the Method's Eight Steps Had Nowhere to Put Their Answer

    The published method asks the team to judge the potential for human recovery, which is step five of eight, and to classify each failure as a physical error, a mistake or a violation, which is step three. The worksheet could record neither, and both feed step seven's choice of remedy, so the tool asked practitioners for a judgement it had no field to keep. Both are now fields on the worksheet row, carried through the editor, the report and the guide. The recovery judgement was the single change the method walk named as most strengthening the tool rather than the paperwork.

  • SART: Two Surfaces of One Project Computed the Figure Differently

    Inside a project file, a SART assessment reached the assessment register through one formula and reached an HTA node and the cross-tool dialogue through another, so the same session could read 45 on one screen and 65 on another. Neither surface was wrong about its own arithmetic. They were written at different times and had never been reconciled, which is the kind of thing a line-by-line read exists to catch. The banded figure wins, because it is the one with a stated rationale, a test class and a monotonicity guard behind it, and because it is the shape the rest of the platform uses for an ordinal result. The retired formula also mapped the best possible score to zero, and on a risk column a plausible zero is the hardest kind of wrong number to notice. That is why the platform now holds absent and zero apart at the type level, so no screen can render one as the other.

  • A Default Is Not a Rating

    SART's dimension average treated an untouched slider as a rating, so a session left partly rated still produced a total. Unanswered items are now genuinely unanswered: the slider rests off scale on a dedicated detent rather than at the midpoint, so a practitioner can see at a glance what has and has not been rated, and a total computed over an incomplete set says so rather than quietly averaging the gap away.

  • ATWIT: An Unanswered Prompt Is Now a Recorded Choice

    Stein's 1985 trial recorded missed responses as maximum workload responses, on printed page 22, and it says so in the past tense about that study rather than as a rule of the technique. Reading the sentence rather than our own transcription of it changed the answer. The practice is now available as an explicit per-session setting, off by default so no existing assessment moves, cited to the page it came from, and every figure derived from the session states which basis produced it. The number is allowed, and it says what it is.

  • Social Network Analysis: Key Agents on Centrality as Well as Status

    Houghton and colleagues apply their key-agent rule to both of their metrics and take their most interesting observations from comparing the two, including a network read as maladaptive because an agent had high centrality without high sociometric status. ErgoSphere named key agents on sociometric status alone, so that comparison could not be made. Key agents are now named on centrality as well, presented as one card with three groups, and the platform's own broker finding is kept and labelled plainly as ours rather than as the source's.

  • ErgoRadar: Criteria Per Area, a Combined Conclusion, and Clustered Conditions

    Three places where the published assessment cycle asks the assessor to write something down and the tool had nowhere to put it. Acceptance criteria are specific to each key performance area, so they are now recorded per area instead of once per stage. Each cycle takes a combined conclusion of one of the three published types, and where the design passes it carries the requirements and assurance levels for the next level. Varying conditions become a body of their own that can be clustered, because a cluster may play a role in more than one scenario.

  • Compliance: A Score Stated Over No Input at All

    A compliance register with no applicable clauses in it returned zero per cent. Zero is on the scale and is its worst value, so a register that had not been assessed yet was indistinguishable from one that had scored badly. The score is now genuinely absent when there is nothing to score, and every surface refuses in its own idiom rather than printing a number. Putting the question to the compiler found two surfaces the search had missed, the per-standard column in the Excel breakdown and the same column in the Word compliance matrix, which is the argument for making absence a type rather than a convention.

  • The AS 7470 Register, Read Back Line by Line

    The register's own inclusion rule says that a permissive clause qualifies other clauses, is never assessed, and must be excluded from the score's denominator. That last arm had not been implemented, so permissive clauses were counted in the denominator and moved the percentage with them. It is implemented now, and with it a set of transcription repairs found by reading the standard's sentences individually rather than trusting an earlier extract: two hundred and twelve source sentences carrying a normative modal, checked one at a time, taking the register from 232 clauses to 249 with every added row verbatim.

  • Two Requirement Families the Register Had Never Carried

    The standard's six phase-deliverable tables and its obligations on the HF analysis report had no rows at all, and both needed somewhere in the product to live rather than only a row in a file. They arrive with the first shipped lifecycle template that seeds a project's deliverables directly from the standard, closing the seam where a phase's required outputs had to be typed in by hand and nothing checked that none were missed. Acceptance criteria now reach the exported compliance matrix.

  • The Compliance Dossier Was Scoped Too Narrowly, So It Was Re-scoped

    The first compliance dossier asked one question thoroughly: does ErgoSphere implement AS 7470 faithfully. But the capability is not AS 7470. It is a generic standards-compliance engine plus a human factors assurance process, and the clause set is data: seven standards ship and a user can author their own. Verifying one standard is worth doing and was done thoroughly, but on its own it does not establish the engine or the process that every other standard runs through. The dossier now takes those two as its subject, the register's granularity is normalised to one row per source item, and the re-extraction that followed caught and corrected nine rows that had matched the wrong source passage, which is the wider read earning its place immediately.

ErgoSphere Viewer
  • In Final Testing, With a Small Group of UsersPre-release

    The free companion reader is in its last stage before public release and is currently with a small invited test group rather than on general download. It is the piece of the platform a client's own client actually opens, so it is being walked screen by screen against the application it came from before it goes out. Everything in this section is in the hands of those testers now, and their notes are shaping the final cut. More about the Viewer →

  • Every Tool Now Draws Its Own Findings Board Inside the Deliverable

    A recipient opening an assessment lands on the same findings view the practitioner sees in the application: the tool's own tiles, dials, charts and validation cards, laid out the way that tool lays them out rather than reduced to a generic summary. It began as two pilots and finished as the whole catalogue, cognitive, usability, physical, reliability and specialised, then the awkward remainder one at a time until the pending list was empty. Fifty-three of fifty-three tools, with a parity test that fails if a tool ever ships without one.

  • The Navigation Became the Three Questions People Arrive With

    Three people open the same file with three questions. The manager asks what you found, who owns it, and whether the file can be trusted. The engineer asks to be shown the assessment and let into the model. The reviewer asks what it was based on, what was left out, and where comments go. The navigation is now those three doors: This Deliverable holds Overview, Issues, Assessments and Programme; Behind It holds Evidence and Sign-off; Your Record holds Review. The registers stopped appearing twice under two different headings, and a screen called Deliverable inside a heading called This Deliverable stopped reading as a folder.

  • A Printed Figure on the Report Sheet Opens Live, Where It Sits

    Click a figure on the page and it comes alive in an overlay over the sheet it belongs to: the graph pans and zooms, the chart reads against its numbers, the scene turns. The separate Results tab is retired, because it was laying the same set of figures out a third time beside the findings board and the report sheet. The report the recipient was actually sent is now the thing that comes alive, rather than a fourth rendering of it somewhere else in the application.

  • A Live Scene in the Deliverable, and a Model Button That Says It Is There

    An ErgoDesign workstation now travels inside the package as a real scene rather than as pictures of one, and opens on its own canvas: orbit it, look through the operator's eye, and switch between cones, volumes, bands and contours on a ribbon that mirrors the application's own. The Model button appears only on documents that carry a scene, so its presence is itself a signal, and the findings board grows a model card with thumbnails of the baked views. A test fails if a scene-bearing document ever ships without that card.

  • The HTA Arrives as a Tree You Can Live In

    Hierarchical task analyses are notoriously hard to read on A4, and the HTA is the platform's backbone, so it took more effort than anything else in this section. The reader opens on the tree itself: a searchable hierarchy rail down the left listing every real node with its number, goal and risk pill, the live diagram in the centre with tap to select and drag to see what sits behind, icons and risk colours on a toggle, and a detail panel on the right carrying the node's plan, description, performer, preconditions, task types, risk indices, human error probability and linked assessments. Nothing recalculates and nothing is saved; the deliverable is read, not edited.

  • Read Reports as Accessible Text

    The Viewer has always carried a second renderer that draws a report as native text rather than as baked pages, for screen readers and as the fallback when a package arrives from a newer version of ErgoSphere. It used to sit as a button beside the page view, which made one report look like two. It is now a preference in Settings, where a reader who needs it turns it on once and every report follows.

  • Recent Packages Are Cards

    Recently opened packages were a list of blue links on the home screen. They are now style cards, the way recent projects appear in the application itself, so a reviewer working through several deliverables can pick the right one by sight rather than by reading filenames.

  • Seven Golden Cases, Proved Side by Side

    Seven tools were chosen for enough variation that the rest fall in behind them: HTA, RULA, NASA-TLX, ErgoDesign, ErgoSense, ErgoLoop and SCTA. The bar is a paired screenshot, the tool's findings page in the application beside the same assessment's findings page in the Viewer, and the two have to look almost the same bar the model card. Placement counts, not just presence, because elements that are all there but badly arranged still read as a different product. Every remaining tool goes through the same comparison.

ErgoDesign
  • An Animation Timeline and TransportNew

    Objects and the figure can now be animated along a timeline that follows the grammar of a professional 3D package rather than inventing its own: a scrubber with a draggable playhead across the foot of the viewport, transport controls, Auto Key for recording as you move and Set Key for deliberate placement. The whole stream was walked by hand across three rounds before it was accepted, and a report exported with the playhead parked mid-timeline captures every figure at the design as it stands at that moment.

  • X-Ray: Read the Figure Through the Workstation

    A posture disappears behind the desk it is reaching over, which is exactly the moment you most want to see it. X-Ray draws the hidden part of the figure through the geometry in front of it, tinting only the fragments that are genuinely occluded rather than washing the whole body. It is a deliberate exception to the tool's standing rule that geometry occluding geometry is the truth being drawn, so it is coloured red while it is on, it applies to the figure alone, and it stops dead at the viewport: nothing it does reaches a report, an export or a capture.

  • Clicking a Camera, a Light or an Axes Frame Now Selects It

    Those three are drawn as line geometry, which carries no triangles, so the hit test had nothing to hit. The click resolved nothing, fell through to the deselect at the end of the handler, and threw away whatever the analyst already had selected. From the outside that reads as the click doing nothing, which understates it. They are now picked by their projected footprint, through the same matrix the engine renders them with and the same projector the selection marquee uses, without putting invisible proxy geometry into a scene that five other things have to walk.

  • Dimensions Live in the Scene, One Set Per Camera

    Item extents, height above floor and the gap dimensions between items used to be drawn on a two-dimensional overlay owned by a single pane, so they existed for one view and vanished in the others. They are now scene geometry with bitmap text, drawn by whichever camera is looking: the active pane, the three passive panes and the report capture. Text keeps a constant world size, growing and shrinking with the zoom as annotation on a drawing does. The perspective pane is deliberately given none, because a dimension in perspective is a number that is true at one depth only.

  • The Axes Box Gets Its Own Controls, and Draws Correctly Under Every View

    Two causes, and only one of them was ours. The underlying renderer draws a partly open box by default, which is right for the graph it ships for and wrong for a measuring frame placed in a workstation, so the default is inverted where the meaning is known and the open form is one checkbox away. The second was ours: the axes were rendering one item transform behind the frame they belong to, so a correct number sat beside a wrong picture until the next drag repaired it. Proving that needed a test that builds a real scene on a windowless graphics device and runs a frame, which the code base had never had and which any future rendering-order defect can now use as an oracle.

  • The Marquee and the Group Gizmo

    Box selection and the gizmo that appears over a multi-item selection were both fixed and walked. Together with the selection work above, the practical effect is that everything in the scene, including the things that are not solid objects, now behaves the same way when you click it or drag a box across it.

ErgoGlare
  • Both Editors Move Onto the Shared Shell

    Twenty-six work packages took the outdoor and indoor glare editors onto the same shell ErgoDesign uses, so an analyst moving between the two tools is not learning a second application. One right-hand panel with two tiers of tabs and a status bar, a captioned ribbon with header tabs, and the same words for the same things in both places. Where a behaviour had to differ indoors, it differs because the room demanded it rather than because the two editors were built at different times.

  • The Sun Time Bar

    The animation band's place at the foot of the viewport is taken by a sun time bar: scrub the day and the sky, the shadows and the glare geometry follow, with sunrise and sunset marked on the ruler and a date cell for the day being studied. Play runs the day through, and scrubbing by hand stops a running animation. A polar day or night, where there is no sunrise for the solver to find, is left unmarked rather than given a fabricated time.

  • Navigation Cluster, Compass Cube, Quad View and the Jog Gizmo

    The navigation cluster arrives in the dock with pan, zoom, field of view, region zoom, zoom all and extents. A live rotation cube sits as a compass with faces reading north, east, south, west, top and bottom, derived from where the camera actually is rather than from a stored guess. The quad view splits the viewport into four live cells. The jog gizmo, extracted out of ErgoDesign into a shared component so the two tools cannot drift apart, brings precise move and rotate with a per-view ring plan.

  • Wire, Edges, Solid, All

    The shading pill from ErgoDesign now sits in both glare editors, including inside the quad view's individual panes. Edges are built for the room shell as units and for obstruction boxes after their faces, so an interior in Edges reads as a room rather than as a mesh.

  • Findings In Page, and a Black Result That Names Its Cause

    Results moved into the page behind a Findings tab and now run on entry, so there is no stale-results warning to dismiss and no separate run button to remember. Two honesty fixes came with it: a black fisheye now states why it is black instead of leaving the analyst to guess, and the tool refuses to run a moment when the sun is below the horizon rather than producing an empty result that looks like a finding. The annual run keeps its own place and its progress bar, and never starts by itself.

  • Multi-Selection, Link and Sets

    Several items can be selected at once, by clicking with a modifier or by dragging a box, then linked or grouped into named sets. Deleting many items asks once rather than once per item, and a locked item refuses a drag rather than starting one and leaving a stale transform behind it.

  • The Interior Editor Catches Up

    The indoor editor now opens on the 3D view rather than a flat plan, and the plan itself is the engine's own orthographic projection everywhere it appears, including as a cell in the interior quad, so the plan and the model can no longer disagree. Left click selects and left drag box-selects, the observer is a selectable item like anything else, and clicking a furniture row in the explorer highlights it in the 3D view. The compass cube, the time bar, the navigation cluster, the shading pill and the jog all arrived indoors as well.

Fixes and User Requests
  • The Sky Toggle Crash in ErgoGlare

    Hovering the sun ruler could take the application down. It was found in an internal walk-through of the running application and fixed the same day, before it reached anyone. The readout was a tooltip built in code and forced open, which the underlying framework refuses unless it owns the tooltip itself. It is now drawn as a small panel inside the time bar, which cannot throw, and the rule was written down so the next control does not repeat it.

  • The Flicker When Leaving a Quad Cell

    Clicking into one cell of a quad view left the other cells blank for a moment. Measuring it rather than guessing turned the fix around: the gap was 105 to 140 milliseconds, six to eight frames, and two thirds of it passed before the first replacement pane was even created. So the fix was to stop rebuilding all three passive panes when only one cell actually changes role, rather than the redraw work it looked like it needed.

  • The Orbit Tool Was Drawing a Selection Box

    In both glare editors, dragging with the orbit tool active started a selection marquee instead of turning the camera. Plain left drag now belongs to the camera whenever orbit is the active tool. A defect in the test instruments came up with it, and it is worth naming: a helper that reads a method's body returned the wrong block for one style of method, so a guard had been asserting against text from somewhere else. The helper was corrected and every suite carrying it was swept for the same pattern. Checking the checkers is part of the same programme.

  • A Deliverable That Had Pictures and No Scene

    The first test packages exported with a 3D scene arrived carrying the figures but not the model. The scene exporter was throwing on any material with a specular or emissive colour, which is every workstation item the tool builds, and the export completed without reporting it. Fixed during Viewer development, on QA packages: live scenes are new in this cycle, so no deliverable that has ever been issued could carry one. The export path now fails loudly if it cannot write what it was asked to write.

  • The Figure Looks the Same in the Viewer as in the Tool

    The Viewer and ErgoDesign were lighting the scene with two different rigs, so the manikin read brighter and whiter in the deliverable than it did in the tool that posed it. The Viewer now uses the application's own lighting, so what the recipient sees matches what the practitioner set up. Found and fixed in pre-release testing.

  • Report Figures That Left the Figure Out

    The side and top views captured for a report hid the manikin by design, on the reasoning that the figure obscured the workstation. Seeing the two side by side reversed the decision: the manikin is the one thing giving the workstation its scale, so it now appears in both. A figure captioned as an interactive workstation view was also only ever a side elevation, and is now the three-dimensional view its caption described.

Compatibility & Data Safety
  • Your Existing Work Opens Unchanged

    Every change in this release is additive or migrated. Projects saved by 1.6 and earlier open in 1.6.1 and keep their data. The new judgement fields on the HE-HAZOP worksheet, the ATWIT session basis and the SART rating state all arrive empty on an existing document rather than being filled with a guess, and the project is upgraded when you next save it.

  • Where a Number Moved, It Moved for a Reason That Is Written Down

    Two figures move in this release, and only under conditions worth stating precisely. The SART correction settles the assessment register onto the banded figure the tool's own HTA nodes were already carrying, because the two could not both be right, and the banded one is the one with a written rationale and its own tests behind it. The compliance score changes only where a register had nothing applicable in it, which is an unassessed register rather than a poorly scoring one. Nothing else moves. Both changes are recorded in the method's dossier with the source passage that decided them, so a practitioner who is asked why a figure in an older report differs from the same assessment reopened today has the answer in writing rather than having to reconstruct it.

  • Issued Deliverables Stay Byte Identical

    Nothing in the Viewer work touches an issued package. A review still produces a new file, the sealed region of the original is never rewritten, and re-exporting the same assessment produces the same bytes.