← Release Notes / Version 1.6.2.0
Version 1.6.2.0
18 September 2026 Latest Fifty-Fourth Tool

Two weeks ago we wrote that the catalogue was closed at fifty-three tools. This release carries a fifty-fourth, and the first section below explains why that is not a change of mind. ErgoCulture was already built and held back; the requests for it arrived, so it is released. It is a safety culture maturity assessment for the people who answer to a board or a regulator, and it sits one level above every other tool in the platform: eleven dimensions, five levels, and a rule that a rating without evidence behind it is stored but never counted. It ships as a Preview. The dossier programme read nine more methods back against their sources this cycle, the HSE manual handling trio, the NIOSH lifting equation, micro-FMEA and the three human reliability methods, and every finding the reads raised is now built or declared. The programme also produced its first software assurance documents, which look at the platform around the methods, starting with how a project is opened, saved and kept apart from the last one. ErgoSphere Viewer gains an installer, a file type, its licence and privacy documents, a first-run gate, and twelve tools whose findings pages now render as the application draws them. The HTA can now be played: timed steps, a transport, lanes by performer and a live observation walk. ErgoDesign answers a thirteen-item list from an experienced user of digital human modelling tools: three selectable figures, individual finger control, a figure that stops at its own surfaces, and measurements that stay. Your existing projects open unchanged, and where a result recomputes, the reason is written down.

A Fifty-Fourth Tool, and Why the Catalogue Is Still Closed
  • Built Before the Closure, Released Because It Was Asked For

    The last release notes said the method set was closed at fifty-three tools and that the engineering effort would go into proving them. That still stands: no method gets added because a catalogue looks better with one more entry in it. ErgoCulture was not added. It had been built alongside the other Originals and held back from release while its content was read against its sources, which is why it was not counted among the fifty-three. Then the requests arrived. After a live demonstration, an executive audience asked a question no released tool could answer, where is our safety culture now, on what evidence, and what do we do next, and the tool that answers it was already sitting finished. Releasing it is not the same as writing a new one. It is also a different shape of thing from the methods: every method in the catalogue works on something smaller than the organisation, a task, a posture, an error mode, while this one works on the organisation itself, and it sits in the Direction group beside ErgoCompass and ErgoRadar, which reason about the assessment programme rather than about a workstation. The catalogue is now fifty-four: thirty-seven published methods and seventeen ErgoSphere Originals.

  • ErgoCulture: Safety Culture Maturity, Rated on EvidenceNewPreview

    A trained assessor rates the organisation on eleven dimensions, each on a five-rung ladder from Pathological through Reactive, Calculative and Proactive to Generative. The dimensions are leadership commitment and visibility, information flow and reporting, just culture and response to failure, learning and improvement, risk awareness and hazard management, worker participation and voice, competence, training and resourcing, the balance of production and safety, contractor and interface management, procedures and work as done, and cohesion across teams and levels. Every cell of the ladder carries a descriptor written in observable terms, what you would see, hear and find, rather than in judgement terms. The tabs are Setup, Assess, Playbook, Plan and Findings, and the Findings board draws ten cards, among them a hexagonal mosaic of the eleven dimensions, a profile radar with current, target and previous stage, a trajectory across re-assessments and a signals card for survey perception by group. It is an assessor-rated instrument, not a survey platform: there is no respondent portal and no employee response data is held.

  • A Rating Without Evidence Is Stored, and Never Counted

    The tool refuses to let a maturity level stand on assertion. A rating at Proactive or Generative needs at least two distinct evidence types with at least one of them strong; Calculative needs a document or a data item; the lower rungs need at least one item of any kind. Evidence is a document, an interview recorded by role and count rather than by name, an observation, or data, which can be a linked ErgoSphere assessment or an imported survey or metrics file. Confidence is derived from the count, diversity and strength of what is attached, never typed in. A rating with nothing behind it is kept, shown struck through on the ladder and hollow on the mosaic, and listed under Unverified ratings and gaps with the sentence naming what would verify it. The headline figure follows a floor rule: it is the lower of the overall level and the lowest verified level among the three foundations, leadership, information flow and just culture, because an organisation with broken reporting is not proactive regardless of how good its training is. Nothing defaults to a middle level, and the headline reads not assessed until all three foundations are verified.

  • Stages, Data Intake, Playbooks and a Plan

    One document holds a series of stages. Re-assess opens a new stage with targets set from the previous levels and evidence cleared, earlier stages become read-only, and the radar and trajectory read across them. Import CSV on the Setup tab takes a survey file or a metrics file and turns it into data evidence per dimension, with strength graded by sample size and date and with cohort gaps kept as signals for the assessor rather than as ratings. Every rating carries the date it was made, and one with newer evidence behind it, or older than twelve months, is flagged for review; nothing changes a level on its own. The Playbook tab holds a transition card for every dimension and every step up the ladder, what good looks like, three to five sequenced actions, the failure mode and a lead indicator, and a dimension verified at the top two rungs is named a strength with its own sustain entry. Any action can be adopted into the Plan with an owner, a due date and a status, and the plan survives re-assessment. The report is a DOCX whose first section is an executive one-pager, the free Viewer draws the same ten cards from the exported package, and the tool is enrolled in the compiled close-out.

  • What It Draws On

    The level names and their characteristics come from Westrum's typology of organisational information flow as extended to five rungs by Parker, Lawrie and Hudson. The dimensions are our own synthesis of Reason, Flin and colleagues, Guldenmund and the regulators' models, including the Office of Rail and Road's RM3, the IAEA's INSAG-4 and the HSE's HSG65, with AS 7470:2024 and the Rail Safety National Law cited where they bear. Seventeen sources are cited in all, and the report's scope and method section names them and states the standing of each citation, so a reader knows exactly what a level rests on. The descriptor and playbook text is original prose, checked for overlap against every published safety culture instrument we hold. It ships as a Preview, as ErgoCompass and ErgoRadar did, and the content is English only.

The Dossier Programme: Nine Methods Read Back, and the First Software Assurance Documents
  • Nine Tools Read Against Their Sources, Every Finding Built or Declared

    This cycle's reads were the HSE manual handling trio of ART, MAC and RAPP, the NIOSH lifting equation, micro-FMEA, and the three human reliability methods HEART, THERP and SLIM. The findings were grouped by shape rather than by tool, because methods written at the same time tend to share the same habits, and each group was then strengthened once across every affected tool: a result that is not complete never prints as if it were, a published table lives in exactly one place behind the guarded calculator, an unrated input reads as unrated rather than as nought, and each method guide was rewritten to the method as shipped, because the report drafts its Method and References sections from the guide. Every change carries the source passage that decided it, from the HSE's INDG 438 and INDG 478, NIOSH publication 94-110, ISO/TR 24971, Williams and Bell's HEART+ paper and the two NUREG reports behind THERP and SLIM. Where a departure from the source is deliberate it is declared in the dossier with its reason. The items below are the ones a practitioner will notice.

  • Snook: Initial and Sustained Force, in the Units the Tables Use

    The push and pull editor now takes two forces, initial and sustained, both in kilograms-force to match the published tables, each blank until typed and refused if absent, so a push or pull result always rests on the force the analyst entered. The retired forty per cent one-handed reduction, which appears in no published Snook table, is gone from every report, and the one corrected table cell is declared on the results strip and in the DOCX. Lifting, lowering and carrying are unchanged.

  • HEART and THERP: One Probability Ladder, and No Number for an Incomplete Result

    An incomplete HEART result now reads Incomplete on the editor, in the DOCX and in the project list, prints no probability, names the conditions still unresolved, and is not offered to the HTA until it is complete. The probability ladders that had grown up separately across the two tools' screens and reports are now one, captioned as ErgoSphere's practitioner convention because neither NUREG/CR-1278 nor the HEART papers publish one. THERP requires a tree to be complete before it can be finalised. HEART's guide was rewritten to HEART+ with its nine task types, and its references and on-screen citations now name Williams (2015) and Williams and Bell (2023). SLIM gained a warning when the calibration fit is poor, at a threshold declared as our own, and a saved SLIM analysis now reads its stored result on open rather than recomputing it.

  • ART, MAC and RAPP: One Classifier, Both Arms, and a Row Per Assessment

    In MAC, the load-and-frequency chart and the score sheet now share one Factor A classifier, so the band on the chart is the band on the sheet, and a selection made in one mode no longer carries into another. Team assessments take a weight box, the environmental card reads not rated until it is ticked, and the DOCX recomputes on export rather than printing a stored figure. In ART, a two-arm assessment keeps both arms intact when one factor is edited, intermediate scores are available as INDG 438 permits, and the force grid carries the five unscored cells that page 5 of that document describes. In RAPP, two assessments with the same title each keep their own register row. Both tools' load tables are now proven identical to the HSE publications by test, and the guides cite the verified revisions.

  • NIOSH: A Refused Lift Reads as Refused, and an Absent Index Has No Needle

    A lift the equation refuses now reads refused rather than draft. The input sliders were widened past the published limits so that the calculator's own refusal is what the user sees rather than a clamp, the unit toggle recomputes, the report prints one limit for one lift, and the guide was brought into line with the publication. On the ErgoLens and ErgoSense review and live surfaces, an absent lifting index now draws no needle at all: the dial face still draws, and the readout carries the method's own words, No limit where the equation's answer is zero, in red, and Not applicable where the method declined, in neutral. The dial's mapping is now linear against section 1.4.3 of publication 94-110, so a populated needle sits exactly where the index puts it.

  • Micro-FMEA Takes ISO/TR 24971's Severity Names

    The severity scale names are now those of ISO/TR 24971:2020 Table 4, Catastrophic or Fatal, Critical, Serious or Major, Minor and Negligible, the risk priority thresholds must stay ordered, and a report exports only once the worksheet has rows. The filed risk density figure is declared as ErgoSphere's own, and IEC 60812:2018 and ISO/TR 24971:2020 join the references.

  • One Risk Scale on the HTA Link, and One Ladder for the Node

    When an assessment is linked to an HTA node it publishes a risk index the node carries. Twenty-one methods link, and they had each been converting their own result to the node's scale in their own way. There is now one genuine 0 to 100 scale on the link, the per-method converters are retired, and the project schema migrates on load: link scores for REBA, RULA, NIOSH and ART are recovered as stored, and those for MAC, RAPP and ErgoLens are set to absent until the assessment is next saved, each noted on the load report. The node itself now bands through a single ladder, Unacceptable, Tolerable and Acceptable at 70 and 40, with Not assessed as a fourth state that is never a zero, and the dossier records that no HTA source publishes a risk quantity, so those two numbers are ours. A CSV-imported tree bands the same way. Delivered Viewer packages render exactly as before, verified against eight real deliverables.

  • SHERPA, SCTA, REBA and SPAR-H: The Second Triage

    A second triage covered the findings from those four methods, and each was re-read against the shipped code before anything was built, which is now the standing order. Among what landed: SCTA criticality reads Not rated until the analyst rates it; the REBA neck chip uses the published maximum of three; a SHERPA HTA node's risk reading now follows the portfolio risk it links to; an HTA link created before assessment carries no score rather than a zero; and the SHERPA report regained its two-mode passage from the guide. Two findings were raised rather than built and are in the queue.

  • ErgoGlare Outdoor: Rebuilt Against the Sandia Manuals

    The outdoor glare method was read against both Sandia publications behind it, the Solar Glare Hazard Analysis Tool's technical reference manual and its user's manual, and rebuilt to them. The published angle-dependent reflectance fits replace a single value; the acceptance cone includes the sun's own angular size; the published clear-day irradiance profile is used; the array-limiting angle applies only where it is the smaller; and pupil diameter, ocular transmission and eye focal length are analyst parameters within the published bounds on a new Irradiance and ocular parameters card. The caption Meets FAA guidelines is retired, because the source publishes no such criterion, and the screening criterion is declared as ErgoSphere's own. Outdoor documents recompute against the rebuilt method when next opened. Flight-path receptors are still analysed as a single point, which is the next step for this method.

  • Every Project Store Now Reports What It Could Not Load

    A project file is loaded by ninety-one stores, one per kind of document it can carry. Every one of them now writes anything it cannot load to the Partial Load report, with the type and message of what went wrong, so a corrupt document and a filtered one are distinguishable, and an error on the report blocks a regular save. The Partial Load dialogue was rebuilt at the same time: each issue has a heading and a wrapped message, the details region scrolls, and a Copy to Clipboard button takes the full report while the dialogue stays open.

  • The Regression Evidence Behind Each Dossier, Counted Properly

    Each dossier's regression component counts from a manifest naming the test classes that stand behind that method. A sweep found that the manifest had been naming a fraction of what exists: 215 test classes across thirty-five of the forty-two methods stood behind a method and were listed nowhere. ErgoGlare's dossier, for one, credited thirteen tests while 526 more were running unlisted. The manifest now names 412 slots where it named 192, a written ruling defines what the list means, and a guard asks the reverse question so it cannot fall behind again. The counts on the engineering record will rise at the next full run, and we are saying so in advance. No dossier text was edited.

  • Two Smaller Corrections

    In the compiled HF Analysis Report, an appendix that cannot be re-rendered now reads Dismissed - Not rendered, cleanly. The HF User Requirements Register gained the same provenance guard its sibling, the HF Issues Register, already had: a raised item's source tool, document and node are set once and never rewritten. No production code needed to change, because the discipline already held at every surface, which is the outcome a guard is supposed to record.

  • Software Assurance: The Dossier Programme Turns to the Platform ItselfFocus

    The dossier programme produces the verification and validation dossier and the functional requirements document for each method. From this release it also produces software assurance documents, which look at the platform around the methods: the project file, the save path, the encryption, the navigation, everything a practitioner assumes behaves. The product is decomposed into twenty-seven bounded assurance units, each with a known state from Not reviewed to Assured. A reviewer who may not touch production code inspects a unit, remediation is a controlled piece of work of its own, and a finding closes only when it is verified afresh by someone other than the person who fixed it. The stated goal is not to claim the software is defect-free but to replace unknown confidence with traceable confidence that increases, unit by unit. The first two documents, the discovery report and the master breakdown, join the published dossier pack. How the verification work is run →

  • The First Unit: Project Lifecycle and State Isolation

    The first unit reviewed was the one with the most to protect, how a project is created, opened, closed and kept apart from the last one: ninety-four project services and sixty-four session containers across 184 files. Its remediation is built and verified. New, Open and Recent on the Advanced Practitioner home now route through the one canonical project lifecycle, so the unsaved-work check and the full restore sequence apply from every entry point. Failures on clear, on collection load and on plugin load are reported rather than absorbed, and the project reports ready only once loading has finished. The remaining units are queued in the order of what they protect.

  • Cancelling a Password Prompt Simply Cancels

    Pressing Cancel at the password prompt on an encrypted project now aborts the open and leaves the project you already had exactly as it was, including its key state; genuine corruption still recovers from backups as before. Opening a plain project after an encrypted one selects the plain project's own encryption context, and a cancelled or failed load leaves the previous one usable. There is no change to the project format or to how keys are derived.

ErgoSphere Viewer
  • Still With the Invited Group, Now With the Things a Release NeedsPre-release

    The free companion reader remains in the hands of a small invited group rather than on general download, and this cycle gave it the things it needs to go further: an installer, an identity, a file type, its own legal documents and a first-run gate. It is packaged as an installable Windows application with its own version line, starting at 1.0.0.0, and it declares no network capability at all. Double-clicking a .ergview file opens it, with the ErgoSphere deliverable icon and type name in Explorer, and a second package opens in its own window. The main application gained the same courtesy: a .ergsphr project file now has an icon, the type name ErgoSphere Project, and double-click opens it, switching projects in the same window and asking about unsaved work first if it needs to. A reader moving from the earlier loose build to the installed package starts with fresh settings and an empty recent list.

  • Licence, Privacy, Terms, and a Gate That Asks Again on Reissue

    Under Settings, the Viewer now carries its own End User Licence Agreement, Privacy Policy and Terms of Use, written for what it is: a free, perpetual licence on any number of devices, with the right to pass on the unmodified installer; a privacy policy that states there is no account, no telemetry, no analytics, no crash upload and no network connection, and names the one case in which entered data leaves the device, a review the reader chooses to send back; and terms stating that the content of a package belongs to whoever issued it. On first launch the reader is shown the three documents, two plain-language consent boxes, and a light or dark theme choice that re-themes the window behind it; Accept is disabled until both boxes are ticked and Decline closes the application recording nothing. Consent is recorded against the document revision and the Viewer version, so a reissued document asks again.

  • Twelve Tools' Findings Pages Now Render as the Application Draws Them

    The bar set last release was a paired screenshot, the tool's findings page in the application beside the same assessment's page in the Viewer, and the ruling since then was that the two had to be identical, not roughly alike. Five capture rounds ran against a golden package of real assessments, the last in both themes with both halves scrolled, twenty-four pairs across twelve tools, and each round's marks became the next round's work. The RULA score and dial share one card at the application's width, NASA-TLX's breakdown, radar and bars sit where the application puts them, dark-theme figures bake a dark twin so nothing draws white on a dark card, ErgoSense's recorded sessions draw as the application's row cards, and REBA, ATWIT, SART, DRT and Snook were brought to the same standard. The twelve are HTA, RULA, NASA-TLX, ErgoDesign, ErgoSense, ErgoLoop, SCTA, REBA, Snook, SART, ATWIT and DRT. A type audit then matched the hero score and every card title to the application's sizes.

  • One Card, Drawn Twice

    Matching two renderings of the same card by eye works, but it has to be done again every time either one changes. The approach changed: a findings card is now one control, drawn by both applications from one specification, so the Viewer stops re-implementing it and the match holds by construction. The first five shared cards are the recommendations card, the final score hero used by REBA, RULA and NIOSH, component scores, task profile and score derivation, which is now live in the Viewer with the same Export PNG the application offers. An absent NIOSH lifting index draws no needle in either application, and an excluded task's hero draws green in both. The rest of the catalogue migrates card by card from here. A package exported before this release keeps drawing the way it did until it is re-exported.

  • ErgoLoop's Diagram Comes Alive, With Play

    An ErgoLoop package now opens on a Diagram surface ahead of Findings, laid out as the application lays it out: a Loops rail with reinforcing and balancing badges that highlights one loop and dims the rest, a Model panel with variables, links, density, delays and complexity, the live diagram with Fit and Restore, and panels for the selection, leverage points and archetypes. A transport with Play, Reset and a scrub track replays a simulation that the application recorded at export with its own engine; the Viewer computes nothing and saves nothing, so a reader can drag the diagram about and Restore returns the analyst's arrangement. A package without a recorded simulation shows no transport and says why.

  • The SCTA Tree, and Error Tables You Can Flick Through

    A safety-critical task analysis now earns the same Tree button the HTA has. The rail lists steps in number order with the safety-critical ones tinted, the root's detail is the hazard context, and a step's detail is its step table followed by one heading per error row with the worksheet's columns, the performance-influencing factor tables and the recommendations. Previous and Next in the detail header walk the rail, the HTA gets the same pair, and a Safety-critical only chip narrows the walk. Nothing is editable, which is the point.

  • First Person Is a Head, Not a Free Camera

    In the eye view the reader now turns the head inside the figure's own neck envelope, measured from the figure's facing, and it stops at the limit; the look survives a posture change, and a package without an envelope keeps the free camera. The full heads-up display travels whole, the yaw and pitch rulers with their tick numbers, the comfort banding, the line-of-sight notch and the visual field legend, ninety-eight overlay shapes where sixteen travelled before, with a light and a dark palette so the Viewer picks by its own theme, and the projection travels with it so the rings draw at their true angles. First person is offered whenever the package carries a saved posture, because the saved pose is what was assessed, and an export declines to bake an eye camera for a design that records no posture, so a package never carries a sight line from an unsaved manipulation. Designs are re-captured in the editor to carry the new overlay.

  • Imported Models Keep Their Textures

    A model's base colour map now travels into the deliverable, downscaled to 1024 pixels on the long edge, stored once however many items share it, with a write-time package budget that refuses by name rather than silently. A second route reads the image out of a single-file .glb model, matched by name, and refuses rather than guesses when it cannot. The capture records how many textures were carried. On a real workstation project, every one of 192 textured meshes arrived in the Viewer with its texture.

  • The Viewer's 3D Chrome Is the Application's

    The pose ribbon over a live scene is now the ErgoDesign ribbon, transcribed rather than imitated: the same markup and the same tokens, with Posture, Transition and Hands groups, and the transport pill floating over the view exactly as it does in the editor. The groups that write to a design, Pose, Adjust, Interact and Library, are not copied, because the Viewer writes nothing. Wire, Edges, Solid, All and X-Ray sit at the top left with the view switcher beneath them, the ribbon scrolls with the wheel, the Show group carries Figure, ERP, Dims, Contact, Reach, Volumes and Contours as the application does, and a Cones button splits the vision zone shells out of the eye reference point layer. Fly navigation with the keyboard was ported across too.

Hierarchical Task Analysis
  • The Task Comes AliveNew

    An HTA has always been a static tree. It can now be played. Each step takes a timing estimate with a minimum, a maximum, a basis and a source, and an absent timing never reads as zero. A small plan expression grammar, then, any, all, repeat until, if and else, and wait, sits in a second field beside the plan text with a live preview of how it will be played, and named scenarios hold alternative runs. A transport bar at the foot of the diagram plays, pauses, steps and restarts at speeds from half to instant, with a scrubber, a Gantt timeline and a readout that says how many steps are timed. Spotlight dims everything off the running path. Lanes lays the run out by performer with the handoffs and waits between them. Trace draws a cumulative human error probability curve over the run with stacked demand channels, and says in words when no step carries a probability rather than drawing a flat line. The critical path is stated only when every step is timed; otherwise the steps without timing are listed and clickable. In the Viewer, the task hierarchy screen gains a replay strip with Play, a scrubber and a rate, and computes nothing itself.

  • Walk It With the Operator, and Watch Two States Morph

    A Walk tab is built for live observation: touch-sized tiles for each step, marks for skipped and repeated, notes, and afterwards a comparison of observed against planned with deviation and variability whiskers and an Adopt median action that turns what was seen into the estimate. Story view morphs the tree between a before state and an after state, drawing the delta only when both are fully timed, and replays the arrival of evidence. Report figures and a timings table land in the DOCX, and any frame exports as a PNG. Untimed steps take a nominal beat during playback and are excluded from every total. Playback is new this release and will keep being refined from use. Existing packages are re-captured before they can be replayed.

ErgoDesign
  • A Thirteen-Item List From Someone Who Has Used the Alternatives

    Most of this section answers one document: thirteen items of feedback from an experienced user of commercial digital human modelling tools, written after time in ErgoDesign. Ten of the items are built and described below. Two are not, and we would rather say which. A button that keeps the figure within joint limits during posing is parked until we hold a range-of-motion dataset we can cite, because a comfort clamp without a source is exactly the kind of number the dossier programme exists to refuse. Reach measured from each shoulder separately rather than from one central sphere is blocked on the same kind of source. A separate note from another user, that clearance gaps read better against a body than against the robot figure's panels, started the first item.

  • Three Selectable FiguresNew

    A Figure section now sits above Anthropometrics in the settings pane, and its chooser offers the robot figure that has always been there, still the default, plus a male and a female human figure. The choice is saved per design, and an existing design opens with the robot without asking. They are representations, chosen so that a posture reads as a posture and a clearance reads against a body rather than a panel; they are not anthropometric bodies, they are not percentile figures, and the basis panel remains the only source of the assessed dimensions. Both human figures are excluded from GLB, OBJ and STL geometry exports with an explicit omission message, and appear in ErgoDesign, in reports and in Viewer packages.

  • Individual Finger Control

    The request was to show an index finger operating a switch. The two hand-shape buttons on the Pose ribbon are now one Fingers toggle that opens a pinned window with an illustrated hand: click a finger to select it, drag its tip to curl it through four snapped stops, choose from six presets including the new Point and Pinch, lift, neutral or press the selected finger, copy the hand to the other side, and undo one gesture at a time. Fifteen bones per hand, on all three figures. The report, the Findings tab, contact recompute and the free Viewer all render the same hand.

  • Interact Means a Fingertip, a Palm, a Wrist or the Head, Not Just a Hand

    The first Interact click now resolves through a nine-choice contact picker: palm, index fingertip and thumb tip on each hand, either wrist, and the head. The contact point is taken from the chosen figure's actual skin, the reticle scales to the effector, and the solve places that point on the surface, reporting the shortfall when it cannot. Choosing Head and then a point on a surface turns the figure's gaze to it from its own eye point; if the neck envelope cannot reach, it clamps and says by how much. One undo step for each, and the viewport holds its framing throughout.

  • The Figure Stops at Its Own Surfaces

    An Interact drag, a joint rotate ring and the move gizmo now all stop where the figure's own surfaces meet, and the posing status line names the two parts and the depth: the right forearm would pass through the upper trunk by 101 mm, so the drag stopped at contact. The Findings pane prints the same sentence under the shortfall row, and a joint turned back out clears it. A posture that already penetrates is reported, never edited. The surface model is declared in Findings and in the report, a capsule fit at the ninetieth percentile with its worst measured deviation and a 16 mm allowance, and the report states that the measurement is geometric. It is not range of motion, not comfort and not an ergonomic result, and nothing in the tool describes it as one. The free Viewer's Interact runs the same constraint.

  • The Solver Keeps the Shoulder Within Its Cones

    Every path that places a hand, the move gizmo on a hand, Interact, the contact solver and the Viewer's own Interact, now solves within the shoulder cones, and a target the cone cannot reach is reported as unreached rather than served by an arm no human has. Elbows do not bend backwards on hand placement, the upper arm stops twisting at a declared cap, and the four preset postures still load.

  • Measure to the Figure, and Make a Measurement Stay

    The Measure tool now snaps to the figure. Within reach of one of sixteen landmarks the pill names it before the click, and the reticle sits on the figure's skin, named by the nearest landmark or by segment, so the readout reads near left elbow to Desk: 412 mm and the status line says the figure is postulated. A Pin action turns a fixed measurement into an annotation that survives clear, save, reload, the top and side report captures and the free Viewer under the Dims toggle, carrying its words and value with a witness tick and an arrowhead at each end; click it with Measure armed to select it and Unpin to remove it. The single-axis object's selection box now bounds the axis itself. The shoulder landmark is the rig's joint centre; a true acromion surface landmark is a follow-on.

  • Materials: Imported Models Keep Their Maps, Placed Objects Get a Finish

    The figure was already lit with physically based materials; the workstation around it now is too. An imported glTF or GLB model loads with its metallic-roughness, normal and occlusion maps in the viewport, and the report bake and the Viewer keep its colour. Placed primitives gain a Surface section under the colour strip in the Modify panel with two dials, roughness and metalness, and a Clear chip; empty means no finish, it is undoable, and it is disabled with a reason on imported models and scene lights. The finished object appears with its material in the top, side and 3D report captures and in the free Viewer. Two limits are worth knowing: the two dials do not survive a GLB export round trip, and only the base colour map, not the metallic-roughness, normal or occlusion maps, is carried into the report bake and the Viewer.

  • Flip Faces, Shift to Snap, an Angle Increment, and Z

    A Faces row in the Modify panel, under Lock and Visible, offers Flip, which reverses an item's winding and normals and travels into exports and the report bake, and Force 2-sided, which is display only and never exported, for imported geometry whose faces point inward. A rotate now snaps when Snap mode is on or Shift is held, and holding Shift while the mode is on frees that one drag; an angle increment sits beside the millimetre snap, from 1 to 90 degrees with 10 as the default, and the status bar prints both. Bare Z frames the selection, or everything when nothing is selected, and in Pose it frames the selected body segment. A hotkey card of thirty-two rows shows while the Help ribbon tab is up. The two-dimensional rotate gizmo now follows the same increment, which is a behaviour change worth noticing.

  • Body Breadth and Depth, From a Declared Source

    Five rows now print on the Findings basis card and in a Body breadth and depth section of the report: abdominal extension depth sitting, hip breadth standing and sitting, bideltoid breadth and thigh clearance, declared as ANSUR II 2012, US Army, each with its definition, posture, landmark and observer error, at the fifth, fiftieth and ninety-fifth percentiles only. A combined-sex design prints both sexes' values, and any absence prints its reason. Both surfaces carry the independence caveat, that fewer than one man in a hundred is at or above the ninety-fifth percentile in both stature and hip breadth, because these are a basis and not a clearance conclusion. A declared clearance volume in the scene is the next step.

  • Smaller Things You Will Notice

    Report captures are anti-aliased to match the viewport, so the top and side drawings, the posed figure and the eye view export with the same smooth edges you see on screen. A lost or starved graphics device degrades to the 3D view unavailable state with the two-dimensional schematic, in the editor and in the Viewer. A neutral contact shadow sits under the figure and placed items in the 3D viewport and in the report's perspective figure only, as a depth cue that makes a floating chair obvious; it is not a lighting result and is never exported. A new design whose figure has not yet been posed says no posture recorded under the Postures header in Findings, so nothing reads as assessed until it is. Imported models of any size travel with the project: their bytes live as entries in the project package rather than inside the document, and the same file placed twice is stored once. The ribbon toggle formerly labelled ERP now reads FOV, and a separate ERP toggle shows or hides the eye reference marker and sight line. Gizmo hover lights exactly the handle drawn, and a selected joint in Pose shows its full ring with the active quarter bright.

Across the Platform
  • Assurance: Screen, Designate, Then Assess

    A clause in a standard does not become a requirement on a project until it has been designated applicable, which is what MIL-STD-1472H's tailoring sections and AS 7470:2024 section 9 both say. The Assurance module now works that way in three stages. On the Standards page, each section of a standard is screened Applicable, Partial or Not applicable with a rationale, date and attribution, a Partial section opens to clause-level decisions, and documents supporting a client's acceptance can be linked from the same pane. The designated set then appears on a new Requirements page with four cards, Designated, Compliant, Non-compliant and Not assessed, and that is where assessment happens. A project screened before this release scores what it scored before. The tab strip reads Overview, Lifecycle, Standards, Requirements, Gates or Reviews, Evidence and Extracts.

  • Recent Sessions on the Home Pages

    With no project open, both Home pages, Advanced Practitioner and the six curated lenses, show Recent Projects as they always have. With a project open they now show Recent Sessions instead: every tool session in the project, newest first, each with its tool icon, a Latest pill on the first row and a Complete mark where the tool reports it, and a strip of chips, one per tool present with a count, that filters the list. A session opens through the same lock-guarded path as the tool's own home, and a session with no recorded time sorts last and shows nothing rather than an invented one.

  • The Published Dossier Pack Grows to Seven

    The published pack that accompanies the verification work now holds seven documents, produced as HTML and PDF, with the two software assurance documents joining the five that were there. Each document generates its own cover from its own data: the requirement strip from the requirement table, the hazard matrix from the hazard register, the architecture layer stack and the security tier ladder. The verification page →

  • A Build With Nothing Left to Warn About

    The build now reports zero compiler warnings and zero errors across the application, the test suite and the packaging project, and it is guarded to stay that way. The rules for getting there were that nothing is suppressed, no test is weakened, and no null fallback is introduced that would turn an absence into a value. The one warning that touched production code was in the RAPP report builder and was closed by proving the value non-null; the report's bytes did not change.

Compatibility & Data Safety
  • Your Existing Work Opens Unchanged

    Projects saved by 1.6.1 and earlier open in 1.6.2 and keep their data. The HTA link score migration runs on load and is noted on the load report where it sets a value to absent. ErgoDesign designs open with the robot figure and their imported models are promoted into the package on the next save. An ErgoCulture document from the first content pack loads with the two newer dimensions added empty rather than assigned a level. The Assurance module's screening decisions carry across without a format change.

  • Where a Result Recomputes, and Why

    Where a method's read against its source changed how a result is derived, the result recomputes when the document is next opened, and the dossier for that method records the passage that decided it. In summary: Snook push and pull assessments compute from the initial and sustained forces entered; ErgoGlare outdoor documents compute against the rebuilt Sandia method; populated NIOSH needles on the ErgoLens and ErgoSense review dials sit on the linear mapping; HEART and THERP band labels read from the single ladder; and HTA link scores for MAC, RAPP and ErgoLens return when the assessment is next saved. Existing documents are not re-flagged, for the reason given last release, and any figure the platform publishes can be explained rather than only defended.

  • Issued Deliverables Stay Byte Identical

    Nothing here touches an issued package. HTA-carrying packages issued before the risk ladder change render exactly as they did, verified against eight real deliverables. A review still produces a new file and the sealed region of the original is never rewritten. To carry the new Viewer content, the full eye overlay, textures, the shared cards, ErgoLoop's recording and HTA replay, an assessment is re-captured in its editor, marked ready again and composed into a new package; a package that predates this release keeps drawing the way it did.