Jidoka — built-in quality and autonomation (Andon)
≈ 23 min read · 4,504 words
Your printer stops and displays “paper jam” — it doesn’t keep spitting out crumpled, unusable sheets. The washing machine stops and beeps if the spin load is unbalanced; the warning light on a modern car’s dashboard comes on and the engine switches to “limp mode” before it damages itself; the smoke detector sounds before there is real trouble. They all do the same thing: the machine notices by itself that something has gone wrong, and stops or signals — instead of continuing to produce the defect. This is jidoka, in English built-in quality and autonomation. The idea is simple: we build “human judgment” into the machine so that on an abnormality it stops by itself and signals — so the defect surfaces where it arises, not at the customer. Let’s look at what it is, why it works, and where it is used.
Jidoka (autonomation) is the lean principle that a machine, on detecting an abnormality, stops by itself and signals so that a defective product cannot move on. It is one of the two pillars of the Toyota Production System (TPS) alongside Just-In-Time, and it rests on two basic principles: (1) the machine can stop automatically when it detects an abnormality, and (2) human and machine work are separated, so the person is not the machine’s watchman. The first delivers built-in quality (a defective product does not move on), the second delivers cost savings (one person can oversee several machines). The warning device of jidoka is the Andon, for the immediate visual and audible signaling of a problem. poka-yoke is the tool-level implementation of jidoka’s “don’t pass the defect on” principle.
Figure 1 — the four steps of jidoka (detection → stop and Andon → short-term fix → long-term, root-cause prevention → better quality), with the classic green/yellow/red color logic of the Andon below.
Who is this for?
Section titled “Who is this for?”This article is for those who deal with defect detection and the culture of stopping in practice: operator · production and plant manager · shift supervisor · process engineer · quality engineer · maintenance technician · automation / control engineer · Lean/CI specialist · HSE.
Learning objectives
Section titled “Learning objectives”After reading this article you will be able to:
- explain the two basic principles of jidoka, and say which is responsible for built-in quality and which for cost savings;
- walk through the four steps to follow in case of a problem, and justify which one makes the improvement durable;
- distinguish the Andon types and the green/yellow/red logic;
- recognize where jidoka ends and where the certified safety system (SIL/LOPA) begins;
- design a simple jidoka loop (detection → Andon → reaction chain) for one of your own operations.
The essence
Section titled “The essence”- Jidoka is “failure-sensitive autonomation”: the machine itself recognizes the fault and stops before the scrap moves on.
- Two basic principles: the machine stops automatically on an abnormality + human and machine work are separated (one person can oversee several machines).
- Origin: Sakichi Toyoda’s automatic loom — the automatic loom in 1902, and by 1926 the machine could already detect a broken thread and stop, so the problem could be solved.
- In case of a problem, 4 steps: recognition → immediate stop and signal → short-term fix → long-term, root-cause prevention.
- The Andon is jidoka’s signaling system: a visual, often color-coded (green/yellow/red) device that can be automatic (e.g. tool breakage) or operator-triggered (e.g. a quality problem).
- The goal of jidoka: best quality – lowest cost — the defect surfaces and is resolved where it arises, not at the end of the line.
- In process industries its logic is the basis of safety shutdowns, alarms and the “stop the line” culture — but it does not replace certified protection systems.
Everyday jidoka examples (you have definitely met them)
Section titled “Everyday jidoka examples (you have definitely met them)”Jidoka is not an abstract factory concept — you use it day in, day out, you just don’t call it that. The common thread: the machine does not rely on human attention to notice the fault; it stops and signals by itself.
| Everyday example | What it detects, and what it does | Jidoka element |
|---|---|---|
| Printer on a paper jam | stops and displays the error | detection + stop + signal |
| Washing machine on an unbalanced spin | stops and beeps | detection + stop + Andon (sound) |
| Car engine-fault light + “limp mode” | signals and limits performance | signal + protective reaction |
| Smoke detector | alarms before there is trouble | detection + signal |
| Residual-current device (RCD) on a fault current | cuts off immediately | detection + automatic stop |
| Elevator door sensor on an obstruction | stops, does not close | detection + stop |
poka-yoke makes the error impossible in the first place (prevention). Jidoka notices and stops it if the error happens anyway (detection). Together they are strong: poka-yoke is the tool-level implementation of jidoka’s “don’t pass the defect on” principle.
Why does it matter? (the stakes)
Section titled “Why does it matter? (the stakes)”An abnormality on its own is cheap — the trouble is the chain reaction if the machine does not stop and, operation by operation, more material and work are built onto the defective part. The same defect is pennies when it arises; once it reaches the next operation, then the customer, or the storage tank as an off-spec batch, it is orders of magnitude more expensive and riskier.
Figure 2 — the escalation of an unstopped abnormality: the further down the chain you catch it, the more expensive and dangerous it is. Jidoka stops the defect at the very start of the chain — at the origin, at the point where it arises.
The lesson is the same as with poka-yoke: the cheapest scrap is the one we stop at the moment it arises. That is why it pays to put detection and stopping at the start of the chain, rather than repairing expensively at the end.
What is jidoka, and where does it come from?
Section titled “What is jidoka, and where does it come from?”Jidoka is one of the load-bearing pillars of the “temple” of the Lean operating system: alongside Just-In-Time, the “Best Quality – Lowest Cost – Shortest Leadtime – Safety” goal system rests on these two basic principles. The two pillars arose decades earlier: the concept of jidoka was created by Sakichi Toyoda in the early 1900s, while the JIT principle came from his son, Kiichiro Toyoda, in the late 1930s. From this, Taiichi Ohno consolidated the TPS in the late 1940s, with the support of Eiji Toyoda.
The origin story comes from the weaving mill: in 1902 the automatic loom was born, and by 1926 the automatic loom could already detect a broken thread and stop, to ensure the possibility of solving the problem. This is “failure-sensitive autonomation”: the machine does not keep producing defective (broken-thread) fabric, but stops and signals. This had two enormous benefits: on the one hand no scrap was produced, and on the other an operator did not have to stand beside a single machine and watch it — since the machine stops by itself, one person could oversee several machines.
The way the word is written is telling: into the middle character of the Japanese “jidoka” a human radical was inserted, so its meaning is “automation with a human touch / with human intelligence” — not mere mechanical automation, but automation that builds human judgment (recognizing the fault and the decision to stop) into the machine. Hence the English rendering: autonomation (autonomy + automation), and low cost intelligent automation (LCIA).
How does jidoka work?
Section titled “How does jidoka work?”Jidoka stands on two basic principles, is realized in a four-step reaction chain, and the Andon signaling system makes it visible. Let’s take them in turn.
The two basic principles
Section titled “The two basic principles”- Machines are able to stop automatically when they detect an abnormality. This guarantees built-in quality: a defective product does not move on in the process, where we would waste further parts and labor on a product the customer won’t buy anyway.
- Human and machine work must be separated — the person should not be the machine’s watchman. Machines equipped with jidoka do not require constant supervision; the operator only needs to be at the machine while performing the material exchange, or when detecting an abnormality. This delivers the cost savings (less supervisory labor, multi-machine service).
The four steps in case of a problem
Section titled “The four steps in case of a problem”Jidoka does not stop at stopping — the stop is only the first step in a four-step reaction chain:
- Recognition — detecting the problem (abnormality). This can be by machine (a sensor, e.g. a broken thread, an out-of-tolerance setting) or by human (the operator sees a quality problem).
- Immediate stop and signal — the process stops, and the Andon immediately signals to those responsible. The goal is a quick reaction and that the problem be dealt with at the place where it arises (at its origin).
- Short-term fix — an immediate intervention to solve the problem so production can continue (screening out the defective part, clearing the fault).
- Long-term prevention — eliminating the root cause so the problem never recurs (see 5-why and root-cause analysis). This is the step that turns jidoka from one-off firefighting into durable quality improvement.
The Andon — jidoka’s signaling system
Section titled “The Andon — jidoka’s signaling system”The Andon is the tool of visual management for signaling the state of production: a (usually electronic) device that most often uses colors to indicate the state of operations, so that on a problem it enables intervention as soon as possible. It has two essential properties:
- It can work automatically (e.g. on tool breakage the machine gives the signal itself), or the operator can also trigger it (e.g. on detecting a quality problem or machine fault).
- It must be placed so that the responding worker can see it clearly. The light signal can be accompanied by a sound signal — in most cases the Andon cannot work effectively without sound. For production lines close to one another a different sound must be chosen, to reduce the number of false alarms.
A central Andon can display the state not only of one machine but of several production lines, often together with production information (planned quantity, produced quantity, availability) — here a monitor is used rather than lamps.
Andon types:
| Type | English | Function |
|---|---|---|
| Warning andon | warning andon | Signaling a problem on the production line: button + lamp at every operation; the worker can signal the responder. |
| Signal / paging andon | paging andon | Signaling material need: if material runs low, on the signal the material-handling operator delivers. |
| Operation andon | operation andon | Lamp on the machine’s state: green = working, yellow = waiting for intervention / a within-cycle problem, red = stopped due to a problem. |
| Progress andon | progress andon | For long cycle times the operation is divided (e.g. into 10 parts), and progress can be followed on a display. |
The classic three-color logic for the operation Andon:
- Green — the machine is working (the operator pressed the start button, the cycle is running).
- Yellow — a problem has occurred, but the cycle has not yet ended; if the fault is cleared within the cycle time, the line can go on without stopping. Its other use: the machine has finished the cycle and is waiting for a material exchange / a new cycle.
- Red — the machine has stopped due to a problem (machine fault, tool breakage, or the setting has gone out of tolerance).
Related controls
Section titled “Related controls”- Automatic line stop: the line stops automatically if, e.g., a certain produced quantity is reached or a material shortage occurs.
- Fixed-position stop: when the operator presses the stop button, the line does not stop immediately, but only when the product reaches a fixed position (e.g. the boundary of the operations). This way there is often enough time to clear the problem with a quick intervention before the line stops at all. If it does stop, the system prevents the bigger problems that would arise if the line could stop just anywhere.
How is jidoka different from plain automation or final inspection?
Section titled “How is jidoka different from plain automation or final inspection?”They all work against defects, but their mechanism differs. Jidoka is strong because it builds fault recognition into the machine/process — it does not rely on human attention or on end-of-line inspection:
| Approach | What it does on a defect | Its weakness vs. jidoka | |
|---|---|---|---|
| Jidoka (autonomation) | the machine detects the defect, stops and signals | — | |
| Traditional automation | only produces; it multiplies the defect just as fast | runs “blindly,” a human has to notice it | |
| Final inspection | screens out scrap at the end of the line | expensive, late — the defect has already happened and been built in | |
| [[poka-yoke.en | poka-yoke]] | makes the defect impossible in the first place | can only be sized for known, recurring mistakes |
So jidoka does not replace the others, but takes the weakest link — human attention, or late inspection — out of the equation: the defect surfaces where it arises.
Process-industry context and safety
Section titled “Process-industry context and safety”Jidoka was originally made for discrete manufacturing (weaving mills, car plants), but its logic transfers directly to the continuous-operation, process-industry environment — precisely because of safety it is at least as strong a tool:
- “Stop the line” → safety shutdown. In a process plant the principle “stop and signal if there is an abnormality” is the philosophy of safety interlocks, interlock logic, emergency shutdowns (ESD/trip): if a parameter goes out of tolerance, the system reacts automatically (alarms or shuts down), it does not keep producing in a dangerous or off-spec state.
- Andon = alarm system. The control room’s alarm matrix, the color-coded indications, the audible and visual signals are functionally the process-industry equivalents of the Andon: on a problem, an immediate, clearly visible signal to the responsible operator, so the problem is dealt with at the place where it arises.
- Built-in quality = on-spec product. Quality control built into the process (online analyzers, automatic feedback) prevents off-spec product from moving on to blending or storage — this is a direct jidoka idea.
In process industries the jidoka principle does not replace certified functional safety systems. Jidoka is a management and quality philosophy; the emergency-shutdown logic must always be designed according to risk analysis and the relevant standards (LOPA, SIL / IEC 61511). At the same time, jidoka’s “don’t pass the defect on” principle culturally reinforces the willingness to report near-misses and to intervene.
Putting it into practice (roadmap)
Section titled “Putting it into practice (roadmap)”Introducing jidoka is not the installation of a single tool, but building a system of defect detection and reaction. Suggested order:
0. Prerequisite — a stable base. Before jidoka there should be 5s and standard work: without a standard there is nothing against which to define an “abnormality.” An abnormality is what deviates from the standard.
1. Designating a pilot area. Choose a machine / operation / plant section where the quality or stability problem hurts and is measurable. Define precisely what counts as an abnormality (which parameter, with what tolerance).
2. Designing detection. How is the fault revealed? It can be:
- Machine/automatic detection (a sensor, a poka-yoke fail-safe solution, online measurement), or
- Operator-triggered signal (Andon button / cord), if human judgment is needed.
3. Installing the Andon. Place the signaling device so that the responder can see it (and/or hear it). Define the color logic (green/yellow/red) and the sound. For multiple lines take care to reduce false alarms (different sounds).
4. Fixing the reaction chain. Write down the four steps as a standard: who recognizes it, who is notified (the escalation chain), what the short-term fix is, and how the root cause gets onto the agenda (5-Why, San Gen Shugi). Key question: on a signal, who reaches the machine, and how fast?
5. Reinforcement and rollout. Without the management’s interest and support jidoka does not survive: the leader should not punish but encourage stopping and signaling (“stopping is good”). Extend the pattern gained in the pilot (abnormality definition, Andon logic, reaction standard) to further areas, continuously refining it with the pdca cycle.
Who does what (in brief): the plant engineer / Lean PMO designs the detection and the Andon; the operator signals and intervenes short-term; the shift supervisor escalates and leads the root-cause investigation; management ensures that the culture of stopping is supported.
Hands-on / example
Section titled “Hands-on / example”The most vivid illustration of the jidoka logic is the 5-Why root-cause analysis — precisely the fourth step (long-term prevention). The classic stop → root-cause chain:
- Why did the machine stop? — The overload fuse tripped.
- Why did the fuse trip? — There was not enough oil on the shaft.
- Why was there not enough oil? — The oil pump was not delivering enough, because the shaft was worn.
- Why did the pump not work well? — The oil filter was clogged with metal shavings.
- Why did the filter clog? — There was no preventive maintenance / weekly cleaning.
Lesson: eliminating the root cause may take more time in the short term, but the investment pays off quickly, because the problem never recurs. A root-cause-based problem-solving culture leads to higher OEE, higher productivity and a motivated workforce.
The human side of jidoka is reinforced by the principle of San Gen Shugi: the fault must be recognized and handled where it arises — Gemba (the real place), Genjitsu (the real data/information), Genbutsu (the real part). “In production nothing is critical if we look at it from the office… You will never find the root cause in an Excel sheet.” The cautionary counterexample is precisely a deviation management where the fault codes are administered but no one goes out to the scene, so the problem is never solved — jidoka is the opposite of this.
Homework. Choose a machine or operation in your own area. Define what counts as an abnormality (which parameter, with what tolerance), design a detection for it (machine or operator Andon), and write down the four steps: who recognizes it, who is notified, what the short-term fix is, and how the root cause gets onto the agenda.
Measurement / audit
Section titled “Measurement / audit”The “hard” metric of jidoka is quality, which is the third factor of OEE:
- Q (Quality ratio) = good quantity / total produced quantity. Jidoka’s first basic principle (a defective one does not move on) directly improves this Q.
- The full OEE formula: OEE = A × SL × Q, where A = availability (uptime / scheduled production time), SL = performance efficiency (the ratio of actual to theoretical speed), Q = quality ratio.
Auditable, jidoka-specific metrics (practical logic):
- Number of Andon activations per period — and, more importantly: in what % they led to a root-cause action (not just short-term firefighting).
- Reaction time: the time from the signal to the responder’s arrival / to the end of the stoppage (lower = better).
- Rate of recurring faults: if the same abnormality returns, step 4 (root-cause prevention) is weak.
- Effectiveness of built-in quality: the ratio of faults screened out during the process to faults that reached the customer.
Target logic: an Andon activation is not bad in itself — the goal is not to drive signals to zero (that would hide the problems), but that every signal triggers a quick reaction and — on recurrence — root-cause elimination, so that over time the number of recurring faults decreases.
Common mistakes
Section titled “Common mistakes”The pitfalls of jidoka almost all stem from the same thing: stopping or signaling is taken as a goal in itself, instead of the reaction chain behind it. In anti-pattern ↔ correction pairs:
- Thinking stops at the stop. Jidoka does not end with the stop; without step 3 (short-term) and especially step 4 (long-term, root cause) there is only repeated firefighting. Instead: take every signal through to the root cause (5-Why).
- The Andon signal is punished. If the consequence of stopping or signaling is a scolding, operators will hide the fault. Instead: stopping must be encouraged — “stopping is good.”
- There is no standard against which the “abnormality” can be measured. Without 5s and standard work there is no reference base; jidoka’s “deviation from the standard” principle runs empty. Instead: first the stable base, then jidoka.
- Too many, blindly alarming Andons. With poor design and many false alarms (e.g. the same sound on nearby lines) people get used to it and ignore the signal. Instead: design the signal (different sounds, clear color logic) so that every signal counts.
- Trying to solve the fault from the office. In an Excel sheet, without viewing the Gemba, the root cause cannot be found. Instead: go to the gemba (San Gen Shugi: real place, real data, real part).
- Andon without sound. Mere light is easily missed. Instead: in most cases the Andon needs sound as well (mere light is not enough).
- Completely eliminating quality control. The goal of built-in quality is good, but at certain points (e.g. incoming inspection) quality control may still be necessary regardless. Instead: jidoka complements, and does not in every case replace, inspection.
When NOT to use it? (limits of the method)
Section titled “When NOT to use it? (limits of the method)”Jidoka is strong but not universal. Knowing where it ends is just as important as the method itself:
| Situation | Why (primarily) not jidoka | The right answer | |
|---|---|---|---|
| A certified safety function is needed | jidoka is a management/quality principle, not a certified, audited protection layer | design per [[lopa-sil.en | SIL/LOPA]], IEC 61511 |
| The root cause is unknown | the stop treats the symptom, not the cause | first cause investigation ([[5-miert.en | 5 Whys]]), then detection |
| Where ad-hoc stopping is itself dangerous | a continuous-operation unit cannot be stopped “just like that” | a planned, safe shutdown sequence (safe-state), not an improvised line-stop | |
| A one-off, non-recurring deviation | there is nothing to build durably into the process | one-off root-cause analysis, recording the lesson |
Rule of thumb: jidoka is strongest for recurring abnormalities that are measurable against a standard. It does not replace certified safety and planned, safe shutdown — it complements them.
Take it home (keys)
Section titled “Take it home (keys)”- A defect is not yet a scrap series — if the machine stops at the origin, you cut the chain at a single part.
- Detection → stop → signal are the three moves: the machine should notice, stop, and speak up.
- Step 4 is the point: without the root cause, jidoka is just firefighting; prevention makes it durable.
- The Andon is not an alarm but a call for help — many signals are good, as long as each one triggers a quick reaction.
- Standard first, then jidoka: an abnormality can only be measured against a standard (5s, standard work).
- In process industries it is a cultural force, but it does not replace certified SIL/LOPA.
Self-test
Section titled “Self-test”- What are jidoka’s two basic principles, and which is responsible for built-in quality, which for cost savings?
- An Andon signals red. List the four steps, and say which one, if missing, will bring the same fault back next week.
- Where is the boundary between jidoka’s “stop the line” principle and a certified emergency shutdown (ESD/SIL) — why are the two not the same?
How does it appear in digital practice?
Section titled “How does it appear in digital practice?”The jidoka principle does not end on the production line: the same logic is realized in software too. Instead of the physical Andon lamp, here automatic anomaly detection, enforced stopping and digital signaling carry the “notice → stop → speak up” triad — the mechanism differs, the principle is the same.
| Jidoka principle | Digital implementation | What it delivers |
|---|---|---|
| Automatic stop on an abnormality | threshold-based alarm; the process/step cannot be closed in a faulty state | the faulty state does not move on |
| Andon (visual signal) | digital status dashboard, color-coded alarm, push notification to the responsible person | the problem is immediately visible to the responder |
| Four-step reaction chain | recorded deviation → short-term action → root-cause action (owner, deadline) | an audit trail from signal to solution |
| Escalation | automatic forwarding if there is no reaction within a given time | not a single signal is “lost” |
| Recurrence monitoring | automatic detection of recurring abnormalities | step 4 (root cause) becomes measurable |
Modern digital systems realize the same principle as Sakichi Toyoda’s loom: “notice the fault, stop, and signal.” If a system does not let an abnormality run on silently, chances are the logic of jidoka is at work in the background.
Connection to OPEREX (shift diary)
Section titled “Connection to OPEREX (shift diary)”Jidoka’s deviation-management log fits naturally into the shift diary: the triggering event of the Andon signal (what the abnormality is, which machine/plant section, an automatic or operator signal), the short-term corrective action, and the long-term root-cause action (what is to be done, who is responsible, by when) can be logged per shift, retrievably, in the OPEREX shift diary. This way the chain leading from the signal to root-cause elimination leaves an audit trail, recurring faults can be filtered out, and at the handover between shifts a pending intervention is not lost.
Terminology (HU / EN / JP)
Section titled “Terminology (HU / EN / JP)”| Hungarian | English | Japanese / note |
|---|---|---|
| Jidoka, autonomáció | autonomation, low cost intelligent automation (LCIA) | 自働化 — “automation with a human touch” |
| Beépített minőség | built-in / building-in quality | the result of the TPS’s first jidoka principle |
| Andon | andon | 行灯 — originally a “paper lantern”; a visual signaling device |
| Figyelmeztető andon | warning andon | button + lamp at the operation |
| Működést jelző andon | operation andon | green/yellow/red status indicator |
| Hibára érzékeny autonomáció | failure-sensitive autonomation | the machine stops on a fault |
| Fix pozíciós megállító rendszer | fixed-position stop | the line stops at the next fixed position |
| Gemba / Genjitsu / Genbutsu | the real place / data / parts | San Gen Shugi — the principle of reality |
What are jidoka's two basic principles?
(1) The machine stops automatically when it detects an abnormality; (2) human and machine work are separated, so the person is not the machine’s watchman. The first delivers built-in quality, the second cost savings.
What is the difference between jidoka and the Andon?
Jidoka is the whole principle (defect detection, stopping, built-in quality). The Andon is its signaling system — the visual (and audible) device that signals to the responsible person immediately on a problem.
Where does jidoka come from?
From Sakichi Toyoda’s automatic loom: the automatic loom appeared in 1902, and by 1926 it could already detect a broken thread and stop, so the problem could be solved.
What should be done when the Andon signals?
Four steps: recognize the problem, immediately stop and signal, fix it short-term, then long-term — by eliminating the root cause — prevent recurrence.
Why is it not bad if the Andon signals often?
Because the goal is not to hide the signals but to surface and solve the problems. In a good system every signal triggers a quick reaction and — on recurrence — root-cause elimination, so that over time the number of recurring faults decreases.
Is jidoka the same as a certified emergency shutdown (SIL/ESD)?
No. Jidoka is a management and quality principle that culturally reinforces the “stop and signal” reaction. Safety-critical protection layers (emergency shutdown, interlock) must be designed according to risk analysis and standards (SIL/LOPA, IEC 61511) — jidoka complements these, it does not replace them.
Related concepts
Section titled “Related concepts”just-in-time | poka-yoke | 5-why | gemba | oee | standard work | 5s | pdca | kaizen | tps
Next step
Section titled “Next step”If you have understood this, from here it is worth going on — in this order:
- poka-yoke — the tool-level counterpart of jidoka: how to make the defect impossible in the first place, not just detect it. Start with this.
- 5 Whys — the engine of the fourth step: the root-cause analysis that turns jidoka into durable improvement.
- standard work — the standard against which the “abnormality” can be measured at all; without it jidoka runs empty.
References / Further reading
Section titled “References / Further reading”- Taiichi Ohno: Toyota Production System: Beyond Large-Scale Production. Productivity Press, 1988. — the canonical foundational work on the two pillars of the TPS (JIT + jidoka).
- Jeffrey K. Liker: The Toyota Way. McGraw-Hill, 2004. — jidoka as one of the pillars of the TPS, with practical examples.
- Sakichi Toyoda’s automatic loom (Toyoda Automatic Loom) — the machine that stops automatically on thread breakage, the original industrial implementation of jidoka.
In practice
The triggering event of the Andon signal (abnormality, line or plant stop), the short- and long-term actions of the four jidoka steps, and the owner and the deadline can be logged per shift, retrievably, in the OPEREX shift diary, so that deviation management leaves an audit trail.
Learn more: Shift log →