Strobes, haze and lasers: a safety policy for automated lighting

The HitLight team · · 7 min read

Software that runs a rig on its own has to decide what it is allowed to touch, and the honest version of that decision is a list rather than a promise. HitLight's Auto Show drives colour, intensity, a steady open shutter and eligible movement. Everything with a physical hazard attached to it — smoke, flame, lasers, flashing strobes, blinders, UV, and anything the software cannot read the meaning of — is removed from every automatic code path, not held back by good behaviour at runtime.

That distinction matters. A rule enforced in code cannot be forgotten, cannot be overridden by a clever prompt, and does not depend on the assistant behaving well on a bad night. The assistant cannot reach those channels either.

Key facts

What Auto Show drives
Auto Show drives colour, intensity, a steady open shutter and eligible movement, following the beat and structure of the music in the room through the Mac's microphone.
What Auto Show never drives
Auto Show will not drive smoke machines, hazers, fans, flame projectors, flame ignition, any pyrotechnic channel, lasers, flashing strobes, blinders, UV, fixture macros or unverified effect channels.
What the exclusions are not
The exclusion list reduces one specific risk — software firing a hazardous channel unattended. It is not a substitute for venue safety procedures, and it says nothing about how your rig is addressed, rigged, powered or supervised.

Which channels will Auto Show never drive, and why?

Six channel classes are excluded, each for a different reason. The reasons are worth stating separately, because "dangerous" is doing a lot of work as a single word: a hazer and a laser are both excluded, but almost nothing about why they are excluded is the same.

The channel classes stripped from every automatic path in HitLight, and the hazard behind each exclusion.
Channel classWhy it is excluded
Smoke machines, hazers and fansAtmospherics are a venue-policy problem before they are a lighting problem. Output can trip smoke detection, needs the venue's agreement, takes minutes rather than seconds to clear, and reduces visibility on escape routes. None of that is a decision software should be making from a microphone.
Flame projectors, flame ignition and any pyrotechnic channelIgnition risk. Flame and pyro require a competent operator, exclusion zones, and in most jurisdictions a permit and a named responsible person. An automatic system firing an ignition channel unattended is the single worst failure this list exists to prevent.
LasersEye safety. Projected laser light can cause injury at distances where ordinary stage light is harmless, and audience-scanning is separately regulated in most countries. Laser output belongs to a trained operator with a risk assessment, not to a beat detector.
Flashing strobes and blindersPhotosensitivity. Rapid flashing can trigger seizures in people with photosensitive epilepsy, and blinders additionally disorient a room and destroy night vision on stairs and in crowds. Auto Show holds a steady open shutter instead.
UVExposure. Ultraviolet output is not obviously visible as 'on' in the way a white wash is, so sustained unattended output is easy to miss and unpleasant to be underneath. It stays a manual decision.
Fixture macros and unverified effect channelsUnknown meaning. A macro channel can hide anything the manufacturer chose to put there — a strobe burst, a motor reset, a hazer purge, a full-power flash. Software that cannot verify what a value does must not send it.

The last row is the one people underestimate. Most genuinely alarming behaviour from automated lighting comes from a value written into a channel whose meaning nobody checked, rather than from a system deliberately deciding to strobe. Refusing to drive channels it cannot interpret removes a whole category of surprise.

Does Auto Show strobe?

No. Auto Show does not drive flashing strobe channels or blinders — it holds a steady open shutter and works with colour, intensity and movement instead. Where HitLight does produce strobe bursts elsewhere in the app, they are capped for photosensitivity. Both of those are design decisions in the software, and neither is a medical guarantee.

Photosensitive epilepsy is triggered by flash rate, contrast, coverage of the visual field and duration, in combinations that vary between individuals. No cap makes a light show safe for everyone. If your programming includes flashing content — whether or not you programmed it by hand — signage at the entrance and a warning before the show remain a venue responsibility, and in many venues a legal one.

What is the difference between Stop, Fade Out and Blackout?

They are three separate operator actions with three different outcomes, and knowing which one you want before you need it is worth more than any amount of programming. Stop leaves the rig lit, Fade Out takes it down over a second, and Blackout is immediate.

The three operator controls, and what each one does to the rig.
ControlWhat it doesWhen you want it
StopHolds the last safe look on the rig. Nothing changes until you act again.The automatic show is doing something you do not want, but you still need the room lit — a speech, an announcement, a band that has stopped playing.
Fade OutTakes the rig down over one second.A controlled ending. Gentle enough that a room full of people is not suddenly in the dark, which matters on stairs and near a crowd.
BlackoutImmediate. It sits next to the Auto toggle and takes effect at once.Something is wrong now. This is the control you should be able to find without looking, and the one every person who can touch the desk must know.

The reason these are three controls and not one is that "make it stop" means different things at different moments. An operator who only has Blackout will use Blackout for problems that did not need the room to go dark, and an operator who only has Stop has no way to end anything quickly.

What happens if the software itself hangs?

HitLight runs a native watchdog outside the interface that latches DMX output to an all-zero frame within two seconds if the app stops responding. Output stays down until an operator explicitly restores it. The design choice there is deliberate: a hung application should take the rig dark rather than leave the last frame on the wire indefinitely, and it should not quietly resume on its own once it recovers.

Note what that means in practice. A software fault produces darkness, not a stuck strobe — but it does produce darkness, on a live rig, with no warning. That is a scenario worth having a house-light answer for, in exactly the same way you would for a power cut.

Does "the software will not do it" mean the rig is safe?

No. The exclusion list means one specific thing: an automatic system will not fire those channel classes on its own. It says nothing about whether your rig is safe, because almost everything that makes a rig dangerous happens outside the software entirely. The operator remains responsible for all of the following, and no amount of restraint in an application transfers any of it.

  • Addressing and patching. A fixture patched in the wrong DMX mode will read the wrong channels for everything, which is how a value intended for a dimmer lands on something else. Confirm the mode and address on the physical unit, not on the patch sheet.
  • Rigging and installation. Clamps, safety bonds, load ratings, trim heights and what is underneath a fixture are mechanical questions with mechanical answers.
  • Electrical safety. Supply, protection, cable condition and inspection regimes are governed by local regulation and by your venue, not by a lighting application.
  • Atmospherics, lasers and pyro. If you fire them manually, every rule that applies to them still applies. The software declining to automate them is not permission to skip the risk assessment when you do it yourself.
  • Fixture profiles you generated. Generated profiles stay marked as drafts until you test the channels on the real fixture and confirm them, because a wrong profile is a wrong channel map and a wrong channel map is how surprises happen.
  • Venue rules and the audience in front of you. Warnings, signage, sightlines, egress lighting and who is standing where are yours.

How do you test Blackout at a new venue?

Test it before doors, every venue, every time. It takes fifteen seconds and it is the only way to know that the control you will reach for in a hurry is actually connected to the lights in front of you.

  1. 1

    Bring the rig up to a real look

    Not one fixture at 10% — a look with everything you intend to use lit, at the level you will actually run. Testing Blackout against an almost-dark rig proves nothing.

  2. 2

    Press Blackout and watch the room, not the screen

    Every fixture should go dark at once. If one stays lit, you have found an addressing or universe problem now rather than in front of an audience.

  3. 3

    Restore, and check what came back

    Confirm the rig returns to the look you left, and that nothing came back at the wrong level or the wrong colour.

  4. 4

    Show one other person where it is

    At least one person who is not you should be able to take the rig dark. In a venue, that is whoever is on shift; on a gig, it is whoever is standing nearest the desk.

Is any of this a substitute for venue safety procedures?

No. HitLight's exclusion list, strobe caps and watchdog are software behaviours, and they are not a substitute for venue safety procedures, risk assessments, local regulation or a competent person being responsible for the rig. They narrow one failure mode. Everything else on the list above is unchanged, and the person operating the show still carries it.

We would rather write that plainly than imply otherwise. Automatic lighting is useful precisely because it is boring about the dangerous parts, and a tool that claimed to have made your rig safe would be making a claim it is in no position to make.

The fuller policy, including how fixture profiles are verified and what the assistant is and is not allowed to reach, lives on lighting safety. What HitLight sends to a model, and what it never sends, is on AI and your data.

Try it on your own rig

Patch your fixtures, describe the look you want, and watch it on the 3D stage before you connect anything.

Free during the public beta, with no credit card. Launch pricing has not been announced. Requires macOS 14 or later for hardware output.