Vendor and Product Reality

Sandvik Mining and Rock Solutions ships AutoMine as a product family spanning single-machine teleremote operation through multi-machine fleet coordination for underground loaders and trucks, and surface and tele-operated drilling. Publicly, the platform is positioned to run on Sandvik's underground truck and loader ranges, to interoperate with Sandvik's production and information-management tooling, and to expose interfaces toward third-party fleet-management systems. Sandvik has reported AutoMine deployments at production scale across a number of large underground operations. Where this article references specific mine sites, deployment types, or interface standards, treat them as illustrative of the category rather than as verified specifications of any single installation.

Underground autonomy looks nothing like surface autonomy. There is no GNSS, lighting is artificial and dust-laden, drift walls are typically mapped by onboard LiDAR combined with inertial dead-reckoning, and traffic is mixed: autonomous machines can share haul drifts with manned support equipment around shift changes. AutoMine addresses this in part through an isolated production-area concept, a geofenced zone with access interlocks and a supervisory controller, inside which autonomous machines operate without human entry, and a teleremote envelope outside it. This is a mature, safety-conscious architecture, and the comparison below is not that AutoMine does this poorly. The comparison is about a specific structural axis: how a proposed actuation is evaluated, graduated, and verified after the fact.

Sandvik operates in a competitive field that includes Epiroc and Caterpillar underground autonomy offerings. A common commercial differentiator in this segment is fleet density, the number of autonomous machines a single supervisory controller can coordinate, benchmarked against manned baselines on throughput and availability. Governed actuation is orthogonal to that differentiator; it addresses how each commitment is governed, not how many machines are coordinated.

The Architectural Axis

In a conventional underground autonomy stack, a load-haul-dump cycle is encoded as a sequence of waypoints and actuation primitives, and mission handling tends toward a binary between executing the planned action and a hard fallback (stop in place and wait for human resolution). The architectural question governed actuation raises is not whether such a stack works, but whether the space between "execute at nominal magnitude" and "abort" is expressed as a first-class, policy-defined, auditable structure.

The distinction matters most at production-area boundaries and at draw-point loading. When a machine approaches a draw point, it commits to a bucket trajectory against a fragmentation model that may be stale; if the muck pile has shifted, a graduated response can degrade the fill rather than terminate the cycle. When a truck queues at a tip, it commits to a reverse-and-dump maneuver that depends on ore-pass geometry and on the vehicle ahead; a partial or stale sensor view is a candidate for a deferred commitment rather than a hard stop. Whether a given platform expresses these as graduated modes or as a binary is an architectural choice, not a defect, and it is the choice governed actuation makes explicit.

Regulators and operators are moving toward risk-based assurance for autonomous underground equipment, and toward demonstrable evidence that a machine executed the action its supervisory system authorized. Reconstructing that evidence from forensic logs after an incident is one approach; producing it as a designed-in artifact of every actuation is another. Governed actuation takes the second approach.

What Governed Actuation Provides

Governed actuation, as disclosed in U.S. Provisional Application No. 64/049,409, treats a physical actuation not as a direct command but as a governed, revocable, auditable act. A proposed actuation is passed through a composite admissibility evaluator that produces one of a graduated set of outcomes, disclosed as admit, gate, defer, solicit, reject, and escalate, over credentialed observations, an authority taxonomy, observation freshness, and governance policy. This is the structural primitive that a binary execute-or-abort model does not provide.

On top of that evaluation sits a graduated-actuation mode selector. Rather than a single go/no-go, the specification enumerates a plurality of policy-defined modes per actuator class, including disabled, simulated (dry run with no physical effect), advisory, consultative (emit and await confirmation), shadowed, partial (reduced magnitude), constrained (subject to spatial, temporal, or conditional limits), stage-gated (executed in interruptible stages), deferred, and full. As composite admissibility rises, the selector moves toward more autonomous modes; as it falls, it moves toward less autonomous ones, and it supports de-escalation of an actuation already in progress. Mapped onto a draw-point cycle, a fragmentation-versus-LiDAR disagreement beyond threshold selects a partial or constrained mode instead of an abort; a transient pose-uncertainty spike selects a deferred mode; an ore-pass geometry that violates policy yields a rejected commitment recorded with a typed rationale rather than a generic fault.

Reversibility is a first-class input. The specification discloses a reversibility-aware commitment-point evaluator that prefers reversible actuation paths where feasible, so that a machine biases toward commitments it can still back out of. Harm minimization is handled by a harm-minimization deviation mechanism that selects among candidate deviation paths under governance policy. In an underground context, harm is geometric and energetic: a degraded commitment should leave the machine off the ventilation circuit, clear of the haul path, and, on battery-electric loaders, above the reserve needed to clear the area under remote control. These are exactly the kind of constraints a harm-minimization deviation encodes, and the commitment-point evaluator biases the machine toward recoverable states rather than rescue-requiring ones.

Every one of these steps is recorded. The specification discloses lineage-recorded actuation provenance covering each admissibility evaluation, mode selection, preemption event, commitment-point determination, harm-minimization selection, and verification outcome. Post-actuation verification compares observed effects against an expected-effect specification produced at execution time, classifies any discrepancy (nominal, degraded-actuator, degraded-observation, environmental-perturbation, adversarial-interference, or policy-defined), and feeds the result back into confidence thresholds and the actuator's published capability envelope. The audit trail is a byproduct of how the system runs, not a reconstruction after the fact.

Composition Pathway

Nothing here displaces a certified safety layer. The specification is explicit that governed actuation is a governance layer over actuation, and it defers to authoritative safety hardware. In an AutoMine-style deployment, the on-machine safety controller, access-control interlocks, and e-stop network remain the authoritative safety layer; governed actuation sits above them, wrapping proposed waypoint and actuation messages as admissibility-evaluated, mode-graduated, verification-tagged variants. A skilled implementer would introduce the composite admissibility evaluator and mode selector at the boundary between the on-machine planner and the supervisory controller, leaving legacy clients seeing the same actuation surface while commitment-aware clients see the mode, the admissibility outcome, and the verification result.

Mesh coordination composes cleanly with existing arbitration. Where converging machines are resolved today by a centralized lock at the supervisory controller, governed actuation lets each machine publish its current and intended commitments and reduces the supervisory controller's role from synchronous arbiter to witness, which lessens sensitivity to the intermittent communications that dominate unplanned stops in deep-mine deployments. This is one embodiment; the same commitment vocabulary supports centralized, distributed, and hybrid topologies, and the specification discloses the composite admissibility evaluator operating identically across them.

Domain-specific verification is the natural integration point for a vendor's own intellectual property. The expected-effect predictors and discrepancy classifiers that encode a specific fragmentation model, an ore-pass tip check, or an articulation-against-drift-wall check are supplied by the operator or OEM; the governed-actuation reference primitive supplies the generic evaluator, mode selector, and lineage machinery into which those domain predictors plug. Embodiments range from a single actuator on a single machine to a mixed-fleet site sharing one commitment vocabulary across OEMs.

Commercial and Assurance Implication

The commercial logic follows the assurance logic. Operators adopting risk-based assurance frameworks increasingly want auditable evidence of post-actuation verification as a condition of approving autonomous deployment in new production areas. A platform that produces a typed, replayable commitment-and-verification record as a designed-in artifact shortens the path from acceptance testing to first autonomous production, because the evidence the assurance framework asks for already exists.

Because governed actuation is a shared substrate rather than an OEM-specific feature, a common commitment vocabulary is what lets mixed-fleet, brownfield sites interoperate at the supervisory layer without a bespoke integration per vendor. A vendor's competitive advantage in fleet density and domain-specific verification is preserved; the governed layer makes that advantage legible to operators, regulators, and the finance and insurance layers that increasingly price autonomy risk against the auditability of the supervisory record. A commitment lattice that records not only what a machine did but what it declined to do, and why, is a form of operational transparency that autonomous operations are now increasingly expected to provide.

Disclosure Scope

The inventive subject matter described here, composite-admissibility evaluation over credentialed observations, an authority taxonomy, and freshness and policy; graduated-actuation mode selection; reversibility-aware commitment-point evaluation; harm-minimization deviation; preemption budgets; post-actuation verification; and lineage-recorded actuation provenance with graceful degradation, is disclosed in U.S. Provisional Application No. 64/049,409. This article is a dated public disclosure of that subject matter and is intended to enable a skilled implementer to build a governed actuation layer over a physical actuation stack across the embodiments and variations described above.

All references to Sandvik, AutoMine, Epiroc, Caterpillar, specific mine sites, regulators, standards, and assurance frameworks are external context describing the market and technical landscape. Product names and marks are the property of their respective owners. Statements about any third-party product describe the general architecture of the category and are not claims of, or representations about, the internal implementation, certification status, or performance of any specific commercial system, nor are they part of the subject matter claimed in U.S. Provisional Application No. 64/049,409.