I tried to include as many links as possible to allow the reader to go down rabbit holes as they see fit.
I don’t work in an advanced or new fab, but have some glimpses into them.
I used Claude Sonnet 5 for two (2) text blocks and interactive animations. I disclose Claude’s writing for the text blocks. The animations are disclosed by this paragraph.
Philosophy
Automate Where Possible
Semiconductor Fabs III: The Data and Automation discusses why automation is so important in a fab from a material perspective: it’s faster, safer (for the product), easier, and cheaper. But it also applies physical safety as well. Humans in the loop can be catastrophic—they misinterpret something, make the wrong decision, perform the wrong action, or be really stupid. Having physical connections, electrical signals, and default safe conditions do the work minimizes the chance of taking the wrong action and enforces stupidity, just in the way that computers are stupid and do exactly what they’re told to.
All Intention, No Accidents
Sometimes safety mechanisms must be overridden for legitimate reasons. When this happens, it shouldn’t be an accident or something someone stumbled upon. Instead, it should be the physical equivalent of those annoying pop-up boxes making sure that continuing is the desired action. This almost feels like the equivalent of long-term nuclear waste warning messages: as one gets closer to fully overriding some protective measure, it should be more obvious that they probably shouldn’t be doing that.
(In)Conveniences
Safety should be easy. Doing the right thing should be easy. Doing the wrong thing should be difficult (see section directly above) and inconvenient. Trivial inconveniences exist and apply in the fab, even if the rules try to claim they don’t. People will be unsafe if being safe is too much of a pain in the ass.
Some examples of making safety easy and convenient:
Ensuring safety gear (hard hats, safety glasses, gloves) are adequately stocked in all necessary areas so employees don’t have to go searching for it.
Creating custom tools that are simple to find, simple to use, and make the job easier. The tool should have a designated storage location where users store it after use.
Avoiding pressuring employees to work faster than is safe or they are comfortable. Calling them four times in an hour to ask for “status updates” conveys something that feels more like desperation and pressure than urgency and checking in. Being kind and ensuring that safety is a top priority—and reflecting that in actions—is key to encouraging safe behavior.
Better Safe Than Sorry
When in doubt, take a step back and get a better idea. Some organizations use the PAUSE methodology (pause, assess, understand, share, execute), which is great! It gives someone who is uncomfortable a way to assess the situation at hand before continuing.
Everyone should be better safe than sorry (injured, maimed, dead). This could mean stopping work until someone more experienced can work on it, asking for help, or refusing to do something outright because it is a safety concern.
Redundancy
Shit happens. It can come in the form of a failed part, a forgotten procedure, or plain human mistakes. This is why redundancy is built in to the equipment and other methods. We want to have at least two points of “shit happening” before it can affect the worker!
when an employee is killed on the job or suffers a work-related hospitalization, amputation, or loss of an eye
Since I’m not an expert on OSHA violations, I asked Claude Sonnet 5 to summarize what happens:
When a semiconductor fab has a fatality, in-patient hospitalization, amputation, or loss of an eye, the clock starts immediately: employers must report a death to OSHA within 8 hours, and a hospitalization, amputation, or eye loss within 24 hours. Failing to report on time is itself a separate, citable violation under 29 CFR 1904.39.
Fatalities almost always trigger a full OSHA inspection, and severe injuries frequently do — especially in a hazard-dense environment like a fab, with toxic gases, high-voltage equipment, and cleanroom chemical exposure. Employers are also required to preserve the incident scene until OSHA releases it, which can mean idling the affected tool or line for days or weeks while the investigation runs.
The costs that outlast the headline fine are often the bigger operational hit: a spike in the company’s workers’ compensation experience modification rate (raising premiums for years), disqualification from safety-prequalified client contracts, and — for repeat or egregious cases — placement in OSHA’s Severe Violator Enforcement Program, which brings mandatory follow-up inspections. For a fab, where a single tool going down can stall an entire process flow, the downtime from a scene-preservation hold or a corrective-action order is frequently more costly than the citation itself.
I’m unable to find papers rigorously quantifying downtime impact in terms of $/hr, although it’s certainly a lot. Engineers and technicians may have to physically fix the equipment, parts may break and require replacement (money and time), equipment has to get requalified, and line speed drops substantially as a result of all the delays associated with each of those. Time and money are the name of the game!
Reputation
Being known as an unsafe company speaks volumes about the culture, repelling potential talent and pushing them towards places where they know they’ll get to see their family at the end of the day.
The People
Mandatory Clothing
Let’s first dispel the myth that the cleanroom suits fab personnel wear are for the people’s safety. They are not. They are for the chip’s safety. They serve to prevent the wearer’s skin and hair from getting onto the chips. We lose a fair amount of skin and hair every day and any of that falling on a chip can be catastrophic, even existential. Why risk this when you can simply doom your wage slaves to a day of sweat, discomfort, and modesty?
Next, we’ll move onto a fit check. Safety glasses? Check. But those better be ANSI Z87.1 or OSHA will want a word. Z87.1 is focused on minimizing and/or preventing injuries such as “impact, non-ionizing radiation and liquid splash exposures in occupational and educational environments such as machinery operations, material welding and cutting, chemical handling, and assembly operations”. Fabs are a place where liquid can splash, parts can fall through the floor into the subfab below, and both very high and very low pressure environments can fail (also known as explode and implode, respectively) if the right sequence of events happens. I’d want to protect my eyes, too!
40 kg. Imagine having to move this by hand and dropping it on your toe. Your toe would cease to exist.
Shoe-wise, some folks like rocking the Nike Fab 11s, which is my overused joke for steel-toed boots. (Nike or Jordan really should start supplying cleanroom boots for the collab potential—just imagine a TSMC x Air Jordan.) Fabs are basically just filled with super fancy, super expensive machinery. And machinery comes with heavy parts that people may need to carry around. I’d want to protect my toes from a big block of steel from falling on them, too! (To be clear, steel-toed boots aren’t required at my fab, but can be purchased.)
That’s about it for mandatory clothing. Wear some safety glasses, wear something on your feet, and wear a bunny suit. And gloves! But those are also for the wafer’s protection. What’s between the bunny suit and skin is pretty much up to the person—I’ve seen some questionable shirts while walking through the office!
Sometimes-Needed Clothing
Sometimes special garments must be donned for safety purposes, generally when someone is entering an area where special dangers exist.
Acid Clothing
There are a lot of acids in a fab: hydrofluoric, sulfuric, phosphoric, just to name a few. All of them are harmful to the human body, so we protect it by wearing:
Tychem suits: This godforsaken suit has zero breathability whatsoever. It feels like it is constantly exchanging dry air for humid air to make the inside of the suit even hotter. Their unofficial motto is “start sweating within 30 seconds guaranteed or your money back!”. I’ve never gotten my money back. In all seriousness, the lack of breathability is by design. I don’t want some horrible liquid leaking through the fabric if it spills on me!
Face shield: Covers the entire face, not just the eyes. I like my face without any burns or holes, thank you very much.
Acid gloves: More protection in case you need to handle something around acid.
Electrical Clothing
Arc flashes are no joke and will fry your skin to a crisp if you aren’t wearing equipment. If you are wearing equipment, then at least it’ll be an open casket funeral. Electrical work in certain areas, especially when “hot” (or electricity is live), requires arc flash equipment that is not dissimilar to a bomb suit (which it’s colloquially called by electricians), minus the protection against shrapnel.
Head Protection
Hard hats are required in spaces where you can easily hit your head on something or parts can fall down from above. Some people wear bump caps in confined spaces to protect against bumps, but they are no substitute for hard hats when falling objects are a risk.
SCBA
Robotic dexterity hasn’t caught up to humans yet, so we still occasionally have to do some nasty work with gases and chemical that requires self-contained breathing apparatuses (SCBA; note the lack of a ‘U’(nderwater) since fabs aren’t underwater). SCBA users get fit checks before using it to ensure the mask seals securely against their face. Not coincidentally, it’s also the only time some people shave their beards—this helps the mask better seal against the face, else the hair would cause leaks.
Practices
The practice that keeps you safe 99% of the time—where the 1% is the unpredictable, unexplainable, unstoppable shit that very rarely happens, and much less often affects someone when it does happen—is pretty simple: don’t be an idiot. I stop and ask myself “if someone else did this and got hurt because of it, would I think they’re an idiot?” before doing something potentially dangerous and if the answer is yes, I reassess my strategy and refine my plan until the answer is no. There are other, more official strategies like PAUSE.
Not on the via negativa side of things, being a clear, loud communicator is important when working with a partner. There are many loud noises and dangerous situations that require messages to be received correctly lest the receiver act based on an incorrect message.
My modus operandi is a command-acknowledgement structure of:
The person in the dangerous position (pd) commands the person in the safe position (ps) what to do. This prevents ps from doing something that endangers pd.
ps acknowledges the command by verbally repeating it, waiting a second, then performing the command. pd should be in a safe position since they know what’s about to happen.
Ex: ps replies by saying “moving robot1 blade1 10 counts forward”, then waits a moment, then issues a robot command to move 10 counts forward
Repeat as needed for the rest of the work.
Other commands-responses may be hold-holding, lift-lifting, etc.
a safety procedure that ensures dangerous equipment is properly shut off and not able to be restarted prior to the completion of maintenance or repair work. It requires that hazardous energy sources be “isolated and rendered inoperative” before work is started on the equipment in question. The isolated power sources are then locked and a tag is placed on the lock identifying the worker and reason the LOTO is placed on it. The worker then holds the key for the lock, ensuring that only that worker can remove the lock and start the equipment. This prevents accidental startup of equipment while it is in a hazardous state or while a worker is in direct contact with it.
This system is incredibly effective provided the worker actually follows it. Equipment is designed so that at least the main power switch can be locked out. Other individual components (such as RF power generators) may have LOTO capabilities on their associated electrical breakers so that the equipment as a whole may operate as normal except for said component; this is to allow troubleshooting or maintenance that requires general power, but doesn’t require that specific component. (To connect this with the Interlocks section, interlocks should prevent any of these bad components from turning on if someone is working on the equipment, but there may be some freak accident, so LOTO is a foolproof way of eliminating the risk.)
LOTO locks can be removed by someone other than the owner under certain circumstances that must be run through the site’s safety lead. If it’s removed without consulting said person and someone finds out, bye bye!
Procedures are important because they standardize tasks into best known methods to ensure consistency, quality, and safety when performed. By documenting them into an easy-to-read, step-by-step format, workers won’t miss any safety-related subtasks.
An interlock is a feature or device that is commonly used in engineering and safety systems to keep machines, devices, and processes from operating until the guards are in place or the required circumstances are met. When being utilized, interlocks are used to prevent or reduce the chances of injury to the operator, damage to the equipment, and actions being completed in the wrong order or in an unsafe way.
Fab equipment is filled with interlocks of various types:
Hardware: Enabled or disabled by jumper configuration, these can be physically changed at the tool, but require specialized knowledge of what to move and where.
Software: Written into the equipment’s programs, these are effectively absolute. There exist ways to trick the interlocks into being satisfied to allow, but these are a very quick ticket to the unemployment line if done improperly.
What are some examples of interlocks? Let’s look at this random interlock card I found on the internet!
Going down the list in a non-exhaustive manner:
GP OK: Is the gas panel door closed and are any other issues present?
SLT VLV CLSD: This is the “door” to the buffer chamber where the robot that transfers wafer in and out of the chamber exists. The SV being open could expose the buffer to nasty gases, which could in turn contaminate other chamber if said gases lingered for too long. Overridden by taking a magnet and tricking the sensor that detects the SV being open or closed.
CUST VAC: Not exactly sure, but this means customer vacuum, so likely verifying the facility is pulling vacuum somewhere.
RGH PUMP FAIL: Checks if the pump is in a good state?
CHAM LID CVR: There’s a cover that sits over the chamber lid itself, likely to protect against electricity or other hazards. This needs to be installed for the interlock to be satisfied.
CHAM LID: The chamber lid needs to be closed because we don’t want to flow nasty gases into the fab air.
HTR HUB OT: The heater hub temperatures needs to be low enough for the interlock to be satisfied.
Why would someone want to override these interlocks? After all, they’re there for our safety! This is true, but sometimes overriding interlocks is needed to troubleshoot. For example, watching problematic robots move while troubleshooting is very helpful in order to hear noises, feel vibrations, watch for jerky movements, etc. But often times the only way to get a clear view is to override interlocks. The equipment manufacturers understand this and make it easy enough to override interlocks while ensuring it’s intentional.
Tools will output alarms (or warnings, which are less severe and disruptive) that will result from abnormal conditions, which aren’t necessarily always a safety hazard, but can be. This may stop the tool from processing to prevent something small from turning catastrophic. For example, a low water flow fault may be the result of a large leak. If the tool kept processing and applying gross amounts of power that eventually connected with the water, then neither the tool nor the equipment engineer would have a very fun day.
Ergonomics
Equipment parts can be heavy and often cumbersome to lift because the equipment’s small footprint doesn’t allow for personnel to get easy leverage on said parts. It can be a jungle inside, underneath, or on top of equipment!
It’s a lot of parts in a small footprint!
Equipment manufacturers will often include various ergonomic fixtures to help personnel with maintenance. Examples may include motorized cranes that can assist with lifting parts straight up and down instead of forcing personnel to come from the side; fixtures to compress high-pressure gas springs; and specialized tools that fit in certain areas to minimize potential pinch points or awkward angles for employees.
If custom solutions are required, then fabs can outsource to companies who will build tools to their specification. For example, take this lift from Alum-a-Lift:
No idea what is does besides lift lithography equipment, but looks cool!
(Not super-related to safety: fabs often have their own machine shops on-site that engineers can send drawings to for quick prototyping. These have most of the standard shop equipment—mills, lathes, bandsaws, drill presses—so most things can get done. If they don’t have the capability or capacity, the job may be sent to a larger shop that the company works with.)
The Emergency Off Circuit, or The Big Red Button
All equipment comes equipped with emergency off (EMO) buttons at strategic locations to maximize accessibility. When pressed, the entire tool and anything external connected to the EMO circuit shuts off immediately because the physical connection is severed. Uninterruptible power supplies (UPS) will generally be connected to equipment computers to maintain data and allow for proper shut down if needed.
Why would someone want to press the EMO button? Here are some example situations:
Pyrophoric gas, or gas that ignites into flames when exposed to air is leaking from the tool. Pressing the EMO button will cause all valves related to that gas to close immediately, stopping the leak (this is presuming a weld or something didn’t break, of which there are other solutions since a valve may not be able to stop that depending on where it is).
A robot is actively pressing against a person who wasn’t aware it was still able to move. Pressing the EMO button will turn off the robots motor and allow the person to move the robot out of the way.
A water line is leaking water all over sensitive electronics. Pressing the EMO button will turn off valves and stop water flow.
Example of EMO and “Robot Interrupt” buttons, the latter of which stops the robot without powering off the equipment
Because power is removed from everything, parts will default to the power-off state, which is generally synonymous with “safest state”. For example, valves that control the flow of gases can be either normally-open (N/O; power off means gas can flow) or normally-closed (N/C; power off means gas cannot flow). Valve states are strategically chosen based on the gas: purge gases that help dilute toxic gases, like nitrogen, have N/O valves so that if power shuts off, the equipment gets purged properly; toxic gases have N/C valves so that they stop flowing immediately upon power off. The orientations are physically manufactured, so the only way that someone can mess up is by installing the wrong valve, which is mitigated by labeling and different colors.
I’ve pressed an EMO button once in my life, but that was at my university fab and because of a major operator error. EMO presses at the industrial level are rare because of how well the equipment is designed and the people are trained. You do not want to press the EMO! If you are pressing the EMO, your day is probably really bad or about to get really bad! (I’ll admit that pressing the EMO is kind of fun because of how forbidden it is and its nice tactile feel, so if the equipment is ever off do yourself a favor and get a nice lil’ press in.)
The Building
The building itself—the foundation, the trusses, the waffle floor—isn’t anything special, but rather the features and systems that interact with the equipment and facilities.
Fire Suppression Systems
NPFA 318: Standard for the Protection of Semiconductor Fabrication Facilities “presents requirements to safeguard facilities containing cleanrooms from fire and related hazards to protect against injury, loss of life, and property damage”. (Note the linked document is from 2006 because I couldn’t find an updated one on the internet.) Here are some nice features:
Optical flame detectors that will respond to the flame signature of silane shall be provided at silane gas cylinders in the open dispensing systems described in Section 8.4. Activation of detectors shall result in the closing of the cylinder automatic shutoff valves described in 8.1.2.
A local visual and audible alarm shall be provided to indicate activation of any interlock. [Intentionally silencing the alarm is much better than not hearing it at all.]
Tools utilizing hazardous chemicals shall be designed to accept inputs from monitoring equipment. [This allows the monitoring equipment to tell the tool to shut off because something is wrong.]
They seem to really care about silane given it has two subsections and one main section devoted entirely to the gas!
Gas detectors are placed at strategic locations to maximize detection capabilities so the faster it’s detected, the sooner it can be stopped and fixed.
Gas detectors smelling arsine knowing full well some shit has hit the fan
Some places that gas detectors are located:
Exhaust: Vacuum chambers and places that have one barrier of protection between hazardous gases and humans (e.g., gas panel gas lines) have exhaust pipes that are connected to vacuum pumps, creating slight negative pressure and pulling in any gases in the volume it’s connected to. Gas detectors are connected to these pipes and constantly monitoring for any nasty gases. If it detects any, there is definitely something wrong, so it sends a signal to stop the tool and/or stop the gas flow on the facility side.
Gas Cabinets: Similar to the exhaust pip detectors, some gases are housed in standalone cabints to improve detection capabilities (smaller volume means a larger concentration per a constant leak) and improve safety.
Some gases are housed in double-walled pipes, where the pipe that carries the main gas is enclosed within another pipe filled with an inert gas, such as nitrogen. This creates an added layer of safety and immediately dilutes the dangerous gas.
General Mortality and Disease Rates for Fab Employees
I’ve heard some crazy health-related rumors throughout my fab life: exposure to photoresist will cause men to become sterile; photoresist will cause women to only have female children; working in a fab will make you go clinically insane because of the long hours and insane pressure and mind-boggling physics that make magic seem real.
That said, fabs are incredibly safe thanks to the equipment manufacturers and fab companies working together to minimize their liability take care of their precious employees. Here’s Claude’s response after researching semiconductor fab deaths and major safety incidents:
Looking at recent history, the semiconductor industry’s fatal incidents fall into three distinct categories, and conflating them overstates the risk of actually working in an operating fab.
A third, distinct category is long-latency illness from chemical exposure, which shows up in the data as elevated disease risk rather than a single incident. A cohort study of South Korean semiconductor workers employed between 1998 and 2012 found elevated leukemia mortality specifically among female wafer-fab line operators, though not across the workforce as a whole.
Taken together, the pattern suggests that acute fatalities on an active fab floor are genuinely uncommon; most of the fatal incidents making headlines happen during the construction of new fabs, which carries risks more typical of large industrial construction generally rather than semiconductor manufacturing itself.
Preface
I tried to include as many links as possible to allow the reader to go down rabbit holes as they see fit.
I don’t work in an advanced or new fab, but have some glimpses into them.
I used Claude Sonnet 5 for two (2) text blocks and interactive animations. I disclose Claude’s writing for the text blocks. The animations are disclosed by this paragraph.
Philosophy
Automate Where Possible
Semiconductor Fabs III: The Data and Automation discusses why automation is so important in a fab from a material perspective: it’s faster, safer (for the product), easier, and cheaper. But it also applies physical safety as well. Humans in the loop can be catastrophic—they misinterpret something, make the wrong decision, perform the wrong action, or be really stupid. Having physical connections, electrical signals, and default safe conditions do the work minimizes the chance of taking the wrong action and enforces stupidity, just in the way that computers are stupid and do exactly what they’re told to.
All Intention, No Accidents
Sometimes safety mechanisms must be overridden for legitimate reasons. When this happens, it shouldn’t be an accident or something someone stumbled upon. Instead, it should be the physical equivalent of those annoying pop-up boxes making sure that continuing is the desired action. This almost feels like the equivalent of long-term nuclear waste warning messages: as one gets closer to fully overriding some protective measure, it should be more obvious that they probably shouldn’t be doing that.
(In)Conveniences
Safety should be easy. Doing the right thing should be easy. Doing the wrong thing should be difficult (see section directly above) and inconvenient. Trivial inconveniences exist and apply in the fab, even if the rules try to claim they don’t. People will be unsafe if being safe is too much of a pain in the ass.
Some examples of making safety easy and convenient:
Better Safe Than Sorry
When in doubt, take a step back and get a better idea. Some organizations use the PAUSE methodology (pause, assess, understand, share, execute), which is great! It gives someone who is uncomfortable a way to assess the situation at hand before continuing.
Everyone should be better safe than sorry (injured, maimed, dead). This could mean stopping work until someone more experienced can work on it, asking for help, or refusing to do something outright because it is a safety concern.
Redundancy
Shit happens. It can come in the form of a failed part, a forgotten procedure, or plain human mistakes. This is why redundancy is built in to the equipment and other methods. We want to have at least two points of “shit happening” before it can affect the worker!
Redundancy comes in the form of interlocks, safety practices, and proper procedures.
Why Does Safety Matter?
Liability
Reportable incidents are defined by OSHA as:
Since I’m not an expert on OSHA violations, I asked Claude Sonnet 5 to summarize what happens:
I’m unable to find papers rigorously quantifying downtime impact in terms of $/hr, although it’s certainly a lot. Engineers and technicians may have to physically fix the equipment, parts may break and require replacement (money and time), equipment has to get requalified, and line speed drops substantially as a result of all the delays associated with each of those. Time and money are the name of the game!
Reputation
Being known as an unsafe company speaks volumes about the culture, repelling potential talent and pushing them towards places where they know they’ll get to see their family at the end of the day.
The People
Mandatory Clothing
Let’s first dispel the myth that the cleanroom suits fab personnel wear are for the people’s safety. They are not. They are for the chip’s safety. They serve to prevent the wearer’s skin and hair from getting onto the chips. We lose a fair amount of skin and hair every day and any of that falling on a chip can be catastrophic, even existential. Why risk this when you can simply doom your wage slaves to a day of sweat, discomfort, and modesty?
Next, we’ll move onto a fit check. Safety glasses? Check. But those better be ANSI Z87.1 or OSHA will want a word. Z87.1 is focused on minimizing and/or preventing injuries such as “impact, non-ionizing radiation and liquid splash exposures in occupational and educational environments such as machinery operations, material welding and cutting, chemical handling, and assembly operations”. Fabs are a place where liquid can splash, parts can fall through the floor into the subfab below, and both very high and very low pressure environments can fail (also known as explode and implode, respectively) if the right sequence of events happens. I’d want to protect my eyes, too!
40 kg. Imagine having to move this by hand and dropping it on your toe. Your toe would cease to exist.
Shoe-wise, some folks like rocking the Nike Fab 11s, which is my overused joke for steel-toed boots. (Nike or Jordan really should start supplying cleanroom boots for the collab potential—just imagine a TSMC x Air Jordan.) Fabs are basically just filled with super fancy, super expensive machinery. And machinery comes with heavy parts that people may need to carry around. I’d want to protect my toes from a big block of steel from falling on them, too! (To be clear, steel-toed boots aren’t required at my fab, but can be purchased.)
NanoBanana coming for Tinker Hatfield‘s job
That’s about it for mandatory clothing. Wear some safety glasses, wear something on your feet, and wear a bunny suit. And gloves! But those are also for the wafer’s protection. What’s between the bunny suit and skin is pretty much up to the person—I’ve seen some questionable shirts while walking through the office!
Sometimes-Needed Clothing
Sometimes special garments must be donned for safety purposes, generally when someone is entering an area where special dangers exist.
Acid Clothing
There are a lot of acids in a fab: hydrofluoric, sulfuric, phosphoric, just to name a few. All of them are harmful to the human body, so we protect it by wearing:
Electrical Clothing
Arc flashes are no joke and will fry your skin to a crisp if you aren’t wearing equipment. If you are wearing equipment, then at least it’ll be an open casket funeral. Electrical work in certain areas, especially when “hot” (or electricity is live), requires arc flash equipment that is not dissimilar to a bomb suit (which it’s colloquially called by electricians), minus the protection against shrapnel.
Head Protection
Hard hats are required in spaces where you can easily hit your head on something or parts can fall down from above. Some people wear bump caps in confined spaces to protect against bumps, but they are no substitute for hard hats when falling objects are a risk.
SCBA
Robotic dexterity hasn’t caught up to humans yet, so we still occasionally have to do some nasty work with gases and chemical that requires self-contained breathing apparatuses (SCBA; note the lack of a ‘U’(nderwater) since fabs aren’t underwater). SCBA users get fit checks before using it to ensure the mask seals securely against their face. Not coincidentally, it’s also the only time some people shave their beards—this helps the mask better seal against the face, else the hair would cause leaks.
Practices
The practice that keeps you safe 99% of the time—where the 1% is the unpredictable, unexplainable, unstoppable shit that very rarely happens, and much less often affects someone when it does happen—is pretty simple: don’t be an idiot. I stop and ask myself “if someone else did this and got hurt because of it, would I think they’re an idiot?” before doing something potentially dangerous and if the answer is yes, I reassess my strategy and refine my plan until the answer is no. There are other, more official strategies like PAUSE.
Not on the via negativa side of things, being a clear, loud communicator is important when working with a partner. There are many loud noises and dangerous situations that require messages to be received correctly lest the receiver act based on an incorrect message.
My modus operandi is a command-acknowledgement structure of:
Lockout/Tagout
The Lockout/tagout (LOTO) Wikipedia page does a good job of explaining it:
This system is incredibly effective provided the worker actually follows it. Equipment is designed so that at least the main power switch can be locked out. Other individual components (such as RF power generators) may have LOTO capabilities on their associated electrical breakers so that the equipment as a whole may operate as normal except for said component; this is to allow troubleshooting or maintenance that requires general power, but doesn’t require that specific component. (To connect this with the Interlocks section, interlocks should prevent any of these bad components from turning on if someone is working on the equipment, but there may be some freak accident, so LOTO is a foolproof way of eliminating the risk.)
LOTO locks can be removed by someone other than the owner under certain circumstances that must be run through the site’s safety lead. If it’s removed without consulting said person and someone finds out, bye bye!
Click here to test your LOTO skills!
Procedures
Procedures are important because they standardize tasks into best known methods to ensure consistency, quality, and safety when performed. By documenting them into an easy-to-read, step-by-step format, workers won’t miss any safety-related subtasks.
The Equipment
Interlocks
From Wikipedia:
Fab equipment is filled with interlocks of various types:
What are some examples of interlocks? Let’s look at this random interlock card I found on the internet!
Going down the list in a non-exhaustive manner:
Why would someone want to override these interlocks? After all, they’re there for our safety! This is true, but sometimes overriding interlocks is needed to troubleshoot. For example, watching problematic robots move while troubleshooting is very helpful in order to hear noises, feel vibrations, watch for jerky movements, etc. But often times the only way to get a clear view is to override interlocks. The equipment manufacturers understand this and make it easy enough to override interlocks while ensuring it’s intentional.
Click here to play an interlock game!
Alarms
Tools will output alarms (or warnings, which are less severe and disruptive) that will result from abnormal conditions, which aren’t necessarily always a safety hazard, but can be. This may stop the tool from processing to prevent something small from turning catastrophic. For example, a low water flow fault may be the result of a large leak. If the tool kept processing and applying gross amounts of power that eventually connected with the water, then neither the tool nor the equipment engineer would have a very fun day.
Ergonomics
Equipment parts can be heavy and often cumbersome to lift because the equipment’s small footprint doesn’t allow for personnel to get easy leverage on said parts. It can be a jungle inside, underneath, or on top of equipment!
It’s a lot of parts in a small footprint!
Equipment manufacturers will often include various ergonomic fixtures to help personnel with maintenance. Examples may include motorized cranes that can assist with lifting parts straight up and down instead of forcing personnel to come from the side; fixtures to compress high-pressure gas springs; and specialized tools that fit in certain areas to minimize potential pinch points or awkward angles for employees.
If custom solutions are required, then fabs can outsource to companies who will build tools to their specification. For example, take this lift from Alum-a-Lift:
No idea what is does besides lift lithography equipment, but looks cool!
(Not super-related to safety: fabs often have their own machine shops on-site that engineers can send drawings to for quick prototyping. These have most of the standard shop equipment—mills, lathes, bandsaws, drill presses—so most things can get done. If they don’t have the capability or capacity, the job may be sent to a larger shop that the company works with.)
The Emergency Off Circuit, or The Big Red Button
All equipment comes equipped with emergency off (EMO) buttons at strategic locations to maximize accessibility. When pressed, the entire tool and anything external connected to the EMO circuit shuts off immediately because the physical connection is severed. Uninterruptible power supplies (UPS) will generally be connected to equipment computers to maintain data and allow for proper shut down if needed.
Why would someone want to press the EMO button? Here are some example situations:
Example of EMO and “Robot Interrupt” buttons, the latter of which stops the robot without powering off the equipment
Because power is removed from everything, parts will default to the power-off state, which is generally synonymous with “safest state”. For example, valves that control the flow of gases can be either normally-open (N/O; power off means gas can flow) or normally-closed (N/C; power off means gas cannot flow). Valve states are strategically chosen based on the gas: purge gases that help dilute toxic gases, like nitrogen, have N/O valves so that if power shuts off, the equipment gets purged properly; toxic gases have N/C valves so that they stop flowing immediately upon power off. The orientations are physically manufactured, so the only way that someone can mess up is by installing the wrong valve, which is mitigated by labeling and different colors.
Click here to test your valve knowledge!
I’ve pressed an EMO button once in my life, but that was at my university fab and because of a major operator error. EMO presses at the industrial level are rare because of how well the equipment is designed and the people are trained. You do not want to press the EMO! If you are pressing the EMO, your day is probably really bad or about to get really bad! (I’ll admit that pressing the EMO is kind of fun because of how forbidden it is and its nice tactile feel, so if the equipment is ever off do yourself a favor and get a nice lil’ press in.)
The Building
The building itself—the foundation, the trusses, the waffle floor—isn’t anything special, but rather the features and systems that interact with the equipment and facilities.
Fire Suppression Systems
NPFA 318: Standard for the Protection of Semiconductor Fabrication Facilities “presents requirements to safeguard facilities containing cleanrooms from fire and related hazards to protect against injury, loss of life, and property damage”. (Note the linked document is from 2006 because I couldn’t find an updated one on the internet.) Here are some nice features:
They seem to really care about silane given it has two subsections and one main section devoted entirely to the gas!
Gases
Some gases that fabs use have very low median lethal doses (arsine to phosphine), low flammability limits, or are asphyxiants. I’ve heard the high-(LD/LC)50 gases referred to as “two-step gases” because once you inhale them and take two steps, you’re dead. Here are the most toxic gases in a fab (and an explanation on LC50 and LD50):
Gas detectors are placed at strategic locations to maximize detection capabilities so the faster it’s detected, the sooner it can be stopped and fixed.
Gas detectors smelling arsine knowing full well some shit has hit the fan
Some places that gas detectors are located:
Some gases are housed in double-walled pipes, where the pipe that carries the main gas is enclosed within another pipe filled with an inert gas, such as nitrogen. This creates an added layer of safety and immediately dilutes the dangerous gas.
General Mortality and Disease Rates for Fab Employees
I’ve heard some crazy health-related rumors throughout my fab life: exposure to photoresist will cause men to become sterile; photoresist will cause women to only have female children; working in a fab will make you go clinically insane because of the long hours and insane pressure and mind-boggling physics that make magic seem real.
That said, fabs are incredibly safe thanks to the equipment manufacturers and fab companies working together to
minimize their liabilitytake care of their precious employees. Here’s Claude’s response after researching semiconductor fab deaths and major safety incidents:See Also