A meaningful share of male operators cannot reliably tell red from green, which is a problem when so many control screens use exactly that pair to mean stop and go or alarm and normal. A color-blind-safe HMI palette is a colour scheme designed so that those operators can still read every status correctly, and it works less by finding magic colours than by making sure colour is never the only thing carrying the meaning. This guide explains why red and green alone are risky, how redundant coding solves it, and how to build a palette that works for everyone.
Color-blind-safe palette in one line: A color-blind-safe HMI palette is an interface and alarm colour scheme designed so that operators with colour vision deficiency, roughly one in twelve men, can still distinguish every status. Because red and green are the hardest pair for the most common deficiencies, the key principle is redundant coding: status is also carried by shape, text, position, or blinking, so meaning is never conveyed by hue alone.
Colour vision deficiency is common, affecting a meaningful fraction of men and a much smaller fraction of women, and its most frequent forms, the red-green deficiencies, make it hard to distinguish exactly the colours control systems lean on most. To an operator with such a deficiency, a red alarm and a green normal state can look similar or even identical, which means a screen that signals trouble purely by turning something red may signal nothing at all to that operator. This is not a rare edge case; on any sizeable operating crew it is likely that someone is affected.
The risk is sharpened by how deeply the red-equals-bad, green-equals-good convention runs through industrial interfaces. Alarms, valve states, pump status, and permissives are all commonly shown with red and green, so a single deficiency can affect an operator's reading across the whole HMI rather than in one isolated place. When the entire signalling scheme rests on a colour distinction the operator cannot make, the interface quietly fails for them, and it can fail at the worst moment, when a fast, correct read of an alarm matters most.
It is also worth noting that colour perception degrades for everyone under real conditions, not only for those with a deficiency. Poor lighting, glare on a screen, aging displays, and fatigue all erode colour discrimination, so a design that leans entirely on subtle hue differences is fragile for the whole crew. Designing for colour vision deficiency therefore tends to produce an interface that is more robust for everyone, which is a large part of why the practice is worth adopting.
The central principle of accessible HMI design is redundancy: any status conveyed by colour should also be conveyed by at least one other visual attribute, so that an operator who cannot see the colour still gets the message. This is the single most important rule, because it means the design does not depend on finding colours that every operator can tell apart, but instead ensures that even when the colour is lost, the meaning survives through another channel. Colour becomes an enhancement rather than the sole carrier of information.
There are several channels that can carry that redundancy. Shape is a strong one, so an alarm might use a distinct outline or symbol shape rather than only a colour, and different alarm priorities can use different shapes. Text and labels remove all ambiguity by stating the condition in words, such as OPEN, CLOSED, or the alarm priority, which no colour deficiency can obscure. Position can encode meaning when a symbol's orientation or a marker's location reflects state. Blinking or flashing distinguishes an unacknowledged alarm regardless of its colour, and different fill patterns or textures can separate states that would otherwise rely on hue.
In practice a robust status indicator combines several of these. A high-priority alarm might be a particular shape, in a strong colour, with a priority number shown, and blinking until acknowledged, so it is unmistakable through shape, text, and motion even if its colour reads as something else. The design goal is that if you converted the whole screen to greyscale, an operator could still tell every state apart, which is a simple and revealing test of whether the interface truly depends on colour alone.
Beyond redundancy, the colours themselves can be chosen to help rather than hinder. Where colour is used, picking hues that remain distinguishable under common deficiencies, and relying on differences in lightness and not only in hue, gives operators the best chance of reading them, because lightness contrast survives most colour deficiencies even when hue does not. Palettes developed specifically to be distinguishable across the common deficiencies exist and can be adapted, and designers can check a proposed scheme by simulating how it appears under each type of deficiency before committing to it.
This fits naturally with high-performance HMI philosophy, which already argues for restrained use of colour: keeping normal states in muted, low-saturation tones and reserving strong colour for genuine abnormal conditions. That restraint helps accessibility because it reduces the number of colour distinctions an operator must make and makes each meaningful colour stand out more, and it pairs well with redundant coding because the few strong signals can each carry shape, text, and motion cues as well. Accessibility and good HMI design push in the same direction rather than pulling against each other.
For a distributed SCADA operation the case for an accessible palette is even stronger, because screens may be viewed on many different devices and in many conditions, from a control-room console to a phone in bright field sunlight. A cloud SCADA platform such as Merobix presents the same status colours and symbols across all those contexts, so building redundant, accessible coding into the standard symbols and alarm scheme once means every operator, on every device and with any colour vision, reads status the same way. Because the symbols and their state cues are defined centrally and reused across every site, accessibility is applied uniformly across the whole fleet rather than left to the choices made on individual screens.
Red-green colour vision deficiency is common among men, affecting roughly one in twelve, and much rarer among women. On any sizeable operating crew it is likely that at least one person is affected, so an interface that relies on distinguishing red from green cannot be assumed to work for everyone. This is why designing for colour vision deficiency is treated as a normal requirement rather than a niche concern.
Redundant coding means conveying a status through more than one visual attribute rather than colour alone, so meaning survives even when the colour cannot be seen. Common redundant channels are shape, text or labels, position, blinking, and fill patterns. A high-priority alarm, for example, might combine a distinct shape, a priority number, a strong colour, and blinking, so it is readable through several cues at once.
A quick test is to view the screen in greyscale: if you can still tell every state apart, the design does not depend on hue alone. Beyond that, tools can simulate how the screen appears under each type of colour vision deficiency, so you can verify that important distinctions still read. The most reliable approach is to ensure redundant coding so that no status is signalled by colour alone in the first place.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.