The Gatekeeper


After the security ‘bot brings Eve across the ship (with Wall-e in tow), he arrives at the gatekeeper to the bridge. The Gatekeeper has the job of entering information about ‘bots, or activating and deactivating systems (labeled with “1”s and “0”s) into a pedestal keyboard with two small manipulator arms. It’s mounted on a large, suspended shaft, and once it sees the security ‘bot and confirms his clearance, it lets the ‘bot and the pallet through by clicking another, specific button on the keyboard.

The Gatekeeper is large. Larger than most of the other robots we see on the Axiom. It’s casing is a white shell around an inner hardware. This casing looks like it’s meant to protect or shield the internal components from light impacts or basic problems like dust. From the looks of the inner housing, the Gatekeeper should be able to move its ‘head’ up and down to point its eye in different directions, but while Wall-e and the security ‘bot are in the room, we only ever see it rotating around its suspension pole and using the glowing pinpoint in its red eye to track the objects its paying attention to.

When it lets the sled through, it sees Wall-e on the back of the sled, who waves to the Gatekeeper. In response, the Gatekeeper waves back with its jointed manipulator arm. After waving, the Gatekeeper looks at its arm. It looks surprised at the arm movement, as if it hadn’t considered the ability to use those actuators before. There is a pause that gives the distinct impression that the Gatekeeper is thinking hard about this new ability, then we see it waving the arm a couple more times to itself to confirm its new abilities.


The Gatekeeper seems to exist solely to enter information into that pedestal. From what we can see, it doesn’t move and likely (considering the rest of the ship) has been there since the Axiom’s construction. We don’t see any other actions from the pedestal keys, but considering that one of them opens a door temporarily, it’s possible that the other buttons have some other, more permanent functions like deactivating the door security completely, or allowing a non-authorized ‘bot (or even a human) into the space.

An unutilized sentience

The robot is a sentient being, with a tedious and repetitive job, who doesn’t even know he can wave his arm until Wall-e introduces the Gatekeeper to the concept. This fits with the other technology on board the Axiom, with intelligence lacking any correlation to the robot’s function. Thankfully for the robot, he (she?) doesn’t realize their lack of a larger world until that moment.

So what’s the pedestal for?

It still leaves open the question of what the pedestal controls actually do. If they’re all connected to security doors throughout the ship, then the Gatekeeper would have to be tied into the ship’s systems somehow to see who was entering or leaving each secure area.

The pedestal itself acts as a two-stage authentication system. The Gatekeeper has a powerful sentience, and must decide if the people or robots in front of it are allowed to enter the room or rooms it guards. Then, after that decision, it must make a physical action to unlock the door to enter the secure area. This implies a high level of security, which feels appropriate given that the elevator accesses the bridge of the Axiom.

Since we’ve seen the robots have different vision modes, and improvements based on their function, it’s likely that the Gatekeeper can see more into the pedestal interface than the audience can, possibly including which doors each key links to. If not, then as a computer it would have perfect recall on what each button was for. This does not afford a human presence stepping in to take control in case the Gatekeeper has issues (like the robots seen soon after this in the ‘medbay’). But, considering Buy-N-Large’s desire to leave humans out of the loop at each possible point, this seems like a reasonable design direction for the company to take if they wanted to continue that trend.

It’s possible that the pedestal was intended for a human security guard that was replaced after the first generation of spacefarers retired. Another possibility is that Buy-N-Large wanted an obvious sign of security to comfort passengers.

What’s missing?

We learn after this scene that the security ‘bot is Otto’s ‘muscle’ and affords some protection. Given that the Security ‘bot and others might be needed at random times, it feels like he would want a way to gain access to the bridge in an emergency. Something like an integrated biometric scanner on the door that could be manually activated (eye scanner, palm scanner, RFID tags, etc.), or even a physical key device on the door that only someone like the Captain or trusted security officers would be given. Though that assumes there is more than one entrance to the bridge.

This is a great showcase system for tours and commercials of an all-access luxury hotel and lifeboat. It looks impressive, and the Gatekeeper would be an effective way to make sure only people who are really supposed to get into the bridge are allowed past the barriers. But, Buy-N-Large seems to have gone too far in their quest for intelligent robots and has created something that could be easily replaced by a simpler, hard-wired security system.


Wall-E’s Audio Recorder


Each Wall-E unit has an integrated audio recorder with three buttons: Record, Play, and a third button with an orange square. We see Record and Play used several times, but the orange button is never visibly pressed. Reason and precedent suggest it is a stop function.

What the original purpose of this capability is unclear. Wall-E uses it to record snippets of songs or audio clips from movie that he enjoys. There is no maximum length shown. There is no visible method to rewind, fast forward, or seek along the soundbite, though the clips shown are short enough that it doesn’t affect Wall-E’s ability to hear what he wants to hear.



This is a very simple interface, and Wall-E is shown being able to operate it without looking at the buttons. Since all three are relatively large, placed on the front of his chest, have physical indentions, and are physically separated, it would be possible for a person with a tactile sense to tell the buttons apart once they learned the order of buttons.

Increasing the indentation of the symbols, and adding a different texture on each would make tactile discovery even easier.


The recording capabilities shown are also short. This means that it is excellent for a contained thought, song, or event to be referenced later. Short clips allow the user of the system (in this case Wall-E) to never need to worry about where the recording is cued up to, and play whatever it is he remembers being in memory.

The Orange Button?

Unlike the Play and Record buttons, which are shown meeting standard interface practices of today, the lineup has that odd orange button that is never shown being used (except when Eve is frantically trying to wake Wall-E up, but that tells us nothing about its intended use).

My best guess, based only on its inclusion with the other two buttons, is that it represents a pause function or stop. This conjecture isn’t 100% certain because either function could easily be co-located on the play button as a dual function. Push once to play, push a second time to pause.

So what is the orange button for?

No idea.

The lesson here is that when you’re designing an interface, make sure that each button is absolutely necessary and well placed. Given the location and tactile focus of the interface, the two most used functions (record and play) should have been larger and had distinguishable texture. The third button has a less-than-obvious purpose, meaning that any humans attempting to use it in the far future will need to use trial and error to understand what it’s for.

Two of the buttons are easy to understand. But designers for this system would want to make sure that a person with no access to documentation could quickly understand the third button through immediate feedback and a function that is non-destructive to the data stored in the audio recording.

Dust Storm Alert


While preparing for his night cycle, Wall-E is standing at the back of his transport/home. On the back drop door of the transport, he is cleaning out his collection cooler. In the middle of this ritual, an alert sounds from his external speakers. Concerned by the sound, Wall-E looks up to see a dust storm approaching. After seeing this, he hurries to finish cleaning his cooler and seal the door of the transport.

A Well Practiced Design

The Dust Storm Alert appears to override Wall-E’s main window into the world: his eyes. This is done to warn him of a very serious event that could damage him or permanently shut him down. What is interesting is that he doesn’t appear to register a visual response first. Instead, we first hear the audio alert, then Wall-E’s eye-view shows the visual alert afterward.

Given the order of the two parts of the alert, the audible part was considered the most important piece of information by Wall-E’s designers. It comes first, is unidirectional as well as loud enough for everyone to hear, and is followed by more explicit information.


Equal Opportunity Alerts

By having the audible alert first, all Wall-E units, other robots, and people in the area would be alerted of a major event. Then, the Wall-E units would be given the additional information like range and direction that they need to act. Either because of training or pre-programmed instructions, Wall-E’s vision does not actually tell him what the alert is for, or what action he should take to be safe. This could also be similar to tornado sirens, where each individual is expected to know where they are and what the safest nearby location is.

For humans interacting alongside Wall-E units each person should have their own heads-up display, likely similar to a Google-glass device. When a Wall-E unit gets a dust storm alert, the human could then receive a sympathetic alert and guidance to the nearest safe area. Combined with regular training and storm drills, people in the wastelands of Earth would then know exactly what to do.

Why Not Network It?

Whether by luck or proper programming, the alert is triggered with just enough time for Wall-E to get back to his shelter before the worst of the storm hits. Given that the alert didn’t trigger until Wall-E was able to see the dust cloud for himself, this feels like very short notice. Too short notice. A good improvement to the system would be a connection up to a weather satellite in orbit, or a weather broadcast in the city. This would allow him to be pre-warned and take shelter well before any of the storm hits, protecting him and his solar collectors.

Other than this, the alert system is effective. It warns Wall-E of the approaching storm in time to act, and it also warns everyone in the local vicinity of the same issue. While the alert doesn’t inform everyone of what is happening, at least one actor (Wall-E) knows what it means and knows how to react. As with any storm warning system, having a connection that can provide forecasts of potentially dangerous weather would be a huge plus.

Eve’s Gun


For personal security during her expeditions on Earth, Eve is equipped with a powerful energy weapon in her right arm. Her gun has a variable power setting, and is shown firing blasts between “Melt that small rock” and “Mushroom Cloud visible from several miles away”


After each shot, the weapon is shown charging up before it is ready to fire again. This status is displayed by three small yellow lights on the exterior, as well as a low-audible charging whine. Smaller blasts appear to use less energy than large blasts, since the recharge cycle is shorter or longer depending on the damage caused.


On the Axiom, Eve’s weapon is removed during her service check-up and tested separately from her other systems. It is shown recharging without firing, implying an internal safety or energy shunt in case the weapon needs to be discharged without firing.

While detached, Wall-E manages to grab the gun away from the maintenance equipment. Through an unseen switch, Wall-E then accidentally fires the charged weapon. This shot destroys the systems keeping the broken robots in the Axiom’s repair ward secured and restrained.

Awesome but Irresponsible

I am assuming here that BNL has a serious need for a weapon of Eve’s strength. Good reasons for this are:

  • They have no idea what possible threats may still lurk on Earth (a possible radioactive wasteland), or
  • They are worried about looters, or
  • They are protecting their investment in Eve from any residual civilization that may see a giant dropship (See the ARV) as a threat.

In any of those cases, Eve would have to defend herself until more Eve units or the ARV could arrive as backup.

Given that the need exists, the weapon should protect Eve and the Axiom. It fails to do this because of its flawed activation (firing when it wasn’t intended). The accidental firing scheme is an anti-pattern that shouldn’t be allowed into the design.


The only lucky part about Wall-E’s mistake is that he doesn’t manage to completely destroy the entire repair ward. Eve’s gun is shown having the power to do just that, but Wall-E fires the weapon on a lower power setting than full blast. Whatever the reason for the accidental shot, Wall-E should never have been able to fire the weapon in that situation.

First, Wall-E was holding the gun awkwardly. It was designed to be attached at Eve’s shoulder and float via a technology we haven’t invented yet. From other screens shown, there were no physical buttons or connection points. This means that the button Wall-E hits to fire the gun is either pressure sensitive or location sensitive. Either way, Wall-E was handling the weapon unsafely, and it should not have fired.


Second, the gun is nowhere near (relatively speaking) Eve when Wall-E fires. She had no control over it, shown by her very cautious approach and “wait a minute” gestures to Wall-E. Since it was not connected to her or the Axiom, the weapon should not be active.


Third, they were in the “repair ward”, which implies that the ship knows that anything inside that area may be broken and do something wildly unpredictable. We see broken styling machines going haywire, tennis ball servers firing non-stop, and an umbrella that opens involuntarily. Any robot that could be dangerous to the Axiom was locked in a space where they couldn’t do harm. Everything was safely locked down except Eve’s gun. The repair ward was too sensitive an area to allow the weapon to be active.

In short:

  1. Unsafe handling
  2. Unauthorized user
  3. Extremely sensitive area

Any one of those three should have kept Eve’s gun from firing.

Automatic Safeties

Eve’s gun should have been locked down the moment she arrived on the Axiom through the gun’s location aware internal safeties, and exterior signals broadcast by the Axiom. Barring that, the gun should have locked itself down and discharged safely the moment it was disconnected from either Eve or the maintenance equipment.

A Possible Backup?

There is a rationale for having a free-form weapon like this: as a backup system for human crew accompanying an Eve probe during an expedition. In a situation where the Eve pod was damaged, or when humans had to take control, the gun would be detachable and wielded by a senior officer.

Still, given that it can create mushroom clouds, it feels grossly irresponsible.

In a “fallback” mode, a simple digital totem (such as biometrics or an RFID chip) could tie the human wielder to the weapon, and make sure that the gun was used only by authorized personnel. (Notably Wall-E is not an authorized wielder.) By tying the safety trigger to the person using the weapon, or to a specific action like the physical safeties on today’s firearms, the gun would prevent someone who is untrained in its operation from using it.

If something this powerful is required for exploration and protection, it should protect its user in all reasonable situations. While we can expect Eve to understand the danger and capabilities of her weapon, we cannot assume the same of anyone else who might come into contact with it. Physical safeties, removal of easy to press external buttons, and proper handling would protect everyone involved in the Axiom exploration team.

The Dropship


The Axiom Return Vehicle’s (ARV’s) first job is to drop off Eve and activate her for her mission on Earth. The ARV acts as the transport from the Axiom, landing on the surface of Earth to drop off Eve pods, then returning after an allotted time to retrieve the pods and return them to the Axiom.

The ARV drops Eve at the landing site by Wall-E’s home, then pushes a series of buttons on her front chest. The buttons light up as they’re pushed, showing up blue just after the arm clicks them. At the end of the button sequence, Eve wakes up and immediately begins scanning the ground directly in front of her. She then continues scanning the environment, leaving the ARV to drop off more Eve Pods elsewhere.

If It Ain’t Broke…

There’s an oddity in ARV’s use of such a crude input device to activate Eve. On first appearance, it seems like it’s a system that is able to provide a backup interface for a human user, allowing Eve to be activated by a person on the ground in the event of an AI failure, or a human-led research mission. But this seems awkward in use because Eve’s front contains no indication of what the buttons each do, or what sequence is required.

A human user of the system would be required to memorize the proper sequence as a physical set of relationships. Without more visual cues, it would be incredibly easy for the person in that situation to push the wrong button to start with, then continue pushing wrong buttons without realizing it (unless they remembered what sound the first button was supposed to make, but then they have one /more/ piece of information to memorize. It just spirals out of control from there).

What was originally for people is now best used by robots.


So if it’s not for humans, what’s going on? Looking at it, the minimal interface has strong hints of originally being designed for legacy support: large physical buttons, coded interface, and tilted upward for a person standing above it. BNL shows a strong desire to design out people, but leave interactions (see The Gatekeeper). This style of button interface looks like a legacy control kept by BNL because by the time people weren’t needed in the system anymore, the automated technology had already been adapted for the same situation.

Large hints to this come from the labels. Each label is an abstract symbol, with the keys grouped into two major areas (the radial selector on the top, and the line of large squares on the bottom). For highly trained technicians meant to interact only rarely with an Eve pod, these cryptic labels would either be memorized or referenced in a maintenance manual. For BNL, the problem would only appear after both the technicians and the manual are gone.

It’s an interface that sticks around because it’s more expensive to completely redo a piece of technology than simply iterate it.

Despite the information hurdles, the physical parts of this interface look usable. By angling the panel they make it easier to see the keypad from a standing position, and the keys are large enough to easily press without accidentally landing on the wrong one. The feedback is also excellent, with a physical depression, a tactile click, and a backlight that trails slightly to show the last key hit for confirmation.

If I were redesigning this I would bring in the ability for a basic- or intermediate-skill technician to use this keypad quickly. An immediate win would be labeling the keys on the panel with their functions, or at least their position in the correct activation sequence. Small hints would make a big difference for a technician’s memory.


To improve it even more, I would bring in the holographic technology BNL has shown elsewhere. With an overlay hologram, the pod itself could display real-time assistance, of the right sequence of keypresses for whatever function the technician needed.

This small keypad continues to build on the movie’s themes of systems that evolve: Wall-E is still controllable and serviceable by a human, but Eve from the very start has probably never even seen a human being. BNL has automated science to make it easier on their customers.

WALL-E (2008): Overview

Release date: 27 June 2008, United States


Humanity’s materialistic society has left Earth uninhabitable. A powerful mega-corporation – Buy-N-Large – offered resort-like spaceships for humanity to live on while they left behind an army of solar-powered trash collection robots to clean up the mess. Fast forward seven centuries, and Wall-E is the only surviving trash robot left. He continues to do his job, kept company by a cockroach who has also managed to survive the end of civilization.

Wall-E’s life is abruptly interrupted by the arrival of Eve, a BNL (Buy-N-Large) probe meant to search for any signs that life is returning to Earth. After becoming emotionally attached to Eve, Wall-E shows her a plant he found during his trash collection. She “freaks out”, collects the plant, and leaves the planet. He follows her back to her home and what may be the last surviving outpost of humanity: the Axiom, an all-inclusive lifeboat and pleasure cruise that has been waiting to return to Earth for 700 years.

Aboard the Axiom, Wall-E opens the eyes of people who have become so accustomed to having every wish granted to them by BNL that they have stopped doing anything for themselves. Eve and Wall-E fight the Axiom’s autopilot and security systems for the plant, and draw in the humans aboard the Axiom to the fight.

After the people on board the Axiom realize that they need to start doing things for themselves, they are able to deactivate the Axiom’s deceitful autopilot and trigger the ship’s return mode to land back on Earth. Wall-E, Eve, and the other robots of the Axiom then help people rebuild civilization on an Earth that is beginning to heal.


Introducing Clayton Beese

Now this this exciting.’s first guest review begins this week! That’s right, someone took a look at the terrifying Contribute! page, and stepped up to the sci-fi plate! So with no further ado, let me introduce Clayton Beese, and share his answers to a few questions I posed to him.

Clayton Beese

Hi there. Tell us a bit about yourself. What’s your name, where are you from, how do you spend your time?

Hi! I’m Clayton Beese, a User Experience designer from Overland Park, Kansas, and I’m someone who is drawn to the idea of storytelling as a very basic human activity. Outside of work I bike, I’m an amateur writer, I am usually the designated photographer on family trips, and I like taking random classes in things like rock climbing, blacksmithing, and Tai Chi to see what they’re like. Science fiction has always captured my interest because it asks questions about our needs as people, and what we want to see out of our future.

What are some of your favorite sci-fi interfaces (Other than in Wall-E)? (And why.)

