August 18, 2026 · Hexagon Intergalactic
Designed for the bad night
Crash snapshots after every edit and outputs that fail to a state you chose - the parts of Filament you'll hopefully never see, listed anyway.

Nobody buys show software for its failure handling, and everybody eventually wishes they had. I've had ten years of occasional bad nights - a laptop restarting mid-set, media drives accidentally yanked out, you name it. Filament is shaped by these experiences. Here's what's built in for the night things go sideways.
Your work survives the crash
Filament snapshots your project a second or two after every edit, not on a timer, on the edit. The next launch asks whether to restore if a session ends wrong - crash, force-quit, the machine going to sleep at the worst moment. Autosave runs separately on a 1-to-60-minute timer. The distance between "the app died" and "I lost the show" is one dialog.
And when output has to stop (project unload, app shutdown, a runtime restart, an input timeout), the safe-state policy does what you chose per event: blackout, or hold the last frame. Your call, made once, in daylight.
Failures stay small
The quiet design rule: one broken thing must not take the rig with it.
- An effect whose shader fails renders passthrough and shows the error. The chain keeps running.
- If a live NDI/Syphon/Spout sender dies, the cell goes black on the next tick, with no frozen stale frame, and quietly retries every second or so. When the sender returns, so does the picture, with nobody sprinting to FOH.
- When a media drive goes missing, cells that point into it dim with a badge while the rest of the show keeps playing, and they re-bind when the folder comes back.
- Channel conflicts are surfaced as a clickable list before they're a mystery on hardware. Click a row and Filament selects the culprits and scrolls you to them. A channel nudge that would collide is simply refused.
Check the rig before doors open
Run Preflight generates a readiness report against your actual routing: missing or invalid targets, conflicts, transport binding problems, your safe-state settings - worst first, with a button that jumps to the offending Surface. Output tests (including an identify flash) go through the same transport as the real show, so a passing test means the path works, not that a different path works.
The software is rarely the problem
This July we ran seven thousand pixels for three nights: generative content, multiple machines synced to a shared clock, projection mapping, the whole conceptually difficult pile. The only real failures of the weekend were two missing rubber o-rings. Two seed pixel strings in the trees let water into their connectors and glitched on the first night. O-rings replaced, smooth sailing after that. The same weekend, four people spent 30 minutes on one seized bolt in a projector frame.
That's why this article is about mechanisms instead of promises. The software's job on the bad night is to be the thing you don't think about - to keep the rest of the show running while you're up a ladder with a headlamp fixing the thing that actually broke. Every mechanism above exists so that one wet connector, one dead drive, one crashed patch stays exactly one problem big. None of this shows up in a demo video, which is why I'm writing it down instead.
Download Filament. It is the full editor - no signup, no time limit.
live-performance · reliability


