Kenexis Functional Safety Podcast
A single sentence about staying safe until someone deliberately chooses otherwise opens a surprisingly deep discussion of how operators actually interact with safety systems. Ed Marszal works through Clause 11.2.6 on human factors—why maintainability demands thinking through physical reach, manual strength, and the cultural confusion of red-versus-green meaning—then moves to Clause 11.2.7 and the reset function that keeps a tripped process latched in the safe state. Along the way he weighs DCS targets against field-mounted solenoid latches, recounts an Ohio ice storm that froze every manual reset in place, and explains when automatic reset becomes the lesser hazard. The episode rewards anyone who has ever watched an operator struggle with a poorly placed switch or debated whether the board operator or field hand should restart the pump.
In this episode of the Kenexis Functional Safety Podcast, the discussion centers on the concept that once the Safety Instrumented System places the system in a safe state, it should remain there until an operator manually intervenes.
Tune in to the latest episode of the Kenexis Functional Safety Podcast, hosted by Ed Marszal, President and CEO of Kenexis. Now available on Spotify and Apple Podcasts, Ed offers his expert insights on the IEC 61511 standard.
With decades of experience in safety instrumented systems and as a Principal Engineer, Ed has a unique perspective to offer. He has been an active contributor to the ISA 84 committee since 1994, adding to his deep understanding of the field.
In this inaugural season, Ed delves into the IEC 61511 standard, unpacking the meaning behind each word and providing a thorough interpretation of its application. Through personal stories from his career and committee work, he offers valuable context and insights for professionals in the industry.
Full Episode Transcript
KENEXIS FUNCTIONAL SAFETY PODCAST — S1E31 TRANSCRIPT (Markdown)
Cleaned & reflowed for web publication and AI crawlability.
The JSON-LD block below is schema.org structured data. If your CMS lets you
add raw HTML to a post, paste it into the page
body — crawlers read it either way). Fill in PLACEHOLDER_EPISODE_PAGE_URL
once the post exists. Everything from the "# Kenexis Functional Safety
Podcast…" heading down is the transcript body — paste it into your post.
–>
"`html
"`
# Kenexis Functional Safety Podcast — Season 1, Episode 31: IEC 61511, Clauses 11.2.6–11.2.7 (Human Factors and Manual Reset)
—
## Episode Teaser and Introduction
Once the safety instrumented system puts the safety instrumented system into the safe state, it's best for it to stay in the safe state until the operator manually does something about it.
Welcome to the Kenexis Functional Safety Podcast. I'm your host, Ed Marszal, President and CEO of Kenexis. Kenexis is a technical safety consultancy that helps chemical process industry companies to analyze risk and design engineered safeguards like safety instrumented systems and fire and gas detection systems. Kenexis also provides the industry-leading suite of software tools, including our best-in-class Vertigo software for SIS safety lifecycle management.
In this first season of the podcast, we are going to focus on the IEC 61511 standard, doing a deep dive into the standard, including more depth of information on what the standard means and how to apply it, brought to life with personal war stories and behind-the-scenes discussions of the committee members as we develop the standard in ISA 84 and IEC SC 65.
Before we start, a little disclaimer. I will be providing my opinion on technical and engineering topics. This information is provided on a best-effort basis and is of a general nature. The information presented in this podcast might not be applicable to your specific application.
It is the obligation of every engineer to thoroughly analyze any system that they are designing and not blindly rely on any general advice presented in this podcast. All right, well, welcome to the show. Uh, and welcome to my backyard. Actually, you can't see my backyard, but uh, if you listen closely you might be able to hear the birds in the background and so on. And, well, my dog's sleeping over there, but it's uh, it's a hot day in July, and I'm working from home. Uh, so please, uh, I apologize, please bear with me.
I apologize for the sounds of the birds in the summer, but I don't apologize. All right, let's get into it. Um, last week we closed off talking about Clause 11.2.5, so we're starting up at Clause 11.2.6, where we're going to talk a little bit about human factors. Uh, but a lot of what we're going to do today is we're going to talk about 11.2.7. I've just got uh, two sentences in that clause, but there's all kinds of discussion that needs to be had because there's all kinds of options for how you do your design, why you do things the way you do them.
And, uh, you know, a lot of style choices, a lot of best practices, a lot of things to consider uh, in the world of the manual reset. We will get into that shortly, but right now let's start it off with clause 11.2.6 which is going to talk about human factors.
## Clause 11.2.6 Human Factors Overview
And now when we're talking about human factors you have to remember that we are in clause 11 which is sis design and engineering.
So when we're talking about human factors in the design and engineering of the sis we're specifically talking about how human beings are going to interact with the safety instrumented system so what um what actions are they going to take and how easy is it for them to take the correct actions when they need to take the correct actions and how are we going to prevent them from doing the wrong thing or doing things when we don't want them to so uh something like sitting on the emergency stop button causing your plant to shut down is something that we would prefer to avoid if at all possible.
Okay so clause 11.2.6 uh has a couple sentences of normative text and there's going to be an informative note uh so let's start out with the uh normative text so 11.2.6 the design of the sis shall take into account human capabilities and limitations and be suitable for the tasks assigned to operators and maintenance staff. Okay that's sentence number one. So as we're designing our safety instrumented system we need to think about what humans are capable of doing when we design the safety instrumented system.
And this is going to apply to safety instrumented system component vendors uh we're gonna we're we're gonna get to the world of the safety
manual and all of the lunacy that i have seen in poorly written safety manuals i cannot believe that certification agencies let equipment vendors get away with some of the stuff they've gotten away with but uh in terms of interaction in terms of maintenance in terms of testing making sure that what you're expecting the human being to do when they interact with the system is physically possible for a human being of normal manual means is going to be important so for instance um if a maintenance activity
includes uh something like manually holding a valve open while you do a partial stroke test well no human being is going to be able to use their hands to hold it open um so even even something like opening a 72 inch valve for maintenance purposes. So let's say i want to test the open limit switch so i need the valve to go fully open and i need to manually open that valve um you know if it's elevated uh uh we need to make sure that what we're asking for is possible is the bottom line and that the equipment is going to be available for them to do those types of activities.
So if you're going to be opening and closing a an elevated valve you might want a chain mechanism that allows you to perform that from the ground um anything that requires you to physically move pieces of equipment may require a certain degree of manual strength that not everyone has at their disposal. So being able to turn a ball valve sometimes you could do it with your hands. Sometimes you need a cheater bar uh sometimes you're going to need to come along to uh chain that thing up and try to move it.
Maybe we need a jeep with a winch to uh actually move that device all this stuff needs to be thought through during the design process. Virtually everything that you're asking the safety instrumented system to do and you're asking the maintenance and operations team you need to think through how they're going to do it. We have to make these devices maintainable. We have to make them usable. And that's something that engineers uh rightly get a black eye for because a lot of times that's not part of their thought process when they're putting together these systems.
And you end up with uh you know some bad designs so we need to take into account human capabilities and human limitations when we think about all the tasks that require an operator to interface with the device
## Operator Interface Design Principles
um second uh sentence of the clause of the normative part says that the design of operator interfaces shall follow good human factors practice and shall accommodate the likely level of training that operators should receive. So loaded sentence there a couple things to think about while you're working your way through that um good human factors practice with relations to operator interfaces. So what are some of the things that we need to think about?
Well number one operator interface is a very loaded phrase because it encompasses a lot of things uh operator interface um operator interface might mean the led lights that are on i.o. Cards to tell you whether or not you've energized an output. Not the best operator interface but it's something to think about uh a little bit uh more relevant and also still kind of basic uh would be uh lights uh lights and switches on panels that might be in the field. They might be in the control room so um as you're designing your lights where are they located?
So who can actually see them is the is a person of average height going to be able to see uh the lights from where they are normally located so uh is it going to be on the control panel? Is it going to be on the wall? Is the view of these lights going to be obstructed uh customs what does red mean red versus green means different things to different people. Being a chemical engineer that came up through the oil and gas business when i see a green light on a pump that means that it's running. Everything's okay. We're in the operational state.
But to a lot of people that maybe came up through the power generation industry or more electrical engineers red means it's energized.
So thinking about who your audience is what their expectations are when you're developing that user interface is going to be really important uh from a design perspective and here we're just talking about lights and switches so so those were lights and then also how big is the light in addition to what color uh little tiny leds big lamps if you're using an led or a lamp as part of a critical process you might also want to think about something called a lamp test.
So you might say that well because the red light isn't on then that means that i'm okay to perform this action like opening up the reactor. Well the light might not be on because it's burned out. So some sort of lamp test to make sure that the light will turn on if I ask it to might be an important part of that process. Or you might have green is good, red is bad.
So you're going to have two lights so that something is always lit while you're doing these activities. Switches. There are a wide variety of switches and different people have different preferences. I am a big fan of the two position selector switch so that when I put a switch into a position, it's going to stay in that position until I move it into a different position as opposed to just, you know, pulsing a contact. So I'm a big fan of the two position disconnect switch, which is going to have, you know, the ability to have multiple sets of contacts to do multiple different things.
So I could use one set of contacts on that switch to actually either connect or disconnect power. To the final element in the field. I could use the other set of contacts to send a signal back to the DCS. I could use another set of contacts to send that signal hardwired to the BPCS if that's something I wanted to do. So, you know, how many contacts you have on a switch and the type of switch is something that needs to be thought through?
And again, you need to think about people's expectations. Whereas I like to have a two position selector switch for a shutoff, a lot of people are more into a momentary contact spring return push button switch where when you actually have the switch depressed, you're either closing or opening the circuit, usually opening the circuit for de-energized to trip signals. And then when you let go, the switch immediately goes back to the position where you're energized, which hopefully is not going to automatically restart your process.
We're going to get to that in the next clause when we talk a whole lot about resets. But yeah, what type of switch are you using? Where are those switches located? Are they out in the field for the operator to manipulate? Are they in the control room for the board operator to manipulate? So who is going to be doing the manipulating? What are their expectations on what they're going to see?
## Computer-Based HMIs and ISA 101 Standard
So all of that is still kind of focused on the more basic instrumentation and control engineering side of the fence. But there's also a whole other level, an order of magnitude or two orders of magnitude more complexity when we start talking about computer-based human machine interfaces like DCS screens or dedicated panels in the field, dedicated panels in the control room. And there you need to start thinking about, well, I can make everything a wide variety of colors. I can have blinking lights. I can have bright reds, bright oranges, yellows.
In the beginning, when we first started doing computer-based operator interface displays, they were horrible. I still remember going to the ISA show in 1993. I believe it was in New Orleans. Maybe. Maybe it was in Philadelphia. That's neither here nor there. But you would go to the booths of Wonderwear and, you know, some of the other, you know, brand new HMI companies. And every one of them would have a graphic display of a fired heater firing. So you get all kinds of swirling red, orange, and yellow colors. That's very pretty to look at. But for an operator, it's very distracting.
And it's drawing your attention to nothing. So you're not focusing on what you should be focusing on. So in order to get around that, I'm going to point you to the ISA standard on human-machine interfaces. I hope it's ISA 101. But it might not be. So go ahead and do your own research on that.
ISA has a great standard on how to design operator interfaces. And it's going to include a lot of things like making everything normal, be dark, be shades of gray, be cool colors when everything is kind of in its normal operating condition. And only use hot colors to draw attention to something that's abnormal. So if you're going to use the orange, the red, and the yellow, that should be something is basically an alarm and it needs your attention right now. It's the only time that you should be using hot colors. And well, blinking lights, oh my goodness.
That's a whole other level of complexity.
So yeah, I'm going to apologize for the airplane you can probably hear flying over right now. But I'm not going to apologize. Again, it's a beautiful summer day. I'm hanging out with my dog, Sammy in the backyard. So this is the type of thing that happens in addition to all those crickets and cicadas you can hear in the background. Okay, sorry about that. Continuing on.
## Interface Security and Inadvertent Operation
So ISA 101 is how you're going to want to design your graphic interfaces. The other thing to talk about before we leave this section is as you're designing all these switches, designing these interfaces, you need to think about security and making sure that people don't do things by accident that they don't want to do.
And those accidental things would be, you know, pressing a switch they didn't want to press or maybe somebody who's not authorized and doesn't know what they're doing pressed a switch. So at a minimum on your switches, you're going to want to have a cover that would prevent inadvertent pressing of a push button, especially if it's a push button. It's another reason that I like to position switches so much is it's much less likely that you'll do the deed by accident. Whereas push buttons, especially those gigantic mushrooms are real easy to press by accident.
So covers over the switches to make sure that you don't hit them by accident. Give some thought as to whether or not you want to lock those covers to prevent people from doing things they shouldn't, especially if one of those switches is associated with a bypass. I know right now my friend Tony Downs, formerly of Honeywell, put together a process safety beacon, I believe, where they're talking about a case where something was inadvertently bypassed out in the field. So something to watch out for.
And, you know, that's for physical switches, but also in terms of security, if you're talking about CRTs, if you're talking about CRTs, what am I talking about? Who uses cathode ray tubes? I believe that we just passed either the 10th or the 20th anniversary of Apple selling their last CRT. That kind of showed up in my Twitter feed. But LCDs, so displays out in the field, you want to make sure that just people wandering by aren't going to start being able to touch the screen and do things that you don't want them to do.
All right, so you would think that we're done and I have spent almost 20 minutes talking about this subject, but there is still a note that we need to hit here for clause 11.2.6.
## Note 1 Human Factors Studies and Data Entry
Note 1, which says, for example, human factor studies may be necessary if operation requires data entry of limits or other input on a regular basis. Okay, so this goes back to the end of that last clause that we were just talking about where it says training. You know, what are you asking the operator to do? Are you asking the operator to just press a button to start? That's pretty simple. That doesn't require that much training. Although pressing the start button is probably part of a procedure.
That procedure probably has training and qualification associated with it. So even something as simple as pressing that start button might be something that requires some training. But now you might also need to ask an operator to put in a batch code. Or you might have the operator put in numbers. Like, this is how many bags of reactant that I dumped into the reactor. So as you're setting up these operator interfaces, think about all the things that they can do wrong and engineer aspects of that interface that are going to prevent them from doing the wrong thing.
Which could include something like range checks. So, you know, if the operator inadvertently types in that they dumped in 11 bags of reactant, you might say, oh, no, no, no, it's it's one, it's two or three. It's not going to be more. There have been way too many accidents related to operators misreading and misentering things into operator interfaces. So let's, uh, let's do what we can as engineers to engineer our systems to prevent operators from doing the wrong thing.
And that might require a formal, uh, human factors study to think about all the things that can go wrong and what safeguards we have in place in our design to prevent those things from happening. Okay, so that is clause 11.2.6.
## Clause 11.2.7 Manual Reset Requirement
Now we're going to move on to a couple sentences of clause 11.2.7. But these are a couple sentences that are going to take a lot of discussion. Because there are so many design choices. There are so many design considerations. Some best practices work for this group of people, but they don't work for that group of people. And we're talking about the reset. Specifically, we're talking about the need for a manual reset. And, uh, you know, you think, oh, well, you just press the reset button when you want to start the plant back up, Ed. How, how difficult can this topic be?
Well, a lot of times your reset button is not necessary. You don't want it. When you do want it, sometimes it's not called a reset button. Uh, it's called something like a start button. So you're pressing a start button, which performs the reset action. And you didn't actually have to do a reset. Sometimes you do your reset out in the field. Sometimes you do it in the control room. And what is it that you're resetting when you press the reset button? Maybe you need to do multiple resets for a SIF. Maybe you need to do multiple resets for a specific device.
So, uh, resetting is actually kind of a complex topic and it's something that, uh, it's discussed in a whole lot of detail in the Kenexis integrated safety suite. So if you get on KISS, you go into the process safety training center, the SRS training class has an entire section that's dedicated toward resetting, probably take you an hour or two to get through just that training class. So check out the process safety training center, with a whole lot of detail on resets. But let's, let's talk about what the standard says.
And then that's going to lead us into the plethora of different options that you're going to run into and actually implementing it. Okay. So clause 11.2.7, two quick sentences. It says, the SIS shall be designed in such a way that once it has placed the process in a safe state, the process shall remain in the safe state until a reset has been initiated, unless otherwise directed by the SRS. Wow. I was wrong. It's only one sentence. I'm actually looking at the standard right now. Obviously one of these days I might do one or more of these podcasts on video so that you can see what I'm doing.
Uh, but right now, because I'm outside by the pool, uh, I'm recording in garage band on an iPad. And, uh, I, when you're, I don't know if any of you are familiar with garage band on the iPad, but you really can't be doing anything else on your iPad while you're using garage band. So I had to pull up a copy of the standard on my iPhone and the text is inhumanely small. So, uh, when I saw that safe state, there's a comma after it, not a period after it. So one sentence, let me do this again.
The SIS shall be designed in such a way that once it has placed the process in a safe state, the process shall remain in the safe state until a reset has been initiated unless otherwise directed by the SRS. So let's pick this apart one bit at a time.
## Safe State Latching and Fired Heater Example
So once the SIS has placed the process into a safe state, so a trip has happened, the safety function is activated. I have moved final elements into a place where a safe state will be created. So let's do a simple example of a fired heater, uh, high fuel gas pressure shut down. We're going to want to close off fuel gas. So, uh, my final elements will be a double set of double block valves will move to the closed position. Um, I will also generally have an additional action of a bleed valve going to the open position. That's not part of the SIF.
It's a, uh, non safety critical, if you will, additional action.
So those are the actions that were taken. Now, as soon as I do that, there is a chance that the fuel gas pressure, if it's measured downstream, uh, is going to go low. So when the fuel gas pressure goes low, I don't want the valves to fly open again because the pressure went low. Uh, otherwise I'm going to have this vicious cycle where I open the valves, pressure goes high. I close the valves, it goes low. And now my valves are going open, closed, up and close, up and closed. Uh, I'm not maintaining my safe state because I keep introducing more fuel gas into the fired heater.
So once I put those valves into the closed position, the shutoff valves are in the closed position, I want them to stay in the closed position until I choose to do something about it manually. Okay. So there's going to be this manual activation that says, okay, now I'm ready to restart. Please go open again. Now in the interim, there's probably a whole lot of activities that are going to happen. So the operations team, both inside operators and outside operators are going to try to diagnose what went wrong. Was this a real trip? Did the pressure actually go high?
Why did the pressure actually go high? Um, and you know, when, when, when a trip like this happens, there's a lot of busyness, a lot of activity because, well, you know, you just lost production or maybe you lost production. Maybe you won't lose production if you get the heater back online quick enough. Um, so there's a flurry of activity that's happening, but ultimately we need to know why did the shutdown happen? Is it safe to restart the process, which will occur kind of after you take some sort of action to get the process ready to restart.
And with a fired heater for the most part, and you know, the, the, the best practice is going to be to purge your heaters before you restart them. Uh, there are a lot of cases where some hot rodders don't do that. I don't, uh, condone that. Uh, but you know, I'm not going to ignore reality either. That's something that can, uh, that can happen. So there needs to be some sort of action to diagnose what went wrong. Take actions to return the process to a state where it's ready to be restarted and only then will you restart the process.
## Post-Trip Recovery and Restart Process
Now that you're going to do the restarting of the process, how do you actually do it? So at this stage in the game, kind of temporally, we shut down. All of our final elements went into the safe position. Now we need to get them to go back to the normal operating state. How do we get them there? Well, number one, the process needs to be ready to restart, which normally means that your process variable has returned to a safe condition. Sometimes it does not return to a safe condition.
So we will talk about in just a few minutes, something called the auto startup auto bypass, actually bypasses first.
So auto bypass auto rearm is a technique that you're going to use if your process does not return to a safe state, uh, before you need to restart it. So we'll, we'll come back to that. Um, but let's say, so in this case, let's say the, the pressure went back down below the high fuel gas pressure shutdown. So that's, that's start, step number one, process variable needs to come back to its normal condition. Now we need the operator to take an action. So let's say that there's a reset button.
Now, when we reset, you could be forgiven for thinking that we're going to reset one SIF, one safety instrumented function at a time, uh, which would include basically pressing a single button. Um, in, in this case that would cause both of the shutoff valves to go to the open position and the bleed valve to go to the closed position. So there one action is going to, or one button push is going to cause multiple final elements to move.
## Fired Heater Startup Sequence and Reset Timing
Okay. That's an idea, but a lot of times that's not how you do it because starting up a plant is generally a complex process that occurs during multiple steps at multiple times. So for instance, restarting that fire-fired heater is going to require you to go through a startup sequence, which begins with confirming that all the fuel gas valves are closed. Then you need to, uh, get airflow, get flow through the fire box to purge it out. That might be steam, that might be forced air, that might be induced air.
Uh, there are a lot of ways to get that airflow and then we're going to need that airflow to go for a certain duration of time. Then we're going to need to get fuel gas up to the double block and bleed assembly.
And we have to make sure that the pressure of the fuel gas header is above the low fuel gas pressure trip. And only at that point in time would you open the valves to allow gas to the burner. And then you need to open the burner valve and light the valve. So it's very complex process. Now for a fired heater, a lot of times this process is fully automated. So all that the operator needs to do is press a button that would be labeled start. And then the PLC does all of this sequencing for you. But in a lot of processes, things are manual.
So you would manually open the fuel gas valves to get the fuel to the header. So you would close the bleed valve first, then you'd open the main gas valves to get the gas out to the burner. Then you'd have an operator go out to the field and manually open the burner valve and light the burner, make sure that the it's lit before continuing on in the sequence. So pressing a button in that process, you generally don't want all the valves to open simultaneously.
Making it a little bit more real is let's say we have a reactor where there's a runaway reaction that could open a depressuring valve. Well, closing the depressuring valve once it's open is the thing that you want to do first. But getting the reaction going again might involve starting with flow. So bypassing or getting that low flow shutdown addressed so that we can start the pump and get fluid flowing through the reactor. Then we're going to want to start a fired heater, which I just talked about.
So there's a big case that says it's rare that you want to activate all of your final elements at the same time. So pressing one button and having 10 valves fly open out in the field is generally not something you want to do. So a lot of times the reset is going to be a reset button that's associated with one specific final element.
So when I press reset button for XV-103, that's going to cause my depressuring valve on the reactor to move from the safe state, which is open, to the normal operating state, which is closed. So I would do those resets one at a time for every final element. Now, so let's say we're looking at a reset functionality that is one final element at a time.
## Reset Mechanisms: DCS Target vs Physical Switch
How do you do that? Do I press a physical switch in the control room? Do I press a physical switch in the field? Do I use something like a solenoid reset latch out in the field? Uh, you've got a lot of options on how you do this and, uh, you know, physical switch versus virtual switch, uh, in the basic process control system. So let me tell you, let me begin with the most common way to reset valves.
I'll start with valves. The most common way to reset valves is to have a single switch per valve, and it will be a virtual switch on the operator interface. So a DCS target that you push that. And when you push that, that's going to, that's all that the SIS needs to know to make that valve move to its normal operating position. So a shutoff valve will go to the open position when I press the reset button on the DCS.
Now, another option for, um, valves is to do a, uh, a physical reset out in the field.
So, uh, most shutoff valves are equipped with a solenoid valve, which is the signal transducer, which is going to convert the DCS's 24 volt DC electrical signal, or the SIS's, uh, into a pneumatic on-off signal. Uh, that's why, uh, solenoid valves are tagged with a Y, because they are transducers. They convert from one signal type to another. Please do not tag solenoid valves as SOV. There's a whole other training class in the Kenexis Process Safety Training Center about properly tagging things that Jim McGlone is developing right now as we speak.
And that would be wrong to label us an SOV an SOV. It's going to get tagged with a Y, because what does it do? It's a transducer. I digress. I'm getting a little bit off topic.
A lot of times the solenoid valves are going to have a handle on them to where it will stay in the de-energized state until you physically lift the handle up. Now, why would people make this decision to force the operator to go out in the field and lift the handle?
Well, number one, it's a physical piece of equipment. It doesn't require any programming, so it's simple. It's usable on, you know, non-PLC-based, so relay-based shutdown systems. And it requires the operator to go out in the field and check things out, make sure everything is safe. Well, what's the argument for not using this? Well, there are two things. Number one, its advantage is also its weakness. The operator has to go out to the field to check things out.
## Field Reset Drawbacks and Remote Operations
And after the BP Texas City incident, we really looked at where we're locating people. And there was a big drive to move, and still is, to move people away from the process. Your control rooms are now a half mile or a mile away from the plant. So we're trying to do things remotely or with cameras, and we want to minimize the amount of people actually out in the field. So that's a case for not using the manual reset latch.
Another reason to not use the manual reset latch is it's prone to abuse the coat hanger. So there are a lot of crafty people who have taken a metal coat hanger and kind of stretched it out to where they were able to take the hook and put it on a piece of pipe above the shutoff valve and then bend the bottom of the hanger so that it holds that solenoid latch up and never drops out.
So that's a homemade, jury-like, where there's a way. People will bypass things. They've got all kinds of crafty methods for doing so. That would be one of them. But how could that same kind of bypass functionality happen by accident? Well, I won't name the person, and he probably wouldn't mind me naming him because he does a lot of, writes a lot of papers and magazine articles and such.
But up here in Ohio, there is a chemical plant that had, in past tense, a lot of manual reset latches on the solenoid valves in the field. Well, another thing that we have here in the great state of Ohio is ice storms. So what an ice storm is, is the temperature drops very rapidly, and you get precipitation in the form of sub-cooled rain.
So the water drops as a liquid from the sky, but the temperature of the water droplets significantly drops below the freezing point, even though it's a liquid. Now, as soon as this sub-cooled water finds a resting place, it lands somewhere, it will immediately turn into ice.
And if you've ever seen pictures of an ice storm, it is just beautiful. You get these trees where all the branches have a nice thick coating of ice on them. Power lines have a nice thick coating of ice, which is pretty, as long as they don't collapse, and now you don't have power, which is not so fun. And also happens a lot here in Ohio. But now, picture that nice coating of ice on your solenoid valve latch. That's right. So this operating company had all of the solenoid valves in their plant frozen in place so that the shutoff valves would not go to the safe position.
Simultaneously, that ice storm snaps the power lines, and they lost power to their facility. So when you lose power, you're going to lose your pumps, but you're going to maintain your fired heaters, and all kinds of insanity ensues.
Very bad things. So your safety system is going to trigger, because your safety system's on an uninterruptible power supply, it's going to trigger all your shutdowns to activate. But guess what? Those solenoid valves are frozen in position, and your shutoff valves ain't going nowhere. So after that, everything's okay. They were able to use BPCS valves to get themselves to a safe state. And, you know, after they calmed down, cleaned out their pants, and, you know, tried to reset themselves back into the, you know, the reality that they're not going to die today.
They immediately started an engineering project to go ahead and remove all those manual reset latches.
So, as I mentioned, most common way to do it is by the board operator using a DCS target. But, again, board operator using a physical switch, not unheard of. That's going to require a lot of switches, so not very common. Doing things out in the field, still not uncommon, but be careful for common cause failures that will cause all of your shutdown valves to not work at the same time. Are a possibility if you're going to use those. Now, the other type of final element that you're going to run into is the motor starter for the rotating equipment.
## Rotating Equipment Resets and Two-Step Process
So, what are we going to do with our motor starters on our rotating equipment? Generally, you don't start a pump from the control room.
Now, I should be very careful here because everyone is going to have really entrenched positions based on the industry that they come from. And, as I've mentioned before, I was born in an oil patch.
So, I worked for UOP and I did startups of oil refineries all around the world. It's where I learned. It's where I grew up. It's where I cut my teeth in the industry. And, in an oil refinery, pressing a button to start a pump from the control room is essentially unheard of. Because oil refineries generally run from 4 to 7. And, they're trying to stretch it out to 10 years at a time. So, am I going to create a whole bunch of automation to start a pump that starts once every 5 years?
No. If you're going to start a pump once every 5 years, we can have somebody walk out to the field and press the button. But, that being said, in order to keep the logic straight in the logic solver, you're still probably going to press a reset button in the control room. So, for most rotating equipment, it's a two-step process. There's going to be an operator in the control room that's going to press a DCS target that resets the SIS logic, but doesn't start the pump. Starting the pump requires somebody to go out in the field and hit that run-stop auto switch out in the field.
We'll get to that run-stop auto switch again because sometimes auto is bypass. So, be careful.
So, we're going to reset the logic in the control room with the board operator, and then we're going to reset or actually start the pump by the field operator physically pressing the run button and turning the pump on. Okay. So, that's the reset. Now, before we leave the topic of pumps, before we leave the topic of the actual mechanism by which you do your reset, let's talk a little bit about the first step. So, going way back to like 15 minutes ago, I said that the first step is making sure that your process variable goes to the normal state before the reset is allowed to happen.
Well, sometimes that can be a problem.
So, let's go to a low flow shutdown. And, you know, for low flow shutdowns, we could go back to that fired heater. Fired heaters! Just so ubiquitous of a use case for safety instrumented systems that I'm always drawn back to them. But fired heaters are generally going to have a low pass flow shutdown. So, if the flow goes low, you're going to want to shut down the heater, which is usually a two-part process. To get to a safe state, we're normally going to close the fuel gas valves and open the bleed valve.
But you're also going to generally take the auxiliary action of commanding the pump to stop. So, we don't know why the flow stopped. But we're shutting down the heater and we're getting to a known state. So, we're generally going to stop the pump too. Now, we have a low flow shutdown on the discharge of a pump. Well, unless you've designed your shutdown properly, your shutdown system worked so well that it will prevent you from ever starting your plant again. Because in order to start the pump, the flow needs to be high, but the flow can't go high unless the pump has already started.
So, here is the place where we're going to want to do the auto bypass auto rearm.
## Auto Bypass Auto Rearm Functionality
And it's something that is kind of ubiquitous in industry, but it's something that might not be intuitive and you might not have considered. Now, when we get into operator interface, we're going to talk about the need to prevent the operator from manually bypassing things. Or we're going to want to prevent the operator from taking manual actions if the operator doesn't have to. And putting things in the bypass is one of those critical things because you can get it wrong so often.
And again, I was telling you about that process safety beacon that Tony Downs is putting together. And it has to do with the bypass that was being used for operational purposes. Something like this. You know, I need to bypass the low flow shutdown in order to get my pump started. And then once my flow has been established, I take it out of bypass. Well, sure, that's something you can have done manually. You can have it in your procedures. But why do something manually that you can easily automate? And that's where the auto bypass auto rearm comes in.
So how that safety function would work is the shutdown signal is not a hold. It's not shut down and hold de-energized. It's a pulse off for 10 seconds, 20 seconds, one minute, however long you want that pulse to be. And then you reinstitute the signal for that shutdown, allowing the pump to be restarted. So energizing that shutdown string on the pump to allow you to start the pump again.
So we're only going to hold that bypass for, or I'm sorry, we're only going to hold the shutdown for about, you know, 10 seconds to a minute. And then we're going to re-we're going to, it's going to be automatically bypassed, allowing the operator to go out to the field and hit the start button. So now, granted, you're in that state where, well, the pump's not going to restart until the operator, you know, physically presses the start button.
So that's going to be our reset action is to press the start button. But that's not the whole story. Once the operator presses the start button, the signal's going to come into the SIS that's going to start a timer. That says, okay, the operator pressed the start button. Now I have so many seconds to get to a normal flow rate. If I don't get to the normal flow rate within the allotted time, I'm just going to shut the pump off again. Okay.
But if I do get to that normal flow rate and hold above that normal flow rate for a set period of time, like five to 10 seconds, then I'm going to rearm my safety function and allow kind of the normal operating condition to exist, where if the flow now drops back down below the set point, it will shut the, uh, shut the pump off again. So that whole sequence is referred to as the auto bypass auto rearm functionality. Uh, and it is a mechanism of, uh, resetting, restarting the bypass, uh, or resetting the safety function after the trip has occurred.
## SRS Documentation and Automatic Reset Cases
Now, going back to the standard, it says a couple of things. So let me, let me, let me pull the, the, the, the words in the, in the clause, uh, again, and I'm going to highlight a couple of things before I let you go for this episode.
So it says that, um, the, you're supposed to remain in the same safe state until a manual action has taken for a bypass, unless otherwise directed by the SRS. So, um, again, Kenexis SRS training class in the process safety training center, highly recommend it, uh, talks about, uh, the fact that you should never assume when you're, when you're talking about resets. So your SIS, uh, I'm sorry, your safety requirement specifications, your SRS should always explicitly describe how you're going to perform your shutdowns.
Explicitly.
But if for some reason you get into a position where you're looking at an SRS, and trust me, there are more bad SRS than good, uh, and your SRS doesn't say anything about resets, then you, as the designer of the system, need to install a reset, a manual reset.
And obviously you're going to be able to use your own judgment because the only restriction is that there needs to be a manual reset. Who does it, how it gets done, I guess is going to be up to you. But, uh, you know, you should never leave this to your equipment vendors, to your systems integrators. If you're an operating company person, if you're a, uh, engineering firm, don't leave it up to somebody else. This should be clearly documented in your SRS. Now, we've been, I've been talking for a long time about all of the different options you have to do your reset.
Auto bypass, auto rearm from the DCS, from the field, manual devices, digital devices. But what I didn't tell you is the situations where you don't have a manual reset, and they do exist.
They are rare. Maybe one in a thousand, one in ten thousand, maybe one in a hundred. It depends on what your plan is. But some situations, you're going to want to automatically reset the position of your final element.
Now, when would you want to do that? Or when do you have to do that, honestly? And that is the situation where if you leave the valve, or if you leave your final element in the safe state for a long period of time, you will create a brand new hazard that can cause harm that you need to do something about. So let me give you the best example of that.
And this is working on an electrolyzer. So if you're looking at an electrolyzer or any kind of membrane separation, you're going to have a membrane with one gas on one side and one gas on the other side. So let's say I was making chlorine by electrolyzing salt water. I'd have chlorine on one side. You're going to have hydrogen on one side. A traditional electrolyzer where we're electrolyzing water, you're going to have oxygen on one side, hydrogen on the other side. Now, on the hydrogen side, the pressure can get high.
If you block in downstream, your pressure is going to get jacked up. And in a worst case scenario, if you compromise your separator, you could push your hydrogen back into your oxygen. You've created a flammable mixture that will very easily ignite and cause very serious damage. So a lot of times you're going to want to put in a high pressure shutdown.
Okay, great. So I'm going to measure the pressure on the hydrogen side of my electrolyzer. If the pressure goes high, I'm just going to open up a vent to a safe location that's going to vent that hydrogen out. It's going to go straight up in the sky. I'm not going to put any caps over top of it. I'm just going to send it out to atmosphere and it's going to dissipate safely. Now, if I open up that pathway to atmosphere long enough, eventually the pressure in the electrolyzer is going to drop and the oxygen from the atmosphere is going to want to backflow into the electrolyzer.
And guess what I just did? I created that explosive atmosphere again where if I find a very mild source of ignition, I can blow my electrolyzer to smithereens.
So that's one of those cases where to get to a safe state, I'm going to want to open the vent valve. But if I leave the vent valve open too long, I'm going to create the brand new hazard of an explosive mixture in the hydrogen side of my electrolyzer. So to prevent that secondary hazard from occurring, I'm going to want to automatically reset my safety function to close that valve that goes out to atmosphere to prevent the ingress.
So that's the one situation where, well, I should never say one. Never say never when you're talking about safety instrumented systems. There are probably other situations, but the thing to think through is can I leave my final element in the safe state indefinitely and not introduce a new hazard?
If that's the case, you're probably going to want to do a manual reset. But if leaving your final element in the safe state for an extended period of time creates a new hazard, you're probably going to want to consider a manual reset or maybe even redefinition of what your safe state is. All right.
## Episode Close and Preview of Clause 11.2.8
That was a very long episode. I'm pushing. We're pushing up over an hour on this episode. And we just covered three sentences in the standard. But this reset is something that requires a lot of discussion.
In the next episode, we're probably going to spend the entire episode on one clause, 11.2.8, which is manual means. There's a whole lot of stuff historical wise. There's a whole lot of stuff going forward in the future because the manual means clause in the next version of the standard, the committee has changed it. And I know this because I'm in the committee. So lots to talk about clause 11.2.8.
But I'm going to be talking about that next week.
## Kenexis Vertigo Software Advertisement
Talk to you then. Now that you've heard some insights on technical safety, functional safety, and the IEC 61511 standard, let me tell you a little bit more about how to easily and effectively implement the safety lifecycle using the Kenexis Integrated Safety Suite and our SIS Safety Lifecycle Management Tool Vertigo. Vertigo is a comprehensive tool set for performing assessment calculations, documenting, and maintaining the design of safety instrumented systems.
Analysis begins with importing or synchronizing a list of safety instrumented functions with their definitions and associated performance targets from our open PHA tool for HAZOP and LOPA documentation.
Each safety function can then be analyzed by performing a SIL verification calculation, complete with a collection of tools for optimizing designs and a database of thousands of potential instruments to define failure rates and diagnostic coverage capabilities.
After the SIL verification calculations are defined, you can build an SRS by automatically generating a cause and effect diagram from the SIF definitions and other defined instruments.
Each SIS instrument will include a customizable data sheet and general requirements that are applicable to the SIS as a whole and can be entered individually or even bulk imported from customizable libraries.
After the design phase, you can even use Vertigo to track and document testing throughout the entire life of the facility.
Kenexis Vertigo is the most integrated, easy-to-use enterprise tool for allowing the development of SIS design basis information more efficiently and effectively than any other software application.
> *
*