I live in the HMI fault logs, and I take every alarm personally. Lost an hour today thanks to a chattering low-flow switch on a wash loop. HMI lit up, VFD tripped, ops took the blame. Root cause: dry contact, no debounce, and a start permissive misused as a running alarm. Trend showed on-off-on darts. Well, there's your problem: we built noise into the logic, then acted surprised.
My rules: if it can hurt equipment or spec faster than a human can react, interlock it. If it tends to chatter, filter it: deadband, time delay, or 2oo3. Permissives live before start; trips need proven instruments and sane delays. Alarms must be operator-fixable in under a minute without tools. The rest goes to maintenance, not the operator.
How do you draw the line? Do you standardize deadbands and timers by service, or let each project wing it? For chattering devices, do you fix the instrument first or add logic to get production back while you plan the repair?