Alarms Aren't Controls: Interlock It When It Matters
An alarm is not a control. If a piece of equipment can eat itself in under a minute, no operator is going to save it with an acknowledge button. We designed it that way, then we blame ops for “not reacting.” That’s on us.
Example: a transfer pump kept losing bearings every few weeks. Suction strainer blinded, HMI threw low suction and high vibration. Night shift throttled a valve and hoped. Pump still cavitated to death. Well, there’s your problem. We added a DP across the strainer, blocked start if DP was high, and tripped the pump on a fast DP rise with a 5 s debounce and rate-of-change check. Also added a small bypass relief to avoid deadhead. Zero failures since, and the alarm list is quiet.
Not every trip belongs in logic. Pick interlocks by consequence to people/env, asset cost, and realistic operator response time. Then tune: hysteresis, latching with manual reset, and proof-test it.
Where do you draw the line between alarm-only and hard interlock? What logic blocks saved you the most grief?