OSHA’s PSM and EPA’s RMP standards require the employer to develop the Process Safety Information (PSI) regarding each covered process’s “safety systems”.
1910.119(d)(3)(i) Information pertaining to the equipment in the process shall include:
…
1910.119(d)(3)(i)(H) Safety systems (e.g. interlocks, detection or suppression systems).
§68.65 Process safety information.
…
(d) Information pertaining to the equipment in the process.
(1) Information pertaining to the equipment in the process shall include:
…
(viii) Safety systems (e.g. interlocks, detection or suppression systems).
This requirement resides in the PSI requirements for these process safety standards as this is meant to be a building block from which we will perform our PHA, write our Operating Procedures, and establish our MI inspection/testing and write maintenance procedures for these safety systems.
Define our Safety Systems
Do we know ALL of the “systems” that our operators and maintenance personnel rely on to operate and maintain the process? This includes ever alarm tone and light we expect an employee to respond to, every indicator (manual and electronic) we expect to provide personnel critical process safety data, every interlock that we expect to put the process into a safety safe should an operator fail to respond in a timely manner, every detector that will provide us early warning of a LOPC event, every fire protection system we rely on should their be a fire/release, etc.
Define “Logic” of these systems
Once we have defined what our safety systems are, we then have to define how they function and their intended results. Every person operating the process should know:
1) Every process safety alarm – this means there may be other alarms within the process, but we MUST define the process safety alarms and ensure these alarms are DISTINGUISHABLE from other alarms either by VISUAL or AUDIBLE means (or both). “Human Factors” plays a role in the NUMBER of process safety alarms a single operator may be tasked with, the COLOR of the VISUAL alarms and the TONES of the AUDIBLE alarms.
2) Every process safety interlock – this means that there may be other interlocks within the process, but we MUST define the process safety interlocks and ensure these interlocks are managed as process safety systems. This means our interlocks are tied into the Alarm system, as we want our operators to be the FIRST LINE of DEFENSE for a process deviation. This means we should be getting an ALARM well BEFORE activation of any process safety interlock. But once the operator is not able to respond to the alarm (e.g. deviation) (for whatever reason), the interlock logic MUST BE defined and the operator MUST know what is going to happen when the interlock takes control of the system/process. Define the set point of the alarm and interlock, then the function that takes place once the interlock set point has been achieved. Operators MUST then VALIDATE the interlock functioned as desinged and that the process is in a SAFE STATE.
3) Every process detector – keeping in mind that there are often two or more layers of “detectors” deployed within a process safety system:
- Process
- Perimeter
- Personal
We need to define the set points and actions each set point or operator takes. The actions we take based on the layer of detection that alarms are often times VERY DIFFERENT, but we first have to define the systems and their set points. If these detectors are tied into an interlock, this logic needs to be defined as to what functions the interlock takes when tripped.
Conduct our PHA(s) using our PSI
Once we have our “safety systems” defined (as well as all the other PSI) we can now conduct our PHA on our process(s). During the PHA we will examine the “upset” scenarios and consider our “safety systems” as a safe guard to help PREVENT the scenario from initiating, PROTECT our assets once the scenario begins, or MITIGATE the consequences of scenario. It is here that we MUST understand the INTENT of the safety system(s) and how the safety system(s) is INTENDED to function. Looking at everything from alarm set points, interlock set points, operator availability/staffing, means to communicate process deviations (e.g. call-out systems ARE WITHOUT A DOUBT a “safety system”). If our process alarm is only 5 increments from the interlock and we can go through these 5 increments in 30 seconds, yet the operator needs at least 2 minutes to respond we have a SERIOUS PROBLEM with the design of our “Safety System”. We have to realize that in even the most simple of processes the Safety System design is usually done by someone different than those who write the SOPs and in turn establish the safe upper and lower OPERATING limits – and remember, Process Safety “safe upper and lower DESIGN limits” are very DIFFERENT from our “safe upper and lower OPERATING limits”. We MUST be able to distinguish between our safety systems intended to protect our Process Components vs. those safety systems intended to maintain our process within our SAFE operating envelopes. We MUST always think “LAYERS of PROTECTION” in our safety systems design!
Write Operating and Maintenance Procedures from the PSI
We will use our PSI Design limits to establish our Safe Operating Envelopes which will be within the Design Limits established in our PSI. And once we establish our Safe Operating Envelopes and we write our operating procedures to maintain our process within these limits, both OSHA and EPA require these procedures to contain the “safety systems” that are in place that will aid the operator in maintaining the process within its established safe operating envelop.
We will also use the PSI Safety Systems information in writing our maintenance procedures for the functional testing and inspection of these safety systems. The maintenance procedures can be part of the Work Order system, but they MUST state just about everything that is in the PSI, the set point and all the functions when tripped. The maintenance personnel will then verify, on a prescribed time-frame, that the safety system performed as designed and within the time frame intended. This means every alarm could be heard/seen, each interlock function occurred in the order it is intended and within the time frame expected, etc.. All of this data is provided in the W.O./procedure but originates from the PSI “Safety Systems” documentation.
Here is a crude example using “Level” with Xylene Storage Tank that sort of gives us an idea as to what needs to be included in our “safety system” documentation and how it can be displayed:
Tank-100 (50,000 gallon Xylene atmospheric storage)
LEVEL
- Safe Upper Design Limit – 90% (45,000 gallons / 324,000 pounds)
- Safe Lower Design Limit – 2% (1,000 gallons / 7,200 pounds)1
1 Safe Lower Limit established based on the depth of the xylene on the 3″ dip tube being maintained at least 1.5″ up on the dip tube so that flow rates can be maintained at 15 gpm for a non-conductive flammable liquid.
Safety System(s) – Level
High Level Alarm @ 80% (40,000 gallons)
- Alarm light tree goes to “yellow” at unloading station control panel.
- The alarm tone is “Hi-Lo” and is sounded only at the Unloading station.
High-Level Alarm also makes notification to:
-
- All Operators on shift within unit via 2-way radio
- Unit Supervisor responsible for the vessel involved via cell phone
High-High Level Alarm @ 87% (43,500 gallons)
- Alarm light tree goes to “red” at unloading station control panel and control room board.
- The alarm tone at BOTH locations is a “constant piercing tone”.
High-High Level Alarm also makes phone notifications to:
-
- All Operators on shift within unit via 2-way radio
- Unit Supervisor responsible for the vessel involved via cell phone
High-High Level Interlock @ 89% (44,500 gallons)
- Alarm light tree begins to strobe “clear” at unloading station control panel and flashing control room board.
- The alarm tone is a “fire truck siren” which can be heard at ALL unloading stations and in the control room.
High-High Level Interlock also makes phone notifications to:
-
- Op’s Manager via cell phone
- EHS Manager via cell phone
- ERT Superientendent on Shift via 2-way radio
- Unit Supervisor responsible for the vessel involved via cell phone
High-High Level Interlock Logic:
When the High-High Level Interlock set point is reached, the designated alarms will sound making notifications to those specified above. The interlock will:
- TURN OFF unloading Pump(s) P-100 and P-1012
- CLOSE manual fill valves (ESDV-100 and 101) on Tanks 100 and 101
2 Start-up following this ESD will require Op’s Unit Manager to enter his/her Password to reset pumps
Secondary Containment Containment for Tank-100 is sized @ 55,000 gallons
Dike is NOT equipped with a sump pump – EHS manager MUST approve any pumping from dike
Dike is NOT equipped with a drain valve – EHS manager MUST approve any pumping from dike
Process/Dike LEL Detector Alarm
- Set to alarm at UNLOADING Station @ 2% LEL (20,000 ppm)
- LEL alarm light goes to a steady “red” at unloading station LEL Panel and Tank Farm LEL panel.
- The alarm tone is a “pulsing same tone” which can be heard at ALL unloading stations and tank farm.
LEL detector(s) also makes phone notifications to:
-
- All Operators on shift within unit via 2-way radio
- Unit Supervisor responsible for the vessel involved via cell phone
Process/Dike LEL Detector Alarm and Interlock
- Set to alarm AND SHUTDOWN ALL transfers to AND from Tank-100 and Tank-101 (west) @ 5% LEL (50,000 ppm)
- LEL alarm light goes to a strobe “red” at unloading station LEL Panel, Tank Farm LEL panel, and control room board.
- The alarm tone is a “falling-off tone” which can be heard at ALL unloading stations, tank farm, and control room board.
LEL detector(s) also makes phone notifications to:
-
- All Operators on shift within unit via 2-way radio
- Op’s Manager via cell phone
- EHS Manager via cell phone
- ERT Superientendent on Shift via 2-way radio
- Unit Supervisor responsible for the vessel involved via cell phone
There are a lot of different ways to document and display this information, but the details of the content should be very similar to what I have explained. More complex process will have much more work involved in developing this logic and more documentation to maintain than those smaller and simpler processes. Bottom line is that we need this information in a usable format to build our process safety management systems such as PHA, Operating Procedures, and MI inspection and testing programs/procedures. The example provided was a SINGLE storage tank and covered a SINGLE process parameter – LEVEL. In reality we would want to do the same exercise for ALL those process parameters for which we designed to, such as pressure, temperature, etc.
