Imagine having a pressure vessel that has a MAWP of 300 psi and yet there is no high-pressure alarm before 300 psi is reached. How would an operator know he/she is approaching their consequence limit? As I wrote about earlier this year, a well-designed process will have both alarms – BEFORE the safe upper/lower operating limit is achieved so that the operator(s) can “AVOID the deviation” and another layer of alarms once the safe upper/lower limit is reached so that the operator(s) can “CORRECT the deviation”. Some processes may even have a 3rd layer of alarm(s) with an interlock or some other type safety system just in the case the operator(s) were unable to respond in a “timely manner” for whatever reason(s). For example, using “pressure” as our critical process parameter…
we would establish our safe upper and lower “operating pressure limit” for the vessel. This limit, as we have discussed many times, will be low enough to ensure adequate response time BEFORE the MAWP is exceeded and we end up with an LOPC event via our pressure relief system. For this article let’s use a MAWP of 300 psi and a Safe Upper-Pressure Limit of 250 psi.
We then discuss the “human factors” associated with the operation of this vessel and realize it is run without constant monitoring AND the response time from operations could be XX minutes. This makes this vessel an excellent candidate for an early ALARM (i.e. 215 psi) so as to provide an EARLY indication that the pressure is outside the normal range (i.e. 100-215) and thus the operator can begin his/her investigation into this alarm. Again, the steps the operator would be following at this stage of the event would be “steps to AVOID” a process deviation. Should the operator not respond in a timely fashion and the pressure continues to rise, the vessel would alarm again and this alarm would be an indication that the vessel has now exceeded the safe upper limit (i.e. 250 psi) and the steps the operator would be taking at this time would be called “steps to CORRECT” a process deviation.
And yet, some vessels/processes may have even another layer of alarm, oftentimes accompanied with an independent safety system like an interlock. This 3rd alarm set point would be the emergency shutdown point, should the operator(s) be unable to avoid/correct the deviations. This set point is usually 15-20 psi lower than the relief system set point when the RD discharges to the atmosphere. Sometimes, a company will use a smaller safety margin when the RD discharges to a destruction/treatment system.
But this entire process design BEGINS with some type of INDICATOR that communicates with a trained operator who then uses operating procedures to try an AVOID/CORRECT the deviation.
NOTE: Some facilities may wish to claim “shift rounds” as an indicator and this may work very well in some situations; however, when the pressure rise can outpace the frequency of “rounds”, claiming “rounds” as a layer of protection is just playing games with process safety. Some RAGAGEPs allow up to a 72-hour window for rounds and if our process can go from its “normal range” to a “deviated state” requiring operator intervention in 2 hours, a 72-hour rounds schedule will fall short as our necessary “indicator”.
Bottom line… when SAFTENG is involved in designing or analyzing processes, it is our expectation that all process safety-critical parameters are equipped with at least an indicator for when the process exceeds the safe upper/lower limit for that parameter. The earlier alarm is nice, although depending on the HMI for the process, we may also strongly suggest it, as well as the ESD system.
