Executing Work Inside a Fixed Outage Window
Purpose
To execute work inside an outage window that has a fixed handback time, and to hand the system back on time every time. The control that makes this work is not the schedule and not the crew's speed. It is the abort decision: a clock time, computed backwards from handback rather than forwards from the start, owned by one named person, at which the crew stops advancing the work and starts restoring it. A shop that sets that time before the window opens hands back on time even on the days the work goes badly. A shop that does not is relying on the work going well, which is not a plan.
Scope
Applies to any work at an institutional or commercial site where a system is taken out of service inside an agreed window with a committed return-to-service time: electrical distribution, mechanical plant, water systems, life safety systems, process equipment. It covers the period from the day before the window through the record entry after handback.
It does not cover how the window was obtained or how it was priced; those are separate articles in this library. It assumes the window, the isolation boundary and the interim measures are already agreed in writing.
Roles and responsibilities
| Role | Held by | Responsible for |
|---|---|---|
| Window lead | The shop, one named person on site the whole window | The abort decision, the milestone gates, all outbound communication |
| Authorizing individual | The facility | Permitting the outage, authorizing return to service, accepting handback |
| Isolation authority | The facility's operator or engineer, or the shop where the facility delegates it in writing | Operating valves and disconnecting means, applying and removing isolation |
| Crew | The shop | Executing the task, reporting milestone status, stopping when told |
| Interim measures attendant | Whoever the agreement names | Fire watch, temporary lighting, temporary cooling, occupant control |
One person holds the window lead role for the whole window. If a shift change is unavoidable, the handover is face to face, at the run sheet, with the abort time read aloud.
Procedure
1. Build the timeline backwards from handback, the day before.
Start at the committed handback time and subtract, in this order: the walk-down and proving time with the facility's representative, the restore and re-energize sequence, and a contingency of at least the length of the restore itself. What remains is the working period. Building forwards from the start time is how crews arrive at the handback hour with the system in pieces, because forwards planning always spends the contingency on the work.
2. Set the abort time and name the fallback state.
The abort time is the end of the working period from step 1. Write it on the run sheet in large figures. Then write the fallback state next to it: the specific condition the system will be in if the abort is called. "Original breaker reinstalled and torqued" is a fallback state. "We will put it back" is not. A fallback state is only real if the parts and tools to reach it are on site and the removed component has been kept serviceable rather than dismantled.
3. Verify the preconditions the day before, not on the morning.
- Materials complete, including the fallback parts and the consumables for the restore.
- Permits issued and covering the whole window: hot work, confined space, line breaking, alarm impairment. Confirm whether any expires at a shift boundary inside your window.
- People cleared, badged, and their badges tested at the doors and at the hours the window runs.
- Interim measures confirmed with the person providing them. Two commonly bite: losing normal power puts egress illumination onto batteries, and life safety requirements are built around emergency illumination for at least 90 minutes, so a multi-hour outage needs temporary lighting arranged in advance; and a fire alarm panel on secondary power is sized for a defined standby period under NFPA 72, commonly 24 hours for a protected premises system plus an alarm period, which holds only if those batteries are known good.
4. Open the window with isolation and verification, and do not compress this.
The isolation is executed by the isolation authority and verified by the window lead. For electrical work the disconnecting means is locked and tagged under 29 CFR 1910.333(b)(2), and the circuit is proved dead with an adequately rated tester checked on a known live source immediately before and immediately after the test, per NFPA 70E-2021, 120.5. For mechanical isolation and stored energy the standard is 29 CFR 1910.147: relieve pressure, block or discharge stored mechanical energy including charged closing springs and accumulators, and verify at zero before anything is opened.
Two hazards belong to the isolation act itself and land on people who are not in your work area. De-energizing a board that feeds elevators can trap a person in a car, so confirm every car is parked at a landing with doors open and the building swept, with the facility's elevator procedure followed, before the disconnecting means is opened. And confirm which life safety systems sit downstream of your isolation, because the answer determines whether a fire watch starts at the same moment your lock goes on.
5. Set milestone gates with a clock time and a numeric criterion.
Not "check progress." Each gate is a clock time, a state the work should be in, and a tolerance. A workable default is a tolerance of 0.5 hour at each gate: at or inside 0.5 hour behind plan, proceed; more than 0.5 hour behind, the gate is failed and the plan is revised at that gate rather than at the abort time. Tune the tolerance to the length of the window, but state it as a number before the window opens, because a tolerance decided in the moment is always generous.
6. Identify the point of no return and require explicit authorization to cross it.
Exactly one task in most windows makes the fallback state unreachable: the cut, the dismantling of the removed component, the download that overwrites the old configuration. Mark it on the run sheet. Nobody starts it without the window lead saying so out loud, and the window lead does not say so if the preceding gate failed. This single rule prevents most overruns, because overruns are rarely caused by the work being slow. They are caused by the work being slow and someone starting the irreversible task anyway.
7. Execute with a fixed communication cadence.
The window lead reports to the authorizing individual at each gate, briefly, whether the news is good or not. Reporting only when there is a problem trains the other side to read your silence as trouble. Report a slip of 15 minutes as a slip of 15 minutes, at the moment it appears.
8. If the abort is called, restore first and argue later.
The abort branch is not a failure and is not negotiable at the time. Stop advancing, return to the fallback state, restore, prove, hand back. The conversation about the remaining work happens after the system is up, from a position of credibility rather than from the middle of an overrun.
9. Restore and prove in a defined sequence.
Restoration is the highest-consequence part of the window and it lands at the tired end of it. Remove tools and personnel from the equipment, account for them by count against the inventory taken at the start, refit guards and covers, then re-energize or refill in the documented order with nobody inside the arc flash boundary or in line with a pressurised joint. Prove function against the criteria agreed in advance, not by inspection. Where water has been isolated in an occupied building, flush the branch to drain before it reaches fixtures, minimising aerosol at the discharge point, and coordinate the return to service with the facility's water management program.
10. Hand back to a person, not to a clock.
Handback is the authorizing individual confirming the system is accepted, with the time recorded. Until someone accepts it, it is still your outage.
11. Close the record in their system, the same day.
On institutional work the facility's work order or maintenance management ticket is frequently the only record that counts. Enter what was done, what was not done and why, the actual times, and any temporary condition left in place with its removal date. Your own paperwork is not a substitute and will not get you paid.
Worked example: the run sheet for a courthouse switchboard window
A county courthouse main switchboard, annual maintenance, agreed Sunday window 06:00 to 16:00, handback committed at 16:00. Crew of three. Building closed to the public, security staff present.
Backwards timeline, built the previous Thursday.
| Element | Duration | Clock |
|---|---|---|
| Handback | - | 16:00 |
| Walk-down and prove with the county electrician | 0.75 h | 15:15 |
| Re-energize sequence | 1.25 h | 14:00 |
| Contingency | 1.25 h | 12:45 |
| Abort time | - | 12:45 |
| Working period | 6.00 h | 06:45 to 12:45 |
| Isolation, lock, tag, prove dead, discharge springs | 0.75 h | 06:00 to 06:45 |
Fallback state: original main breaker reinstalled, torqued to specification and ready to close. The original breaker is kept assembled and serviceable on a cart until the replacement components are proven, which is what makes the fallback reachable at all.
Gates, with a 0.5 hour tolerance each:
- 06:45, gate one: every point of work proved dead, springs discharged. Pass or abort immediately at no cost.
- 09:30, gate two: cleaning, infrared survey and connection torque checks complete. This gate precedes the point of no return.
- 12:15, gate three: breaker service complete and reassembly begun.
- 12:45: abort time.
The first draft of this sheet carried 1.00 hour of contingency against a 1.25 hour restore, which fails step 1's own rule that contingency is at least the length of the restore. It was caught on the Thursday, not on the Sunday, and the abort moved back fifteen minutes. A rule that only gets applied when it is convenient is not a rule, and the cheapest place to find that out is at the table.
Point of no return: dismantling the main breaker's operating mechanism, scheduled to start at 09:30.
What actually happened. At 09:30 the crew was 0.6 hours behind, because the torque check found three connections that had to be re-terminated rather than re-torqued. Gate two failed on its own stated tolerance of 0.5 hour, so the window lead did not authorize the breaker dismantling. That was the correct call and an unpopular one with a crew that felt it could make the time back.
The revised plan spent the remaining working period on the in-scope items that stayed restorable: the balance of the terminations, the ground and bonding inspection, and the labelling, running 09:30 to 12:15. Close-up ran 12:15 to 12:55, the re-energize sequence 12:55 to 14:10, and the walk-down with the county electrician finished at 14:55. Handback was accepted at 14:55, 65 minutes ahead of the committed time.
The counterfactual. Had the crew crossed the point of no return at 09:30 while 0.6 hours behind, the breaker would have been in pieces at the 12:45 abort with no fallback available, because the fallback state depended on the breaker being assembled. The overrun would have been open-ended, the fire watch and temporary lighting posts would have extended hour for hour, and the county would have been managing a building with no main breaker into Sunday evening. The 0.6 hour of slippage was not the problem; starting the irreversible task while carrying it would have been.
What handing back early bought. A second three-hour window for the breaker service at the next available Sunday, granted without argument, because the shop had demonstrated that its abort time was real.
References
- 29 CFR 1910.333(b)(2) (electrical work practices) and NFPA 70E-2021, 120.5 (establishing and verifying an electrically safe work condition)
- 29 CFR 1910.147 (control of hazardous energy, including stored mechanical energy)
- NFPA 72 (fire alarm secondary power standby requirements) and NFPA 101 (emergency illumination duration)
- 29 CFR 1910.134 (respiratory protection program)
- See related: How to Negotiate a Shutdown Window; What an Outage Window Really Costs Both Sides