How to Clear a Lockout Without Losing the Evidence
Why this matters
The single most wasted act in controls work is walking up to a locked-out machine and pressing reset. It takes two seconds, it usually works, and it destroys most of what the machine had to say. The tech then spends the next hour trying to recreate, from a running machine, a state that was sitting there fully formed when they arrived.
The claim: the evidence around a lockout decays at wildly different rates, so the capture has to be ordered by how fast each kind disappears, with the clear itself last because it is the only irreversible step in the procedure. The order below is that decay order, fastest first, and each step states its own half-life so you can judge what is already gone before you start.
Establish why it locked out before you clear it
The lockout is a report. A machine that locked out because a protective device operated has told you a physical condition existed. Clearing it, resetting it repeatedly, or replacing the device that reported it all reach the same end state as jumpering that device, one step slower. Nothing in this procedure clears anything until the capture is complete and you have a hypothesis about the condition.
And the terminology warning, because it kills people: a control lockout is not an isolation. The machine is fully energized and can start the instant it is cleared. Under 29 CFR 1910.147(b) an energy isolating device is a mechanical device that physically prevents energy transmission, and that definition excludes control circuit type devices. Any work inside the machine means real isolation: 29 CFR 1910.333(b)(2) for electrical, with live-dead-live verification per NFPA 70E-2021, 120.5, and 29 CFR 1910.147 for mechanical isolation and stored energy such as a spring-return actuator, an accumulator or a pressurized line.
Where a capture step needs the circuit live, 29 CFR 1910.333(a)(1) permits energized work only where de-energizing would introduce additional or increased hazards or is infeasible for the equipment design, using a meter rated at or above the system voltage in the correct measurement category, with leads and probes inspected for damage first as 29 CFR 1910.334(c) requires, and the shock and arc-rated protection of 29 CFR 1910.335(a) and NFPA 70E-2021, 130.7. If the machine burns fuel, wear a personal CO monitor on your collar before anything is cleared, because the first thing a successful clear does is fire it.
Step 1: Take the customer's account before you offer any explanation
Half-life: hours, and it shortens the moment you speak.
Ask what they saw and heard, in what order, and at what time, before you say a single word about what you think is happening. A customer who has been told "it's probably the sensor" will start reporting sensor-shaped observations within the same conversation, without any intent to mislead. Their raw account is only available once.
Ask three things specifically: what they did immediately before it stopped, whether anyone has already pressed anything, and whether the power has been off since. The last two determine how much of everything below still exists.
Skip this and you contaminate the only witness.
Step 2: Read the volatile physical state
Half-life: tens of minutes to about an hour for small components in still cabinet air, longer for large masses and for anything still under pressure.
This is the fastest-decaying evidence and it decays whether you clear or not, so it goes first among the physical steps.
Read component surface temperatures with a non-contact infrared thermometer from arm's length rather than by touch, because a housing that ran under load will burn through a general-handling glove. Use these readings as a binary only: a component clearly above surrounding cabinet metal dissipated energy, one indistinguishable from it did not. A surface temperature is not the internal temperature and it is not a runtime measurement, so do not convert it into how long or how hard something ran.
Also record, without moving anything: the resting position of every actuator, whether any rotating element is still turning, whether any pressure differential remains on a gauge, and whether condensate or wetted surfaces are present where a completed process would leave them.
Skip this and the bracket you would have built is gone by the time you finish reading the display. The companion article on establishing where in the sequence it stopped is what these readings feed.
Step 3: Capture the live electrical state that exists only while locked out
Half-life: instantaneous on clear or on any power interruption.
Some controls hold specific outputs in a defined state during lockout, and some inputs sit in the state that caused the fault. Those readings exist right now and will never exist again on this fault.
Take them at accessible external test points where the design provides them, under the energized-work conditions above, with the enclosure in its normal configuration. If the readings require opening a barrier and reaching past energized parts, they are not worth it; note what you could not measure and move on.
Skip this and you lose the only chance to see the fault condition as the controller saw it.
Step 4: Photograph the displayed state before you navigate away from it
Half-life: instantaneous on clear, and on many controls also on a menu change.
Photograph the code, the indicator, or the flash pattern exactly as found, including how many flashes and in what grouping if that is how the control reports. Do it from outside the arc path with the enclosure as you found it. Then write down the wall-clock time, because a code without a time cannot be matched against a utility event, a weather event, or the customer's account.
If the control shows a flash pattern rather than a code, record it in the raw form first and translate it second. Translating from memory later is where a two-plus-three pattern becomes a five.
Skip this and every later conversation is about what you remember seeing.
Step 5: Read the volatile fault buffer before touching power
Half-life: survives a reset button on most controls, does not survive a power interruption on many.
Many controls hold a short list of recent faults in working memory that is not the same store as the permanent history. That list is where an intermittent lives, and it is the specific thing a power cycle wipes. This is why "just cycle the power" is the most expensive clear method available and belongs last, not first.
Skip this and an intermittent fault becomes a single-event fault in the record.
Step 6: Read the nonvolatile counters
Half-life: not time, but future events. Rolling buffers overwrite oldest first, so a machine that faults twenty more times before the next visit may no longer hold today's entry.
Read and write down every counter the control exposes with the date and time: trials or attempts, cycles or starts, run hours, lockout occurrences, and the permanent fault history. Reading them now rather than after the clear matters even though they survive the clear, because the clear itself frequently increments one of them and you want the before figure.
Skip this and you have no baseline to compare against on the next visit, which is the whole mechanism by which a repeat call gets solved.
Step 7: Clear it, by the least destructive method available
Half-life: n/a. This is the irreversible step.
Rank the available methods and take the highest one that works:
| Method | What it preserves | When to use it |
|---|---|---|
| Manual reset at the device or control | Counters, history, and usually the volatile buffer | First choice, always |
| Controller menu clear | Counters and history; buffer varies | When there is no reset control |
| Demand cycle or timed self-clear | Everything, since you did nothing | When you can wait for it |
| Power interruption at the disconnect | Counters and history only | Last resort |
| Lifting a conductor or pulling a fuse | Nothing, and it introduces a new fault | Never |
Before you press anything, stand clear of every moving part and the flue and relief path, with all guards in place, and tell anyone present that the machine is about to start. A successful clear starts the machine, immediately, with no further warning.
The capture record, filled in
One machine, arrived roughly forty minutes after the customer reported the stop.
| Field | Captured |
|---|---|
| Customer account | Stopped during a normal run, no one pressed anything, power has not been off |
| Air mover housing | About 22 F above surrounding cabinet metal, so it ran |
| Output device body | Indistinguishable from cabinet metal, so it did not |
| Actuator position | At driven position, not rest |
| Displayed code | Photographed, output proving failure, at the recorded wall-clock time |
| Volatile buffer | Same code three times, spanning about eleven minutes |
| Trial counter | 1,431 |
| Run hours | 2,206 |
| Lockout occurrences | 14 |
| Clear method used | Manual reset at the control |
The buffer entry is what earned the visit. Three identical faults inside eleven minutes, on a control with a 3-trial budget, means the machine spent its whole budget in one demand cycle and the condition was continuously present. That is a persistent fault, diagnosable live, and it justified staying rather than clearing and leaving.
What the record was worth on the next visit. The machine locked out again eleven days later. Counters read: trial counter 1,449, lockout occurrences 20.
The differences are 1,449 - 1,431 = 18 trials, and 20 - 14 = 6 lockouts. Cross-check those against each other: 18 trials at 3 per lockout is exactly 6 lockouts, so every one of the 18 trials failed and none succeeded. Two independently maintained counters agreeing is what makes that conclusion solid rather than an assumption, and it is the reason to record both rather than whichever one is easier to reach.
Run hours over the same eleven days had moved by less than an hour, against a machine that should accumulate several hours a day under the demand it was seeing. So the machine was attempting and failing continuously, not working intermittently, and the customer's report that it had "been alright some days" was about the auto-retry cadence rather than about the machine running.
What would have changed the reading. If the 18 trials had produced only 2 lockouts, then 12 of the 18 trials succeeded and this is a genuinely intermittent fault requiring instrumentation rather than a live diagnosis. If run hours had moved normally, same conclusion. And if the lockout occurrence counter is one that resets on a manual clear, which varies by control and should be confirmed rather than assumed, the difference of 6 is not a difference at all and the trial counter has to carry the finding alone.
The failure mode this procedure exists to prevent. On the first visit, pressing reset on arrival would have produced a machine that started and ran. The volatile buffer would have survived that particular clear, but nobody would have looked at it, because a running machine does not prompt anyone to. The visit would have closed as no fault found, and the second visit eleven days later would have started from zero instead of from two counter readings that settled the fault class in under a minute.
References
- 29 CFR 1910.147 for isolation of hazardous energy, including the definition of an energy isolating device at 1910.147(b) that excludes control circuit type devices
- 29 CFR 1910.333(a)(1) for the conditions permitting energized measurement, 1910.333(b)(2) for de-energizing and lockout of electrical circuits, 1910.334(c) for test instrument inspection, and 1910.335(a) for electrical protective equipment
- NFPA 70E-2021, 120.5 for live-dead-live verification and 130.7 for protective equipment selection
- Manufacturer control documentation for the retry budget, which counters reset on a clear, and whether the recent-fault buffer survives a power interruption
- See related: What a Lockout Condition Means to the Equipment; How to Establish Where in the Sequence It Stopped; What a Manual Reset Is Telling You