How to Establish Where in the Sequence It Stopped

Why this matters

Most of a control sequence runs faster than a person can watch, and you almost never arrive while it is running. You arrive afterwards, at a machine sitting still, with a customer who says it "just stops" and a controller showing a fault label that names a consequence rather than a location.

The method here is a bracket. You establish the stop point by finding the last step that left a physical trace behind and the first step whose absence left one, then closing the gap between them. That works on a machine that has been off for two hours, it works with no documentation, and it does not require you to be lucky enough to be standing there when it happens.

Before anything else, establish why it is stopped

If the machine is sitting on a safety device or a lockout rather than an ordinary off state, you do not get to re-run it to see what happens until you know what opened and why. Replacing or resetting a device that operated correctly reaches the same end state as jumpering it, one step slower. Establish the opened device and the physical condition that opened it first; the sibling articles on lockout conditions and manual resets carry that work.

For the hands-on that follows: any enclosure you open for a reading gets de-energized and locked out per 29 CFR 1910.333(b)(2), proved dead live-dead-live against a known source per NFPA 70E-2021, 120.5. Readings that genuinely require the circuit live fall under 29 CFR 1910.333(a)(1), which permits energized work only where de-energizing would introduce additional or increased hazards or is infeasible for the equipment design, and they need a meter rated at or above the system voltage in the correct measurement category, with leads and probes inspected for damage before first use as 29 CFR 1910.334(c) requires. Mechanical isolation and stored energy - a spring-return actuator, an accumulator, a pressurized line - is 29 CFR 1910.147 instead, and 1910.147(a)(1)(ii)(C) is why those are two different standards rather than one.

While the machine runs, stand outside the swept path of any rotating or driven part with all guards in place and no loose clothing or lanyards, and if the machine burns fuel, wear a personal CO monitor on your collar before it fires and stay out of the flue and relief-opening path.

Step 1: Get a coarse timeline, even a wrong one

You cannot bracket without an ordered list of steps. Use the published sequence if there is one. If there is not, write a coarse one from what the machine physically has: an enable, a first mover, a proof of that mover, a wait, a second output, a proof of that, a run state. Five to eight steps is enough, and deriving one properly on an undocumented machine is its own article.

Skip this and you lose the frame entirely. Every later observation becomes an isolated fact with nothing to attach to, which is what "I checked everything and it all reads fine" actually means.

Step 2: Set the lower bound from what left heat, motion, or a moved part behind

Walk the machine cold, before you touch a reset. Physical traces of completed steps persist for minutes to hours:

  • A motor or coil that ran is warm. Read it with a non-contact infrared thermometer from arm's length rather than touching it, because a housing that ran under load will burn through a general-handling glove.
  • A driven actuator that completed its travel is sitting at its driven position rather than its spring or rest position.
  • A retained counter has incremented: run hours, cycle count, trial count.
  • Condensate, a warmed pipe section, or a settled float all indicate a process actually happened.

The latest step in your list that has a trace is your lower bound. The machine got at least that far.

Skip this and you lose the only evidence that decays. Thermal traces are gone in under an hour on small components, and the first reset you press may clear the counters. This step is second rather than first only because Step 1 gives you somewhere to write the answer.

Step 3: Set the upper bound from what is conspicuously at rest

Now the mirror. Find the earliest step in the list with clear evidence it never happened: a solenoid body at exactly ambient while its neighbours are warm, an actuator still at its rest position, an unfired heat source, a downstream section of pipe or duct at room temperature.

That is your upper bound. The bracket is now every step between the two, inclusive of the upper bound and exclusive of the lower.

Skip this and the bracket is open at the top, which means you are back to testing every device downstream of the last known good point. On a seven-step sequence that is usually four or five devices instead of one or two.

Step 4: Close the bracket with one timed re-run

If the bracket contains a single step, you are done. If it contains two or more, you need one controlled re-run, and the whole value of it is the stopwatch, not the watching.

Start a stopwatch on the enable command and record the wall-clock second of every audible or visible transition and the second everything stops. Do not estimate. The difference between a stop at 41 seconds and a stop at 44 seconds is frequently the difference between two unrelated faults, and "about forty seconds" throws that away.

Run it from a position outside the hazard zone described above, with the panel closed and secured, and with the machine's own protective devices all in place. Nothing about this step involves defeating anything.

Skip this and you are guessing between the bracket's members, which usually resolves as replacing the most accessible one.

Step 5: Match the stop time against the sequence's own durations

The stop time is only diagnostic when compared against a published or derived duration. A stop that lands exactly at the end of a trial period means the trial ran and nothing proved. A stop that lands a second or two INTO a period means a permissive dropped at the moment something energized, which is a different fault with a different cause list.

Skip this and the timing was wasted. A number with nothing to compare it against is not evidence.

Worked example: a bracket that closed on one step

A packaged machine with a seven-step sequence. Published durations: proving window 10 seconds from the start command, purge period 30 seconds running from the moment proof is made, output trial 4 seconds. Arrived to find it stopped with a fault label reading, in effect, that the output failed to prove.

Cold walk, roughly ninety minutes after the last attempt:

Observation Reading What it bounds
Air-moving device motor housing Clearly above the surrounding cabinet metal Ran
Damper actuator At its driven position, not its spring position Completed travel
Output device solenoid body Indistinguishable from cabinet ambient Never energized long enough to warm
Ignition-side component Same as ambient No trace

Lower bound: the damper drive completed, which is step 3. Upper bound: the output device never energized, which is step 6. Bracket: steps 4, 5 and 6.

Note what the fault label did and did not contribute. It named the output proof, which is a consequence at the END of the bracket. On its own it would have sent a tech straight to the output proving device. The bracket says the same thing but keeps steps 4 and 5 alive as candidates, which is the point.

One timed re-run, stopwatch started on the enable:

Wall clock (seconds) Event
0 Enable, air-moving device starts
7 Proving transition audible
40 Output device energizes, audible click
44 Everything stops

Now compare against the durations. Proof at 7 seconds is inside the 10-second window, so step 4 passed. Purge should run 30 seconds from proof at 7, which puts its end at 37 seconds, and the output energized at 40. Those do not match, and the 3-second discrepancy is worth naming rather than rounding away: either the purge timer is set 3 seconds longer than the published 30, or the controller holds the full 10-second proving window open regardless of when proof actually arrives and starts its purge clock at the expiry of that window, which puts the purge at 10 through 40 and the output at 40 exactly. The second reading fits the observation without any setting being off, and it is a real convention difference between controllers, so record it as an unresolved detail rather than a fault.

The stop at 44 seconds sits exactly 4 seconds after the output energized at 40, which is exactly the published trial length. So the trial ran to full duration and nothing proved. The bracket closes on step 6, and steps 4 and 5 are eliminated on evidence rather than assumption.

What would have changed the conclusion. Had the stop landed at 41 seconds, one second into a 4-second trial, no trial timeout could explain it. That points instead at a permissive dropping the instant the output loaded the circuit, which is a supply or coil-pickup problem, not an output-proving problem, and the two share no parts. Same machine, same fault label, same bracket, opposite repair, distinguished only by three seconds on a stopwatch.

The failure mode. The common wrong ending is to trust the fault label, replace the output proving device, and hand the machine back running because the re-run happened to succeed. It often does succeed once. When the complaint returns in a week, the record now contains a replaced part and no timing, so the next tech starts from a worse position than the first one did.

When the bracket will not close

Two cases, both worth recognizing rather than fighting.

It runs correctly every time you watch it. Then the fault is not a fixed stop point and bracketing is the wrong tool; you need a fault the machine records itself, or a logging setup left in place across several cycles. Forcing repeated re-runs to catch it is hard on the equipment and on any protective device that has to operate each time.

The bracket spans steps with no physical trace between them. Some sequences have two or three consecutive logic-only steps that move no metal and generate no heat. There the timed re-run is not a tiebreak, it is the only evidence, and it is worth running twice to confirm the stop time repeats before you build on it.

References

  • 29 CFR 1910.333(a)(1) for the conditions under which energized troubleshooting is permitted, 1910.333(b)(2) for de-energizing and lockout of electrical circuits, 1910.334(c) for inspection of test instruments and leads
  • 29 CFR 1910.147 for mechanical isolation and stored energy, including 1910.147(a)(1)(ii)(C), the exclusion that separates it from electrical work on utilization equipment
  • NFPA 70E-2021, 120.5 for verification that a circuit is de-energized
  • Manufacturer service documentation for published step durations, purge clock reference points, and retained counter behaviour
  • See related: How to Read a Sequence of Operation as a Diagnostic; What a Sequence Tells You That a Wiring Diagram Cannot; What a Lockout Condition Means to the Equipment