How to Establish Why a Safety Device Opened

Why this matters

A tripped limit is the easiest fault in the trade to make disappear and one of the harder ones to actually solve. Press the button, the machine runs, the customer is happy, and you have learned nothing about the condition that put it there. Replacing the device instead of pressing the button reaches the same place one invoice later, with a part on the ticket that makes it look like work was done.

The device is a witness. It saw a quantity cross a boundary at a specific place at a specific moment. The whole job is to get that testimony out of it before you do anything that destroys it.

The steps below are ordered by what skipping each one costs you, worst first, which is not the order you would naturally work them. Two are deliberately out of their comfortable position: capturing the record sits near the top because it is perishable, and evaluating the device itself sits at the bottom because doing it early is precisely what costs people a good part and a return visit.

The gates before any of it

If the equipment is electric, decide the energized-work question consciously. Measuring a running circuit is permitted under 29 CFR 1910.333(a)(1) where de-energizing would introduce additional or increased hazards or is infeasible given the equipment design, and a live sequence measurement is a standard example of the second. Use a test instrument whose measurement category rating suits the circuit and the point you are attaching to. When you move to opening a cabinet rather than observing one, that is 29 CFR 1910.333(b)(2) for electrical isolation, and the live-dead-live proving sequence on a known live source before and after is NFPA 70E-2021, 120.5.

Heat is the one that gets people on this specific job. Resistance elements, combustion surfaces and heat exchangers hold enough energy to burn for many minutes after the circuit drops, so confirm temperature with a contact probe on the part you intend to touch rather than on the cabinet beside it, and keep out of a discharge opening that may still be carrying hot air.

Step 1: Do not reset, and find out whether the condition is still there

Cost of skipping: you restart the machine into the exact condition the device stopped it for, and you erase a latched state you cannot get back.

Before a finger goes near a reset button, answer whether the thing that tripped it is still happening. Is the surface still hot, is the pressure still high, is the guard still open, is the current still drawn. A latched device is holding the machine in a safe state, and clearing that latch is the one action in this procedure that is not reversible.

Step 2: Capture what is perishable

Cost of skipping: evidence that no later measurement can reconstruct.

Photograph the panel with every indicator visible. Write down which devices are latched and which are not, in what order the indicators are lit, and the current readings on any display before you touch a menu. Pull the controller's alarm or event buffer now, because those buffers are finite and they roll: on a machine cycling frequently, an event from last night can be gone by the time you finish lunch. If the buffer has timestamps, get the controller's clock offset from real time in the same pass, or every time you read later will be wrong by an unknown amount.

Step 3: Reconstruct what changed, while it is still recoverable

Cost of skipping: you find the condition and never find the cause, and by tomorrow nobody remembers.

This is the step people leave for last and it belongs here, because human memory of "what was different" decays within days. Ask what changed: a filter change, a setting adjusted, a door propped, a load added, a season turned, another contractor on site, a part replaced. Ask when the trips started and whether they cluster at a time of day. Then look at the written record for the same period, and treat a gap in the record as information rather than as nothing: a repack, a board swap or a wiring change with no note beside it is a place where something could have been disturbed.

Step 4: Name the quantity and the location

Cost of skipping: every measurement you take afterwards is confidently measuring the wrong thing.

A protective device senses one quantity at one point. Write both down before you measure anything. Not "temperature" but the temperature of the air stream at the disc location a few inches downstream of the elements. Not "pressure" but the pressure at the discharge tap ahead of the check valve. This is where most wrong diagnoses are born: a tech measures the quantity the device is named after, at the place that is convenient, gets a normal number, and concludes the device is faulty. The device was reading somewhere else.

Step 5: Measure it there, under the condition that trips it

Cost of skipping: you finish with a hypothesis, and you will defend it.

A measurement taken at idle proves nothing about a device that trips under load, at the end of a cycle, or on a hot afternoon. Instrument the point the device senses, run the machine through the condition that produced the trip, and record the value continuously rather than as a spot reading. If the trip is intermittent, this is the step that costs time, and it is the step that is worth the time.

Step 6: Compare against setpoint and against the actual trip point

Cost of skipping: you cannot tell a drifted device from a real condition, which is the one distinction this whole job exists to make.

Two numbers, not one. The setpoint is what the nameplate or the configuration says. The actual trip point is where the device opened when you watched it. If your measurement crossed the setpoint, the condition was real and the device was right. If the device opened well below its setpoint, the device has drifted or its sensing element has failed. Read the nameplate rather than reciting the value you expect; devices get substituted.

Step 7: Evaluate the device, last, on purpose

Cost of doing this first: a good part on the invoice, a machine that trips again, and a customer who now believes you guess.

Only after steps 1 through 6 have shown the condition did not reach the setpoint does the device become the suspect. Then you check its sensing element, its contacts, its mounting and its electrical connections. Nothing about that check is difficult. The discipline is entirely in refusing to do it first.

Worked example: an electric duct heater that stops on the manual reset

A duct heater, secondary manual-reset high limit found open, second call in a week.

Steps 1 to 3. The heater was cold and the fan was running, so the condition was not currently present. Indicators photographed, the reset left alone. The event buffer showed the trips clustering at the end of heating cycles rather than during them, which is a strong hint on its own. The occupant said nothing had changed; the service record showed a controls board replaced two months earlier with no note about the fan timing.

Step 4. The manual-reset limit senses air temperature at a disc mounted in the discharge a few inches downstream of the element bank. Its nameplate, read on the unit rather than assumed, gave a fixed non-adjustable trip point. For this walkthrough take that as 150 F.

Step 5. A probe was fitted at the disc location and the unit run through a full cycle.

  • Design airflow from the unit data sheet: 2,000 cfm, with a design rise of 32 F
  • Measured airflow: 1,150 cfm, about 58 percent of design
  • Entering air: 70 F

At constant electrical input, temperature rise varies inversely with airflow, so a rise of 32 F at design flow becomes 32 / 0.575 = about 56 F at the measured flow. That relationship assumes the input power is unchanged and standard air density near 0.075 lb per cubic foot; at altitude, or in a stream this warm, the usual sensible-heat constant runs optimistic and the real rise is somewhat higher.

Predicted discharge: 70 + 56 = 126 F. Measured discharge with the fan running: 126 F. The prediction and the measurement agree, and 126 F is comfortably below the 150 F trip. So the running condition does not explain the trip, which is exactly why step 5 says to run the full condition rather than a steady state.

At the end of the call, a clamp on the fan circuit and on the heater circuit showed both dropping within about a second of each other. Over the following 80 seconds the disc location climbed from 126 F to 168 F, crossing 150 F at roughly the 45-second mark.

Step 6. The device opened at a measured 168 F against a 150 F setpoint. The condition was real. The limit was right, on both calls.

Step 7. Not reached. There is nothing wrong with the limit.

The two faults, and why fixing one is not enough. The soak is the trip mechanism: with the fan stopping alongside the elements, residual element heat goes into stagnant air at the disc. That is the absent fan-off delay. But airflow at 58 percent of design is what made the soak fatal. At design flow the running discharge would be 70 + 32 = 102 F, leaving 150 - 102 = 48 F of margin; at the measured flow it is 126 F, leaving 24 F, exactly half.

Restore airflow alone and the soak would start from 102 F. The observed soak added 42 F, which would land at 144 F, under the trip. So airflow alone stops the trips, and stopping there is the wrong call: that leaves 6 F of margin against a soak whose size is not a constant. It depends on how much heat is stored in the elements and how much stagnant air sits at the disc, so it moves with entering air temperature, with element condition, and with how long the unit ran before shutdown. Treating 42 F as a fixed number to add is an approximation, not a design value. Both faults get corrected: airflow restored to design, and the fan-off delay set so the fan runs until the discharge has fallen, per the installation instructions.

What a shortcut would have produced. Reset and leave: a return call within days. Replace the limit: the same, plus a good part. Fit an auto-reset limit so nobody gets called: the trips continue silently and the element bank cycles above its limit temperature indefinitely, which is the outcome the manual reset existed to prevent.

References

  • 29 CFR 1910.333(a)(1) for the conditions permitting energized troubleshooting, and 1910.333(b)(2) for de-energizing electrical circuits and equipment
  • NFPA 70E-2021, 120.5 for establishing and verifying an electrically safe work condition
  • Manufacturer installation instructions for fan-off delay and limit device specifications
  • See related: What a Manual Reset Is Telling You; The Difference Between a Limit and a Control; The Danger of Just Resetting a Safety Device Without Diagnosing Why