Interlocks and Why They Are Not Control

Why this matters

Half the complaints that arrive labelled "the interlock is causing it" are describing a machine that ran when it should not have, and an interlock cannot make anything run. It has no output to give. Understanding that one asymmetry deletes most of a suspect list before you open a panel, and it is the difference between a two-hour diagnosis and a return visit five weeks later on a part that was never faulty.

It also protects you legally and practically. When a machine hurts someone and the investigation asks what caused it, "the interlock failed" and "the interlock caused it" are two different sentences with two different consequences, and people conflate them under pressure.

Before you put a meter in a live panel

Energized troubleshooting is allowed under 29 CFR 1910.333(a)(1) only where de-energizing introduces additional or increased hazards or is infeasible due to equipment design or operational limitations, and diagnosis that genuinely requires the circuit live is the standard example. Decide that gate consciously and be able to say why, because "it is faster" is not one of the two conditions.

If you are working it live: use a test instrument with a measurement category rating appropriate to the circuit and the point in the system where you are attaching it, not merely to the voltage, and inspect the leads for damage before every use. If instead you are taking the circuit dead to work on it, that isolation is 29 CFR 1910.333(b)(2) for electrical work rather than 1910.147, which excludes exposure to electrical hazards from work on conductors in electric utilization installations at (a)(1)(ii)(C), and the live-dead-live proving sequence on a known source is NFPA 70E-2021, 120.5.

One more gate before any of that. If an interlock has operated, you do not yet know that the interlock is wrong. Establish what condition it saw before you treat the device as the fault, because replacing a correctly-operating interlock lands you in exactly the same place as jumpering it, one invoice later.

The rule, in one sentence

An interlock is a permission. A permission can only prevent. It cannot cause.

Everything below is that sentence applied.

A control device decides. It reads a measured value, compares it to a target, and commands an output: run, don't run, open this far. An interlock does not decide anything. It sits in series with an output somebody else commanded and either passes it through or does not. Put a contact in series with a coil and the only thing that contact can do is take the coil away. It has no path by which to energize a coil the controller left de-energized.

The three things the word gets used for

The vocabulary is loose in the field, so name which one you have before you reason about it. All three obey the rule above; they differ in who owns them and what happens when they operate.

Kind What it protects Typical trip behaviour Who gets to change it
Safety interlock People. A guard door, a light curtain, an access panel switch Removes power or motive force, usually latched Nobody in the field, ever
Process permissive The sequence. A prerequisite that must be true before the next step is allowed Blocks the step, often self-clearing The controls engineer, through the sequence
Equipment protection interlock The machine. Low oil pressure, high discharge temperature, airflow proving Stops the driven equipment, sometimes with a lockout count Manufacturer settings only

A safety interlock is a distinct category with its own engineering criteria and the sibling article on what a safety circuit is for owns that ground. The point here is only that all three are permissions rather than commands, so all three carry the same diagnostic asymmetry.

Case one: it will not start

A packaged unit will not start on a call. The start string has six interlock contacts in series ahead of the contactor coil, plus the command source itself. That is seven candidates.

The rule does not narrow anything here, and that is the honest answer: on a won't-run complaint, every permission in the string is live as a suspect, because any one of them opening produces exactly this symptom. What the rule does give you is confidence that the answer is in that string and not somewhere exotic, so you work it in order and you stop at the first open element.

Suppose the third contact, an airflow proving switch, is the one found open. You are not done. The question that remains is whether it is open because there is no airflow or because the switch is wrong, and those resolve in opposite directions: one is a blocked filter bank or a failed fan and the other is a switch. Measure the quantity the switch senses, at the location it senses it, before you touch the switch.

Case two: it ran when it should not have

Same machine, different complaint: the compressor ran with the supply fan off. The airflow proving switch is one of the six interlocks that exists specifically to make that impossible.

Run the rule. An interlock can only remove an output. None of those six contacts, in any condition, can energize the contactor coil. So six of the seven candidates from case one are eliminated as causes by topology alone, in the time it takes to read the ladder. What is left is the command source and anything that provides a path around the string.

That is what it turned out to be. A hand-off-auto selector on the compressor circuit had been left in HAND after a previous service call. HAND is a maintained command that feeds the contactor coil directly, around the auto path and around all six permissions with it. The airflow switch was not in the circuit at all in that position, so it could not have prevented anything and it did not fail.

The failure mode is what makes this worth writing down. The first tech on that call replaced the airflow proving switch, and during the work the selector got knocked back to AUTO. The machine then behaved correctly for five weeks, which everyone read as confirmation, until someone used HAND again. The shop paid for a good part, about two hours of return-visit labour, and the credibility hit of a repeat call, all of which a ladder reading would have prevented.

"It failed" and "it caused it" are different sentences

Case two has a real interlock finding in it, and it is not the one the first tech wrote down.

A permission that is defeated, jumpered, stuck closed, or bypassed by a parallel path has failed to prevent. It has still not caused anything. That distinction matters because it points at different work: a cause gets removed, a failure-to-prevent gets restored and then asked why it was defeatable in the first place. In case two the HAND position is a designed bypass of a protection, which is a design question for whoever specified that selector, not a defect anyone is going to find with a meter.

Write your findings in those terms. "The compressor was commanded through the HAND position, which bypasses the airflow permissive" is a finding a customer can act on. "The airflow interlock failed" is not true and points the next person in the wrong direction.

Where this rule stops holding

The rule is stated for the geometry it was derived under: a contact in series in the path that energizes the thing it permits. Two arrangements break that geometry, and both are common enough that you have to look rather than assume.

De-energize-to-trip protective outputs. Where the protective action is itself an energized event, a dump solenoid that opens on loss of a permissive, a fail-open damper released by a held circuit, an alarm horn driven from a normally-closed contact, then opening that permission does cause an action. The rule that a permission can only remove an output is true of the permitted output; it says nothing about a separate circuit wired to the same contact's other pole. Trace the contact's full set of poles before you apply the rule.

Software permissives. In a controller, a permission is an AND term in a rung, and the same asymmetry holds for that rung. But a permissive that has also been given a latch, a retry counter, or a forced output has been given decision-making, at which point it is a control element that someone labelled as an interlock. The tell is that it has a timer or a count associated with it. A pure permission has neither.

Neither exception rescues the reading in case two, and that is the useful part: exceptions to a rule are worth knowing precisely so you can confirm they do not apply, rather than as a reason to stop using the rule.

Checking your read

Read the ladder or the logic and answer one question in writing before you pick up a meter: for the symptom in front of you, does the suspect device need to have removed an output or supplied one? If it needs to have supplied one, no permission in the string is your cause, and you are looking for a command or a parallel path.

Then confirm the topology rather than trusting a label. A contact labelled INTERLOCK in a drawing has been known to be wired in parallel with a run command by a previous installer, which makes it a command with a misleading name. Ring it out, or observe its effect: open the contact deliberately, with the machine in a state where losing that output is harmless and the process owner has agreed to the test, and confirm the permitted output drops. A permission that removes nothing when opened is not in the path you think it is in.

References

  • 29 CFR 1910.333(a)(1) for the conditions permitting energized troubleshooting, and 1910.333(b)(2) for de-energizing electrical circuits and equipment
  • NFPA 70E-2021, 120.5 for the process of establishing and verifying an electrically safe work condition
  • Manufacturer control drawings and sequence documentation for the machine in front of you
  • See related: What a Safety Circuit Is For; Why Defeating an Interlock Is Never the Fix; How a Permissive Chain Is Supposed to Work