The Difference Between a Limit and a Control

Why this matters

A limit and an operating control can be the same shape, the same size, sold by the same supplier, wired with the same colour, and mounted six inches apart. They mean opposite things when they operate, and a tech who reads them with the same eyes will either ignore a real finding or chase a normal one.

The distinction pays off in one specific way that is worth stating up front, because everything else in this article supports it: a control is supposed to operate constantly, and a limit is supposed to never operate. So a limit that has operated is evidence about the control side, not about the limit.

Before you instrument a hot vessel

Most of what follows requires temperature readings on live equipment. Insert a probe only into an existing thermowell or an existing test port; do not drill, tap, or push a probe through any part of a pressure boundary on a vessel in service, and do not open a well plug on a pressurized vessel to fit one. Water above roughly 140 F scalds on brief contact and a hot vessel surface will burn through a glove designed for handling rather than for heat, so route the leads and stand where a release from a fitting cannot reach you.

Where the readings mean opening an enclosure on the control circuit, that is 29 CFR 1910.333(b)(2) for de-energizing, with the live-dead-live proving sequence per NFPA 70E-2021, 120.5. Live readings for diagnosis are permitted under 29 CFR 1910.333(a)(1) only where de-energizing introduces additional or increased hazards or is infeasible, with a test instrument whose measurement category rating suits the circuit.

Duty cycle is the distinction

Everything else follows from expected operations per year.

An operating control lives in the middle of the process. Its job is to hold a variable near a target, which it does by turning something on and off, or modulating it, over and over, thousands of times a season. Every one of those operations is normal and none of them is a finding.

A limit lives at the edge. Its job is to stop the equipment when a variable reaches a boundary that must not be crossed, and in a healthy installation it does that zero times. Its entire working life is spent as a closed contact doing nothing. When it operates, something that should have kept the variable away from the boundary did not.

This is why "it trips sometimes" is a normal report about a control and an abnormal report about a limit, even though the words are identical.

The separation budget

For a limit to never operate in healthy service, its setpoint has to sit above everything the control side does normally, with every source of variation stacked on top. For it to protect anything, it has to sit below the boundary that actually matters. The gap between those two is the whole design, and once you can build that stack you can diagnose from it.

The terms, in the order they stack:

  • The top of the control's own action, which is the setpoint plus whatever part of the differential sits above it
  • Overshoot after the control cuts out, which is real energy already in transit
  • The control sensor's tolerance, taken in the direction that lets the process run hot
  • Normal process transients, meaning the load steps the equipment is expected to see
  • The limit's own sensing tolerance, taken in the direction that trips it early

And above all of that sits the boundary: the equipment's design temperature, the fluid's flash point, the material's rating, whatever number the limit was installed to defend.

Worked example: where the limit setpoint has to sit

A heated vessel with an operating control set at 180 F and a differential of 6 F centred on setpoint, so it cuts out at 183 F and cuts in at 177 F. Note the convention, because it matters: a control whose differential runs entirely below setpoint cuts out at 180 F instead, and the whole stack below shifts down by 3 F.

Build the stack:

Term Value Running total
Control cut-out 183 F 183 F
Measured overshoot after cut-out 5 F 188 F
Control sensor tolerance, unfavourable direction 2 F 190 F
Normal load transient 4 F 194 F
Limit sensing tolerance, unfavourable direction 3 F 197 F

So 197 F is the floor: a limit marked below that will operate during normal service, and everyone on site will learn to treat it as an operating control, which is exactly how a protection stops being one.

The boundary for this vessel is 210 F. That leaves a window of 210 - 197 = 13 F for the limit setpoint. A limit marked 200 F sits in it with 3 F of headroom above the nuisance floor and 10 F below the boundary.

One condition, and it is the one that ruins this arithmetic most often in the field: every value above is a temperature at the sensing location of the device that reads it, and the control sensor and the limit sensor are not in the same place. A limit mounted closer to the heat source sees a higher temperature than the control does at the same instant, and that offset is a separate term this stack does not contain. Measure it rather than assuming it: run the equipment at steady state and read both locations together. If the limit's location runs 8 F hotter than the control's, the 13 F window shrinks to 5 F, and a 200 F limit no longer fits.

When the limit operates, which term moved

The stack is not just a design tool. Once a limit has operated, one of those terms grew, and each one has its own signature.

Control cut-out moved up. Somebody adjusted the setpoint or widened the differential. This is the first thing to check and the fastest, because it is a reading rather than a test, and it is common on equipment that has had a comfort complaint.

Overshoot grew. The heat input did not actually stop when the control commanded it to. A valve passing, a contactor with welded poles, a solid-state relay failed on. Or the thermal path changed: flow dropped, so the same input is going into less mass. Overshoot growth is the term most likely to indicate an active fault rather than an adjustment.

Control sensor drift. The control believes the vessel is cooler than it is, so it keeps adding heat past the real setpoint. The tell is that the control appears to be doing its job perfectly while an independent measurement disagrees, and the sibling article on drifting sensors carries that case.

Transient grew. The load changed: a bigger step, a faster start, a different duty. Nothing is broken, the equipment is simply being used outside the range the stack was built for, and the fix is a design conversation rather than a repair.

Limit sensing tolerance moved. The limit's own element degraded and it now trips early. This is the only entry on the list that makes the limit the fault, it is the least common of the five, and it is the one everybody reaches for first.

Telling them apart when nothing is labelled

Cue Operating control Limit
Setpoint adjustment Wide, accessible, expected to be used Often fixed, sealed, or adjustable only with a tool
Differential adjustment Common Usually none
Reset None, it simply cycles Frequently manual
Sensing location A representative point in the controlled medium The point of maximum severity
Position in the circuit In the demand path In series with the whole output, or on a separate trip path
Expected operations per year Thousands Zero

The last row is the one to trust when the others are ambiguous. Ask the operator how often that device does something. An answer of "all the time" and a device that looks like a limit means somebody has already been living with a protection as though it were a control.

The two substitutions that cause the damage

Treating a limit as a control looks like raising its setpoint because it operates too often. Every degree you add comes out of the 10 F you had between the limit and the boundary, and there is no indicator anywhere on the machine showing how much of that is left. Three separate techs each adding a small amount over a few years is enough to consume it, and none of them did anything that felt reckless.

Treating a control as a limit is the quieter one and the more dangerous. An operating control is not a protection: it has no independence from the thing it controls, and its normal failure modes include failing with its contact closed, which leaves the heat on with nothing watching. A single device that both controls and protects is one failure away from doing neither, which is why the separate limit exists at all and why the sibling article on safety circuits treats independence as a first-order criterion.

Proving the separation is still real

Run this on any equipment where a limit has operated, and on a schedule where it has not.

Read both setpoints, from the devices, and compare against what the documentation or the previous record says. A changed setpoint with no note beside it is the single most common finding.

Measure overshoot directly: bring the process to setpoint under a normal load, let the control cut out, and record the peak that follows. That number is the term most likely to have grown and the one nobody has on file. Do it with the vessel at its normal working condition rather than at start-up, because a cold start and a steady-state cut-out overshoot differently.

Then read the two sensing locations together at steady state and record the offset between them. That single number is what converts the design stack from theory into something specific to the equipment in front of you, and it is worth writing on the panel where the next person will find it.

References

  • Manufacturer documentation for equipment design temperature, limit device ratings, and controller differential conventions
  • ASME and general trade-standard practice for the relationship between operating controls, limit controls, and pressure or temperature design boundaries
  • 29 CFR 1910.333(a)(1) and 1910.333(b)(2) for energized troubleshooting conditions and electrical de-energizing, with NFPA 70E-2021, 120.5 for verification
  • See related: What a Safety Circuit Is For; Why a Drifting Sensor Is Worse Than a Dead One; What a Setpoint Is and What It Is Not