What a Manual Reset Is Telling You

Why this matters

The reset type is printed on the device and it is free information that almost nobody reads as information. A manual reset is not an inconvenience the designer failed to engineer out. It is a statement, made deliberately, that this condition must not be allowed to clear itself and that a person has to arrive and look before the equipment runs again.

Read it before you measure anything and it tells you what class of fault the designer expected. Read it wrong and you spend the visit annoyed at a button.

Before you press any reset

A reset can start a machine. Know what will move, confirm nobody is inside or near it, confirm guards are closed, and confirm the condition that tripped the device is not still present. If someone has hands in the equipment, the reset button is not the control that protects them: isolate at the energy isolating device and lock and tag it under 29 CFR 1910.147.

On any fuel-burning appliance, a manual reset on a combustion safety control is a different animal. Each reset attempt admits fuel for another trial, and repeated attempts accumulate unburned fuel in a space that is about to see an ignition source. Do not reset a combustion lockout more than once without establishing why it locked out. If there is any smell of gas at any point, everybody leaves the building immediately, no switches are touched, no lights are operated, no phone is used inside, and the call to the gas utility and to your dispatcher is made from outside and well away.

What a manual reset asserts

Three things, and each one is a specific claim about the fault.

The condition will clear on its own while the cause does not. A high limit cools down. The reason it got hot has not moved. Fit an auto-reset device to that fault and the equipment cycles on it forever, correctly protecting itself and never telling anybody, which is a machine running permanently in a protected fault.

The restart itself is hazardous or consequential. Motive power returning to a machine somebody may be near, fuel admitted to a chamber, pressure re-applied to a system that just relieved. Where the restart is the risk, no amount of condition-clearing makes an unattended restart acceptable.

Somebody has to be made aware. On a great deal of equipment the manual reset is the only notification mechanism in existence. There is no alarm, no log, no dial-out. The device stops the machine and waits for a human, and the human arriving is the alarm.

Auto reset asserts the mirror image of all three: the condition genuinely self-clears, the cycling is tolerable for the equipment, and an unattended restart is safe. Where any of those is untrue, an auto-reset device is a design defect, and converting a manual reset to an auto reset in the field is that defect installed on purpose.

The four tiers of memory

Reset behaviour is really a question of what the device remembers and for how long.

Tier Memory What it survives What it tells you
Auto reset None Nothing The designer expected this condition to come and go
Electrically latched Held by a circuit The condition clearing, but not a power interruption Attention wanted, but the fault was judged recoverable
Manual reset Mechanical or held latch with a dedicated button The condition and a power interruption A person must attend before restart
Lockout after a retry count A counter in the controller Several occurrences, then requires a human The condition may self-clear, but not this many times

The fourth tier is the most informative and the least noticed. A controller that permits three trials and then locks out is a designer saying that one occurrence is within normal variation and repeated occurrence is not. If you find a machine sitting in that lockout, the count itself is a finding: the condition happened every trial, not once.

The trap sits between tiers two and three. Cycling power to see if a fault clears is not a diagnostic step, it is destruction of evidence: it erases an electrically latched state entirely and it erases the controller's live status without necessarily clearing the stored history. Pull the record before you interrupt power, not after.

The gate: does the reset type match the fault class

One question, applied to whatever you find: is the device's reset type appropriate to the fault that is actually occurring? If yes, the device is doing its job and the fault is your work. If no, the device selection or its wiring is itself a finding, and it changes what you hand the customer. The two cases below run that single question and land in opposite places.

Case one: the device that never told anybody

A refrigeration circuit, complaint of "it works, just not great." Nothing had ever been called in as a fault.

The high-pressure cut-out on that circuit was an auto-reset type. The controller happened to log the switch input, and the log over the previous 30 days showed 212 trips, about 7 a day. The trips clustered between early afternoon and early evening, which is a heat-rejection pattern rather than a switch pattern, and the heat-rejection side turned out to be badly fouled with one condenser fan not turning.

Service calls in those 30 days: none. The equipment protected itself 212 times and told nobody 212 times.

Run the gate. The fault was not self-clearing. The ambient falling in the evening cleared the symptom every night while the fouling and the dead fan stayed exactly where they were, which is the textbook profile of a condition that needs a manual reset. The device fitted was auto reset. So the reset type did not match the fault class, and that mismatch is a finding in its own right, separate from the fouling: this circuit has no mechanism by which a protective operation reaches a human being. The recommendation includes the cleaning and the fan, and it also includes an annunciation path, because fixing the fouling does not fix the blindness.

The 212 in that log is the whole point. Without a controller that happened to record a switch input, that number would not exist anywhere, and the honest version of the finding is that the shop got lucky.

Case two: the device that told somebody once

A heating appliance, six years on site, a manual-reset limit found open. The customer's report was that "the reset keeps needing pressing," which on examination meant it had needed pressing once, that week, and never before in six years.

Run the same gate. Is manual reset appropriate here? The condition self-clears as the appliance cools; the cause does not. The restart admits heat to a system that just exceeded a boundary. Nobody would otherwise know. All three of the assertions hold, so the device selection is correct and the device is not the finding.

What is the finding is the excursion, and the reset type is the reason you know it happened at all. One operation of a manual-reset limit in six years is high-quality evidence: the equipment reached a boundary it had not reached in six years of the same duty. That deserves the full reconstruction, and the sibling article on establishing why a safety device opened is the procedure for it.

Notice what the gate did to the customer's framing. "It keeps needing pressing" implied nuisance and pointed at the device. The reset type, plus the actual count, points the other way entirely: this is a rare, real, well-reported event. Frequency is not severity, and on a manual reset device a count of one is not a small version of a count of many. It is a different kind of finding.

The two moves that destroy the information

Converting a manual reset to an auto reset. Usually justified as reducing callbacks, and it does reduce callbacks, by converting a loud fault into a silent one. Case one is what the result looks like after 30 days. The callbacks were the safety function working.

Clearing without recording. A manual reset device has no counter and no memory of how many times it has operated. Its entire history exists only in whatever somebody wrote down. Press the button without a note and you have not just failed to record a data point, you have made the next tech's count of one indistinguishable from a count of five.

What to write down, and what a reset tells you as you press it

Four fields on every reset, and they take less than a minute: which device, the date and time, what conditions were present when you arrived, and whether it held. That last field is where the diagnostic value is, because the behaviour of the reset itself sorts the fault into three groups before you take a single measurement.

It will not reset at all. The condition is still present, or the device is damaged. Do not force it and do not keep pressing; go measure the quantity it senses.

It resets and trips again immediately. The condition is present under running conditions, which is the easiest case to diagnose because you can reproduce it at will. Instrument the sensing point and run it.

It resets and holds for hours. The condition is intermittent or load-dependent, which is the hardest case and the one where the reset record matters most. A single tech seeing a single hold learns almost nothing; four dated entries showing operations clustered on hot afternoons, or at end of cycle, or after a particular process step, hand the next person the answer.

That last group is why the note is worth more than the reset. The button restores service. The four fields are what eventually finds the fault.

References

  • 29 CFR 1910.147 for control of hazardous energy where a reset could restore motive power to equipment being worked on
  • NFPA 54, National Fuel Gas Code, and manufacturer instructions for combustion safety control lockout and trial-for-ignition limits
  • Manufacturer documentation for protective device reset type selection and retry counts
  • See related: How to Establish Why a Safety Device Opened; The Difference Between a Limit and a Control; The Danger of Just Resetting a Safety Device Without Diagnosing Why