What a Safety Circuit Is For
Why this matters
On unfamiliar equipment nobody hands you a drawing that says which circuit is protecting the machine and which is protecting the person standing next to it. Both are wire, both land on the same terminal strip, and a tech who evaluates a safety circuit with control-circuit thinking will make a change that looks like tuning and is actually the removal of a protection. "It trips a little early, I opened it up a bit" is a sentence that has ended careers.
There is a second reason, less dramatic and more common. A safety circuit that is working exactly as designed is very often the thing standing between you and a machine that will run, which means the pressure to treat it as the fault is highest at the exact moment it is doing its job.
Proving a safety device means running the machine
Everything in this article ends with a proof test, and a proof test is the part that hurts people, so set the conditions before you get there.
Proving an emergency stop or a guard interlock requires the machine to be running, because a device that stops nothing cannot be shown to stop something. Run it unloaded, with everyone clear of rotating parts, couplings, belts, discharge openings and any line that could move, and with the process owner told in advance what you are about to drop. After the trip, confirm zero speed visually and by touch on a stationary point before anything goes near the machine, because a large rotor coasts for a long time after its power is gone.
A guard interlock is not an isolation device and must never be used as one. If you are going to have hands inside the machine, isolate at the energy isolating device and lock and tag it under 29 CFR 1910.147, including the stored energy in any accumulator, spring, or elevated component. An interlock that opens when a door opens can be defeated, can weld, and is not what the standard accepts.
The three criteria a safety circuit is judged on
Independence. The protective function must not depend on the thing it protects against. A high-temperature trip that reads through the same input card, runs through the same program, and drops out through the same output relay as the burner it is protecting is not independent: one failed card removes the control and the protection in the same instant. Independence is why a genuine safety circuit usually has its own sensing element, its own path, and often its own relay.
Fail direction. On loss of power, a broken wire, a corroded terminal, or a dead controller, the circuit must arrive at the safe state on its own. This is why protective devices are almost always wired to de-energize to trip: an open wire and a real trip look identical to the machine, so the failure mode of the wiring is the safe one. A device wired to energize to trip has the opposite property, and its wiring failures are silent.
Provability. You must be able to demonstrate the function works without waiting for the hazard to occur. A protection whose only proof is the accident it exists to prevent is a hope. Provability shows up as test buttons, proof-of-closure switches, self-checking contact arrangements, and a defined interval at which somebody actually performs the test and writes it down.
The criteria that do not apply
Control circuits are judged on accuracy, stability, resolution and response smoothness. None of those are safety criteria, and reaching for them is the specific mistake this article is trying to prevent.
Nobody needs a high limit to be accurate to a tenth of a degree. They need it to open before the boundary is crossed and to stay open. A safety device that trips two degrees early is not miscalibrated in any sense that matters; a control that trips two degrees early is. Likewise, "it nuisance trips" is a diagnosis of the process in almost every case, not of the device, and the sibling article on limits versus controls carries that argument.
The damage of the mix-up is specific and predictable. Applying control criteria to a safety device produces exactly three moves, all wrong: widening a setpoint to stop nuisance trips, adding a time delay so a transient does not trip it, and converting a manual reset to auto so nobody has to attend. Every one of those looks like reasonable tuning and every one of them removes the property the device was installed for.
The survey sheet
When the drawings are missing, build the answer instead of guessing at it. Seven fields, one row per protective device, and the sheet is worth carrying because filling it in forces the questions in the right order.
- Device and what it senses
- Where it sits in the circuit
- Energize or de-energize to trip
- Reset type
- Independent of the controller, yes or no
- How it can be proved without creating the hazard
- Date last proved
Fields 1 and 2 you get by tracing. Field 3 you get by looking at the contact arrangement and confirming it: the device's own labelling will say normally open or normally closed, but what matters is which state exists when the machine is healthy. Field 5 is the one people skip and it is the one that changes the recommendation.
The sheet filled in for one machine
An unfamiliar packaged rotating-equipment skid, four years on site, no control drawings, five protective devices found.
| Device | Position in circuit | Trip direction | Reset | Independent | Provable how |
|---|---|---|---|---|---|
| Emergency stop | Control power path, ahead of everything | De-energize | Manual, twist release plus separate reset | Yes | Press, confirm motive power drops |
| Coupling guard door switch | Dedicated safety relay input | De-energize | Manual reset after door closed | Yes | Open door, confirm drop |
| High discharge pressure | Controller digital input, action by program | De-energize contact, program decides | Auto | No | Test port, not routinely done |
| High discharge temperature | Controller digital input, action by program | De-energize contact, program decides | Auto | No | No method on site |
| Casing vibration switch | Closes on trip, energizes a trip relay | Energize | Manual | Yes | No method on site |
Three findings come straight off that table, and the numbers are worth stating plainly because they set the priority order.
Two of the five, the pressure and temperature trips, are not independent. Both sense correctly, both use a de-energize-to-trip contact, and both then hand the decision to the same controller that is running the machine. A failed input card, a failed processor, or a corrupted program removes the control and both protections together.
One of the five, the vibration switch, is wired energize to trip. A broken wire, a loose terminal, or a failed trip relay coil leaves the machine running with no vibration protection and no indication that anything changed.
Two of the five can be proved in the field without creating the hazard. The other three cannot, and the temperature trip has no record of ever having been proved in the four years the skid has been on site.
Reading the sheet
The priority order is not the order the problems appear in, and the reasoning matters more than the list.
The energize-to-trip vibration switch goes first, because its failure is silent. Nothing on the machine, no alarm, no indicator, and no operator observation distinguishes a healthy vibration protection from one whose wire came off a terminal. Every other defect on this sheet announces itself in some way eventually; this one does not, and a protection you cannot tell is gone is functionally worse than one you know you do not have.
The two non-independent trips go second. Their failure is not silent, because a controller failure that takes out both usually also takes out the machine, but the case that matters is the one where it does not: a stuck input, a scan that hangs while outputs hold, a program change that drops a rung. That requires a specific single failure rather than the everyday one of a wire coming loose, which is why it ranks below the vibration switch and well above the last item.
Unprovability goes last, and it goes last for a reason worth writing down rather than because it matters least. The two items above it are known defects right now. Unprovability is not a defect, it is the reason you would not know about a third one. It ranks below the confirmed problems and above everything not on this sheet, and once the first two are fixed it becomes the top item, because at that point it is the only thing standing between the customer and the next silent failure.
What to hand the customer
Not a jumper, not a parts list, and not a sentence containing the words "the safety is faulty." Three things.
The sheet itself, because it is now the drawing that did not exist, and it will still be right after you leave. The two defects, described as what fails and what that failure exposes: the vibration protection can be absent without anyone knowing, and a single controller fault can remove two protections and the control at once. And a proof interval with a date on it, because the third finding is an absence of testing and the only fix for an absence of testing is a scheduled test that someone signs.
Where the customer pushes back on cost, the honest framing is in effort rather than parts. Rewiring one switch to de-energize to trip is a small fraction of the labour of a single unplanned teardown on that class of machine, and the proof test on the two provable devices adds a few minutes to a visit that is already happening.
References
- 29 CFR 1910.147 for control of hazardous energy and the requirement to isolate at an energy isolating device rather than at an interlock
- 29 CFR 1910.212 for general requirements for machine guarding
- NFPA 79 for electrical standards for industrial machinery, including protective circuit practice
- See related: Interlocks and Why They Are Not Control; The Difference Between a Limit and a Control; What a Manual Reset Is Telling You