What Happens on Power Loss and Restoration
Why this matters
A machine that is dead because the utility is out is not a de-energized machine. It is an energized machine waiting, and the moment supply returns it will do whatever its control scheme says to do, with your hands wherever they are. Before any work on equipment during an outage, isolate it at its own disconnect and lock it out: electrical work on utilization equipment under 29 CFR 1910.333(b)(2), and mechanical isolation and stored energy - a spring-return actuator, an accumulator, a pressurized or elevated mass - under 29 CFR 1910.147, which at 1910.147(a)(1)(ii)(C) is why those are two standards rather than one. Prove dead live-dead-live against a known source per NFPA 70E-2021, 120.5, and remember that proving dead during an outage proves nothing about five minutes from now unless the isolation is locked.
The claim this article rests on: loss and restoration are two separate events with separate failure sets, and restoration is the one that hurts. De-energizing is a designed state - every output drops to its failure position and the machine does what it was built to do with no power. Re-energizing runs a start sequence, and the machine may be entering it from a physical condition the start sequence never assumed.
The asymmetry, stated plainly
On loss, the machine has no decisions to make. Coils drop out. Actuators go to whatever their unpowered position is. Nothing is computed. Whatever the designer chose as the failure position is what happens, instantly and identically every time. This is why loss faults are rare and dull.
On restoration, the controller boots, initializes, reads its inputs, and begins a sequence that was written assuming a particular starting condition - typically at rest, cold, empty, closed, stopped. The process does not reset when the power does. The machine's physical state at second zero of restoration is wherever the outage left it, decayed by however long the outage lasted.
Everything interesting is in that gap.
Four stores of state, and what survives an outage
| Store | Survives? | Decays over |
|---|---|---|
| Controller working memory: step position, elapsed timers, in-flight logic | No, lost at the instant of loss | n/a |
| Nonvolatile memory: parameters, setpoints, fault history, run-hour and cycle counters | Yes, by design | n/a |
| Actuator and output physical position | Yes, but only until the spring, weight or friction acting on it moves it | Seconds to minutes |
| The process itself: rotation, temperature, pressure, level, combustion products | Yes | Its own time constant, from seconds to hours |
The third and fourth rows are the whole problem. The controller loses its place; the machine keeps its condition. So the controller comes back knowing the setpoints and the fault log, and knowing nothing whatever about the fact that a rotor is still turning or a vessel is still hot.
One caution on the second row, because it is the one people over-trust: nonvolatile does not mean instantly written. Counters and fault records are often committed on a schedule or at a state change, so the last few moments before a loss may not be in the log. A fault that occurred and then lost power a second later can be genuinely absent from the record.
The restart classes, and the vocabulary worth knowing
The behaviour on restoration is a design choice, and it has standard names that are worth using because they are what the starter and control documentation will call them.
Low-voltage release. The control drops out when voltage is lost and re-closes automatically when voltage returns. In conventional starter wiring this is what a two-wire control scheme gives you: the maintained device in the control circuit is still calling, so the coil picks straight back up. The machine restarts by itself with nobody present.
Low-voltage protection. The control drops out on loss and stays out until somebody presses start. Conventional three-wire control gives this, because the seal-in contact that was holding the coil in has opened and only the momentary start device can re-establish it.
Restart after a delay. Automatic, but held off by a timer or a permissive so the process has time to reach the condition the start sequence assumes.
Lockout retained. The machine was already in a fault lockout when power was lost, and it comes back in lockout. Whether it does this is a real design difference between controllers and it is worth knowing per machine, because a lockout cleared by a power interruption is a lockout whose evidence is gone.
Which class a given machine uses is not a preference and it is not a wiring accident. It is a decision that has to be made against the gate below.
The gate
Automatic restart is correct only where the machine's start sequence begins from a condition the machine will actually be in when power returns, and where nothing that ran down during the outage must be re-established before starting.
Run two real machines against that single sentence and it resolves them in opposite directions.
Outcome one: automatic restart is the right answer
A circulating pump on a closed loop. No operator, no local attendance, and the loop's job is continuous.
Against the gate: the start sequence assumes a stopped pump and a full loop. On loss, the pump coasts to standstill within a few seconds, and the loop stays full because nothing drained. On restoration, the machine is in exactly the condition the start sequence assumes. Nothing had to be re-established.
So low-voltage release is correct here, and the failure mode of choosing low-voltage protection instead is the one nobody thinks of: the outage happens at two in the morning, nobody presses start, and the loop sits stagnant or freezes until somebody notices, which may be days. Requiring a human for a restart that does not need one is its own hazard.
Outcome two: automatic restart is the hazard
A machine with a high-inertia driven load and a fuel-fired heat source. Same gate, opposite result, and it is worth carrying the numbers.
Measured coastdown from full speed to standstill with the drive removed: 45 seconds. The outage lasted 8 seconds. So at the instant power returned the load was still turning, well above standstill, and the start sequence's assumption of a stopped machine was simply false.
Two consequences follow, and they need different fixes:
The rotating one. Applying a start to a load still turning is a condition the starter and the driven equipment have their own limits on. On a motor large enough to maintain appreciable residual voltage as it decelerates, reconnection while that residual is present is specifically addressed by the manufacturer's published minimum restart interval; on a small fractional-horsepower load it is not usually the governing concern, and the governing concern is instead the mechanical shock and the thermal duty of a start into an already-heated winding. Either way, the machine's published minimum off time is the number that settles it. Say that number is 60 seconds. 60 is greater than the 45-second coastdown, so a delay of that length covers the rotating condition completely.
The thermal one. Here the same timer does not help, and this is the part that gets missed. The heat exchanger surfaces were at full operating temperature when the air stopped moving, and 60 seconds of standing still does not bring them back to anything like a cold-start condition. Meanwhile the start sequence's purge step is sized to clear a volume, not to cool a surface. The two conditions have completely different time constants - seconds for rotation, many minutes for a heated mass - and a single timer sized to the shorter one silently declares the longer one satisfied.
The correct mechanism for the thermal condition is not a longer timer. It is a permissive: a temperature input that has to read below a threshold before the sequence advances. A timer asserts that enough time has passed; a permissive confirms the condition. When the two time constants differ by an order of magnitude, you need the permissive, because any timer long enough to be safe on a hot day is absurdly long on a cool one.
So this machine gets low-voltage protection or a delayed restart with a thermal permissive, and the failure mode of getting it wrong is a machine that restarts into a hot, still-turning condition once per outage, accumulating damage that never correlates with anything in the service history.
The brownout, which is neither event
A sag that dips below the coil's dropout voltage but stays above zero is the case both classes handle badly, and it is the one that arrives disguised as something else.
A contactor coil has a pickup voltage and a dropout voltage, and they are not the same number - dropout sits well below pickup, which is deliberate and is what keeps a coil held in through ordinary supply variation. A sag that lands between them leaves the coil in an indeterminate region: it may hold, it may drop, it may chatter, opening and closing at whatever rate the supply wobbles. Chattering welds contacts and hammers the driven load with repeated starts, and the machine's fault log records none of it because from the controller's point of view nothing faulted.
The tell on a machine that has been through this is physical rather than logged: contact surfaces pitted or welded, a coil that has run hot, a driven load showing evidence of repeated starting. Inspecting contact surfaces means the contactor is dead and stays dead, so isolate at the disconnect, lock it out under 29 CFR 1910.333(b)(2) and prove dead live-dead-live per NFPA 70E-2021, 120.5 before anything comes apart, and read a suspect coil with a non-contact infrared thermometer at arm's length rather than by touch, because a coil that has been chattering will burn through a general-handling glove. If you find that evidence and the fault history is clean, stop looking at the control scheme and start looking at the supply, and the sibling articles on correlating a fault with a power event carry that trace.
References
- 29 CFR 1910.333(b)(2) for de-energizing and lockout of electrical circuits, and 29 CFR 1910.147 for mechanical isolation and stored energy, with 1910.147(a)(1)(ii)(C) as the boundary between them
- NFPA 70E-2021, 120.5 for live-dead-live verification of a de-energized state
- NEMA and starter manufacturer documentation for low-voltage release versus low-voltage protection behaviour, and for coil pickup and dropout voltage ranges
- Manufacturer service data for published minimum restart interval, coastdown time, and purge and permissive requirements, all of which are equipment-specific
- See related: How to Test a Restart Sequence Safely; How to Tell a Reset State From a Real Fault After a Power Interruption; Correlating a Fault with a Recent Power Event