What Proving Actually Means in a Sequence
Why this matters
A sequence of operation says "prove airflow", "prove flame", "prove rotation", and every one of those phrases is a shorthand that hides the actual mechanism. A machine cannot sense airflow. It can sense a pressure difference across a fixed geometry, at one location, and compare it to a threshold somebody set. Those are not the same thing, and the difference is where a whole class of faults lives.
The claim: every proving step proves a proxy inside a window, never the condition it is named for. Once you can state, for any proving step, which quantity is sensed, where it is sensed, and what window the controller accepts, that step becomes diagnosable. Until you can, it is a black box you will end up replacing.
Before you make or break a proving input to test anything
A proving input is frequently the last thing standing between a machine and a condition it is not allowed to enter. Do not jumper one to see whether the rest of the sequence advances, and treat "just for a second" as the same act. If a proving device has operated, establish the physical condition that operated it before you decide the device is at fault, because replacing a correctly-operating device lands in the same place as a jumper, one step slower.
The measurements below mean an enclosure. De-energize and lock out per 29 CFR 1910.333(b)(2) and prove dead live-dead-live against a known source per NFPA 70E-2021, 120.5. Where a reading only exists with the circuit live, 29 CFR 1910.333(a)(1) permits it only where de-energizing would introduce additional or increased hazards or is infeasible for the equipment design, with a meter rated at or above the system voltage in the right measurement category and leads inspected for damage first as 29 CFR 1910.334(c) requires. Where the proof involves a pressurized or spring-loaded element, that is stored energy under 29 CFR 1910.147, isolated and relieved before the device comes apart. If the machine burns fuel, wear a personal CO monitor on your collar before it fires.
The three fields that define a proving step
The sensed quantity. Not the named condition. Pressure difference, ionization current, contact position, motor current, temperature, level. If you cannot name a physical quantity with a unit, you do not yet know what the step does.
The sensing location. A proof made at the outlet of a device and a proof made at the far end of a system are different proofs even with identical hardware, because the quantity being sensed varies across the system while the named condition does not.
The acceptance window, in two parts. A VALUE window: the band the sensed quantity must fall in, usually one threshold with hysteresis around it. And a TIME window: the interval during which the controller looks. Both matter and they fail differently. A quantity that reaches the value one second after the time window closes fails exactly as hard as one that never reached it, and the two look nothing alike on the machine.
The fourth field, which is where the diagnosis lives
The three above describe the step. The fourth describes its weakness: what else, other than the intended condition, satisfies this proxy.
Every proxy has at least one, because a proxy is by definition a narrower measurement standing in for a broader condition. Write it down for each step and the sheet stops being an inventory and starts being a fault list.
The inventory sheet
One row per proving step. This is the artifact; carry a blank one and fill it against the machine.
| Field | What goes in it |
|---|---|
| Step name as written | The sequence's own words, verbatim |
| Condition the name claims | Restate what a reader would assume it guarantees |
| Sensed quantity and unit | The actual physical measurement |
| Sensing location | Both ends if it is differential |
| Value window | Threshold and, where published, the reset differential |
| Time window | When the controller starts looking, when it stops |
| Must-be-clear-first | Whether the input has to read the opposite state before start |
| What else satisfies it | The unintended path or paths |
| How to read it without breaking it | Test port, terminal, or clamp point |
The sheet filled in for one machine
A packaged machine with three proving steps. Values shown are the ones this machine's documentation published; the point is the shape of the row, not these particular numbers.
Row 1: "Prove airflow"
- Condition the name claims: air is moving through the machine at the design rate.
- Sensed quantity: differential pressure across the air-moving device, in inches of water column.
- Location: one tap at the device inlet, one at its outlet, both inside the cabinet.
- Value window: makes on rise past the switch setpoint, breaks on fall below setpoint minus the switch's own differential, which is a fixed mechanical property of the switch and is usually the smaller number.
- Time window: 10 seconds from the start command.
- Must-be-clear-first: yes, must read open at the start command.
- What else satisfies it: a system whose resistance has risen. This is the important one and it needs its condition stated. On a centrifugal air mover with a pressure characteristic that rises as flow falls, which covers most cabinet blowers, increasing the resistance downstream moves the operating point toward lower flow and HIGHER developed pressure. So a loaded filter or a closed damper can leave this proof solidly made while the actual air moving through the machine has dropped well below design. The proxy relationship between this pressure and flow was fixed at one system resistance; change the resistance and it no longer holds, and nothing on the machine tells you it changed.
- How to read it: pressure taps with a manometer, or continuity across the switch with the circuit isolated.
Row 2: "Prove flame"
- Condition the name claims: combustion is established and stable.
- Sensed quantity: a small direct current, in microamps, conducted through the ionized gas of the flame between a sensing electrode and ground. The acceptable minimum is control-specific and published in the manufacturer's service data; do not carry a number from one machine to another.
- Location: at the sensing electrode tip only. This is the field's most common location error, because a flame present at the burner but not reaching the electrode reads as no flame, and a flame reaching the electrode while other burner sections are unlit reads as flame.
- Value window: above the control's published minimum current.
- Time window: within the trial period, then continuously through the run.
- Must-be-clear-first: yes, and this one is safety-critical. The control checks for absence of flame signal before it opens anything, because a signal present before ignition means either a leaking source or a shorted sensing circuit, and both are conditions where opening a valve is exactly wrong.
- What else satisfies it: a sensing circuit fault that conducts current without a flame. That is precisely why the must-be-clear-first check exists.
- How to read it: in series at the sense lead with a meter capable of microamp DC, which is a live reading and falls under the 1910.333(a)(1) conditions above.
Row 3: "Prove position"
- Condition the name claims: the damper is open.
- Sensed quantity: contact state of an end switch, driven by the actuator shaft.
- Location: at the actuator, not at the blade.
- Value window: binary.
- Time window: within the actuator's stated travel time, plus margin.
- Must-be-clear-first: usually yes.
- What else satisfies it: a shaft that turned with a broken or slipped linkage between it and the blade. The switch reports the actuator's position honestly, and the blade stays shut. This is the cleanest example on the sheet of a proof whose named condition and sensed quantity are separated by a mechanical part nobody instrumented.
- How to read it: look at the blade, physically, with the machine isolated and locked out. That is the only reading that closes the gap.
Reading the filled sheet
Three things fall out of a completed sheet that do not fall out of any single row.
The rows sort themselves by trust. Row 3's proxy is separated from its condition by one mechanical link and can be closed by looking. Row 1's proxy is separated by a whole system characteristic and cannot be closed without a second, independent measurement. When two proofs both look made and only one can be wrong, start with the one whose gap is widest, not the one that is easiest to reach.
The must-be-clear-first column predicts your no-start faults. Every yes in that column is a way for a machine to refuse to start with nothing visibly wrong, because the input is stuck in the state that means "good". A tech reading only the wiring diagram sees a closed contact in a permissive path and concludes the permissive is satisfied. It is satisfied and it is disqualifying, and those two facts sit in different documents.
Two proofs that share a location are one proof. If two rows both sense inside the same cabinet section, they will fail together on any condition that affects that section, and the redundancy the sequence appears to provide is not there. That is worth flagging on the sheet rather than discovering during a fault.
Where the sheet is worth building
Building all of this on a routine call is not realistic. It pays on three occasions: a machine that has had a repeat fault survive two visits, a machine nobody at the shop has documentation for, and a machine where someone has already replaced a proving device without the fault changing. In the third case the sheet frequently ends the job, because the row for that device shows an unintended path that was never checked, and the replaced part was doing its job the whole time.
References
- 29 CFR 1910.333(a)(1) for the conditions permitting energized measurement, 1910.333(b)(2) for de-energizing and lockout of electrical circuits, and 1910.334(c) for inspection of test instruments and leads
- 29 CFR 1910.147 for isolation of stored energy where a proving device is pressurized or spring-loaded
- NFPA 70E-2021, 120.5 for the live-dead-live verification sequence
- Manufacturer service documentation for published minimum flame-sensing current, switch setpoints and differentials, actuator travel times, and controller time windows, all of which are equipment-specific
- See related: Why a Proving Signal Can Be True and Wrong; What a Sensor Actually Reports; Where a Sensor Is Reporting From and Why It Matters