What Reset and Integral Action Actually Do
Why this matters
Reset is the setting that makes a loop land on setpoint instead of near it, and it is also the setting most likely to make a working system overshoot into a protective device. Techs add it because a customer wants the number to read exactly right, without knowing that they have handed the loop a memory, and that a loop with a memory can spend ten minutes driving at full output while the process is already past target. The overshoot that follows gets diagnosed as a stuck valve or a failed sensor on the next visit, because by the time anyone arrives the integrator has unwound and everything looks normal.
Before you add or shorten reset
- Reset increases overshoot, and overshoot spends the margin between normal operation and the protective devices. Read the limit trip points and the current operating value first. Never raise, jumper or replace a limit to accommodate an overshoot you introduced; if a limit has been opening, establish why it opened before touching anything, because replacing a correctly-operating device reaches the same end state as jumpering it.
- On combustion equipment, put a personal carbon monoxide monitor on your body before it fires and keep it there. Reset changes firing rate and cycle length, and you will be standing next to the appliance through several cycles watching for overshoot.
- Where a setting must be reached inside an energized control enclosure, 29 CFR 1910.333(a)(1) permits energized work only where de-energizing introduces additional or increased hazards or is infeasible due to equipment design or operational limitations; use a meter and leads rated CAT III at or above the circuit voltage and work to the boundaries and protective equipment NFPA 70E-2021 assigns. Where the panel can be dead, open the disconnecting means, lock and tag under 29 CFR 1910.333(b)(2) in general industry or 29 CFR 1926.417 in construction, and prove dead per NFPA 70E-2021, 120.5.
- Stay out of an actuator's travel path while a loop is being exercised, and to touch a linkage, isolate the actuator, release or restrain the spring, and lock or tag under 29 CFR 1910.147.
What integral computes, in units you can check
Proportional output exists only while error exists. Integral output exists because error existed, and it stays after the error is gone. That is the whole difference, and it is why integral can put a loop exactly on setpoint: at zero error the integral term holds whatever value it accumulated, so the loop can produce 40% output while sitting dead on target.
The setting is expressed one of two ways and they are reciprocals.
- Integral time, in minutes per repeat. With the error held constant, integral action adds an amount equal to the proportional contribution once every integral time.
- Reset rate, in repeats per minute. The same thing inverted. A 10-minute integral time is 0.1 repeats per minute.
Check it with numbers you can carry. With a 10 F band and an error of 4.0 F, the proportional contribution is 40% of output. With a 10-minute-per-repeat integral time and that error held constant, integral adds another 40% over the next ten minutes, which is 4% per minute. The error does not stay constant in real life, of course, because the output is rising and driving it down, which is exactly the point: the loop keeps adding output until the error is zero, and only then stops adding.
Longer integral time means slower, gentler integral action. That trips people up because on most other settings a bigger number means more. Change it by a factor of two when you tune it, not by small increments, because the effect of a 10% change on an integral time is not observable inside the noise of a real system.
The gate
Reset is worth adding when all three of these are true at once, measured at steady state with the load constant, over at least three of the loop's own round-trip times:
- The error is persistent rather than transient, and
- it is one-sided, sitting consistently above or below target rather than wandering across it, and
- it is larger than the acceptable deviation written for that loop.
All three, joined by AND. A persistent one-sided error that is comfortably inside the acceptable deviation does not qualify, and that case is not rare.
Outcome one: the loop that needed it
A modulating heating loop, band 10 F, bias 0%, acceptable deviation plus or minus 1.5 F, holding steady at 4.0 F below setpoint with the output at 40%.
Run the gate. The error is persistent, it has been on the cold side for every reading, and 4.0 F is well outside plus or minus 1.5 F. All three clauses true, so reset is the right tool.
Set integral time at 10 minutes per repeat as a starting point and watch. The output climbs from 40%, the error falls, and the loop settles on setpoint with the output at whatever the load requires. The standing 4.0 F is gone, and it is gone at every load, which is the part the band could never do: a band change relocates the offset, reset removes it.
What it cost. The loop is now slower to settle after a load step, because integral action takes time to accumulate, and it overshoots where before it approached from one side and stopped. On this loop the overshoot was small enough to live with. On a loop whose acceptable deviation is tight in the other direction, it would not have been, and the correct answer would have been a longer integral time and a slower approach.
Outcome two: the same gate, the opposite answer
A pressure bypass loop on the same site. It sits persistently 3% of range below its target with the output steady, and the operator wants it corrected because the display does not read the round number on the drawing.
Run the same gate. The error is persistent, true. It is one-sided, true. Is it larger than the acceptable deviation? The deviation written for that loop is 10% of range. Three percent is inside it. The third clause fails, so the gate says no, and the answer is to leave it alone.
That is not laziness. Adding reset to this loop buys a display that reads nicer and introduces a failure mode that did not exist: every time the system starts, the loop sits far from target with no ability to correct until the pump comes up, and the integrator accumulates through the whole of that interval. The first minutes after every start now carry an overshoot that nobody asked for, on a loop whose original error was invisible to the process.
What would flip this. If the acceptable deviation on that loop were tightened for a real reason - a downstream device with a genuine minimum pressure requirement - the third clause would pass and reset would become correct. The gate is doing real work here, not rubber-stamping.
Windup, and the limit anti-windup cannot see
Windup is the integral term accumulating while the loop has no ability to act on it. The output is already at its maximum, the error persists, and the controller keeps adding to a number that is doing nothing. When the restriction clears, all of that accumulation has to be unwound in real time before the output can come down.
Work it through. That same loop, 10 F band, 10 minutes per repeat, sits at 4.0 F of error for 30 minutes because somebody left a manual isolation valve mostly closed. Thirty minutes is three repeats, so the integral term accumulates three times the 40% proportional contribution, or 120%. Commanded output is 40 plus 120, or 160%, and the physical output is clamped at 100%.
Now the isolation valve is opened. Heat arrives, and the space runs past setpoint to 2.0 F above it. The proportional term is now minus 20%. Commanded output is minus 20 plus 120, which is exactly 100%, so the output is still pinned wide open with the process already above target. The integral term now unwinds at 2.0 divided by 10, per 10 minutes, which is 2% per minute, so it takes about ten minutes to fall to 100% and let the commanded output drop to 80% and begin closing. Ten minutes of full output on an already-overshooting process, and every minute of it makes the overshoot larger.
Most modern controllers clamp the integrator when their own output saturates, and that is what anti-windup means. Here is the part that catches people: anti-windup can only see the controller's own output limit. A restriction that lives downstream of the output is invisible to it. A stroke stop misadjusted so the valve only opens to 60%, an isolation valve partly closed, a starved supply, a fouled coil, a capacity shortfall - in every one of those, the controller believes it still has authority it does not have, so it keeps winding, and the clamp does not engage until the commanded output reaches its own 100%. By then a large term has accumulated.
The field signature is unmistakable once you know it: output pinned at maximum while the measurement is already past setpoint. Nothing else produces that combination. A stuck valve produces overshoot with the output already commanded low. A lying sensor produces a controller that believes it is still short. An integrator unwinding produces a controller that knows it is over and is still commanding full output, and it resolves itself on its own within minutes, which is why it is almost never present when the next tech arrives.
Confirming reset is set right, and catching windup
Make one step change and time the settle, do not judge from steady state. A loop with reset looks identical to one without it once it has settled. The difference is entirely in the approach. Step the setpoint by a small amount with all protective devices in service, and stop the test at the first sign a device is approaching its trip point.
Count the overshoot and the number of crossings. A well-set integral time gives one overshoot and a settle. Two or three crossings before settling means the integral time is too short, and the correction is to double it, not to trim it. A slow, large oscillation with a period far longer than the loop's round-trip time is reset-driven, and it will not respond to band changes.
Watch one startup from cold, not just a running system. Windup lives in the transition, and a loop that behaves perfectly at steady state can produce its worst overshoot of the day thirty seconds after a restart. If you cannot stay for a startup, ask the customer what the first ten minutes after a restart look like, because they have seen it and nobody has ever asked them.
Check for a downstream limit before you blame the tuning. Stroke the actuator through its full range in hand and confirm it physically reaches both ends. A loop that cannot reach 100% output at the process will wind against that ceiling forever, and no integral time is the right integral time for it.
References
- 29 CFR 1910.333(a)(1) and (b)(2), OSHA general industry work practices for energized and de-energized electrical work
- 29 CFR 1926.417, OSHA construction lockout and tagging of circuits
- 29 CFR 1910.147, OSHA control of hazardous energy, for actuator spring tension and mechanical isolation
- NFPA 70E-2021, 120.5, verifying an electrically safe work condition
- See related: Proportional Response in Plain Terms; Why a Control Loop Hunts; Why Actual Never Equals Setpoint