Why a Proving Signal Can Be True and Wrong

Why this matters

The dangerous proving failure is not the one that stops the machine. It is the one that lets the machine run. A proof that fails open generates a call, a fault code, and a tech. A proof that stays made while the condition behind it has gone away generates nothing, until something further downstream operates and everyone blames that instead.

The claim: a proving signal can be electrically and mechanically correct while the condition it stands for is absent, because the proxy remains satisfiable through a path the designer did not intend. The sibling article on what proving means owns the definition of proxy, sensed quantity and acceptance window; this one is about the shape of the failure and how it is found, through one case that took three visits.

Establish why the protection operated before you touch the protection

Read this before the case, because the case turns on it. When a limit, a pressure switch or an interlock has operated, it has reported a physical condition. Replacing it, resetting it repeatedly, or adjusting its setpoint all reach the same end state as jumpering it, just slower and with a part on the paperwork. Establish what the device sensed and why that condition existed before you decide the device is the fault.

Everything measured below happens on running equipment. Route temperature probes into existing test ports and keep hands, sleeves and leads outside the swept path of any driven part with the guards in place. Cabinet metal downstream of a heat source will burn through a general-handling glove, so read surfaces with a non-contact infrared thermometer at arm's length rather than by touch. If the machine burns fuel, wear a personal CO monitor on your collar before it fires and stay out of the flue and relief-opening path. Any reading requiring an open enclosure is de-energized and locked out under 29 CFR 1910.333(b)(2) with live-dead-live verification per NFPA 70E-2021, 120.5; readings that only exist live fall under 29 CFR 1910.333(a)(1), which permits energized work where de-energizing would introduce additional or increased hazards or is infeasible for the equipment design, using a meter rated at or above the system voltage with leads inspected for damage as 29 CFR 1910.334(c) requires.

The call

A packaged air-handling machine on its third visit for the same complaint: it runs for a while, then stops on a high-temperature limit that has to be reset by hand. Two previous visits each replaced that limit. Both times the machine ran fine on handover. Both times it came back inside a month.

The customer's summary was that the machine "keeps burning out limits". That summary is the reason this article exists, because it had already been accepted twice.

Killing the easy answer first

Hypothesis: the limit is defective, drifting low, and tripping early.

Against it: two devices, from stock, of the same type, behaved identically. A drift fault that reproduces on brand-new parts is not a drift fault. Two independent devices agreeing is evidence FOR the condition they report, not against them, and it should have ended this hypothesis on visit two.

The check that settled it took one reading. With the machine running toward the trip, an independent temperature probe placed adjacent to the limit's sensing element read within a few degrees of the limit's marked setpoint at the moment it opened. The limit was operating at its marked point, on a real temperature. It was correct, and so were the two before it.

What that costs when you get it wrong: two correctly-operating protective devices were condemned and discarded. The end state after both visits was a machine reaching a temperature it should never reach, with a fresh device standing at the boundary and nothing else changed. The only difference between that and jumpering the limit is the interval before the next trip.

Killing the second answer

Hypothesis: the machine is being overdriven, so the heat input is above nameplate and the rise is legitimately high.

This matters because it changes the whole inference chain that follows. Heat input was verified against the nameplate rating by the method appropriate to that machine's energy source, which is a measurement taken with the machine firing and therefore taken with a personal CO monitor worn and the flue and relief openings kept clear, and it read at rating. So the heat going in was what the design assumed.

That elimination is what licenses the next step. Skip it and the temperature-rise reading below can be read two opposite ways.

The measurement that reframed the job

Measure the temperature rise across the machine: entering air and leaving air, both in the airstream, both shielded from line of sight to any hot surface so the probe is reading air rather than radiant energy. That shielding is not a detail, it is the difference between a usable number and one that reads high for no reason.

Nameplate published a design rise band of 35 to 65 F. Measured rise at steady state, several minutes into a run: 78 F.

Convert that to a flow statement, and state the conditions in the same breath, because this relationship is only as good as its assumptions: at constant heat input and roughly constant specific heat, MASS flow varies inversely with temperature rise. Heat input was confirmed at rating in the previous step, so:

78 F measured against the 65 F top of the band is a ratio of 78 / 65 = 1.20. Mass flow is therefore about 1 / 1.20 = 0.83 of the flow that would have produced a 65 F rise. In plain terms, the machine was moving at least 17 percent less air than the minimum its own nameplate accepts, and the true shortfall against a mid-band design point is larger than that.

Two conditions on that number, both real. It is a MASS flow ratio, not a volumetric one, and converting between the two requires the air density at the measured conditions, which changes with temperature and elevation. And it holds only because heat input was verified; an overfired machine produces a high rise at correct flow, which is why that hypothesis had to die first.

Why the airflow proof stayed made

The machine has an airflow proving switch sensing differential pressure across the air-moving device, and it never dropped out through any of this. The differential, measured at the taps with a manometer, read roughly 1.5 times the switch's make setpoint. Solidly proved.

That is not a broken switch. It is the proxy doing exactly what it was built to do, on a machine whose operating point moved. On a centrifugal air mover with a pressure characteristic that rises as flow falls, which describes most cabinet blowers operating left of the peak of their curve, adding downstream resistance moves the machine to lower flow AND higher developed pressure. The switch senses the pressure. The pressure went up. The proof got stronger as the machine got sicker.

The relationship between that pressure and actual flow was fixed at one system resistance, on the day the switch setpoint was chosen. Change the resistance and the relationship no longer holds, and there is nothing on the machine that reports the resistance changed.

The unintended path, stated in the terms the sibling article sets out: the sensed quantity is pressure, the named condition is flow, and increased system resistance satisfies the sensed quantity while removing the named condition. Once written that way it is obvious. It is invisible while the step is called "prove airflow".

Finding the resistance and confirming backwards

With the machine isolated, locked out and the fan at rest, the downstream path was inspected by hand and by sight. A flexible section had partially collapsed on itself, and a balancing damper further along had been closed most of the way during unrelated work.

The confirmation is the part worth keeping, because it runs opposite to intuition. After the restriction was cleared:

Reading Faulted Repaired
Temperature rise 78 F 58 F
Airflow proof differential About 1.5x switch setpoint About 1.1x switch setpoint

The rise fell to 58 F, inside the 35 to 65 F band. The flow ratio between the two states is 78 / 58 = 1.34, so flow rose about 34 percent. And the proving differential FELL, from 1.5x setpoint to 1.1x. A healthy machine proved its airflow less emphatically than a sick one.

That is the confirmation that a swapped part cannot produce, and it is the reason to take both readings rather than one. If clearing a restriction had left the differential unchanged, the restriction was not the operating-point mover and the diagnosis would have been wrong regardless of how much better the rise looked.

What would have changed the conclusion. If heat input had come back above nameplate, the 78 F rise would have been explained without any flow deficit, and the same repair would have been useless. If the machine had used a positive-displacement or axial mover whose pressure characteristic behaves differently across its range, the "proof gets stronger as flow falls" reasoning does not transfer and the differential would have to be interpreted against that machine's own curve. And if the proving differential had read near or below setpoint while the rise was still high, the fault is upstream of the mover rather than downstream, which is a different repair entirely.

The portable version

The generalization is small enough to keep in your head: a proof that is solidly made carries no information about margin unless you know which direction the proxy moves when the real condition degrades. On this machine it moved the wrong way, so a stronger signal meant a worse machine. Ask that question of any proving step before you use its healthy state as evidence of anything.

References

  • 29 CFR 1910.333(a)(1) for the conditions permitting energized measurement, 1910.333(b)(2) for de-energizing and lockout of electrical circuits, and 1910.334(c) for inspection of test instruments and leads
  • NFPA 70E-2021, 120.5 for live-dead-live verification
  • Manufacturer nameplate and service data for the published design temperature rise band, heat input rating, and proving switch setpoint, all of which are equipment-specific
  • Fan and blower manufacturer performance curves for the pressure-versus-flow characteristic of the specific air-moving device
  • See related: What Proving Actually Means in a Sequence; Why a Drifting Sensor Is Worse Than a Dead One; The Danger of Just Resetting a Safety Device Without Diagnosing Why