Thread Content
This post was last edited by The one on 2026-6-3 08:40. Alarm rationalization is the process of arguing for and evaluating the optimization requirements for alarms collected during the identification phase, in order to determine the final solution. Taking the requirement of “adding an alarm” as an example, the process of rationalizing alarms is simplified as follows: “Necessity assessment” is key to rationalizing alarms – determining whether it is necessary to add that particular alarm. Similar “disable alarms” requests also need to be confirmed.
Alarm: Indicates to the operator, through sound and/or visual means, equipment failures, process deviations, or other abnormal conditions that require prompt attention (from GB/T41261). Alarm: audible and/or visual means of indicating to the operator an equipment malfunction, process deviation, or abnormal condition requiring a timely response (from ISA18.2).
The alarm definition can be broken down as follows: ◆ Indicating to the operator through sound and/or visual means: An alarm must be capable of emitting a warning signal, such as sound, color, or light (flashing).
◆ To the operator: The alarm warning signals are sent directly to the DCS operator, rather than being transmitted to team leaders, engineers, or managers.
◆ Requiring immediate response: The operator needs to take action promptly to resolve the issue indicated by the alarm, thereby restoring the production process to a normal and/or safe state.
◆ Equipment failures, process deviations, or other abnormalities: Reflect equipment failures, process fluctuations, or abnormal conditions during the production process.
This post was last edited by The one on 2026-6-3 08:41. Through the analysis of the definition of alarms as outlined above, the basic elements of an alarm can be identified: 1. Reflecting abnormalities in the production process. This is the original purpose of designing alarm functions in DCS systems, namely to alert operators to any abnormalities in the production process. The basic rule is to trigger an alarm in case of any anomaly; otherwise, no alarm is issued. Yet this seemingly simple rule has not been strictly followed. The reality is that most factories are abusing the alarm function; it is not uncommon for alarms to be used to indicate equipment shutdowns, valve closures, the activation of interlocks, or the execution of control procedures. This is why, even during normal operation, you will still see a large number of alarms in the DCS alarm list, especially when the plant is shut down or the backup equipment is offline. The main reason for this situation is the lack of clear alarm design standards in enterprises, with the limitations of DCS functions having a relatively minor impact.
2. Timely response from the operator is required. When an anomaly occurs during the production process, an alarm is sent to the operator so that he or she can take measures to eliminate the anomaly. In other words, the abnormal situation indicated by the alarm is unacceptable, as it may lead to adverse consequences such as equipment damage, shutdown of the plant, losses in production or quality, injuries to personnel, and environmental damage. If there is no impact on the production process, then no operator response is required, and therefore no alarms need to be set up.
I’m sure everyone is familiar with such a scenario: in the control room, where alarm sounds keep ringing, operators carry out their tasks methodically, conduct inspections, and take over shifts, while all work on site proceeds in an orderly manner. The only impact of the alarms is the \"noise\" they create. Such “alarms” do not require operator intervention, but the operator still has to “handle” them by silencing the alarm.
4. No duplicate alarms will be generated. If multiple alarms indicate exactly the same abnormal condition, then such an abnormality will result in multiple alarms being issued, which is not only unnecessary but also can distract the operator. For some process variable measurement points, multiple tables are often designed to monitor the same indicator; if alarms are set up in each of these tables, duplicate alarms will occur. For example, regarding the temperature of a motor’s windings, there are usually three sensors for monitoring this value. If three alarm settings are configured, then all three sensors will trigger an alarm when the temperature of the motor windings becomes abnormal; in such cases, it is sufficient to set only one alarm. This situation is quite common and is the main source of repeated alarms; it should be avoided.
5. Considerating the needs of different states: An excessive process volume that exceeds the alarm range can be caused by abnormal conditions, or it may result from \"abnormal values\" under normal circumstances. For example, when the device is shut down, the system will cool down and discharge material; during operation, the temperatures and material levels that are monitored will inevitably drop below the alarm thresholds. But this is an inevitable consequence of parking and unloading, and it is not an abnormal situation. Low temperature and low material level are normal conditions during the shutdown and discharge process, rather than abnormalities in normal operation; therefore, the failure to trigger an alarm during this period does not indicate any abnormality, and no alarm is required. Therefore, it is advisable to consider using advanced alarm methods for optimized design, such as conditional alarms and status alarms.