Automation Glossary • Setting API 2350 Alarm Levels

How to Set API 2350 Alarm Levels and Response Times

Merobix Engineering • • 4 min read

Setting overfill alarm levels by picking a round percentage of the tank is the classic mistake API 2350 exists to prevent. This how-to walks the response-time-first method for placing levels, aimed at the instrument or process engineer commissioning a tank's overfill scheme. It describes the calculation logic and sequence; the actual numbers and final sign-off belong to your site procedures and a qualified reviewer.

Back to Blog

Setting API 2350 Alarm Levels in one line: To set API 2350 alarm levels, work backward from time, not capacity: fix the maximum safe fill, estimate the total response time to stop the flow (detection, decision, valve closure, and line drain-down), convert that time to a height using the fill rate, and place each level of concern above the last so the critical level still leaves margin. Verify with a proof test, then document the basis.

Establish the Maximum Safe Fill

Start at the top and work down. Determine the highest level the tank can safely reach without risking the roof, seal, or vent - the safe fill level. Everything below is scheduled from this ceiling. Do not start from nameplate capacity; the usable safe ceiling is lower and is the real reference.

Gather the physical inputs you will need next: the tank's cross-sectional area or a tank strapping table to convert height to volume, the maximum expected fill rate for any transfer that can reach this tank, and the drain-down volume that keeps arriving after a valve starts closing.

Budget the Total Response Time

Add up every second between 'a level is reached' and 'flow has actually stopped.' That includes detection and annunciation, the operator or system decision, the time to initiate a stop, the valve stroke time, and the drain-down of product already past the point of no return in the line. This total is the design response time.

Be conservative on the pieces you do not control. Remote or attended transfers, cellular telemetry latency, and manual valve operation all lengthen the budget. Where a fast, automatic path exists - such as a high-high level shutdown tied to valve closure - it shortens the budget, but only for that layer.

Convert Time to Height and Place the Levels

Multiply the response time by the fill rate to get the volume that will enter during the response, then convert that volume to a height using the strapping table. That height, subtracted from the safe fill ceiling, is where the level that triggers the stop must sit - any higher and you run out of tank before flow stops.

Place the remaining levels of concern below it with real spacing between them, following the ladder for the tank's category described under API 2350 levels of concern. Each lower level must leave enough time to escalate to the next. Assign the higher levels to an independent high-level alarm path where the category calls for independence.

Verifying the Result

Prove the path, not just the setpoint. Bench or in-situ proof-test each level so the alarm and any automatic action actually fire at the configured height, and confirm the valve closes in the stroke time your budget assumed. A setpoint that is correct on paper but attached to a slow or stuck valve has not been verified.

Then document the basis of each level - the fill rate, response time, and drain-down you used - so a reviewer can reconstruct the logic. This record is what turns a number in a configuration into a defensible engineering decision, and it is what an auditor or an SPCC plan review will ask for.

Common Mistakes

The signature mistake is setting the high-high at a fixed percentage - 90 or 95 percent - regardless of fill rate. A fast transfer into a tall tank can blow through the remaining 5 percent before anyone reacts. The percentage is an output of the time budget, not an input.

The second is ignoring drain-down. Product in the line keeps arriving after the valve command, and on a long or elevated line that volume is significant. Levels set as if flow stops the instant the valve is commanded will overfill on the drain-down alone.

Frequently Asked Questions

Should I set the high-high alarm at 95 percent of the tank?

Not as a rule. The correct setpoint is derived from the fill rate and total response time, then converted to a height. On a fast transfer that height may be well below 95 percent; on a slow one it may be higher. The percentage is a result, not a starting point.

Why does line drain-down matter for alarm levels?

Product already in the piping keeps flowing into the tank after the valve begins to close. On long or elevated lines that residual volume can be large. Levels that assume instant stop will be overtopped by drain-down, so it must be in the response-time budget.

How do I verify the alarm levels are correct?

Proof-test each level so the alarm and any automatic action fire at the configured height, confirm the shutdown valve strokes within the assumed time, and document the fill rate, response time, and drain-down used. Verification is the whole path, not just the setpoint number.

More in Alarms & Alarm Management
API 2350 Levels of Concern  •  Set Priority From Consequence  •  Setting alarm and trip setpoints  •  Document an Alarm Response Procedure  •  Write an Alarm Response Procedure  •  All Alarms & Alarm Management →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →