Automation Glossary • SSO Prevention Alarm Setpoints

How to Set SCADA Alarm Setpoints to Prevent a Sanitary Sewer Overflow

Merobix Engineering • • 6 min read

A sanitary sewer overflow happens when a lift station cannot move the sewage arriving at it and the wet well climbs until it spills. The alarm setpoints in SCADA are the layer that gives an operator time to respond before that happens, and setpoints placed too high, without enough lead time, or blind to the failure that actually causes overflows leave the station one silent fault away from a spill. This procedure is for the engineer or technician configuring the alarm scheme that guards against an overflow.

Back to Blog

SSO Prevention Alarm Setpoints in one line: To set SCADA alarm setpoints that prevent a sanitary sewer overflow, place a high-level alarm below the lowest incoming invert with enough lead time for a responder to reach the site, add an independent high-high alarm above it as a last warning, and alarm the failures that cause overflows directly - pumps not running, station in manual, and loss of communications - not just the rising level itself.

Set the High-Level Alarm With Real Lead Time

The high-level alarm exists to give a person time to act before the well overflows, so place it where the remaining volume above it buys enough time for the site's actual response. Set it below the lowest incoming pipe invert so it annunciates before sewage can back up into the collection system, and above the normal working band so ordinary cycling never trips it. The gap between the high-level alarm and an overflow, divided by the worst-case net inflow, is the response window, and that window has to be longer than the time it realistically takes to get a responder to the station.

Confirm the alarm is referenced to the same datum as the level sensor and matches the drawing, the same discipline used when you verify the lift-station level control band. A high-level alarm set correctly on paper but shifted by a datum error or a scaling mistake either nuisance-trips during normal operation or, worse, sits too high and gives no lead time. The whole value of the alarm is the warning time it provides, so the level it sits at and the volume above it are what make it work, as the guide on the high wet-well overflow alarm explains.

Add an Independent High-High Last-Chance Alarm

A single high-level alarm shares the analog level sensor with the pump control, so a failed level sensor can silence both the control and the alarm at once. Add a high-high alarm that is as independent as the station allows, ideally driven by a separate device such as a backup float or a second sensor, so it still warns of a rising well when the primary analog path has failed. This is the last-chance layer, and its independence is the whole point, mirroring the design intent in the guide on the independent high-level alarm.

Set the high-high above the high-level alarm and still below the overflow point, so it fires only after the first alarm was missed or the analog path failed, but still with some margin before a spill. Route it to a notification path that escalates hard, because a high-high on a sanitary station is an imminent-overflow condition, not a routine advisory. The verification of the backup device driving it is covered in the guide on how to verify wet-well float backup switches.

Alarm the Failures That Actually Cause Overflows

Most overflows are not caused by a mysterious surge of inflow; they are caused by the station failing to pump what arrives - a pump that will not start, a station left in manual after maintenance, a power loss, or a controller that has lost communications so nobody sees the well rising. Alarm these directly rather than waiting for the level to climb into the high-level alarm, because catching a failed pump early gives far more response time than catching a full well late. A pump commanded to run but not confirming it is running is an alarm; a station switched to manual is an alarm; a lost RTU or communications path is an alarm.

Loss of communications deserves special attention, because a station that has gone silent is a station where the level alarms cannot reach anyone even as the well fills. Configure the SCADA host to alarm on a station that stops reporting within an expected interval, so a communications failure is caught as its own event rather than discovered when an overflow is reported. These failure alarms turn the scheme from one that reacts to a nearly-full well into one that catches the cause while there is still time, which ties into how you configure an alarm in SCADA.

Verifying the Result and Common Mistakes

A verified overflow-prevention scheme has a high-level alarm placed for real lead time below the lowest invert, an independent high-high as a last chance, and direct alarms on the pump, mode, power, and communications failures that cause most spills, all routed to a path that reaches a responder in time. Test each by creating its condition under supervision and confirming the notification arrives. Record the setpoints, the computed lead time, and the notification results as the baseline. On a monitoring platform the level trend and the alarm events are recorded together, so a near-miss shows exactly how much margin remained.

The most common mistake is treating the high-level alarm as the only defense and setting it so high there is no time to respond once it trips. The second is a high-high that shares the same sensor as the primary control, so a sensor failure defeats both at once. The third is alarming only on level and never on the pump, mode, and communications failures that cause most overflows, so the first warning is a well that is already nearly full. The fourth is a correct alarm scheme wired to a notification path nobody actually monitors, which the guide on how to set up SMS alerts in SCADA helps close.

Frequently Asked Questions

Where should the high-level alarm sit to prevent an overflow?

Below the lowest incoming pipe invert so it annunciates before sewage backs up into the collection system, above the normal working band so ordinary cycling never trips it, and low enough that the volume remaining above it, divided by the worst-case inflow, gives a responder enough time to reach the station before it overflows. The lead time the alarm buys is what makes it useful, not the level number alone.

Why alarm on pump and communications failure instead of just level?

Because most overflows are caused by the station failing to move what arrives - a pump that will not start, a station left in manual, a power loss, or a controller that has lost communications so nobody sees the well rising. Catching those failures directly gives far more response time than waiting for the level to climb into the high-level alarm, when the well may already be close to overflowing.

Why does the high-high alarm need to be independent?

Because a single high-level alarm shares the analog level sensor with the pump control, so one failed sensor can silence both the control and the alarm together. An independent high-high, driven by a separate device such as a backup float or a second sensor, still warns of a rising well when the primary analog path has failed. That independence is the entire reason the last-chance alarm exists.

More in SCADA Fundamentals
Set Gas Detector Alarm Setpoints  •  Set Alarm Priorities  •  Configure a Comms-Fail Alarm  •  How to configure an alarm in SCADA  •  How to configure an email alarm notification  •  All SCADA Fundamentals →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →