Automation Glossary • API 2350 Program Elements

Elements of an API 2350 Overfill Prevention Program

Merobix Engineering • • 4 min read

Engineers often meet API 2350 as a level switch and a high-high alarm, but the standard is really asking for a management program around overfill risk. This page lays out the program elements - management commitment, procedures, competency, and equipment - so a facility can check whether it has a real program or just hardware. It is the program-build companion to the basic definition, aimed at the person who owns the plan.

Back to Blog

API 2350 Program Elements in one line: An API 2350 overfill prevention program is a management system, not a single device. It expects documented management commitment and responsibility, written receipt procedures, defined levels of concern with response times, competent and trained personnel, and equipment that is proven, tested, and maintained. The instrumentation is one element; the procedures, roles, and records around it are the rest of the program.

Management System and Responsibility

API 2350 frames overfill prevention as an operator-owned management system with named responsibility, not a bolt-on. Someone has to own the program, the risk assessment behind it, and the decision on how each tank is categorized. That ownership is what turns a pile of switches into a program an auditor can follow.

This is where the standard connects to the broader spill-prevention picture. An overfill event is exactly the release an SPCC plan exists to prevent, so the overfill program and the facility's spill planning are usually managed together. The management element is what keeps them aligned rather than living in separate binders.

Procedures and Levels of Concern

The procedural core is the receipt: a written procedure for how a transfer is planned, executed, watched, and stopped. Central to that is the concept of levels of concern - graduated tank-level thresholds, each with a defined action and the time available to take it. The dedicated page on API 2350 levels of concern breaks those categories down.

Response time is the design driver most facilities get wrong. The gap between the alarm and the physically full tank has to be long enough for a real human or system to stop the flow, accounting for valve closure and line drain-down. A safe fill level is set from that time budget backward, not from how much the tank could theoretically hold.

Equipment, Testing, and Competency

The equipment element expects level detection appropriate to the category, often including an independent high-level path so a single instrument failure does not defeat protection. That independence is the point of an independent high-level alarm separate from the gauging used for inventory. Proof-testing that path on a defined schedule is part of the program, not optional maintenance.

Competency closes the loop. The people planning and watching transfers have to be trained and demonstrably competent, and the program has to keep that current. An untrained operator with perfect instrumentation is still an overfill risk, which is why API 2350 treats training and the equipment as elements of one system.

Common Misconceptions

The biggest misconception is that installing an overfill switch satisfies API 2350. The standard is a program; the switch is one component. Without procedures, categorization, testing records, and trained staff, the switch is hardware without a program.

The second is that inventory gauging doubles as overfill protection. Best practice keeps the safety-instrumented overfill path independent from the gauging used for accounting, so a gauging fault cannot silently disable protection. Sharing one sensor for both is a common and dangerous shortcut.

Frequently Asked Questions

Is API 2350 just about a high-level alarm?

No. API 2350 defines an overfill prevention management program: management responsibility, written receipt procedures, categorized tanks with levels of concern, proven and tested equipment, and trained personnel. The alarm is one element of that program.

What are levels of concern in API 2350?

Levels of concern are graduated tank-level thresholds, each with a defined response and the time available to act before the tank overfills. They let a facility escalate action as a tank fills rather than relying on one final trip point.

Does API 2350 require independent level instruments?

For higher-risk categories the program typically provides an independent high-level detection path separate from inventory gauging, so one instrument failure does not defeat protection. The exact arrangement follows the tank's category and the operator's risk assessment.

More in Standards, Procedures & Compliance
Overfill Prevention System (OPS)  •  SCADA for API 2350 Programs  •  API 570 Program Elements  •  API 653 Program Elements  •  API RP 580 Program Elements  •  All Standards, Procedures & Compliance →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →