Automation Glossary • Fail-Safe ESD Valve (De-Energize to Trip)

What Is a Fail-Safe De-Energize-to-Trip ESD Valve?

Merobix Engineering • • 7 min read

The safest shutdown valve is one that closes when everything else fails, and that is exactly the idea behind de-energize-to-trip. Instead of needing power to act in an emergency, a de-energize-to-trip ESD valve is held open by a continuously energized solenoid, and it trips shut the moment that power or signal is lost. This guide explains how the de-energize-to-trip arrangement works, why it is the preferred fail-safe philosophy, and how it contrasts with the energize-to-trip approach that relies on power being present when it is needed most.

Back to Blog

Fail-Safe ESD Valve (De-Energize to Trip) in one line: A de-energize-to-trip ESD valve is a fail-safe shutdown valve whose solenoid is normally energized to keep the valve open, so that any loss of electrical power or trip signal vents the actuator and lets a spring drive the valve to its safe position, usually closed. It is preferred for safety because a wiring break, power failure, or blown fuse causes the valve to trip to safe rather than being stranded open. This is the opposite of energize-to-trip, which needs power applied at the moment of the emergency to act.

How De-Energize-to-Trip Works

In a de-energize-to-trip valve, the normal, running condition is the energized condition. A solenoid valve on the actuator is kept continuously powered, and while it is energized it directs air or hydraulic pressure to hold the valve actuator against a spring, keeping the valve open so the process flows. The trip circuit that feeds this solenoid is normally live - the logic solver holds the output on to keep the valve open, and it commands a shutdown simply by switching that output off. Removing power is the trip.

When the solenoid de-energizes, whether commanded by the logic or caused by a fault, it vents the actuator, releasing the air or hydraulic pressure that was holding the valve open. With that holding force gone, a spring in the actuator drives the valve to its fail-safe position, which for most ESD service is fully closed. The valve springs shut under its own stored energy, needing nothing from outside to complete the stroke. This is why the arrangement is fail-safe: the energy to close is already stored in the spring, and the trip merely releases it by taking power away.

The elegance of this is that the same act - loss of power to the solenoid - covers both a deliberate shutdown and a wide range of failures. A commanded trip, a broken wire, a tripped breaker, a blown fuse, a failed power supply, a disconnected solenoid: every one of these results in the solenoid losing power, venting the actuator, and springing the valve to safe. The valve does not distinguish between an intended trip and an accidental loss of power, and it does not need to, because in both cases the safe action is the same.

Why De-Energize Is the Preferred Fail-Safe Philosophy

The reason de-energize-to-trip dominates safety shutdown design is what happens on failure. Consider the opposite arrangement, energize-to-trip, where the solenoid must be powered on to move the valve to safe. In that scheme a broken wire, a lost power supply, or a blown fuse means the trip signal can never reach the valve, so at the exact moment an emergency demands the valve close, it may sit open with no way to act. The failure of the trip circuit and the emergency it should respond to can coincide, and the valve is defeated precisely when it is needed. Worse, such a failure is often silent - nothing looks wrong until the trip fails to happen.

De-energize-to-trip inverts this so that failures push the valve toward safety instead of away from it. Because the valve is held open only while power is present, any loss of that power trips it closed, so the same faults that would strand an energize-to-trip valve open will actively shut a de-energize-to-trip valve. The failure mode is toward the safe state, which is the essence of fail-safe design. It also makes faults self-revealing in a useful way: a loss of power announces itself immediately by tripping the valve, rather than lurking undetected until a real demand.

The trade-off is that de-energize-to-trip valves trip on any power interruption, including nuisance ones, so a brief supply glitch can cause an unwanted shutdown. Designers accept this because a spurious trip to a safe state is far preferable to a failure to trip when needed - a plant that shuts down unnecessarily is an operational nuisance, while a valve that fails to close in an emergency is a safety event. The whole philosophy is built on that priority: it is better to fail toward safety and occasionally shut down without cause than to fail toward danger and stay open when closure is required.

De-Energize-to-Trip in Monitored Field Operations

Because a de-energize-to-trip valve treats loss of power and a commanded trip identically, monitoring is what lets operators tell the two apart and confirm the valve is healthy. A cloud SCADA such as Merobix reads the trip-circuit status, the solenoid's energized state, and the valve's actual open or closed position from the field over Modbus, DNP3, OPC UA, and MQTT, so an operator can see not just that a valve is closed but why - whether the logic commanded the trip or the solenoid lost power for another reason. That distinction matters when deciding how to respond to a shutdown.

Continuous monitoring also verifies the fail-safe chain is intact during normal operation. The platform can confirm that the valve is where it should be, that its position agrees with the trip circuit's command, and that the feedback has not diverged - a valve reporting open while its trip output is off, or a position that has not matched its solenoid state, are signs worth investigating. Because Merobix holds this as time-stamped history, a spurious trip caused by a momentary power dip can be reviewed after the fact and distinguished from a genuine process demand, informing whether a nuisance-trip problem needs to be addressed.

For an operator overseeing many wells, separators, and shutdown valves across a field, this visibility scales the assurance that the fail-safe philosophy is actually delivering. The system can flag valves whose position and command disagree, sites where trips are occurring more often than the process warrants, and shutdowns whose cause needs attention, all without a technician standing at each valve. De-energize-to-trip gives the valve its safe-on-failure behavior; continuous monitoring gives field operations the evidence that every valve is still wired, powered, and positioned to trip safely when it must.

Frequently Asked Questions

What does de-energize-to-trip mean for an ESD valve?

It means the valve is held in its running position by a continuously energized solenoid, and it trips to its safe position when that power or signal is removed. Removing power vents the actuator and lets a spring drive the valve shut, so the trip is caused by de-energizing rather than energizing. Any loss of power - commanded or accidental - moves the valve to safe, which is what makes the arrangement fail-safe.

Why is de-energize-to-trip safer than energize-to-trip?

Because its failures push the valve toward the safe state. With energize-to-trip, the valve needs power applied to close, so a broken wire or lost supply can leave it stuck open exactly when an emergency needs it shut, often with no warning. With de-energize-to-trip, those same faults remove the power holding the valve open, so it trips closed - the failure mode is toward safety, and lost power reveals itself by tripping the valve.

What is the downside of de-energize-to-trip?

It trips the valve on any interruption of power, including brief nuisance dips, so it can cause unwanted shutdowns that an energize-to-trip scheme would not. Designers accept this because a spurious trip to a safe state is far preferable to a failure to close when a real emergency arrives. A plant shutting down unnecessarily is an operational nuisance, whereas a valve failing to trip is a safety event, so the philosophy favors failing safe.

Sources and verification

This page references the protocol specifications published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.

Last reviewed: July 27, 2026. Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Maintenance Override Switch (MOS)  •  Fusible Plug / Fire Loop Shutdown  •  Detonation vs Deflagration Flame Arrestor  •  In-Line vs End-of-Line Flame Arrestor  •  Gauge Hatch vs Thief Hatch  •  Guide Pole / Stilling Well  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →