When operators see LSHH on a P&ID they usually already know it means a high-high level switch, but the tag is only half the story - the interesting part is what the switch actually does when the level reaches it. A high-high level shutdown is the automatic action that trips the process to stop a tank or vessel from overfilling once the normal high alarm has been ignored or has failed to catch the rising level. This guide explains the trip logic behind LSHH, how the setpoint is chosen, and why the shutdown must be kept independent from the transmitter that controls the level day to day.
High-High Level Shutdown (LSHH) in one line: A high-high level shutdown (LSHH) is the final automatic safety layer that stops filling before a vessel overflows. When the level reaches the high-high setpoint - above the normal operating high alarm - the LSHH device sends a trip that closes the inlet valve or stops the feed pump, without waiting for an operator. It is deliberately separate from the control-level transmitter so a failure of normal level measurement cannot also disable the last line of defense against an overfill.
Level protection on a tank is built in layers, and the high-high shutdown is the last automated one before liquid reaches the top. In normal service a control-level transmitter regulates the tank, holding the level in a working band. Above that band sits a high alarm, which warns the operator that the level is climbing toward the limit and gives them time to intervene manually - throttle the inflow, start pumping out, or divert the stream. The high alarm assumes a human will respond in time.
The high-high level shutdown assumes they will not. It is positioned above the high alarm at a level called the high-high, or HH, setpoint, and it does not ask the operator to do anything - it acts on its own. When the sensing device detects liquid at that point, it initiates a trip that removes the source of filling. Because it is designed to work precisely when the earlier layers have failed, the LSHH is treated as a safety function rather than a control or convenience feature, and it is engineered, tested, and documented to a higher standard than an ordinary process alarm.
The distinction matters on a P&ID. An LSH tag is a high level switch that typically drives an alarm; an LSHH tag is a high-high level switch that typically drives a shutdown. Reading the two together tells you the tank has both a warn layer and a trip layer, which is exactly the arrangement overfill practice expects. If a drawing shows only one high-level device wired to both the alarm and the trip, that is a design worth questioning, because it collapses two protection layers into one.
The physical action of an LSHH trip depends on how the tank is filled. If liquid arrives through a line from another vessel or a pipeline, the shutdown closes an inlet shutdown valve, ideally a fail-safe valve that springs shut when its actuator is de-energized. If the tank is fed by a transfer pump, the trip stops that pump. In many designs it does both - closing the valve and stopping the pump - so that the fill path is removed even if one final element sticks. The point is to interrupt the incoming flow quickly enough that the remaining space in the tank is not consumed before the flow stops.
That timing is why the HH setpoint cannot simply be placed at the very top of the tank. Between the moment the level reaches the setpoint and the moment inflow actually ceases, several delays stack up: the sensor's response time, the trip logic's processing time, the valve's stroke or the pump's coast-down time, and the extra liquid that keeps arriving during all of that. The volume that enters during this response window has to fit below the point of overflow. So the setpoint is worked backwards from the safe fill level, leaving enough ullage to absorb everything that flows in while the shutdown completes.
A well-designed LSHH also latches. Rather than reopening the inlet as soon as the level drops a little below the setpoint, the trip holds the shutdown state until an operator confirms the tank is safe and deliberately resets it. This prevents the system from chattering - tripping, clearing, and refilling repeatedly - and forces a human to acknowledge that an overfill was narrowly avoided and to investigate why the earlier layers did not hold.
The single most important property of a high-high shutdown is independence from the device that measures level for control. If the same transmitter feeds both the normal control loop and the high-high trip, then any failure of that transmitter - a stuck reading, a frozen output, a lost signal - can defeat both at once. The control loop stops regulating and keeps the inlet open, and the trip that should catch the resulting overfill never sees the true level because it is reading from the same failed source. A tank has then lost every level-based protection to one fault.
For that reason the LSHH is provided as a separate device with its own sensing element, its own wiring, and its own path into the logic that fires the trip. A common arrangement pairs a continuous control transmitter with a dedicated point-level switch at the high-high position, so the two devices share nothing that could fail together. Better still is choosing a different measurement principle for the safety device than for the control device, so that a common environmental cause - coating, foam, vapor, or temperature - cannot fool both in the same way.
This independence is what turns a level switch into a genuine safety layer. An overfill only happens when several things go wrong in sequence, so the value of the high-high shutdown lies entirely in its ability to survive the failures that took out the layers before it. If it shares a sensor, a cable, a power supply, or a logic solver with the control level, it is not really a separate layer at all - it is the same layer wearing a second tag - and the tank is protected far less than the drawing suggests.
A high level alarm warns an operator that the level is climbing and relies on a person to act. A high-high level shutdown sits above the alarm and acts automatically, closing the inlet valve or stopping the feed pump without waiting for anyone. The alarm buys time for a manual response; the shutdown is the last line of defense when that response does not come.
It is worked backwards from the safe fill level of the tank. You start at the point where overflow or damage would occur, then subtract the extra volume that will still enter while the shutdown completes - the sensor response time, logic delay, and the valve or pump stopping time. Whatever level remains below that is where the high-high setpoint is placed, so incoming liquid has room to settle before the flow actually stops.
Because a single transmitter failure would then disable both normal control and the safety trip at the same time, leaving the tank with no working level protection. Keeping the high-high shutdown on its own sensor, wiring, and logic means a fault in the control instrument cannot also blind the layer meant to catch the overfill. Independence is what makes it a real protection layer rather than a duplicate of the one that already failed.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.