Automation Glossary • Alert and Danger Levels

What are vibration alert and danger levels?

Merobix Engineering • • 6 min read

Alert and danger levels are the two rising setpoints that structure a machinery-protection vibration system. The alert, or alarm, level warns that a machine's vibration has climbed above its normal range and needs attention, while the danger, or trip, level marks the point at which continuing to run risks damage and the machine should be shut down. This two-tier scheme separates a call for investigation from a call for protective action, and the logic around it, especially time delays and voting, decides how a trip is allowed to happen.

Back to Blog

Alert and Danger Levels in one line: A vibration alert level is the lower setpoint that raises an alarm to warn that vibration has risen above normal and warrants attention, while the danger level is the higher setpoint that indicates continued operation risks damage and initiates a trip to shut the machine down. Machinery-protection systems apply time delays and voting logic, following standards such as API 670, so that a genuine condition rather than a transient triggers the trip.

The two-tier alert and danger scheme

The lower of the two setpoints is the alert level, sometimes called the alarm level. Crossing it does not stop the machine; it signals that vibration has risen above the range considered normal for that machine and that someone should investigate. It is meant to give early notice while there is still time to plan, so it is set above normal operating vibration but comfortably below the level at which damage becomes a concern.

The higher setpoint is the danger level, also called the trip level. Reaching it indicates that vibration has climbed to a point where continued operation risks real damage to the machine, and the protective response is to trip the machine off automatically. Because a trip has serious operational consequences, the danger level is set high enough that reaching it genuinely means the machine is in trouble, not merely running rough.

The gap between the two levels is deliberate and gives operators a working margin. When only the alert is active, the machine keeps running while staff diagnose the rising vibration and decide on a controlled response, such as reducing load or planning a shutdown. The danger level is the backstop for when that intervention does not happen or the condition worsens too fast, ensuring the machine protects itself even if no one acts in time.

Time delays, voting, and how API 670 governs a trip

A raw vibration signal can spike briefly for reasons that are not a real machine fault, such as a passing transient or electrical noise, so tripping instantly on a single momentary exceedance would cause nuisance shutdowns. To prevent this, protection systems apply a time delay to the trip: the danger level must be exceeded continuously for a set period before the trip is issued, filtering out brief spikes while still acting quickly on a sustained condition. The delay is kept short enough that a genuine problem is not allowed to persist.

Voting adds a further safeguard against a single faulty channel causing a false trip. In a voting scheme the system requires more than one measurement to agree that the danger level is exceeded before it trips, for example demanding that two channels out of two, or two out of three, concur. This means a single failed sensor or a single spurious reading cannot shut a machine down by itself, which is important because an unnecessary trip of a large machine is costly and disruptive.

The industry standard API 670 governs the design of these machinery-protection systems, defining how setpoints, time delays, voting, and the trip logic should be arranged so that protection is both reliable and resistant to false trips. It frames the philosophy that a trip should occur when a real, sustained, and corroborated dangerous condition exists, and not otherwise. Following such a standard is what turns a set of raw setpoints into a dependable protection system that operators can trust to act correctly.

SCADA alarms versus hardwired protection trips

It is important to distinguish the operator-facing alarm carried by SCADA from the protective trip carried by the machinery-protection system, because they serve different roles. The SCADA alarm is for awareness: it tells operators that vibration has crossed the alert level and prompts investigation, and it may also annunciate that a trip has occurred. But the SCADA layer is generally not the thing that actually stops the machine, because it is not designed to the availability and response requirements of a safety trip.

The trip itself is executed by a dedicated, often hardwired, machinery-protection system that acts independently of the operator interface and the control network. This separation matters: the protective action must happen deterministically and quickly even if the SCADA or control system is busy, degraded, or offline. So the danger-level trip is implemented in the protection hardware, while SCADA observes and records the vibration values and the resulting events for the operators and for the historian.

In practice the two work together. The protection system provides the fast, reliable trip and streams its vibration values and alarm states into SCADA, where operators see the alert-level warnings, trend the readings, and receive notifications. Cloud and SCADA monitoring add the wider context, letting reliability staff watch how a machine approaches its alert level over time and act before the danger level is ever reached. The trip remains the last line of defense, hardwired and independent, while the monitoring layer is where the earlier, less drastic decisions are made.

Frequently Asked Questions

What is the difference between an alert level and a danger level?

The alert level is the lower setpoint that raises an alarm to warn that vibration has risen above normal and needs investigation, without stopping the machine. The danger level is the higher setpoint that indicates continued running risks damage and triggers a protective trip to shut the machine down. The alert calls for attention while there is time to plan; the danger level is the automatic backstop.

Why does a vibration trip use a time delay and voting?

A time delay requires the danger level to be exceeded continuously for a set period before tripping, which filters out brief spikes from transients or noise that are not real faults. Voting requires more than one channel to agree that the level is exceeded before tripping, so a single failed sensor cannot shut the machine down. Together they guard against nuisance trips while still acting on a genuine sustained condition, in line with API 670.

Does SCADA perform the vibration trip?

Generally no. The trip is executed by a dedicated machinery-protection system, often hardwired, that acts independently of the operator interface so it works even if the control network is degraded or offline. SCADA displays the alert-level alarms, trends the readings, and records events, and it may annunciate that a trip occurred, but the actual protective shutdown is handled by the separate protection hardware for reliability.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
ISO 10816 Zone Boundary  •  Shaft-Relative vs Bearing-Absolute  •  Shaft Centerline Plot  •  1x Amplitude and Phase Vector  •  Full Spectrum Plot  •  Bode and Polar Plots  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →