Automation Glossary • Alarm Setpoint and Limits

What Are Alarm Setpoint and Limit Types?

Merobix Engineering • • 6 min read

Most analog measurements carry more than one alarm, arranged in tiers that fire in sequence as a value drifts further from where it should be. A tank level might warn you when it gets high, warn you more urgently when it gets dangerously high, and do the same on the low side - a layered set of limits that gives you progressively less margin and demands progressively more decisive action. This page explains the standard Lo-Lo, Lo, Hi, and Hi-Hi limit scheme, what each level is for, and how the tiers map to an escalating operator response.

Back to Blog

Alarm Setpoint and Limits in one line: Alarm setpoints, or limits, are the threshold values at which an analog measurement triggers an alarm, and they are commonly arranged in tiers: Low-Low (LL), Low (L), High (H), and High-High (HH). The inner limits, L and H, warn that a value is leaving its normal range while there is still margin to correct it, while the outer limits, LL and HH, indicate the value has reached a dangerous extreme demanding immediate or automatic action. The tiers escalate priority and required response as the value moves further from normal.

The Tiered Limit Scheme

A single measurement often needs several alarm limits because there is a difference between a value being outside its comfortable range and a value being genuinely dangerous. The standard scheme places up to four limits around the normal operating band. Above normal sit the High limit and, further out, the High-High limit; below normal sit the Low limit and, further out, the Low-Low limit. These are frequently written as H, HH, L, and LL, and in some control systems appear under tag names or descriptors such as PVHI and PVLO for the high and low process-variable alarms. Not every point needs all four - some have only a high pair or only a low pair - but the ordering is always the same, with the first-level limits closer to normal and the second-level limits nearer the physical or safety extreme.

The purpose of the two levels is to give the operator staged warning. The first-level limit, High or Low, is a heads-up: the value has crossed out of its normal band, but there is still time and margin to bring it back before anything bad happens. The second-level limit, High-High or Low-Low, is a serious condition: the value has continued to the point where consequences are near, response time is short, and the situation may already be moving toward an automatic protective action or a trip. Because the second-level limit represents a more severe, more time-critical condition, it is normally assigned a higher priority than its first-level counterpart, so the priority itself escalates as the measurement crosses each successive threshold.

Mapping Limits to Operator Response

The value of the tiered scheme is that each limit implies a different action, and a well-designed set of alarms makes that progression clear. When a High alarm annunciates, the expected response is investigative and corrective: find out why the value is climbing and take control action - throttle a valve, adjust a setpoint, start a pump - to arrest and reverse the trend while there is still room to do so. The operator has margin, so the response is measured rather than frantic. This first-level alarm exists precisely to give that opportunity, catching the excursion early enough that the outer limit is never reached.

If the value continues past the High-High limit, the situation has changed character and so must the response. The margin is largely gone, so the action is immediate and decisive, and often the automated systems have already begun to act - a High-High level might be the point at which an inlet valve is commanded shut or the vessel is tripped to prevent overfill. It is important to keep this alarming layer conceptually separate from any independent safety instrumented function that may also act at an extreme; the alarm asks the operator to respond, while a protective trip acts on its own. Designing the limits well means placing the first-level alarm where the operator realistically has enough time to correct the excursion, and placing the second-level alarm where a genuinely urgent, last-chance response is warranted, so the two levels are not so close together that they effectively fire at once.

Multi-Level Limits in SCADA Monitoring

In a SCADA or cloud monitoring system, the tiered limits are what let a single trend both reassure and escalate. On a dashboard, a value crossing its High limit can be shown in a warning color and raise a routine alert, while the same value reaching High-High switches to a critical presentation and drives an urgent notification. That graduated response is only meaningful because the limits themselves were placed to represent genuinely different degrees of severity, so the platform's escalation mirrors the physical reality of how close the process is to trouble.

For a platform such as Merobix, monitoring remote oil and gas sites, the first-level limits are what make early intervention possible from a distance. A High level or High pressure alarm that fires with margin still remaining gives a remote operator the chance to respond - dispatch someone, remotely adjust an operation, or plan a visit - before the second-level limit and its more severe consequences are reached. Without that inner warning tier, the operator would only learn of a problem once it had already become critical, which on an unmanned site can be too late to prevent an overflow, a shutdown, or a spill.

The two-level scheme also helps the remote operator triage across many sites at once. A screen full of first-level High and Low alarms represents excursions that warrant attention but are not yet emergencies, while any High-High or Low-Low draws the eye immediately as a site that has run out of margin. That built-in severity ordering, coming straight from the limit tiers, is part of what lets one person credibly watch a large fleet: the setpoint structure itself tells them where the real urgency is.

Frequently Asked Questions

What do HH, H, L, and LL mean in alarms?

They are tiered alarm limits on an analog measurement. H (High) and L (Low) are first-level alarms that warn the value has left its normal range while there is still margin to correct it, while HH (High-High) and LL (Low-Low) are second-level alarms indicating the value has reached a dangerous extreme demanding immediate action. The second-level limits sit further from normal and carry higher priority than their first-level counterparts.

Why have both a High and a High-High alarm?

To give the operator staged warning. The High alarm is an early heads-up that lets the operator correct an excursion while margin remains, whereas the High-High alarm signals the value has reached a near-consequence extreme with little time left, often coinciding with automatic protective action. Having both catches problems early and still provides a last-chance urgent alert if the first is not enough.

Is a High-High alarm the same as a safety trip?

No, though they may act at similar extremes. A High-High alarm asks the operator to respond to a dangerous condition, while a safety trip or protective function acts automatically on its own to prevent a hazard. They are kept conceptually separate, and a critical process typically has both an alarm layer that alerts the operator and an independent protective layer that acts regardless of operator response.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Alarm Deadband  •  Alarm On-Delay and Off-Delay  •  Alarm Flood Suppression  •  Alarm Management KPIs  •  Bad Actor Alarm  •  Alarm Response Procedure  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →