Not every upset warrants shutting an entire facility down, and not every emergency can be handled by stopping a single unit. Emergency shutdown systems in oil and gas resolve this by defining levels: a layered hierarchy of shutdown actions ranging from a small, local trip up to a total facility shutdown and, offshore, an abandon-platform response. The levels are nested so that invoking a higher, more severe level automatically pulls in all the lower ones beneath it. This page explains that hierarchy and how a facility escalates through it, taking a broader view than the general definition of emergency shutdown.
ESD Level Hierarchy in one line: ESD levels are a layered shutdown hierarchy in which each level commands a progressively larger scope of shutdown, from a single unit or process up to the whole facility and, offshore, an abandon-platform response with blowdown. The levels are nested, so initiating a higher level automatically initiates all the lower levels below it, ensuring a severe event produces a complete and consistent shutdown.
The core idea is that shutdown comes in graduated scopes, each assigned a level, so the response can match the severity of the event. In a common offshore and gas-plant scheme, the most severe level - often numbered lowest, such as Level 0 - represents a total shutdown, up to abandoning the platform, and typically brings with it emergency depressuring, or blowdown, of the process inventory to flare. Below it sits a facility-wide shutdown that stops the whole plant but stops short of the abandon response. Below that is a process shutdown affecting a major section, and below that a unit or local shutdown, sometimes labeled as a process shutdown at unit scope, that trips a single item or a tight group of equipment.
The exact numbering and naming vary between operators and standards, and this page describes the pattern rather than asserting one universal scheme. What is consistent is the direction: higher levels mean a larger scope and a more drastic response, and blowdown is generally associated with the most severe levels because depressuring is reserved for genuine emergencies where removing the stored energy in the process is warranted. A useful way to hold the hierarchy in mind is as a series of concentric responses, from a pinpoint trip out to a whole-facility action.
It is worth separating shutdown levels from the related idea of a process shutdown as distinct from an emergency shutdown. A process shutdown, or PSD, handles process upsets in an orderly way and often corresponds to the lower levels of the hierarchy, while emergency shutdown handles genuine emergencies at the higher levels. Many facilities integrate both into one layered scheme so that the same level structure spans routine process trips through to full emergency response, which keeps the escalation logic coherent across the whole range of events.
The property that makes the hierarchy work is nesting: a higher level automatically initiates every level below it. When a facility-wide shutdown is called, it does not need to separately command each unit trip, because commanding the higher level inherently includes all the lower-level actions. This guarantees consistency - you can never end up in a state where the top level has been demanded but some subordinate equipment was left running - and it simplifies both the logic and the operator's mental model, since asking for a big shutdown reliably delivers all the small ones it contains.
Escalation runs in the other direction and is where judgment and design meet. A local trip might be all a minor upset requires, but if the situation worsens - a fire spreads, a gas cloud grows, pressure keeps rising - the system, or the operator, escalates to a higher level, widening the shutdown. Some escalations are automatic, wired into the cause and effect logic so that certain severe causes jump straight to a high level and its blowdown; others are manual, invoked from an ESD station when a person judges the situation demands it. The design decides which events force which levels, so that the most dangerous conditions cannot be left to a merely local response.
Because the levels are nested and escalation only ever widens the response, the hierarchy is inherently fail-toward-safe in its structure: there is no path where escalating leaves something less protected. Restoring the plant reverses this, and it is deliberately not symmetric - clearing a high-level shutdown requires working back down through a controlled reset and re-permissioning of the lower levels, rather than a single button that restarts everything at once. This asymmetry, easy to escalate and deliberate to recover, is a hallmark of a well-designed level hierarchy.
During an event, one of the first things operators and support staff need to know is which shutdown level is currently active, because that single fact tells them the scope of what has stopped and what response is underway. A SCADA platform can annunciate the active level prominently, showing whether the facility is in a unit trip, a process shutdown, a full facility shutdown, or the most severe abandon-and-blowdown state. Making the level itself a first-class piece of information, rather than something inferred from a scatter of individual trips, keeps everyone oriented to the same picture of severity.
A cloud SCADA platform such as Merobix adds value by tying the active level to the underlying causes and the affected equipment. Because it carries the live states of the initiating inputs and the commanded outputs, it can show not only that a given level is active but what caused the escalation to that level and which units the nested shutdown has swept in. For a facility supported remotely, that context is essential: the person assisting from off-site can grasp both the severity and the reason without being in front of the local panel, which supports better decisions during the event and a safer, staged recovery afterward.
The monitoring layer also supports the deliberate, level-by-level recovery the hierarchy demands. Because the platform shows which levels remain active and which permissives are met, it can guide operators through resetting from the highest active level down through the lower ones in the correct order, confirming at each step that conditions are safe before the next layer is released. Recording the whole sequence - which level tripped, when, why, and how it was cleared - also leaves an auditable history of the event, which is valuable both for investigation and for improving the escalation logic over time.
They are a graduated hierarchy of shutdown scopes, typically ranging from a unit or local trip, up through a process shutdown of a major section, a full facility shutdown, and, offshore, a total abandon-platform level that usually includes emergency blowdown to flare. The exact numbering and names vary by operator and standard, but higher levels always mean a larger scope and a more severe response.
The levels are nested, so initiating a higher level automatically initiates all the levels below it. A facility-wide shutdown does not need to separately command every unit trip, because the higher level inherently includes all the subordinate actions. This guarantees you can never be in a state where the top level is demanded but some lower-level equipment was left running.
A process shutdown, or PSD, handles process upsets in an orderly way and typically maps to the lower levels of the hierarchy, while emergency shutdown handles genuine emergencies at the higher levels, up to full facility shutdown and blowdown. Many facilities integrate both into one layered scheme so a single level structure spans routine process trips through to full emergency response.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.