An interlock is the automation system's way of saying no - or you must do this first. It is logic that prevents an unsafe or invalid action and forces protective action when conditions demand it. Interlocks are how a plant stops a compressor from starting without lube oil pressure, or trips a well on high pressure. This guide explains what interlocks are, the difference between permissives and trips, and how they relate to safety systems.
Interlock in one line: An interlock is control logic that blocks or forces an action based on process conditions to protect people and equipment - for example, preventing a pump from starting until suction pressure is adequate, or shutting a system down when a limit is exceeded.
Interlocks come in two broad flavors. A permissive is a condition that must be true before an action is allowed - the system will not let you do something until it is safe. A compressor start permissive might require adequate lube-oil pressure, closed guards, and no active shutdowns; fail any and the start command is blocked. A trip (or protective interlock) forces action when a condition goes bad - high-high pressure, low-low level, high vibration - by shutting down equipment or closing valves to reach a safe state, regardless of what the operator commands.
Both are usually expressed as logic in the controller: combinations of discrete inputs (switches, status) and analog comparisons (a measurement crossing a limit) that enable or block outputs. Interlocks are why you cannot simply energize any output at will - the logic enforces the plant's safe operating envelope.
Not all interlocks are equal. Ordinary process interlocks live in the standard control PLC and protect production or equipment. Safety interlocks that protect against hazards to people or major loss - part of a Safety Instrumented System (SIS) or Emergency Shutdown (ESD) system - are engineered to a higher standard, often on separate, certified safety controllers with a defined Safety Integrity Level, so a control-system fault cannot defeat them.
In oil and gas, interlocks and ESD logic are pervasive: high-pressure shut-in of a wellhead, level trips on separators and vessels, fire-and-gas actions, and pump and compressor protections. The intended interlock behavior is documented in the control narrative and verified during acceptance testing. SCADA typically monitors and annunciates interlock and trip status so operators can see what tripped and why, while the interlock logic itself executes in the local controller for speed and reliability - it must act in a fraction of a second and cannot depend on a network link.
A permissive must be satisfied before an action is allowed - it blocks a start until conditions are safe. A trip forces protective action when a condition goes bad, such as shutting down equipment on a high-pressure or low-level limit, regardless of operator commands.
A process interlock lives in the standard control PLC and protects production or equipment. A safety interlock protects people against hazards and is engineered to a higher standard, often on a certified safety controller as part of an SIS or ESD system.
No. Interlock logic executes in the local controller so it acts in a fraction of a second and works even during a network outage. SCADA monitors and annunciates interlock and trip status but does not enforce the interlock itself.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.