API 2350 is the standard for overfill protection of aboveground petroleum storage tanks. It exists because an overfilled tank is one of the more serious failures a facility can suffer - a spill of flammable liquid, a vapor cloud, and a potential ignition source all at once - and it lays out how to prevent that outcome through a layered system of alarms, defined liquid levels, and timely response. Rather than leaving overfill prevention to a single high alarm, API 2350 builds a hierarchy of levels with defined roles and demands that operators have enough time to act at each one. It is the specific standard behind the high-level alarming that a SCADA system carries on tank service.
API 2350 (overfill protection) in one line: API 2350 is the API standard for overfill protection of aboveground petroleum storage tanks in the process and terminal industries. It establishes a hierarchy of defined liquid levels and alarms, requires adequate response time at each, and addresses the independence and reliability of the level detection used, so that a receipt into a tank cannot proceed unchecked into an overfill.
The defining structure of API 2350 is its layered set of levels within a tank, each with a distinct purpose. Rather than one alarm point, the standard frames a progression: a maximum working level that normal operation should not exceed, and above it a set of higher levels that mark escalating concern. A high level provides an early warning that a tank is getting full and that action should begin, while a high-high level represents a more urgent condition demanding immediate response, closer to the point where an overfill becomes imminent.
This hierarchy exists so that an operator is not caught by a single last-second alarm. The lower levels in the progression give warning while there is still comfortable time to divert or stop a receipt; the upper levels represent the situation where routine response has failed and stronger action, potentially automatic, is required. The idea of a level of concern captures this - each level is a point at which a defined degree of concern and a defined response are expected, escalating as the liquid rises.
The reason this layering matters is that overfill is fundamentally a race against a rising liquid surface, and the hierarchy is designed to keep the operator ahead of it. Each level is placed so that when it is reached, there remains enough capacity and enough time for the required response to take effect before the tank actually overfills. Spacing the levels correctly - so the warning is early enough and the urgent level still leaves room to act - is central to what API 2350 asks a facility to engineer.
API 2350 is as much about time as about level, because an alarm is only useful if there is time to do something about it. The standard emphasizes that each level must be set so the response it triggers can actually be completed before the tank overfills. That means accounting for how fast the tank is filling and how long the response - an operator stopping a pump, closing a valve, or an automatic system tripping - will take to take effect. A high-high alarm that sounds too late to stop the flow is no protection at all, which is why response time is a first-class consideration in placing the levels.
The standard also cares deeply about the reliability and independence of the level detection that drives overfill protection. The gauge an operator uses for normal inventory management is not, by itself, sufficient assurance against overfill, because a single instrument can fail. API 2350 pushes toward independent means of detecting a high condition, so that the overfill protection does not share a single point of failure with everyday tank gauging. If the normal level gauge sticks or drifts, an independent high-level detector still stands between the receipt and an overfill.
This principle of independence is the substantive heart of the standard and where it goes beyond a generic high alarm. The concept of an overfill protection layer that is separate from the routine level measurement - its own sensor, its own path to action - is what gives the protection its integrity. The standard frames categories and requirements around how automated and how independent that protection is, recognizing that a purely manual, single-gauge approach carries more risk than an independent, and potentially automatic, protective layer. Matching the level of protection to the risk of the operation is the judgment API 2350 asks a facility to make.
API 2350's hierarchy of levels maps directly onto how a SCADA system is configured for tank service. The high and high-high levels the standard defines become alarm points in the monitoring system, and the escalating concern the standard describes becomes escalating alarm priority. A cloud SCADA platform such as Merobix reads tank level continuously, compares it against these configured levels, and raises the appropriate alarm as liquid rises, giving an operator the early warning and the urgent alert that the standard's hierarchy is built around.
The standard's emphasis on independence carries a design lesson for how this is implemented. Because API 2350 wants overfill protection that does not share a single point of failure with routine gauging, the high-level protection ideally draws on independent detection rather than only the same transmitter used for inventory. Monitoring and alarming on level are valuable, but they support the operator's response; they are not a substitute for the independent, and where warranted automatic, protective layer the standard calls for. A well-designed facility uses SCADA to give early visibility while keeping a truly independent overfill safeguard in place.
Where cloud monitoring is especially powerful is on remote and unmanned tanks, exactly the situation the standard's response-time thinking is most strained by. If no one is standing at the tank, the alarm has to reach someone who can act while there is still time, and that is precisely what a cloud platform does - it delivers the high and high-high alarms to an operator wherever they are, along with the fill rate that tells them how urgent the situation is. The rising-level race API 2350 describes is much easier to win when the operator sees the tank approaching its levels of concern from a dashboard rather than discovering the problem on a site visit.
API 2350 frames a hierarchy of levels rather than a single alarm point, escalating in concern as liquid rises. A high level gives an early warning that a tank is getting full and action should begin, while a high-high level represents a more urgent condition demanding immediate response, closer to where an overfill becomes imminent. Each level is a defined level of concern with an expected response, and they are spaced so there is time to act before the tank overfills.
Because a single instrument can fail, and if the same gauge used for normal inventory management also served as the only overfill protection, its failure would leave the tank unprotected. API 2350 pushes toward independent means of detecting a high condition so that overfill protection does not share a single point of failure with everyday tank gauging. If the normal level gauge sticks or drifts, an independent high-level detector still stands between the receipt and an overfill.
Generic overfill protection is the broad idea of an independent high-high layer that acts to stop a fill, but API 2350 is the specific standard that structures how it should be done. It defines a hierarchy of levels of concern, requires adequate response time at each, and frames categories around how automated and independent the protection is, matched to the risk of the operation. In short, generic overfill protection is the concept, and API 2350 is the standard that sets the levels, timing, and independence requirements around it.
Primary references from the standards bodies and regulators that define this topic:
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.