A large compressor is protected by a dedicated machinery protection system that watches its vibration and shaft position and trips it before a developing mechanical problem becomes a wreck. The way that system decides to trip, using alert and danger levels, requiring channels to agree, and relaxing its thresholds during startup, follows the API 670 practice for machinery protection. This page explains the alert and danger setpoints, how channel voting like two-out-of-two or two-out-of-three works, what trip-multiply does on startup, and how the machinery trip ties into the unit shutdown.
API 670 Machinery Trip in one line: An API 670 machinery protection voting trip is a shutdown initiated by a dedicated machinery protection system that monitors a compressor's vibration and shaft position against alert and danger setpoints. Alert warns the operator, and danger initiates a trip, but to avoid tripping on a single spurious signal the system votes multiple channels, requiring agreement such as two-out-of-two or two-out-of-three before it acts. On startup a trip-multiply function temporarily raises the danger thresholds so normal transient vibration through critical speeds does not cause a false trip, and the resulting danger vote feeds into the unit shutdown key.
The machinery protection system watches signals from proximity probes and other sensors that report how much the shaft is vibrating and where it is sitting, and it compares each signal against two levels. The alert level is the lower one; crossing it means the measurement has risen above normal but not yet to a point that demands stopping the machine, so it annunciates a warning and asks the operator to pay attention. The danger level is the higher one; crossing it means the measurement has reached a value where continued operation risks real damage, so it initiates a trip. Two levels give the operator a chance to react to a developing problem before it reaches the trip.
Separating alert from danger reflects how mechanical problems usually develop. Vibration rarely jumps from normal to catastrophic in an instant; it more often climbs as an imbalance grows, a bearing wears, or a rub develops, so an alert that fires as the trend rises gives warning time. The operator can investigate, reduce load, or plan an orderly stop while the machine is still between alert and danger. Only if the condition worsens to the danger level does the automatic trip take over, so the two-tier scheme catches slow deterioration early and still protects against a fast excursion.
The setpoints are chosen for the specific machine and its normal running behavior, not picked arbitrarily. They sit above the vibration and position the machine shows when it is healthy, with enough margin that ordinary operation never touches alert, but low enough that a genuine problem is caught before it damages the machine. Setting them well is a balance: too tight and the machine nuisance-trips on normal variation, too loose and a real fault is not caught in time. The alert and danger values encode the judgment about what this machine looks like healthy and what looks like trouble.
A single sensor or channel can fail or glitch, and a machinery protection system that tripped a large compressor on one bad reading would cause more outages than it prevented. Voting solves this by requiring more than one channel to agree before a danger trip is allowed. In a two-out-of-two scheme, both channels watching a given measurement must be in danger before the trip fires, so a single channel spiking on its own does not stop the machine. In a two-out-of-three scheme, any two of three channels must agree, which tolerates one failed channel while still tripping on a real event confirmed by the others.
The choice of voting scheme trades availability against protection. Two-out-of-two is resistant to spurious trips because one channel alone cannot trip, but if one channel fails the pair can lose its ability to trip until the fault is fixed, so it leans toward avoiding false trips. Two-out-of-three keeps both a high resistance to spurious trips and the ability to trip with a channel out of service, because it still has two good channels to agree, which is why it is favored where both nuisance-trip avoidance and continued protection matter. Either way, voting means a real mechanical problem, which shows on multiple channels, still trips while a lone sensor fault does not.
Startup adds a wrinkle, because a machine passing through its critical speeds on the way up naturally vibrates more than it does at running speed, and those elevated but normal transient levels could cross a danger setpoint sized for steady operation. Trip-multiply handles this by temporarily raising the danger thresholds during startup, typically by a defined factor, so the machine can accelerate through its critical speeds without a false trip. Once the machine is up to speed and the transient has passed, trip-multiply is removed and the danger levels return to their normal, tighter values, restoring full protection for running operation. This lets the system be permissive during the noisy startup and strict during steady running.
The machinery protection system is a dedicated device, but it does not stop the machine by itself; its danger vote becomes an initiator in the compressor's unit shutdown logic. When a voted danger condition is confirmed, the protection system sends a trip signal into the package control and safety system, where it appears as a trip initiator with its own severity class and its own set of effects, cutting fuel, tripping the driver, opening recycle, and whatever else that class of shutdown commands. So a machinery danger trip is both a decision made by the specialized protection system and an action carried out through the package shutdown key.
Keeping the machinery protection separate from the general control system is deliberate. The protection function watches fast, safety-critical mechanical signals and must remain reliable and independent of the process control, so it lives in its own hardware with its own sensors and voting. Its output to the package shutdown is a clean, qualified trip signal, so the package does not have to interpret raw vibration; it simply receives a confirmed machinery danger and acts on it. This separation keeps the fast, high-integrity protection distinct while still letting it drive the full unit shutdown when it needs to.
For operators and remote monitoring, the machinery protection signals are among the richest early warnings a compressor gives, so they belong in the SCADA and cloud picture. Alert levels trending upward, margins to danger narrowing, and voting status are all visible signs of a machine's mechanical health long before a trip. A platform such as Merobix trends vibration and position against the alert and danger setpoints across time, so a slowly rising vibration, a channel that keeps disagreeing with its neighbors, or repeated approaches to a danger level surface as patterns operators can act on. Turning the machinery protection data into trended history lets a developing mechanical problem be caught at alert, planned around, and fixed before it ever forces a danger trip.
The alert setpoint is the lower level; crossing it means a vibration or position measurement has risen above normal but not to a point that demands stopping the machine, so it annunciates a warning for the operator to investigate. The danger setpoint is the higher level; crossing it means continued operation risks real damage, so it initiates a trip. The two levels give the operator warning time to react to a developing problem before it reaches the automatic trip, while still protecting against a fast excursion.
A single sensor or channel can fail or glitch, and tripping a large compressor on one bad reading would cause more outages than it prevents. Voting requires more than one channel to agree before a danger trip fires, so a lone spiking channel does not stop the machine. Two-out-of-two needs both channels in danger, and two-out-of-three needs any two of three to agree, which tolerates one failed channel while still tripping on a real event confirmed by the others.
When a machine accelerates through its critical speeds it naturally vibrates more than at running speed, and those elevated but normal transient levels could cross a danger setpoint sized for steady operation. Trip-multiply temporarily raises the danger thresholds during startup, typically by a defined factor, so the machine can pass through its critical speeds without a false trip. Once it is up to speed and the transient has passed, trip-multiply is removed and the normal, tighter danger levels are restored for running operation.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.