A wellsite heater keeps the process fluid warm enough to prevent hydrate formation and freeze-ups, but the burner that heats it is a fire fed by a continuous stream of fuel gas. Burner management is the dedicated safety function that lights that burner, watches its flame, and cuts the fuel the instant the flame is lost. It is deliberately separate from the temperature controller: one keeps the fluid warm, the other keeps a puddle of unburned gas from collecting and finding an ignition source. Understanding the split is the key to understanding why a heater can be running normally and still be shut down hard by its burner management logic.
Wellsite Burner Management in one line: Burner management on a wellsite heater is the safety controller that safely lights the burner, continuously proves the flame is present, and closes the main fuel valve within seconds if the flame goes out. Its purpose is to prevent unburned gas from accumulating in the firetube and causing an explosion, which is a different job from regulating the process temperature.
A burner management system, often shortened to BMS, runs a fixed sequence every time it lights a burner and then holds a supervisory watch for as long as the burner is lit. The sequence begins with a purge: before any fuel is admitted, the controller waits long enough for any residual gas in the firetube to clear, because igniting a firetube that already holds a gas-air mixture is exactly the hazard the whole system exists to prevent. Only after the purge does it energize the ignition source and open the pilot valve.
The next step is pilot proving. The controller opens the small pilot gas valve, sparks the igniter, and then looks for evidence that a flame actually established. That evidence comes from a flame sensor, commonly a flame rod that conducts a small rectified current through the ionized flame, or an optical or thermocouple sensor. If the controller does not see a proven pilot within its trial-for-ignition window, it closes the pilot valve and locks out rather than continuing to release gas into an unlit chamber.
Once the pilot is proven, the controller opens the main gas valve and the burner fires at full rate. From that point on its job is supervision: it keeps reading the flame signal, and every reading confirms the burner is consuming the gas it is being fed. The temperature controller, meanwhile, may be modulating or cycling the main valve to hold the process at setpoint, but the burner management layer sits underneath all of that as the last line of defense on the fuel.
The central safety action is the response to a lost flame. If the flame signal disappears while the main valve is open, the burner management controller drives the fuel valves shut, typically both the main and the pilot, within a bounded reaction time measured in a few seconds. This is the safety shutoff, and it is non-negotiable: an open fuel valve feeding a firetube with no flame is filling that tube with gas that will burn all at once the moment anything ignites it. Cutting the fuel fast removes the fuel side of the fire triangle.
Many wellsite installations then attempt an automatic reignition. Flameouts on unattended remote heaters are often caused by a gust, a slug of liquid in the gas, or a brief pressure dip rather than by a real fault, so the controller runs its safe light-off sequence again: purge, prove pilot, then reopen the main valve. Automatic relight keeps a heater in service through transient upsets without a truck roll, but it always repeats the full proving sequence rather than simply reopening the valve, because skipping the purge and pilot-proof would reintroduce the very hazard the shutoff just prevented.
If reignition fails after a set number of attempts, the controller latches into lockout and stops trying. Lockout is a deliberate refusal to keep releasing gas into a burner that will not stay lit, and it usually requires a manual reset. That reset is a design choice, not an inconvenience: repeated automatic relights on a burner that keeps failing would be indistinguishable, from the outside, from a slow gas leak into the firetube.
On an unattended wellsite, the burner management controller is doing safety-critical work with no operator standing next to it, which is exactly where remote monitoring earns its keep. A cloud SCADA platform such as Merobix does not replace the burner management logic - that safety function stays local so it can react in seconds regardless of network conditions - but it makes the controller's status visible from anywhere. The system can surface whether the burner is proven and firing, whether it is in a relight cycle, or whether it has latched into lockout.
The operational value is in the alerting. A latched lockout means a heater is cold and the process is losing its freeze protection, which on a gas well can escalate into hydrate plugging within hours. When that lockout state is streamed to a cloud dashboard, it can raise an alarm and notify an operator by text before the well itself is in trouble, turning a silent overnight failure into a scheduled morning visit. Trending the flameout count over time also exposes a burner that is drifting toward unreliability, such as a fouling pilot orifice or a failing flame rod, well before it locks out for good.
Because the burner management state and the process temperature are logged together in the historian, field teams can also reconstruct exactly what happened during an upset. Seeing that the flame dropped out, the main valve closed, three relight attempts followed, and the heater then held setpoint tells a far more complete story than a single cold-heater callout. That combination of local safety autonomy and remote visibility is the practical model for burner management on modern wellsites.
No. The temperature controller decides how much heat the process needs and modulates or cycles the fuel to hold the fluid at setpoint. Burner management is a separate safety layer that lights the burner safely and shuts the fuel off if the flame is ever lost, regardless of what temperature the process wants. One optimizes the process; the other prevents an unburned-gas hazard.
The purge clears any fuel gas that may have collected in the firetube before ignition is attempted. Lighting an igniter in a chamber that already holds a gas-air mixture risks igniting the whole volume at once. Waiting for a purge period ensures the tube is safe to introduce a controlled pilot flame into, and the sequence repeats the purge on every automatic relight for the same reason.
Lockout is triggered when the burner cannot establish or hold a proven flame. Common causes are a failing or fouled pilot, a dirty or degraded flame sensor, low fuel gas pressure, liquids carrying into the fuel, or wind repeatedly blowing the pilot out. After a set number of failed automatic relight attempts, the controller latches into lockout, closes the fuel valves, and requires a manual reset rather than continuing to release gas.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.