Adding a second level device to a tank feels like it doubles your protection, but if both devices measure level the same way, they can be fooled by the same problem and fail together. Diverse redundancy is the design idea that the safety level device should use a different measurement principle from the control level device, precisely so a single process condition cannot defeat both at once. This guide explains why technology diversity matters for tank overfill, how it defeats common-cause failure, and how engineers pick complementary devices.
Diverse Redundancy in Overfill Protection in one line: Diverse redundancy in overfill protection means the control-level instrument and the safety-level instrument sense level using different physical principles - for example a guided-wave radar for control and a vibrating fork or float switch for the safety trip. The purpose is to defeat common-cause failure: a process condition such as foam, coating, or vapor that fools one technology is far less likely to fool a fundamentally different one. Simply duplicating the same sensor type gives redundancy but not diversity, and leaves both devices vulnerable to the same fault.
Redundancy assumes that two devices fail independently, so that the chance of both failing at the same moment is the product of two small probabilities. That assumption holds only when the two devices do not share a weakness. Two identical level sensors, mounted in the same tank on the same product, share every weakness their technology has. If the measurement principle is confused by foam on the surface, both are confused. If it drifts when the probe coats with paraffin or scale, both drift together. If it loses signal in heavy vapor or reads the wrong interface, both do. The failure is common to both, so instead of multiplying two small probabilities you effectively have one - a common-cause failure.
Real-world overfill incidents have repeatedly involved this trap. A tank fitted with two of the same level device gives an engineer the comfortable impression of redundancy, yet the second device provides almost no additional protection against the process condition that will actually cause trouble, because that condition acts on both instruments in the same way. The tank is protected against a random electronic failure of one unit, which is the easy case, but not against the systematic error that fools the technology, which is the case that overfills tanks.
This is the specific application of common-cause failure to sensor selection. General common-cause analysis looks at shared power, wiring, and location; overfill sensor diversity zeroes in on shared measurement physics. Two radars on one tank might sit on separate cables and separate cards and still both be blinded by the same low-dielectric foam, because the vulnerability lives in the physics of how they sense, not in the wiring. Diversity is the countermeasure aimed exactly at that shared-physics failure.
Diverse redundancy asks the engineer to pair technologies whose weaknesses do not overlap. Level is measured in many ways - guided-wave and non-contact radar, differential pressure, capacitance, displacer and float mechanisms, vibrating forks, and ultrasonic - and each has conditions it handles well and conditions that fool it. A radar that struggles with heavy foam may be paired with a float or displacer that rides the actual liquid regardless of the vapor above it. A capacitance probe sensitive to coating may be backed by a vibrating fork that simply detects wet-or-dry at a point and is largely indifferent to the buildup that troubles the capacitance measurement.
A very common and robust overfill pairing is a continuous transmitter for control - often radar for its accuracy and lack of moving parts - together with a simple point-level switch for the safety trip that works on an entirely different principle, such as a vibrating fork or a float. The continuous device does the everyday job of telling the operator exactly how full the tank is; the point switch does one job supremely well, which is to change state reliably when liquid reaches the high-high position, using physics the continuous device does not rely on. Because the two disagree only when something is genuinely wrong, their divergence is itself a useful diagnostic.
The selection is a judgment about the product and the process, not a formula. An engineer considers what the liquid does - whether it foams, coats, stratifies, changes dielectric, or carries vapor - and chooses a safety technology whose failure modes are least like the control technology's under those exact conditions. The goal is not the most accurate second sensor but the most differently-failing one, because in a safety layer the question that matters is not how precisely it reads but whether it will still respond when the primary measurement has been defeated.
Diverse redundancy delivers a bonus beyond surviving common-cause failure: because two differently-behaving devices watch the same tank, a SCADA system can compare them and detect trouble early. When a radar control transmitter and a diverse point switch are both brought into a platform such as Merobix as separate tags, the system knows the level the transmitter reports and the wet-or-dry state the switch reports, and it can flag the moment they disagree - the transmitter reading mid-tank while the high switch has gone wet, or the switch never changing state even as the transmitter climbs past it. That disagreement is exactly the signature of one device being fooled while the other is not.
Merobix reads these devices from the field over Modbus, DNP3, OPC UA, and MQTT, so a diverse control-and-safety pair becomes two independent trends the platform can log, chart, and alarm on. Over time this catches the slow failures that undermine overfill protection - a probe that has begun to coat and drift, a switch that has stopped exercising, a transmitter that reads plausibly but has quietly diverged from the truth the diverse device still sees. None of these is obvious from a single instrument, but the discrepancy between two diverse instruments makes them visible.
For an oil and gas operator watching many tank batteries at once, this comparison scales protection across the whole field without adding operator burden. The platform, not a person, notices when a diverse pair stops agreeing, and raises it for attention before the next fill turns a hidden sensor failure into a spill. Diversity gives you the two independent viewpoints; cloud SCADA turns having two viewpoints into a continuous, automatic cross-check that keeps the redundancy honest.
Plain redundancy means using more than one device so the system survives a single failure. Diverse redundancy adds the requirement that the devices work on different principles, so a condition that defeats one is unlikely to defeat the other. Two identical radars are redundant but not diverse; a radar paired with a float switch is both, and only the diverse pair resists a common-cause failure that fools a whole technology.
Because two of the same sensor share every weakness that technology has. If foam, coating, or vapor confuses one, it confuses the other in the same way at the same time, so the second device adds little real protection against the fault that actually causes overfills. A second device that fails differently is far more valuable in a safety layer than a second copy of the most accurate one.
A frequent and robust arrangement is a continuous radar transmitter for control and inventory paired with a simple point-level switch, such as a vibrating fork or a float, for the safety trip. The radar accurately tracks the level for everyday operation, while the point switch reliably changes state when liquid reaches the high-high position using different physics. Because they rely on unrelated principles, a condition that blinds the radar is unlikely to disable the switch.
This page references the protocol specifications published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.
Last reviewed: July 27, 2026. Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.