Automation Glossary • Lockout/Tagout

What Is Lockout/Tagout (LOTO)?

Merobix Engineering • • 7 min read

Lockout/tagout, usually shortened to LOTO, is the discipline that keeps a machine dead while someone works on it. The idea is physical and blunt: put a lock on the energy-isolating device so it cannot be operated, hang a tag that says who locked it and why, and then prove the equipment is actually de-energized before anyone puts a hand inside. It exists because the most dangerous moment in maintenance is not the work itself but the accidental restart - a pump that spins up, a valve that swings open, a stored charge that discharges - while a person is exposed. LOTO is the barrier that makes that restart impossible.

Back to Blog

Lockout/Tagout in one line: Lockout/tagout (LOTO) is the practice of physically isolating and locking hazardous energy sources so equipment cannot be re-energized while it is being serviced. A lock secures the energy-isolating device, a tag identifies who applied it and why, and a verification step confirms zero energy before work begins - preventing the accidental startup that LOTO exists to stop.

The Six-Step Energy Isolation Sequence

LOTO follows a defined sequence, and skipping any step is where incidents happen. It begins with preparation: identifying every energy source feeding the equipment - electrical, hydraulic, pneumatic, mechanical, thermal, and any stored energy - because a machine often has more than one, and isolating only the obvious one leaves the others live. Next comes shutdown, bringing the equipment to a stop using its normal controls, followed by isolation, where each energy source is physically disconnected at its isolating device: opening a breaker, closing a block valve, disconnecting a line.

With the sources isolated, the locks and tags go on. Each isolating device gets a lock so it cannot be moved, and a tag naming the person, the date, and the reason. Then stored energy must be released or restrained - draining hydraulic pressure, bleeding down pneumatic lines, blocking a suspended load, discharging capacitors - because an isolated system can still hold enough energy to injure. Only after that does the final and most important step happen: verification, where the worker attempts to operate the equipment to confirm nothing moves, then uses instruments to confirm zero energy, before beginning the actual work.

The sequence runs in reverse to restore service, and that reverse order is deliberate too. The work area is cleared and checked, tools and personnel are accounted for, guards are replaced, and only then are locks and tags removed - each by the person who applied it - before the equipment is re-energized and restarted under controlled conditions. Every person who removes their lock is confirming they and their part of the job are clear, which is why one worker cannot remove another's lock. The discipline of the sequence, run correctly in both directions, is what turns a set of good intentions into a reliable barrier against startup.

Locks, Tags, Group Boxes, and the Try-Out

A lock and a tag do different jobs and are not interchangeable. The lock is the physical barrier - it makes the isolating device impossible to operate, and its key stays with the person who applied it. The tag is the information - it says who owns the lock, when it went on, and why - warning others not to touch the device even if they could. A lock without a tag leaves people guessing who to ask before restarting; a tag without a lock is only a request, easily ignored or overridden. Sound practice pairs the two, with the lock providing the actual protection and the tag providing the accountability.

When several people work on the same equipment, a group lockout keeps each of them protected independently. A group lock box holds the keys to the equipment's isolation locks, and each worker places their own personal lock on the box. The equipment cannot be re-energized until every personal lock is removed from the box, which happens only as each worker finishes and clears. This means no single person can inadvertently release the isolation while others are still exposed - the equipment stays locked until the last person is done, and every worker controls their own protection with their own lock and their own key.

The step that most distinguishes real LOTO from going through the motions is the try-out, sometimes called the zero-energy verification. After isolating, locking, and releasing stored energy, the worker actually attempts to start the equipment using its normal controls and confirms it does not run, then uses a meter or gauge to verify the absence of voltage or pressure. This is the moment that catches the isolation applied to the wrong breaker, the valve that did not fully seat, or the second energy source nobody accounted for. A lock hung on the wrong device gives a false sense of safety; the try-out is what proves the isolation is on the right one before anyone trusts it with their life.

Coordinating De-Energization from the Control Room

On a facility with a control room, LOTO and the process control system have to work together, because the equipment being locked out is often the same equipment the operators are watching and, sometimes, able to command. Before a field crew locks out a pump or a motor-operated valve, the control room typically takes the equipment out of service in the automation system and confirms it is stopped and de-energized on their displays. A cloud SCADA platform such as Merobix lets the operator see that the drive is stopped, the valve is in the expected position, and the feed is off, so the isolation the field crew is about to lock aligns with what the control system shows.

That coordination cuts both ways. The control room must ensure that no automatic action - a level controller that would restart a pump, an interlock that would reopen a valve, a remote command from another operator - can attempt to re-energize a point that a crew has locked out. Being able to see that a piece of equipment is locked out and out of service in the same system used to run the plant helps the operator avoid the disastrous case of an automation sequence or a well-meaning remote command driving toward a point where someone is working behind a lock.

For remote and unmanned sites, where a control room may be many miles from the equipment, this visibility becomes even more valuable. The people applying locks in the field and the operator watching the SCADA screen are often not in the same place, so the shared picture of what is stopped, what is isolated, and what is locked out is the common reference that keeps them in sync. LOTO remains a physical, mechanical barrier applied by hand at the equipment - the software does not replace the lock - but a control system that reflects the isolation and refuses to fight against it makes the whole coordination between the desk and the field far safer.

Frequently Asked Questions

What is the difference between a lock and a tag in LOTO?

A lock is a physical barrier that makes an energy-isolating device impossible to operate, and its key stays with the person who applied it. A tag is an information label that identifies who applied the lock, when, and why, warning others not to touch the device. The lock provides the actual protection while the tag provides accountability; sound practice always pairs the two so the isolation cannot be operated and everyone knows who controls it.

What is the try-out step in lockout/tagout?

The try-out, or zero-energy verification, is the step where the worker attempts to start the equipment with its normal controls to confirm it does not run, then uses instruments to verify there is no voltage or pressure before beginning work. It is the critical check that catches a lock applied to the wrong device, a valve that did not seat, or an unaccounted energy source. Skipping it is how a worker ends up trusting an isolation that was never actually made.

How does a group lock box protect multiple workers?

A group lock box holds the keys to the equipment's isolation locks, and each worker on the job places their own personal lock on the box. The equipment cannot be re-energized until every personal lock has been removed, which each worker does only when they have finished and cleared. This ensures the equipment stays locked out until the last person is done, and no single worker can release the isolation while others are still exposed.

Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Positive Isolation  •  Gas Testing for Permits  •  Control of Work System  •  Pre-Startup Safety Review  •  Management of Change  •  Temporary MOC  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →