Automation Glossary • MooN Voting Logic

What Is MooN Voting Logic?

Merobix Engineering • • 7 min read

Safety systems often use more than one sensor or channel to decide whether to act, and MooN voting is the shorthand for how those channels are combined. The notation means M-out-of-N: out of N channels, at least M must agree before the voted result is taken. Reading MooN as a general framework, rather than memorizing individual arrangements, makes it easy to see how 1oo1, 2oo2, 1oo2, 2oo3, and variants like 1oo2D are all the same idea with different numbers. This page gives that unifying view and the trade-off that choosing M and N really represents.

Back to Blog

MooN Voting Logic in one line: MooN voting logic is a general notation, meaning M-out-of-N, for how a safety function combines several channels: of N total channels, at least M must call for the safe action before it is taken. Choosing M and N sets a trade-off between avoiding spurious trips and maximizing safety availability, and familiar architectures such as 1oo1, 2oo2, 1oo2, and 2oo3 are simply specific values of M and N.

The General M-out-of-N Framework

In MooN notation, N is how many channels the function uses and M is how many of them must agree before the voted outcome is declared. A channel is a sensing-and-decision path - a transmitter and its trip comparison, for example. When at least M channels say trip, the function trips. This single rule contains all the common architectures: with one channel you have 1oo1, with two channels needing both you have 2oo2, with two channels needing either you have 1oo2, and with three channels needing any two you have 2oo3. Rather than treating these as separate concepts, it is cleaner to see them as points in one framework selected by picking M and N.

The framework also accommodates diagnostic variants. In 1oo2D, two channels are arranged so either can trip the function, but built-in diagnostics detect a failed channel and take it out of the vote, effectively degrading toward a safer configuration when a fault is found. The D signals that diagnostics modify how the raw MooN vote is applied. Seeing 1oo2D as a MooN arrangement with an added diagnostic overlay, rather than as a wholly different thing, keeps the mental model simple: the vote is still M-out-of-N, and diagnostics change which channels are allowed to participate.

Because MooN is just a rule for combining channels, it applies equally to sensors on the input side, to logic, and to final elements on the output side, and a full safety function may use different MooN arrangements at each stage. The notation does not care what the channels physically are; it only describes how their votes are counted. That generality is what makes MooN such a useful language - it lets engineers describe and compare very different pieces of a safety loop with one consistent vocabulary.

Choosing M and N: Spurious Trips Versus Safety Availability

Every choice of M and N sits somewhere on a trade-off between two failure directions. One direction is the spurious trip - the system acts when it did not need to, shutting the plant down for no real hazard, which is costly and, through repeated nuisance trips, can even erode trust in the system. The other direction is failure on demand - the system fails to act when it genuinely should, which is the safety-critical failure the function exists to prevent. Raising M relative to N makes the function harder to trip, which reduces spurious trips but also makes it more likely that a real demand is missed if channels have failed; lowering M does the opposite.

This is why the extremes behave as they do. A 1ooN arrangement, where any single channel can trip, is biased toward safety availability - it will act on a real demand even if other channels have failed - but it trips easily and is prone to spurious trips as N grows. A NooN arrangement, where every channel must agree, is biased against spurious trips - one channel alone cannot shut you down - but it is vulnerable to failing on demand, because a single stuck channel that will not vote to trip can block the safe action. The intermediate MooN choices, most famously 2oo3, deliberately sit in the middle to get much of the spurious-trip resistance of a NooN scheme while keeping strong safety availability.

The right choice depends on the consequences on each side. Where a spurious trip is merely expensive and the process is forgiving, a configuration that tolerates disagreement to avoid nuisance trips can be justified. Where failing to act is catastrophic, availability of the safe action dominates and the design leans toward configurations that trip readily. The required safety integrity level, the hardware fault tolerance it implies, and the diagnostic coverage available all feed into which M and N actually satisfy the target, so the selection is an engineered decision rather than a preference.

Configuring and Monitoring a Voting Group in SCADA

A voting group is more than the M-out-of-N rule; it is a set of channels that must be configured, kept in agreement, and watched for the conditions that undermine the vote. A cloud SCADA platform such as Merobix can present the members of a voting group together, showing each channel's live value and trip state alongside the voted result, so an operator sees not just that the function has or has not tripped but how each channel contributed. That visibility turns an abstract voting scheme into something an operator can actually reason about during an event.

The most useful thing monitoring adds is discrepancy detection. In any MooN group with more than one channel, the channels should broadly agree during normal operation, and a channel that has drifted away from its peers is a warning sign even before it fails outright. Surfacing that a channel disagrees - that one transmitter reads far from the others in a 2oo3 group, for instance - lets maintenance address a degrading channel while the remaining channels still preserve the vote. Because the platform holds every channel's history, it can also trend these divergences over time rather than reacting only when a channel finally trips.

Monitoring also matters for the availability side of the trade-off. A MooN scheme only delivers its intended balance while its channels are healthy; a group silently running with a failed or bypassed channel is no longer voting the way it was designed to. A monitoring layer that shows which channels are in service, which are bypassed, and which have faulted keeps the real, current voting configuration visible, so the protection that was engineered on paper is the protection actually in force. For remote and multi-site operations, having that voting-group health visible in one place is what keeps the chosen M-out-of-N logic trustworthy in practice.

Frequently Asked Questions

What does MooN mean in a safety system?

MooN means M-out-of-N: a safety function uses N channels, and at least M of them must call for the safe action before it is taken. Familiar architectures are specific values, so 1oo2 is one-out-of-two, 2oo3 is two-out-of-three, and 2oo2 is two-out-of-two, all described by the same M-out-of-N rule.

How do you choose the right MooN architecture?

The choice balances avoiding spurious trips against maximizing safety availability. Raising M makes the function harder to trip, cutting nuisance shutdowns but risking a missed demand, while lowering M does the reverse. The consequences of each failure direction, the required safety integrity level and its hardware fault tolerance, and the available diagnostic coverage together determine which M and N are acceptable.

What is the difference between 1oo2 and 2oo3 in MooN terms?

Both are MooN arrangements with different numbers. 1oo2 uses two channels and trips if either one calls for action, favoring safety availability but tripping easily. 2oo3 uses three channels and trips when any two agree, which keeps strong safety availability while greatly reducing spurious trips, which is why it is a popular middle-ground choice.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
2oo2 Voting  •  ESD Level Hierarchy  •  Shutdown Valve (SDV)  •  Blowdown Valve (BDV)  •  Startup Bypass  •  Bypass Management  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →