Automation Glossary • Fail-to-start rollover

What is pump alternation fail-to-start rollover?

Merobix Engineering • • 6 min read

Fail-to-start rollover is the control logic that keeps a station pumping when the pump it just called does not actually run. When the selected lead pump is commanded to start but returns no proof of running within a set window, the controller declares it failed, takes it out of the rotation, and immediately calls the next available pump. It is a small but important piece of alternation logic because it turns a single silent pump failure from a cause of overflow into a non-event the operator learns about after the fact.

Back to Blog

Fail-to-start rollover in one line: Pump alternation fail-to-start rollover is control logic that monitors whether a commanded pump confirms it is running within a start-timeout window. If no run feedback arrives in time, the controller flags the pump as failed, latches it out of the rotation, and rolls the start command over to the next available pump so pumping continues, while raising an alarm for the operator.

The start-timeout window and run feedback

When the controller calls a pump, it does not assume the pump is running just because it sent the command. It starts a short timer and waits for independent confirmation that the pump actually started. If that confirmation appears within the window, the start is treated as successful and normal level control continues. If the timer expires first, the pump is judged to have failed to start.

The confirmation, usually called run feedback or run status, can come from several sources. A common one is a motor-run auxiliary contact on the starter or contactor, which proves the motor circuit is energized. Better still is a proof of actual pumping, such as a current sensor showing the motor is drawing load, a discharge flow or pressure switch showing liquid is moving, or a falling wet well level. Using a proof-of-flow signal rather than only a contactor contact guards against the case where the contactor pulls in but the pump does nothing, for example a snapped shaft or an airlocked casing.

Choosing the timeout length is a balance. It must be long enough to allow for a soft starter ramp, a variable frequency drive spin-up, or the moment it takes for flow to establish, so that a healthy pump is never falsely condemned. It must be short enough that a genuinely dead pump is abandoned quickly, before the wet well climbs into alarm. On stations with fast rate of rise, that window is kept deliberately tight.

The fault latch and the rollover

Once a pump fails to start, the logic does two things. First it latches the fault, meaning the pump is marked as unavailable and held out of the alternation sequence rather than being tried again on the next call. This latch is important: without it, the controller would keep selecting the dead pump on every cycle, wasting time on a unit that will not run while the level keeps rising. The latch is deliberately sticky so it survives until someone investigates and clears it.

Second, the logic rolls the demand over to the next available pump in the rotation and issues that start command immediately, then applies the same run-feedback check to the replacement. If that pump also fails to confirm, the rollover continues down the line until a working pump is found or the station runs out of units. In this way a station with two or more pumps can absorb a single start failure with no loss of pumping, and even tolerate a second failure if a third unit is present.

The latched pump stays out of duty until it is manually reset, or in some designs until a maintenance test proves it can run. This prevents a marginal pump that starts intermittently from being trusted with duty it may not deliver. It also means the running pumps carry the extra load, which is why the fail-to-start event is never treated as fully resolved by the rollover alone; it is a degraded state that still needs an operator's attention.

Operator alarm and SCADA visibility

Because the rollover hides the failure from the wet well, the alarm is what makes sure a human still hears about it. The moment a pump fails to start, the controller raises a fault alarm naming the specific unit, and the telemetry system delivers it to the operator through SCADA and, at unstaffed stations, through a callout to on-call staff. The pumping may be safe for now, but a station is running on reduced redundancy until the failed unit is restored.

SCADA also records the sequence, which turns a fleeting fault into diagnostic evidence. The historian shows which pump was called, that no run feedback returned, how long the timeout was, which pump picked up the load, and how the wet well behaved through the event. That record helps maintenance decide whether the fault was a stuck contactor, a tripped overload, a control wiring issue, or a mechanical failure, and it reveals whether a particular pump is failing to start repeatedly.

For field operations, the value is a controlled response instead of a scramble. Rather than being dispatched to a station already in overflow, the crew is notified of a fail-to-start while the remaining pumps hold the level, and they arrive to repair a known unit rather than diagnose a spill. Cloud dashboards make the reduced-redundancy status visible across a fleet, so supervisors can prioritize the stations that are one failure away from losing capacity entirely.

Frequently Asked Questions

What counts as run feedback for a pump start?

Run feedback is any independent signal that proves the pump actually started, as opposed to the command that was sent to it. The simplest source is a motor-run auxiliary contact on the starter, but stronger evidence comes from a motor current sensor, a discharge pressure or flow switch, or a falling wet well level. Using a proof-of-flow signal is safer than a contactor contact alone, because it catches cases where the motor energizes but no liquid moves.

Why not just retry the same pump instead of rolling over?

Retrying a pump that just failed wastes time on a unit that is likely to fail again, while the wet well keeps rising toward an overflow. Rolling over to a known-good standby pump keeps liquid moving immediately, which is the priority. The failed pump is latched out and dealt with by maintenance, so a retry, if any, happens under controlled conditions rather than during a live demand.

How long should the fail-to-start timeout be?

It should be just long enough that a healthy pump always confirms within it, allowing for soft starter ramps, variable frequency drive spin-up, and the time for flow to establish, so a good pump is never falsely condemned. Beyond that it should be as short as practical so a dead pump is abandoned before the wet well reaches alarm. Stations with a fast rate of rise use tighter windows than large wet wells with slow rise.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Staggered restart after power loss  •  Accelerometer Mounting Resonance  •  Stud vs Magnet vs Adhesive Mounting  •  Velocity Pickup vs Accelerometer  •  RMS vs Peak vs Peak-to-Peak  •  Spectral Band Alarm  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →