Automation Glossary • Voting degradation

What is voting degradation on diagnostic fault detection?

Merobix Engineering • • 6 min read

Voting degradation is the dynamic behaviour of a redundant safety system when one of its channels fails and the logic solver automatically changes the voting arrangement to keep the safety function running. Where the static voting pages describe a fixed configuration such as two-out-of-three, voting degradation is what happens the moment a self-diagnostic flags a bad channel: the system revotes, for example dropping from two-out-of-three to one-out-of-two, and keeps protecting the process while the faulty channel is repaired. It is a clever way to preserve availability without lowering the integrity of the trip. The trick only works if the diagnostics are good enough to find the fault in the first place.

Back to Blog

Voting degradation in one line: Voting degradation is when a redundant safety system's logic solver detects, through self-diagnostics, that one channel has failed and automatically reconfigures the voting to a lower arrangement, such as 2oo3 degrading to 1oo2 and then to 1oo1. This keeps the safety function available and safe during the repair window rather than tripping the process or leaving it unprotected, and it depends on high diagnostic coverage to identify the faulty channel.

How the degradation logic works

Consider a common two-out-of-three arrangement, where any two of three channels agreeing is enough to trip the process. If one channel's self-diagnostics report that it has failed, the logic solver knows it can no longer trust that channel to contribute a valid vote. Rather than continuing to demand two out of three, which would now require both remaining good channels to agree, the system degrades its voting to one-out-of-two among the two healthy channels. The safety function stays online, and a trip can still be raised, but the arrangement now reflects the reduced hardware available.

If a second channel then fails and is diagnosed, the system can degrade again to one-out-of-one, relying on the single surviving channel to carry the safety function until repairs are made. At each step the logic solver is making a reasoned choice: keep the function available with the channels it can still trust, rather than either faulting the whole segment or pretending the failed channel is still voting. The sequence of two-out-of-three to one-out-of-two to one-out-of-one is the classic degradation ladder, and each rung is entered only when a diagnostic confirms the loss of a channel.

The direction of degradation is chosen to preserve the ability to reach a safe state. Because the goal of the safety function is to trip when needed, the degradation typically moves toward configurations that make tripping easier or at least no harder, rather than toward configurations that could mask a real demand. This is a deliberate bias: when in doubt about a channel, the system leans toward being able to shut down, accepting a slightly higher chance of a spurious trip in exchange for not missing a genuine demand while running short-handed.

Preserving availability without losing integrity

The reason voting degradation exists is that redundancy is there to survive faults, and blindly tripping the process every time one channel fails would defeat the point. A well-designed degrading voter lets the plant keep operating with a known, documented reduction in redundancy while a technician replaces the bad channel. The safety function is never simply switched off; it continues to protect the process using the healthy channels, which is why availability is preserved even though one leg of the redundancy is temporarily gone.

Crucially, integrity is not sacrificed to buy that availability. The degraded arrangement is still a valid safety configuration that can detect a demand and act on it. What changes is the margin: with fewer channels there is less tolerance for a second, undetected fault, which is exactly why the degradation assumes a bounded repair window. The safety analysis accounts for the time spent in the degraded state and requires the faulty channel to be restored within a defined mean time to repair, so the period of reduced redundancy is short and quantified rather than open-ended.

This behaviour is only trustworthy because of high diagnostic coverage. The whole scheme rests on the logic solver actually detecting that a channel has failed; a fault that the diagnostics miss cannot trigger a revote, so the system would carry on voting with a dead channel and its true integrity would be worse than it appears. That is why degrading voters are paired with strong online self-tests, and why diagnostic coverage figures feed directly into the credit taken for the arrangement. Good diagnostics turn a hidden failure into a detected one that the voter can route around.

Watching degraded states from the control room and cloud

A degraded voting state is a temporary condition that has to be visible and acted on, and this is where monitoring earns its keep. The safety analysis assumes the faulty channel is repaired within a defined window, but that assumption only holds if someone knows the system has degraded. Operations needs a clear, prompt indication that a two-out-of-three loop is now running one-out-of-two, together with which channel failed, so a work order can be raised before the repair window quietly expires.

A cloud SCADA platform complements the local safety system by surfacing these degradation events and, just as importantly, timing them. Because the logic solver knows exactly when it revoted, that transition can be logged with a timestamp and streamed to a historian, so the clock on the repair window is objective rather than something a technician guesses at later. If a loop has been sitting in a degraded state for longer than the analysis allows, that overdue condition becomes a standing alarm rather than a forgotten note in a shift log.

For an operator running remote wellsites or unmanned facilities, this visibility is the difference between a controlled repair and an unnoticed erosion of protection. Merobix and similar cloud platforms can aggregate degradation events across many sites, showing which safety loops are currently short-handed and how long they have been that way, without any part of the monitoring path being inside the trip decision itself. The safety system keeps making its own choices; the cloud layer just makes sure the humans responsible for the repair window can see the clock ticking.

Frequently Asked Questions

What does 2oo3 degrading to 1oo2 actually mean?

It means a two-out-of-three voting arrangement has lost one channel to a diagnosed fault, so the logic solver now votes one-out-of-two among the two remaining healthy channels. The safety function stays available and can still trip, but with one fewer channel of redundancy until the failed channel is repaired.

Does voting degradation reduce the safety integrity of the function?

The degraded arrangement is still a valid safety configuration that can detect and act on a demand, so integrity is preserved in the sense that protection continues. What shrinks is the margin against a further fault, which is why the degradation assumes the faulty channel is repaired within a defined window.

Why does voting degradation depend on diagnostic coverage?

The logic solver can only revote around a channel it knows has failed, and it only knows that if self-diagnostics detect the fault. If diagnostic coverage is poor, a failed channel can keep voting undetected, so the scheme relies on strong online diagnostics to make hidden failures visible enough to route around.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Profibus DP vs PA  •  Profinet IRT vs RT  •  GSD / GSDML file  •  EtherCAT distributed clocks  •  EtherCAT Hot Connect  •  CANopen object dictionary  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →