Engineering Resources • Worksheet

Alarm Rationalization Worksheet

Merobix Engineering •

A worksheet for teams doing alarm rationalization: deciding, alarm by alarm, what deserves to interrupt an operator and why. It is built on the alarm-management lifecycle concepts behind ISA-18.2, described here at a high level in our own words - the standard itself, available from ISA, is the authoritative reference.

Back to Resources

The core test: an alarm exists to tell an operator that an abnormal condition requires their action. If there is no operator action, it is a status indication or an event log entry - not an alarm. Most alarm floods are built one “might as well alarm it” decision at a time, and rationalization is how you unbuild them.

Where Rationalization Fits: the Lifecycle

ISA-18.2 describes alarm management as a lifecycle rather than a one-time project. Paraphrased at a high level, the activities are:

  1. Philosophy - the site-wide document that defines what alarms are for, the priority scheme, and the rules everything else follows. Write this first; the worksheet below assumes it exists.
  2. Identification - collecting candidate alarms from process hazard analyses, P&IDs, incident reviews, and operations input.
  3. Rationalization - the systematic review of each candidate against the philosophy: does it merit being an alarm, what is its priority, what is its setpoint. This worksheet supports this stage.
  4. Detailed design - configuring the rationalized alarms: setpoints, deadbands, delays, messages, and any advanced handling.
  5. Implementation - putting alarms into service, including testing and operator training.
  6. Operation and maintenance - the day-to-day life of the alarm system, including shelving practices and keeping instruments healthy.
  7. Monitoring and assessment - measuring alarm system performance (rates, floods, chattering alarms, standing alarms) against the philosophy’s targets.
  8. Management of change and audit - controlling changes to alarm configuration and periodically checking that practice still matches the philosophy.

Industry guidance documents publish target alarm rates and priority distributions. We deliberately do not reproduce those numbers here - take them from your alarm philosophy, which should cite its own sources.

The Worksheet Fields

One row per alarm. The fields below are the working core of a rationalization record; many sites add columns for classification, testing requirements, and references.

FieldWhat to record
Tag / alarm IDThe instrument tag and alarm identifier, e.g. LT-1201 LAH.
Alarm descriptionPlain-language statement of the abnormal condition being annunciated.
PurposeWhy this alarm exists: the specific abnormal condition it detects and why the operator must know.
Probable causesThe realistic causes an operator should consider when it activates.
Consequence of inactionWhat happens if nobody acts - to safety, environment, equipment, and production. Be concrete.
Operator actionThe specific corrective action expected. If the team cannot name one, the candidate fails the core test.
Time available to respondHow long the operator has before the consequence occurs. Site-specific: it depends on vessel sizes, flow rates, and process dynamics.
Priority and basisThe assigned priority and the reasoning, derived from consequence severity and time to respond per your alarm philosophy - never from gut feel in the meeting.
Setpoint and basisThe alarm limit and why: enough margin below any trip to allow response, far enough from normal operation to avoid nuisance activations.
Advanced handling flagsCandidate for state-based suppression, flood suppression grouping, on/off delay, deadband tuning, or shelving rules.

Worked Example

A generic three-phase separator high level alarm, filled in the way a rationalization team might record it. Values marked site-specific must come from your process, not from this page.

FieldExample entry
Tag / alarm IDLT-1201 LAH (separator liquid level high)
Alarm descriptionSeparator liquid level above the high operating limit
PurposeWarn of rising liquid level early enough to prevent liquid carryover into the gas outlet and to avoid the high-high shutdown trip
Probable causesDump valve failed closed or plugged, downstream blockage, inflow slugging, level controller failure
Consequence of inactionLevel continues to LSHH: unit shutdown and deferred production; possible liquid carryover damaging downstream compression
Operator actionVerify dump valve operation and dump line flow; operate the manual bypass if safe; dispatch a technician if the valve has failed
Time available to respondSite-specific - calculated from vessel holdup between LAH and LSHH at maximum expected inflow
Priority and basisAssigned from the philosophy’s severity-versus-response-time matrix; the equipment-damage consequence typically places it above a purely economic alarm
Setpoint and basisAbove the normal operating band and wave action, below LSHH by enough margin for the response above; site-specific
Advanced handling flagsState-based suppression when the well or inlet is shut in; deadband tuned to prevent chattering from surface movement

Blank Template

Copy this table into a spreadsheet and add one row per alarm. Rationalization is a team exercise - at minimum operations, process engineering, and controls should be in the room.

Tag / IDDescriptionPurposeCausesConsequence of inactionOperator actionTime to respondPriority + basisSetpoint + basisAdvanced handling
          
          
          

Practical Rules That Keep Sessions Honest

Sources & Standards

Primary references for alarm management - this page paraphrases concepts and does not reproduce the text of any standard:

After the Worksheet

The worksheet works with any control system. When the rationalized alarm list is ready, Merobix can be the place where those priorities, setpoints, and notifications actually live.