Displays for startup, shutdown and abnormal events
Graphics are designed for the ninety percent of time the plant runs normally, and used most intensively during the other ten.
Process displays are drawn to support steady-state monitoring. The operator's workload, however, is concentrated in transitions: startup, shutdown, grade changes, equipment changeovers and upsets.
During those periods the operator needs a different set of information, arranged differently, and is usually served by the same screens with the same layout.
What changes during a transition
In steady state the question is whether anything has deviated. During a startup the questions are sequential: what is the current step, what conditions must be satisfied before the next one, and what is blocking.
Activity records on support workstations can complement access logs when accountability requirements are clear. Further details are available through this reference.
Additional industry context is available in the ISA-101 HMI standards.
A standard graphic answers the first kind of question and answers the second badly, because the permissive conditions for a step are scattered across several displays and have to be assembled mentally.
Sequence displays
A purpose-built startup or shutdown display presents the sequence explicitly: the steps in order, the current position, and for the current step the conditions that must be met with their present state.
Where the sequence is automated, this is a view onto the sequence logic. Where it is manual, it is an operational checklist with live values attached, which is considerably more useful than a paper procedure and a separate screen.
The most valuable element is the blocking indication: when the sequence cannot proceed, what specifically is preventing it. Operators frequently spend a long time determining that, and the information exists in the logic.
A permissive display that lists all conditions with green and red indicators answers the question in one glance. A message saying the step cannot start does not.
Displays for characteristic upsets
Most units have a small number of upsets that recur: a compressor trip, a feed loss, a cooling water failure. Each has a known response and a known set of relevant variables.
A display built for that scenario — the relevant measurements, the relevant equipment states, the relevant trends, and the response procedure — collects in one place what an operator currently assembles from three screens under time pressure.
These are not expensive to build. The barrier is usually that nobody has listed the characteristic upsets, which is itself a useful exercise and frequently already exists in the process hazard analysis.
Equipment out of service
Displays generally assume equipment is available. When a unit is deliberately down, the display shows a great deal of information about a system that is not running, and the operator's attention is elsewhere.
Indicating out-of-service state clearly on the display — greyed equipment, an explicit state indication — prevents the situation where an operator misreads a stopped pump as a tripped pump, and it pairs naturally with state-based alarm suppression.
Degraded and failure modes
The display should make it obvious when the information it is showing cannot be trusted: a communication failure to a controller, a bad-quality measurement, a stale value that has not updated.
The common failure is that a lost value continues to display its last known number, indistinguishable from a live one. An operator making a decision on a value that stopped updating ninety seconds ago has no way to know.
Explicit indication of bad quality and stale data is a small configuration matter with a substantial safety consequence, and it is frequently absent because the default behaviour was never examined.
Practising on them
Displays built for rare events are used rarely, which means operators are unfamiliar with them at exactly the moment they matter.
Including them in simulator training and in routine drills is what converts a well-built abnormal-operation display from a good idea into an operational aid. Where a simulator exists, this is straightforward; where one does not, walking through the display during a quiet shift is a reasonable substitute.
Building the scenario list
Purpose-built abnormal displays require knowing which scenarios to build for, and the list usually already exists in a form nobody has connected to display design.
Process hazard analyses, incident records, near-miss reports and operator experience all contain the characteristic upsets. Compiling them produces a ranked list, and the top few justify a dedicated display.
Ranking by frequency and by consequence together is the right basis: a rare event with severe consequences deserves a display as much as a frequent nuisance.
What the operator needs during the first two minutes
Abnormal event response has phases, and the display requirements differ. In the first moments the question is diagnostic: what has happened and how far has it propagated. Later it becomes procedural: what are the steps and what is their status.
A display that serves both puts the diagnostic information — the key measurements, the equipment states, the trends spanning the onset — prominently, with the procedure available alongside rather than replacing it.
Keeping them current
Abnormal-operation displays reference specific equipment and specific procedures, both of which change. A display built for a scenario five years ago may reference a pump that has been replaced or a procedure that has been revised.
Including them in the change process is necessary, and so is periodic review against the current procedures, because procedure revisions frequently happen without anyone considering the display that mirrors them.
Consistency with the written procedure
Where a display exists for a scenario and a written procedure also exists, the two must agree: the same steps, in the same order, with the same terminology.
Divergence between them creates a specific hazard. An operator following the display and a supervisor following the procedure can reach different conclusions about what has been done.
Building the display from the procedure, and updating both together as a single change, is the mechanism. It also tends to improve the procedure, because the process of representing it graphically exposes steps that are ambiguous.
Escalation information on the display
During an abnormal event the operator may need to involve others: the shift supervisor, a specialist, an emergency response team.
Including who to contact and how, on the display for that scenario, removes a search at a moment when it is expensive. It is a small addition and it is the sort of thing that is obvious in the control room and absent from the design.