8. Interlocks (SIS)¶
A safety instrumented system trips the plant when the operator and the controllers have failed to keep it inside limits. The OTS has an interlock engine: trip logic with conditions, a delay, latching, actions that override everything while tripped, bypass, reset and a first-out record. The trainee sees it as a status window; the instructor edits it.
What you will learn
- Writing an interlock: conditions, logic, delay, latching, actions
- What the engine does while a trip holds
- Reset, forced reset, bypass and manual trip
- Reading the first-out and the journal
Prerequisites
- Page 7: you know which alarms the plant raises
The Interlocks window¶
Interlocks... on the Instructor Station opens it with the Configuration tab enabled; the same button on the operator panel and the screens opens it in operator mode (status only, no forced reset).

Configuration¶
| Field | Meaning |
|---|---|
| Name, Description | Shown in the status grid and the journal |
| Enabled | An interlock can be kept in the file and switched off |
| Latching (needs reset) | A latched trip stays tripped until reset; otherwise it clears when its conditions clear |
| Trip when: All / Any | Whether every condition or any condition must hold |
| for (s) | The conditions must hold this many simulated seconds before the trip (0 for immediate) |
| Conditions | Rows of Condition, Target, Property, Op, Value, Alarm |
| Actions | Rows of Action, Target, Property, Value |
Condition kinds:
- Compare: a property of a tag against a value, with
>,>=,<,<=,=,<>, in display units (PIT-001/Monitored Value>430) - Alarm active: a gauge's alarm level (
LL,L,H,HH) is active - Interlock tripped: another interlock (by name) is tripped, for cascaded trips
Action kinds:
| Action | While tripped |
|---|---|
| CloseValve, OpenValve | The valve is driven to 0 % or 100 % and its stem is locked, so controllers and the operator cannot move it |
| StopPump | Target speed is held at zero |
| ControllerToManual | The controller is put in manual with Value as its output (display units of the manipulated variable) |
| SetProperty | Property of Target is written with Value every step |
Actions are re-applied at the start of every step, after the controllers and the operator, so nothing undoes them until the trip is released. Save and apply stores the logic in the flowsheet (save the file afterwards) and loads it into the running session.
Status¶
The Status tab lists every interlock with its state (normal, conditions met, timing, TRIPPED, bypassed), the trip time, the first out (the condition that completed the trip, with its value) and the actions. Buttons:
- Reset: releases a latched trip. Refused while its conditions still hold; the refusal is journaled with the first-out.
- Force reset (instructor): releases it anyway. Not offered in operator mode.
- Bypass on/off: the logic keeps evaluating and journals what it would have done, but takes no action. Use it for maintenance scenarios: "the SIS is bypassed for the test; what does the operator do when the pressure rises?"
- Trip now (test): trips it by hand.
Everything is journaled in the Trip category: Interlock 'High pressure trip' TRIPPED (first out: PIT-001 HH active), resets with who did them, bypass on and off.
Write the sample trip¶
- Open Interlocks... on the Instructor Station, New, name
High pressure trip, latching on, All, for5s. - Condition: Alarm active, target
PIT-001, alarmHH. - Actions: CloseValve
FV-001; ControllerToManualPID-012, value100(the pressure valve fully open). - Save and apply, save the flowsheet.
Now repeat the exercise of page 7: take PID-012 to manual at 0 %. Five seconds after HH, the feed valve slams shut and stays shut whatever the operator does; the pressure controller is handed back with the vent open. The operator panel shows FV-001 0 % (stuck); the screens' Interlocks button turns red with Interlocks: 1 TRIPPED.
To recover, the trainee has to bring the pressure below HH (the vent is already open), open the status window and press Reset. The journal tells the story in three lines.
Interlocks in scenarios¶
- An Avoid objective on Interlock tripped scores "no trip" directly.
- The OPC UA server (page 9) publishes each interlock's tripped, bypassed and first-out, and accepts reset and bypass.
- Remote stations (page 10) see the same status and can reset and bypass; the instructor keeps the forced reset.
The next page adds trends and opens the plant to external clients.