Solutions
Level Alarms

Level Alarm Design: High-High, Low-Low and Interlocks

2026-08-09

Technical guide by Arvin, METRAVON Instruments · Reviewed September 2026

Short answer

A level alarm is a protective function, not merely a sensor that touches material. A high-high alarm must trip early enough to stop the incoming flow before overflow. A low-low alarm must account for hopper geometry, bridging, rat-holing and the material that remains below the sensing point. For consequential trips, evaluate an independent point-level switch in addition to continuous level measurement, and define what the system does after loss of power, broken wiring, buildup or mechanical damage.

Define the alarm function before choosing hardware

FunctionDesign questionTypical action
High levelIs this an operating warning or a capacity limit?Notify the operator or reduce filling rate
High-high levelHow much material enters after the stop command?Stop conveyor, close valve or block a new filling cycle
Low levelDoes the process need replenishment warning?Request refill or change the production plan
Low-low levelWhat equipment is damaged by starvation or dry running?Stop pump, feeder or downstream equipment
Chute blockageCan buildup be distinguished from real blockage?Stop upstream equipment and alarm locally

Calculate trip position from the process response, not from a convenient nozzle. For high-high protection, include maximum inflow, transport delay, valve or conveyor stopping time and material already in transit. For low-low protection, include minimum usable inventory, discharge behavior and the time required for the operator or control system to respond.

Select the sensing principle for the material

Rotary paddle, vibrating rod, tuning fork, capacitance and RF admittance level switches each respond differently to particle size, density, adhesion, moisture, electrical properties and flow impact. No single principle covers every powder, granule and liquid. A device that works in dry pellets may be unreliable in sticky powder, conductive coating or a high-vibration chute.

Check wetted materials, probe geometry, process temperature and pressure, ingress protection, hazardous-area approval, mechanical loading, cleaning access and the required electrical output. Install the switch outside the direct filling stream and protect it from avoidable impact. A side-mounted switch provides a clear alarm elevation, but vessel strength, sealing and material side load must be checked.

Continuous measurement and independent switches

Continuous level instruments are useful for trends, operating alarms and early warning. An independent point-level switch can reduce common-cause risk because it uses a separate location, technology or signal path. Whether independence or redundancy is required depends on the consequence analysis and applicable plant standards.

A standard process level switch is not automatically a safety instrumented function. Where a failure could cause injury, major equipment damage or environmental harm, the project safety lifecycle must define the target integrity, device suitability, proof-test interval, voting, diagnostics and bypass management.

Fail-safe logic and alarm management

  • Separate process alarm, instrument fault and communication fault; do not show all three as the same message.
  • Choose normally energized or de-energized logic so loss of power or wiring can be detected in the complete loop.
  • Use a short, justified delay to reject splashing, moving material or vibration, but keep the delay within the process safety margin.
  • Define latching, reset, acknowledgement and restart conditions. Acknowledgement should not remove the hazardous condition.
  • Control bypass access, display active bypasses and provide an alternative protective measure while a trip is inhibited.
  • Document the cause-and-effect matrix so field wiring, PLC logic, HMI messages and equipment actions agree.

Commissioning and proof checks

  1. Confirm the tag, alarm elevation, orientation, mechanical protection, process seal and cable entry.
  2. Trigger the sensing element with the real material where practicable, or use an agreed equivalent method.
  3. Verify the local indication, relay or transistor output, PLC input, HMI message and final equipment action.
  4. Measure the total time from process detection to stopped material flow, including material already in transit.
  5. Simulate open circuit, short circuit where supported, loss of power and communication failure.
  6. Record the test method, result, bypass status, reset behavior and next periodic test date.

Information required for selection

Provide the material and adhesion tendency, alarm purpose, required trip elevation, maximum filling or discharge rate, vessel drawing, preferred mounting direction, temperature and pressure, hazardous-area classification, power supply, output type, PLC input arrangement, required fail-safe state and the consequence of a missed or false trip.

Frequently asked questions

Can one continuous level meter provide the high-high trip?

It may be acceptable for ordinary process control, but a critical trip should be assessed for independence. One failure should not remove both the level indication and the final protective alarm without the risk being understood.

Will material buildup cause a false alarm?

It can. Review the material's adhesion and electrical properties, choose an appropriate principle and sensitivity, and include realistic material exposure and cleaning requirements in the acceptance test.

Should every alarm have a delay?

No. Apply only enough delay to reject known transient conditions. The maximum permissible delay comes from the process response time and the remaining capacity above or below the trip point.

Should the output be normally open or normally closed?

There is no universal answer. Design the entire loop so loss of power and broken wiring are detectable and the plant moves to the defined safe or controlled state.

From process consequence to alarm setpoint

Start with the consequence, not the preferred switch. For a high-high alarm, calculate the usable volume above the sensing point and compare it with the maximum incoming flow after the stop command. Include valve closing time, conveyor run-down, material already in a pipe and the time required for logic and actuator response. The setpoint must provide margin for the worst credible combination, not only the normal operating rate. For a low-low alarm, consider the product remaining in the outlet cone, suction line or feeder and the minimum quantity needed to avoid cavitation, loss of seal or dry running.

Document normal operating band, operator alarm, trip point, reset point and permitted delays. Closely spaced points can chatter when the surface moves or the product sloshes. Excessive deadband or delay, however, consumes the safety margin. Where the process has variable rates, verify the design at the maximum rate or use a dynamic calculation that has been independently assessed.

Independence and proof-test design

An alarm displayed by the control system is not automatically an independent protective layer. Review whether the sensing element, power supply, input card, logic solver and final element share failures with normal control. If the credited protection requires independence, use a separate sensor and suitable architecture. Define the de-energized state, diagnostics and treatment of bypasses. A normally energized relay can reveal loss of power, but only if the downstream logic distinguishes that state and the circuit is tested.

A proof test must reveal the dangerous failures claimed in the design. Activating a software bit proves little about a probe that may be coated or mechanically blocked. Whenever practicable, expose the sensing element to the real material and confirm the response through the PLC, annunciation and final shutdown device. If full testing is impossible, document the partial-test coverage and the additional inspection required. Record as-found condition before adjustment; otherwise a drifting device can be repeatedly corrected without its reliability being understood.

Alarm management in normal operation

Give every alarm a clear message, priority, operator response and time available to act. Shelving, suppression and maintenance bypasses need authorization and an expiry. Repeated alarms should trigger a review of process conditions, setpoint, installation and response rather than permanent suppression. Track standing alarms and the duration of bypasses because an installed switch provides no protection while intentionally defeated.

After a trip, preserve the sequence of events with synchronized timestamps. The record should show process value, switch state, controller decision and final-element feedback. This distinguishes late detection from slow valve closure, logic delay or continued material flow. Review incidents and near misses against the original timing calculation, then update the setpoint or hardware only through controlled change management.

Acceptance evidence for handover

The handover package should contain the cause-and-effect matrix, datasheet, installation drawing, wiring diagram, setpoint calculation, device configuration, test method and signed results. Identify the product and conditions used during the test. Confirm alarm text, priority, horn or beacon, remote notification, trip, reset and restart permissions. The accepted baseline becomes the reference for maintenance and prevents later ambiguity about whether a changed setpoint remains safe.

Common-cause and environmental checks

Inspect conditions that can defeat several channels together: one blocked impulse path, common power loss, a frozen PLC scan, shared cable damage or product buildup affecting adjacent probes. Where redundancy is claimed, verify physical and functional separation rather than counting devices. Check ambient temperature, vibration, condensation, washdown and electromagnetic interference against the installed enclosure and cable system.

Changes in product grade, density, coating tendency or filling method can alter switch response even though the hardware is unchanged. Include process change review in the alarm lifecycle and repeat a representative functional test before crediting the protection for the new duty.

Record bypass duration, compensating measures and the person authorizing return to normal service.

Engineering note: Final alarm architecture must follow the site's process hazard assessment, electrical standards and approved cause-and-effect documents.

Continue your project research: Review our level alarm solutions. For a model-specific recommendation, send your medium, range, process and installation details to METRAVON.

Related Product Categories

Browse product categories to quickly find a measurement solution suited to your application.

View All Products
Level MeasurementLevel SwitchesIndustrial WeighingWater Level & FlowData Acquisition

Get a Project Quote

Tell us the medium, measuring range, process conditions, mounting method, output signal and estimated quantity. We will recommend a suitable configuration and provide a quotation.