Entry & progression
An alarm system that cries constantly is an alarm system that has been switched off — in the only place that matters, which is the watchkeeper's head. Alarm management is a safety function, and on most vessels it is nobody's job. Make it yours.
The purpose of an alarm is to tell a human being that they must act, and to tell them in time to act. That is the whole specification. Everything that does not meet it — the status message, the nuisance repeat, the alarm on a machine that has been off for a year — is not an alarm. It is noise sitting in the channel that a real alarm needs.
What a good alarm is
- Relevant — something has changed that a person must do something about
- Unique — one condition, one alarm, not eleven alarms from one condition
- Timely — early enough to act, late enough not to be a routine event
- Prioritised — the operator can tell in one second which of the twenty on the screen matters
- Actionable — there is a response, and the operator knows what it is
Alarm flood
A single root event — a generator trip, a lost sensor bus — can put a hundred alarms on the screen in ten seconds. Every one is true. Together they are useless, because the operator is now reading a list instead of solving a problem, and the one alarm that names the cause is somewhere on page three.
Mitigation is engineering, not discipline: suppress the consequential alarms when their known cause is present, group by system, and design the priority levels so that a flood still surfaces the root event at the top.
The inhibit
Every alarm system can inhibit — suppress, bypass, shelve, override. The names differ; the function is identical: this alarm will no longer tell you anything.
Inhibits are legitimate. A machine under maintenance, a failed sensor awaiting a spare, a commissioning test — all real reasons. The danger is never the inhibit. The danger is the inhibit nobody wrote down.
WARNING — The inhibited alarm nobody recorded is the one that will hurt you It was inhibited for a good reason, by a competent person, on a Tuesday, during a job that finished. The person left the vessel. The reason left with them. The inhibit stayed.
Now there is a protection function on your vessel that does not exist, and there is no record that it does not exist, and the plant looks completely normal — right up until the moment the alarm you no longer have was the one you needed.
The inhibit discipline
- Log it — what, why, who, when, and the condition for removal.
- Make it visible — a standing register the watchkeeper actually sees, not a note in a drawer.
- Bound it — an inhibit has an expiry, and expiry means a review, not an automatic renewal.
- Compensate — if the alarm is gone, what replaces it? A manual check, a round, a temporary gauge. Say what it is.
- Remove it — and prove the alarm works again by testing it, not by assuming the removal worked.
The handover
An ETO who leaves the vessel takes the plant's undocumented state with them. Every inhibit, every temporary jumper, every parameter changed at 0300 to get through a night and never changed back — if it is only in your head, it is about to be nowhere.
Write it down. Not for the audit, and not for your successor's convenience. For the person standing in front of a switchboard at some future 0300, trusting a system that you know is quietly lying, and who has no way to know that you know.