Entry & progression
In an unattended machinery space, the alarm system is your watchkeeper. A chief who does not know exactly what it will and will not tell him has delegated the watch to something he does not understand.
Periodically unattended machinery space operation is the normal condition on most modern vessels, including large yachts. The space is monitored rather than manned. A duty engineer is on call, a bridge alarm repeats machinery faults to the watch officer, and an engineer's-call system escalates if the duty engineer does not answer. MO72 recognises this: service on call in periodically unattended machinery spaces can count as qualifying watchkeeping time.
Control loops, briefly
Most shipboard control is proportional-integral-derivative. Proportional action responds to the size of the error, integral action removes the residual offset over time, and derivative action responds to the rate of change. When a loop hunts - oscillates about setpoint - it is usually over-gained, or the sensor is noisy. When a loop takes forever to settle after a large disturbance, suspect integral windup: the integral term saturated while the actuator sat at its limit, and must now unwind before anything happens. Cascade loops - a slow master trimming a fast slave, as in fuel temperature control - reject disturbances far better than a single loop, but they fail in more interesting ways.
WARNING — Sensors lie, and control systems believe them A control system acting on a failed sensor will drive the plant confidently into the very fault it exists to prevent. Cross-check a critical reading against a second, independent indication before you act on it. The gauge that agrees with the alarm is worth more than the alarm.
Alarm management - the failure nobody plans for
The most dangerous condition of an alarm system is not silence. It is flood. When a single fault cascades two hundred alarms into a panel, the one alarm that mattered is invisible. And the day-to-day version is worse: standing alarms that nobody can clear get inhibited, inhibited alarms get forgotten, and six months later the plant is running with its most important protection switched off and nobody aboard remembers doing it.
- Keep an inhibited and suppressed alarm register. Every inhibition written down, with the reason, the person, and a date to restore.
- Review it - at least monthly, with the first engineer, and at every handover.
- Nothing is inhibited to make the panel quiet. An alarm that is always on is either a real fault or a badly set point. Fix one or the other.
- Rationalise the setpoints. An alarm that gives no time to act is not an alarm; it is a notification of failure.
- Test the safety trips and shutdowns on a schedule, and record it. A shutdown that has never been proved is a hope.
The automation you must be able to prove
Blackout recovery: emergency generator start, standby generator auto-start and synchronisation, sequential restart of essential consumers, preferential trip or load shedding of non-essential loads. These schemes are elaborate, they are rarely used, and they are exactly the ones that fail when finally called upon. Test them when you can afford to fail - alongside, in daylight, with the department awake - not at 0300 off a lee shore.