Reference implementation · Piper Alpha, 6 July 1988
Permit Equipment Sandbox
Piper Alpha's last day shift, run on two permit systems at once. One files permits by where the equipment sits, like the platform's paper rack. The other files every record under the equipment it touches, running on PostgreSQL inside your browser. That second system is the data model from Your Permit System Files Documents. The Hazard Sits on the Equipment.
How to use this page
- Follow the three steps in the guided run. Press the orange button in each.
- Watch the two tablets below it. Both hold the same permits. They file them differently.
- At the end, write your own permits at the permit desk and release isolations again.
"Start again" at the bottom puts everything back to the beginning.
Loading the records…
Can the night supervisor see the missing valve?
The situation
Piper Alpha is an oil and gas platform in the North Sea. Two identical pumps move condensate, a light liquid separated from the gas. Pump B runs. Pump A is the standby, and on this day it is out for maintenance, isolated so nobody can start it by accident.
You will run the day on two permit systems at once. System A works like the paper permit rack the platform used: each permit is a document, filed in a box for where the equipment sits. System B files every record under the equipment it touches.
-
Day shift. Two permits are written. One isolates Pump A for maintenance. The other removes Pump A's relief valve, PSV 504, and closes the open pipe with a blind flange, a solid cap bolted over the end.
-
18:00. The contractor hands the valve permit back. The job is not finished. The permit is suspended.
-
21:45. Pump B trips. The plant is heading for shutdown. You are the night supervisor and you want Pump A back. On each tablet below, Pump A is already open on the equipment screen. Press Release isolation on System A first, then on System B.
Waiting for you to press both buttons.
Same two permits, same day. System A could not show the removed valve on the Pump A screen, so the isolation was released. System B showed it, because every record is filed under the equipment it touches. The 18:00 suspension is not the only reason: even before it, the valve permit sat in the C Module box, not Pump A's. Try it at the permit desk: write both permits, skip the suspension, and release again. The inquiry found the lead operator intended to bring Pump A back and, probably, did not know the valve was off. It did not establish what he pressed. This page stops at the decision.
System A · filed by location (the paper rack)
A copy of the paper rack. Active permits sit in a box for the location of the equipment. Suspended permits go to the Safety Office, filed by trade. The equipment tag is typed on the form as free text, so nothing links PSV 504 to Pump A.
The rack
Equipment screen
For engineers: how this screen looks things up
System B · filed by equipment
Every record attaches to a piece of equipment. The equipment list knows what belongs to what: PSV 504 belongs to Pump A. Anything removed stays open until a later record closes it.
Records, by equipment
Equipment screen
For engineers: how this screen looks things up
Write your own permits
Every permit you write goes into both systems. Try the day again with a different order, or refit the valve before you release the isolation.