When to use: Deciding which candidate PLC/SCADA conditions actually qualify as alarms per ISA-18.2, and classifying each into Critical/High/Low priority based on consequence and required response time. Add each candidate condition and answer three questions to get its classification.
ISA-18.2 (Management of Alarm Systems for the Process Industries) defines rationalization as the stage where every candidate PLC/SCADA condition is evaluated against one question: does it require a timely operator response to avoid a consequence? This tool walks that decision for each candidate condition and assigns Critical/High/Low priority based on consequence severity and required response time — the same logic a formal alarm philosophy document specifies.
The single most common failure mode in alarm system design is treating every status change as alarm-worthy because it's easy to wire an alarm to a bit. A condition that does not require a timely operator response to avoid a consequence is not an alarm — it's a status indication or event log entry. It can still appear on the SCADA screen, but without an audible tone, and without counting against the line's alarm rate. Over-alarming is what turns a SCADA system into noise an operator learns to ignore within months of startup.
A priority level that isn't tied to an actual required response time is just a color, not a management tool. Critical priority is reserved for conditions with immediate safety, equipment-damage, or total-stoppage consequences if not addressed within roughly one minute. High priority covers conditions with a real production or quality consequence on a response horizon of a few minutes. Low priority covers conditions worth flagging but tolerant of a longer response — often a pre-alarm giving advance warning before a higher-priority alarm would fire.
ISA-18.2, "Management of Alarm Systems for the Process Industries," is the standard governing the full alarm lifecycle — philosophy, identification, rationalization, detailed design, implementation, operation, maintenance, and management of change. Rationalization is the stage that decides which candidate conditions actually become alarms and at what priority.
ISA-18.2 typically works with three to four priority levels. For a smaller system, three levels (Critical, High, Low) is usually sufficient and keeps the operator's mental model simple — more levels only add value on larger, more complex systems with a genuinely wider range of consequence severities.
ISA-18.2 defines an alarm flood as more than roughly 10 alarms in a 10-minute window per operator position. A single root-cause fault (like an upstream jam) can cascade into several downstream alarms without flood-prevention logic like consequence suppression, which is why rationalization and flood prevention are closely related design steps.
Try our SCADA Studio
More calculators, simulators, and guides for this discipline.
PLC Programming, Wiring, Process Control & Instrumentation — Illustrated Guide (Full Access)
✨ Premium ContentA zoomable interactive reader — free preview, then unlock the full set.