The short answer
The Lift Station That Overflowed With Everything Working
Lift stations overflow with everything working when the design assumes each part will be watched: an alarm that reaches a screen nobody is looking at, a backup float circuit that was never tested, a level band that leaves no time between the high alarm and the overflow, a communication alarm with the same priority as a door switch, and a callout roster with a number that changed. Each part performed; the system had no path from a rising wet well to a person with time to act.
Key points
- An alarm is not a response; the design has to name the person, the path, and the time they have.
- Backup circuits and callouts that are never tested do not exist.
- Level bands must leave response time between the high alarm and the overflow, in minutes, calculated from inflow.
- A communication loss at a critical station is an urgent alarm, not a nuisance.
- Storm mode, generator mode, and the second path are for the night this happens, and they are designed in daylight.
What follows is a composite. No single station did all of this, but every part of it has happened somewhere, and the stations it happened at were not badly built. They had modern controllers, telemetry, generators, and backup floats. They overflowed anyway, and the investigation afterward found nothing broken. That is the point: the failure was in the spaces between the parts.
The night
Rain begins in the evening. By ten the inflow to a duplex station has doubled, and the level control does what it should: the lead pump runs longer each cycle, then the lag pump joins it. At eleven a power blink trips the utility feed for a few seconds, the transfer switch moves to the generator, and both pumps, called by the high level, start on the same second. The generator breaker trips on the inrush. The station is now on neither source. The controller, on its UPS, raises a power failure alarm and a high level alarm and sends both to SCADA over the radio.
At the plant, the alarms arrive on the screen. The operator on shift is in the headworks building dealing with the same storm. The alarm callout system dials the on-call phone for the power failure, a high priority alarm, and reaches a number that belonged to an operator who left in the spring. The high level alarm is configured at the same priority as the power failure; it dials the same number. Twenty minutes later the wet well is at the high float. The backup float circuit, which would run the pumps on floats if the controller were dead, does nothing, because the controller is not dead and the circuit only takes over when the controller watchdog drops. There is no power to run the pumps anyway. At midnight the station overflows into a creek.
What worked
- The level control staged the pumps correctly.
- The transfer switch transferred.
- The controller stayed up on its UPS and generated every alarm it was designed to.
- The radio delivered every alarm.
- The callout system dialed the configured number.
- The backup float circuit was healthy and would have run the pumps if the controller had faulted and power had been present.
What did not exist
- A staggered start on generator
- The design allowed both pumps to start on the same scan when power returned. A few seconds of delay between them, or a rule that only the lead starts on the first scan after a transfer, keeps a generator that carries two pumps running from tripping on two starts.
- A generator sized and tested for the worst case
- The generator was sized for the running load and tested monthly with no load. A test under the actual start sequence would have tripped it in daylight.
- A callout roster that was maintained
- The roster had a number that nobody updated when an operator left, and no escalation to a second person when the first did not acknowledge.
- Priorities that meant something
- Power failure at a station with a generator is a high alarm; high level at a station with no power is urgent. Configured at the same priority, they dialed the same dead number in the same way.
- Response time in the level bands
- The high alarm sat a foot below the overflow. At the storm inflow, that foot was fifteen minutes. The band was set from the well geometry years earlier without asking how long it would give.
- A second path
- When the radio alarm reached a phone nobody answered, there was nothing else: no dialer at the site, no text message to a second person, no alarm on a screen someone was watching.
- A backup that covers this case
- The backup circuit covered a dead controller. It did not cover a live controller with no power, and nothing did.
The chain
Each item above is a small decision, and each was defensible when it was made. Together they form a chain: a design that assumed power would be there or the generator would carry it, an alarm system that assumed a person would answer, and a level band that assumed time. Break any link and the station does not overflow. The generator carries the load; or the operator is reached; or the high alarm comes early enough for a visit; or a second path reaches a second person. Reliability at a lift station is not the reliability of the parts. It is the number of independent ways the wet well can reach a person with time to act.
Breaking the chain
- 1
Calculate the response time
For each station, the volume between the high alarm and the overflow divided by the design storm inflow, in minutes. If it is less than the time it takes to get someone to the site, lower the high alarm or raise the overflow margin, and write the number on the drawing.
- 2
Stagger every start
On any return of power and on every transfer, one pump at a time with a delay, and on generator power the number of pumps allowed to start together limited to what the generator has been tested to carry.
- 3
Test the generator under the real sequence
A monthly test is a load test with the pumps started the way the controller starts them. A generator that trips in the test is fixed in the test.
- 4
Make the callout a maintained system
A roster that is reviewed when anyone leaves, an escalation to a second and third person, an acknowledgment that stops the escalation, and a monthly test call to every number on it.
- 5
Rationalize the priorities
High level at a station with no power, both pumps failed, and communication loss at a critical station are urgent. Everything else is lower. The urgent ones wake people and escalate; nothing else does.
- 6
Add a second path at critical stations
A cellular text alert from the site controller, an autodialer on the high float, or a second radio path, so that one dead phone number cannot be the whole story.
- 7
Cover the no-power case
A portable generator plan with a receptacle and a person who can be there within the response time; or a permanent generator tested under load; or storage that buys the time.
- 8
Test the backup circuit for the case it covers
Fault the controller with power present and watch the floats run the pumps. Then write down the cases it does not cover, so nobody assumes it does.
Afterward
The investigation at a station like this finds nothing broken, and the temptation is to call it an act of weather and move on. The better outcome is a list like the one above, worked through at every station in the system, because the same chain exists everywhere the same design habits were used. The overflow that gets reported is the one that teaches; the ones that do not happen afterward are the ones that were designed out.
Frequently asked questions
- Would a triplex station have prevented it?
- Not with no power. A third pump helps when the pumps are the limit; here the limit was the generator and the callout. Redundancy in the pumps does nothing for a failure in the path to a person.
- Is a cellular text alert reliable enough to count as a second path?
- As a second path, yes: it is independent of the radio and the plant callout system, and independence is what a second path is for. As the only path, no, for the same reason a radio alone is not.
- How much response time is enough?
- The time it takes to get a person and a portable pump or generator to the site at night in bad weather, plus margin; often thirty to sixty minutes. If the wet well cannot provide it at storm inflow, the station needs storage, a permanent generator, or a lower high alarm with a different response.
- Who owns the callout roster?
- Someone named, with the roster on a review schedule and a test call procedure. A roster nobody owns is a list of numbers that used to work.
Related topics
- Lift Station High LevelThe alarm that stands between a lift station and an overflow: where the high-level float goes, what it must do on its own, how much response time the well provides, and how to diagnose a high level that should not be happening.
- Lift Station Generator OperationStandby power at a lift station: what the transfer switch does, how the controls ride through the transfer, staggered pump restarts, what SCADA should see, load testing, and the portable generator connection.
- Lift Station Backup ControlHow a lift station keeps pumping when the transmitter, the PLC, or the SCADA link is gone: float backup logic, the control transfer relay, redundant-off protection, and how to test it with the controller actually dead.
- Lift Station SCADAGetting a remote station onto the SCADA system and keeping it there: which signals to bring back and which controls to allow, the telemetry path from licensed radio to cellular to fiber, and the maintenance that keeps the link up.
- Alarm Notification and CalloutGetting the alarm to the person on call when no one is watching the screen: notification paths, escalation, acknowledgment from the field, which alarms qualify, and the failure modes that leave a station in high level with nobody paged.
- Alarm PriorityHow to assign alarm priorities that operators trust: a consequence-and-time matrix, three or four levels, the target distribution from ISA-18.2 and EEMUA 191, and the mistakes that make every alarm high.
Direct contact
Have a controls question?
Reach Eric Sullivan directly about anything on this site, a controls or automation topic, or one of his personal projects.