Process Safety · Lesson 8 · 7 min read
Startup Is a Controlled Operation, Not a Routine Return

Startup places equipment, safeguards and people in changing conditions. Learn why readiness must be proved, deviations must be acted on early, and production pressure must never replace the approved startup sequence.
Startup changes the risk picture
A process startup is not simply normal operation at a lower rate. Equipment is moving through changing pressure, temperature, level, composition and flow conditions. Utilities and control loops may be entering service in sequence; inventories are being introduced; temporary maintenance arrangements may have been removed; and alarms, trips and relief paths may face demands that do not occur during stable production. The team must therefore manage startup as a distinct operating phase with its own hazards, hold points and decision criteria.
OSHA's Process Safety Management standard requires written operating procedures that address initial startup, normal startup, temporary operations, emergency shutdown, normal shutdown and startup following a turnaround or emergency shutdown. It also requires procedures to identify operating limits, consequences of deviation and the steps needed to correct or avoid deviation. The practical message is that safe startup depends on an approved sequence and defined responses—not on memory, familiarity or confidence.
Readiness must be demonstrated before introducing hazard
Before hydrocarbons or other hazardous inventories are introduced, the team should establish that the plant matches the intended configuration. Confirm completion and handback of work, correct valve line-up, removal or control of temporary equipment, availability of utilities, clear drainage and vent routes, and the required status of alarms, trips, shutdown valves, relief systems, fire and gas protection, communications and emergency arrangements. The exact checklist and acceptance criteria must come from the installation's approved procedures.
Outstanding defects, inhibited safeguards and incomplete actions need explicit review by authorised personnel. Their combined effect matters: an instrument awaiting repair, a restricted flare route and an unavailable trip may each appear manageable alone but create a different risk together. If the technical basis or required compensating measures cannot be confirmed, escalation is the control. A target startup time is not evidence of readiness.
Hypothetical example: an unexpected level response
Consider a hypothetical offshore separator returning to service after maintenance. During controlled introduction of feed, the indicated level rises more slowly than expected while the inlet flow response appears normal. Because production is waiting, someone suggests continuing to the next step and allowing the level to settle once the unit is fully online.
This is an illustrative scenario, not a documented incident. The mismatch is new information. It could reflect process behaviour, an incorrect line-up, trapped inventory, a measurement problem or another cause that has not yet been established. Continuing would add inventory while the team is uncertain whether it can see and control the actual condition.
The disciplined response is to hold or stop at the approved safe point, stabilise the process, verify field and control-room indications, check the line-up and follow the site's troubleshooting and escalation process. The next procedural step is not due merely because the clock says it is. It becomes due when the specified conditions and confirmations are satisfied.
Use hold points as decisions, not paperwork
A well-designed startup procedure creates deliberate pauses before important transitions: introducing inventory, lighting equipment, pressurising a system, opening an export path, placing a controller in automatic or increasing throughput. At each hold point, the responsible team confirms that prerequisites are met and that the process response agrees with expectations. Recording a tick without examining the evidence defeats the purpose.
Trend direction and rate of change are often as important as the current value. A parameter may still be inside its limit while moving rapidly toward it. Operators should compare the observed response with the procedure, process knowledge and independent indications where required. If values disagree, alarms occur unexpectedly, manual intervention becomes excessive or the sequence departs from the approved plan, pause and reassess rather than normalising the difference.
Protect attention, authority and communication
Startup concentrates tasks and decisions. The control room may be handling changing alarms, field confirmations, permits, communications and requests from several disciplines. Define who directs the startup, who operates each system, who verifies critical steps and who has authority to hold or stop. Keep non-essential work and communication away from the operating team during critical phases, consistent with site arrangements.
Handover during startup requires particular care because the process condition, completed steps, inhibited safeguards, outstanding checks and immediate next actions are all changing. If a shift change cannot be avoided, use a structured handover and confirm shared understanding before continuing. The incoming team should know the current plant condition—not merely the intended destination. Fatigue, staffing and competence also require active review before and during a demanding startup.
A documented incident shows why startup governance matters
The U.S. Chemical Safety Board reported that the 23 March 2005 Texas City refinery explosions occurred during restart of a hydrocarbon isomerisation unit after a distillation tower flooded and was overpressurised. Fifteen people were killed and 180 were injured. This article does not use that event as the hypothetical example above; it is a documented investigation cited for learning.
Among its resulting recommendations, the CSB called for malfunctioning process equipment to be repaired before unit startups, additional board-operator staffing during startups, knowledgeable supervision during especially hazardous operating phases, and startup procedures updated to reflect actual process conditions. These recommendations reinforce a broad lesson: startup safety is supported by functioning equipment, realistic procedures, sufficient competent people and organisational willingness to stop when reality differs from the plan.
Three practical actions for today's shift
First, before the next startup, confirm that the approved readiness review addresses actual field configuration, open work, temporary arrangements, impaired safeguards and the status of essential utilities. Second, identify the procedure's critical hold points and agree who verifies each one, what evidence is required and which deviations demand a pause or escalation. Third, during startup, compare expected and actual process response continuously; if they differ, stabilise or stop at the approved safe point and follow the site's authorised troubleshooting process.
Discussion question: At which step in our next startup could schedule pressure most easily encourage us to continue without fully understanding an unexpected response—and what hold point protects us?
This article provides general process-safety learning. Startup preparation, authorisation, sequencing, operating limits, staffing, troubleshooting and escalation must follow the installation's approved procedures and competent technical direction.
Sources
- OSHA — 29 CFR 1910.119(f): Operating proceduresPublished Accessed 20 September 2026
- U.S. CSB — BP America Texas City Refinery ExplosionPublished Final report released 20 March 2007; accessed 20 September 2026
Daily HSSE updates
Subscribe for practical HSSE updates.
Subscribe for the daily message, selected HSSE news and occasional new-resource alerts from Worksite Safety Hub.