An HMI alarm philosophy is a short controlled document that defines what an alarm is, how it is prioritised, how it is shown and who may change it. Write it before the screens are built: define alarm purpose, a consequence-based priority table, setpoint rules, suppression rules and review targets. It keeps operators from drowning in nuisance alarms during a real upset.
What you receive: send your P&IDs, I/O list or existing alarm list and we return a written proposal for the HMI and alarm work within one working day. Request a quotation

By Eng. Junaid Ali, KSA Industrial Automation Company. Published October 2026.
What is an alarm, and why does it need a philosophy?
An alarm is a signal that tells the operator something needs a response now. If no response is possible or needed, it is an event or a message, not an alarm. This single rule removes most of the clutter on a typical screen.
Without a philosophy, every engineer adds alarms in a different style. The result is floods during upsets, stale alarms that never clear, and operators who stop trusting the list. ISA-18.2 describes the alarm management lifecycle that avoids this, and ISA-101 covers the HMI design around it. EEMUA 191 is the other widely used reference. Both give the same practical message: fewer, better alarms.
What should an HMI alarm philosophy contain?
Keep it to a dozen pages. The headings below are enough for most plants.
- Purpose and scope: which systems, which operators.
- Definitions: alarm, event, prompt, shelved, suppressed.
- Alarm criteria: a signal needs an operator action, a consequence if ignored and time to respond.
- Priority table: how consequence and response time give priority.
- Setpoints, deadbands and delays: how they are chosen.
- Presentation: colours, shapes, sounds, text format, acknowledge behaviour.
- Suppression, shelving and bypass rules: who can do it and for how long.
- Change control: how an alarm is added, changed or removed.
- Performance targets and monthly reporting.
- Training and audit.
How do you set alarm priorities?
Use consequence and available response time. Three levels are usually enough.
| Priority | Consequence if ignored | Time to respond | Typical share of alarms |
|---|---|---|---|
| High | Safety, environmental breach or major equipment damage | Under 5 minutes | About 5% |
| Medium | Production loss or equipment stress | 5 to 20 minutes | About 15% |
| Low | Minor loss, needs attention this shift | Over 20 minutes | About 80% |
The shares are a commonly quoted guide, not a target to force. If half your alarms are high priority, the priorities mean nothing. Colour should not be the only cue, because operators may be colour-blind; use shape or position as well.
Worked example: setting a tank high-level alarm
This is an example to show the method; your tank will differ. A tank has a high-high trip at 95% and an overflow point at 100%. The inlet pump fills the tank at 2% of level per minute at full flow. The operator must see the alarm early enough to act.
| Step | Calculation | Result |
|---|---|---|
| Time to move from alarm to trip | Set the alarm at 80%; (95 − 80) ÷ 2 | 7.5 minutes |
| Time needed to respond | Walk to the valve and close it | 3 minutes |
| Margin | 7.5 − 3 | 4.5 minutes |
| Noise protection | Waves of about ±1.5% on the signal | Deadband 2%, on-delay 5 seconds |
The alarm at 80% leaves a margin of 4.5 minutes, so it is Medium. If the margin fell below the response time, the setpoint moves down or the priority rises. The deadband stops the alarm chattering when the level rocks around the setpoint. Record these values in the rationalisation sheet beside the tag, with the reason.
How many alarms can an operator handle?
Aim for no more than about one new alarm every ten minutes in steady operation, a figure used in both ISA-18.2 and EEMUA 191 guidance. In an upset, the system must still be usable, so test the design with an alarm flood scenario during FAT. Track three numbers monthly:
- Average alarms per operator per hour.
- The ten most frequent alarms, which usually produce a third or more of the total.
- Alarms standing for longer than 24 hours.
Fix the top ten first. A single noisy transmitter can account for hundreds of alarms a day. Review each fix after a month to confirm the rate has fallen, and record the result in the change log so the next reviewer sees what was tried.
How do you apply an HMI alarm philosophy to a project?
Write the philosophy early, review each alarm in a rationalisation workshop with operations and process engineers, then enter the agreed values into the PLC and HMI. Test them during FAT and SAT, and lock the alarm settings behind access levels. KSA Industrial Automation Company works with ISA-18.2 and ISA-101 principles where the client specification requires them, on projects for Saudi Aramco, SABIC and the Royal Commission for Jubail and Yanbu.
Our HMI development service builds the screens and alarm lists to the agreed document. Where the alarms feed a plant-wide system, the SCADA integration page covers the supervisory layer, and the tests belong in control system commissioning.
Common questions about HMI alarm philosophy
What does HMI stand for?
HMI stands for human-machine interface. It is the screen, panel or software through which an operator sees the state of a machine or process and sends commands. An HMI can be a small touch panel on a machine or a full control-room workstation.
Can an HMI work without a PLC?
Yes, but it needs another data source, such as a drive, a meter or a gateway. Most industrial HMIs read tags from a PLC, because the PLC holds the control logic, the alarm conditions and the interlocks the screen displays.
How many priority levels should we use?
Three is usual: high, medium and low. More levels blur the differences, and operators rarely remember them. Use a fourth, advisory level only for messages that never need action, and keep it out of the alarm list.
Should every alarm have a documented response?
Yes for high and medium priority. Each alarm record states the cause, the consequence and the expected operator action. This also exposes alarms that have no action, which then become events and leave the list.
How often should the philosophy be reviewed?
Review it at least yearly and after any major plant change. A monthly performance report shows whether alarm rates are drifting, so the review has data behind it and reaches the changes that matter.
Want an HMI alarm philosophy written or applied to your screens? Send your P&IDs or current alarm list and receive a quotation within one working day. Email: inquiry@ksaindustrialautomation.com | Request a quotation
