PSD and ESD are two levels of the same shutdown hierarchy. A process shutdown, PSD, trips a unit or an equipment train because a process variable has gone somewhere the design does not allow, high level, low suction pressure, high temperature, and its job is to protect the equipment and the process. An emergency shutdown, ESD, responds to a hazard, confirmed gas, fire, loss of containment, a pressed manual station, and its job is to isolate inventory, de-energize, and take the plant to a safe state. The hierarchy is strict: a trip at a higher level initiates everything below it, so an ESD takes the PSDs with it, never the reverse.
Key takeaways
- PSD protects the process and the equipment. ESD makes the plant safe when there is a hazard.
- The hierarchy is one-directional: higher levels initiate lower ones, lower ones never escalate on their own.
- Both usually run in the same safety logic solver, but each function carries its own integrity requirement.
- Blowdown and depressurization belong to the emergency levels, never to a PSD.
- The plant's own shutdown philosophy and its C&E matrix are the authority on level names, causes, and effects.
The shutdown hierarchy
Most shutdown philosophies arrange three to five levels. Names and numbering vary by operator, an offshore facility might run APS, ESD, PSD, USD from the top down, an onshore plant might use numbered ESD levels instead, so the table below is a common shape, not a universal one.
| Level | Typical initiator | Typical action |
|---|---|---|
| Abandon platform / total shutdown | Uncontrolled escalation, muster decision | Total shutdown, blowdown, prepare to abandon |
| ESD, emergency shutdown | Confirmed fire or gas, loss of containment, manual ESD station | Isolate inventory, close ESVs, de-energize, blowdown per philosophy |
| PSD, process shutdown | Process deviation the control layer could not arrest | Stop and isolate the affected unit or train |
| USD, unit shutdown | Local equipment protection trip | Stop the single equipment item or package |
Every initiator-to-action mapping in that table lives in the cause-and-effect matrix, one column per action, one row per cause, level by level.
What trips a PSD
PSD causes are process measurements: separator level too high, compressor suction pressure too low, discharge temperature too high. Each one means the basic control layer had the variable and lost it, and the next defense is to stop the affected train before the deviation damages equipment or propagates. The actions are correspondingly narrow, stop the pumps, close the feed, isolate the train, and the rest of the plant keeps running. That narrowness is deliberate: a PSD that reaches further than its unit turns every process upset into a plant trip.
What trips an ESD
ESD causes are hazards, not deviations: confirmed gas detection, confirmed fire detection, low low pressure that implies a rupture, a manual station pressed by an operator who sees something the sensors do not. The actions are wide, close the emergency shutdown valves to cut inventory into isolatable sections, trip rotating equipment, de-energize what must not stay live, and, where the philosophy calls for it, open the blowdown valves and send the inventory to flare. The split between the control layer and this protective layer is the same BPCS and SIS separation that governs everything in functional safety.
On the C&E matrix and the I/O list
The two levels look identical at the I/O layer, mostly DI initiators and DO trip outputs on the safety system, which is exactly why the paperwork has to keep them apart. The C&E matrix carries the level structure. The SIF list carries each function's integrity requirement, some HAZOP finding turned SIF at SIL 2, some equipment-protection trip with no SIL at all. And the I/O list should let you tell, per point, which level owns it, because a commissioning team proving PSD causes one system at a time must know precisely which trips are in scope and which belong to the ESD system above it.
