Local, Remote and Supervisory Control Authority: Safe Mode Selection

A practical authority-state design for MV switchgear that prevents competing commands and safely handles mode changes, stale data, failures and maintenance.

Safe control authority means one clearly identified source can command a device while every other source is predictably blocked and informed. “Local/remote” is often too vague for modern MV switchgear because commands may originate at the breaker mechanism, bay panel, station HMI, control center, maintenance tool or automatic scheme. A mode selector must define authority, not merely change an HMI label.

This article develops a fail-safe authority matrix, logic allocation, transition rules, cybersecurity and FAT/SAT for local, station/supervisory and remote control.

1. Define the control origins

OriginExamplesDesign concern
Mechanical/device localBreaker fascia/mechanism buttons or manual operationPersonnel proximity and maintenance safety
Bay/panel localPanel pushbuttons, bay controller HMIWiring/IED availability and bay interlocks
Station supervisoryStation HMI or station controllerStation-wide topology and operator authority
RemoteControl-center SCADA/dispatcherWAN delay, stale data, cyber and responsibility
AutomaticATS, bus transfer, load shedding/restorationPriority and coexistence with manual modes
Engineering/testIED tool, test client or commissioning controlsProduction isolation, role and audit

2. Use precise mode names

A two-position LOCAL/REMOTE selector may mean local panel versus station HMI in one project and station versus control center in another. Define the physical device, selector contacts, logic and permitted origins in the drawings and operating procedure. Useful states may include DEVICE LOCAL, BAY LOCAL, STATION, REMOTE and MAINTENANCE; not every project needs all states.

  • Use mutually exclusive, positively indicated selector states.
  • Where consequence requires it, use a key-operated or access-controlled selector.
  • Indicate the actual evaluated authority at all HMI levels, not only raw selector contacts.
  • Treat invalid/disagreeing selector contacts as a defined safe degraded state.
  • Separate authority from interlock bypass, protection blocking and test mode.
  • Define whether trip/open is permitted from more origins than close.

3. Example authority matrix

Evaluated modeBay panelStation HMIRemote SCADAAutomatic scheme
Bay localPermitted with checksBlockedBlockedBlocked or trip-only by philosophy
StationOptional emergency trip; close blockedPermitted with checksBlockedAs specifically enabled
RemoteOptional emergency trip; close blockedMonitor/authorized takeover onlyPermitted with checksAs specifically enabled
Maintenance/testTest procedure onlyBlocked/clearly testBlockedBlocked
Invalid/no DCDefined local/manual safe pathBlockedBlockedBlocked except independent protection

This is an example, not a universal rule. Protection trips and emergency opening are separate safety functions and may remain effective in every mode. Remote closing generally deserves stricter gating than tripping.

4. Authority versus protection and interlocking

  • Mode selection determines who may request operation.
  • Interlocking determines whether the present topology permits the requested operation.
  • Synchrocheck determines whether electrical closing conditions are acceptable.
  • Protection blocking/test determines how protection functions behave.
  • Breaker readiness determines whether the mechanism/DC/coil can act.
  • Cyber authorization determines whether the user/client is entitled to issue a request.
  • All required gates must pass; no one gate substitutes for another.

5. Where the authoritative logic should reside

The final close/open permissive should normally be enforced in the bay IED/control circuit close to the equipment so loss of station HMI, gateway or WAN cannot accidentally enable control. The station and remote systems also pre-check and present conditions, but their decision is advisory unless explicitly part of a validated distributed interlock.

  • Hardwire critical selector and emergency-trip paths where the safety philosophy requires independence.
  • Debounce/supervise selector contacts and detect impossible combinations.
  • Expose evaluated mode and raw input disagreement for diagnostics.
  • Do not depend on SCADA database state to enforce local maintenance safety.
  • Automatic functions must enter through a named, gated authority path.
  • Document every distributed GOOSE/remote interlock dependency and failure state.

6. Mode transition rules

  1. Detect and debounce the physical/logical mode change.
  2. Cancel outstanding select-before-operate reservations and pending commands.
  3. Block new commands during a short, defined transition state if necessary.
  4. Evaluate the new authority and all current interlock/process quality.
  5. Report the evaluated mode with source time and audit origin.
  6. Require a fresh operator command; never continue a command queued under the old mode.
  7. Alarm invalid/disagreeing mode and state the allowed degraded behavior.

Test a selector change at every point in a control sequence: before select, after select, during operate/output pulse and before feedback. The outcome must be deterministic and must not produce an unintended second operation.

7. Fail-safe behavior

FailureSafe expected behavior
One selector contact open/brokenInvalid/disagreement; remote close blocked and alarmed
Bay IED rebootNo retained output/pending command; authority re-evaluated
Station LAN/HMI lossLocal protection/control philosophy remains; station/remote quality bad
WAN/control-center lossRemote control unavailable; station/local mode unchanged
Gateway failoverNo duplicate command or implicit authority transfer
Stale/invalid breaker positionRemote close normally rejected; diagnostic alarm
Loss of DC control powerCommands fail safe; loss alarm; manual/mechanical behavior documented

8. Local control and personnel safety

  • Define whether “local” means at the breaker or safely outside the arc-flash boundary.
  • Coordinate racking/earthing/door interlocks with the authority mode; a mode switch must not defeat mechanical safety interlocks.
  • Provide lockout/tagout and test/maintenance procedures independent of software authority.
  • Prevent remote reclosing when personnel have placed the bay in local/maintenance.
  • Make mode/remote-enable status visible at the point of work.
  • Use mechanical key/interlock systems where the risk assessment requires them.
  • Test loss of auxiliary power and manual operating capability.

9. Station and remote supervisory control

  • Station HMI should show topology, authority, fresh quality, interlocks and command result before/after operation.
  • Remote SCADA should not assume the gateway’s TCP connection proves bay data is current.
  • Use select-before-operate and enhanced result handling where justified by consequence.
  • Define which station operator may transfer authority to/from remote and whether physical selector action is required.
  • Prevent simultaneous station and remote active masters.
  • Record takeover/return of authority and any failed command during transition.
  • Include procedures for WAN outage, station evacuation and emergency local operation.

10. Automatic schemes and priority

Automatic transfer, load shedding and restoration may need to operate while manual authority is station or remote—but only if this is an explicit design rule. Define priority among protection trip, breaker failure, emergency trip, automatic open/close and manual command. Closing logic should normally be inhibited by active lockout/protection and maintenance/local conditions.

  • Use explicit auto enable/disable with visible status and authorization.
  • Cancel/lock automatic sequences on mode change according to a documented state machine.
  • Do not let an automatic retry conflict with an operator command.
  • Limit and alarm unsuccessful close attempts.
  • Record sequence state, trigger, each command and abort reason.
  • Test manual takeover at every sequence state.

11. Cybersecurity and identity

  • A physical REMOTE selector enables a source class; it does not authenticate a specific user.
  • Use unique user identities, role-based authorization and controlled privileged access.
  • Restrict command clients/network paths; monitor unexpected associations and mode changes.
  • Protect IED logic, SCL, gateway/HMI databases and selector wiring drawings.
  • Audit physical mode change where observable plus user/client command origin and result.
  • Apply IEC 62351 mechanisms supported for IEC 61850/telecontrol links and test lifecycle/failover.
  • Define incident response that can isolate remote access while preserving local protection/control.

12. Point-list and HMI requirements

  • Raw selector contacts, evaluated authority mode and invalid/disagreement alarm.
  • Control enabled/blocked indication per origin where operationally useful.
  • Current selection owner/pending command state and timeout.
  • Interlock/synchrocheck/readiness summary with drill-down cause.
  • Last command origin, user/client, desired action, time and result.
  • Bad/stale quality and communication-source distinction.
  • Mode change and command SOE with reliable source timestamps.
  • Consistent color/symbol policy that does not confuse authority with primary position.

13. FAT/SAT test matrix

  1. Verify every matrix cell for open and close at each origin/mode.
  2. Test protection trip and emergency trip in every mode.
  3. Operate the selector through all valid/invalid contact combinations and contact bounce.
  4. Change mode during select, operate, output pulse, mechanism travel and feedback timeout.
  5. Try simultaneous bay/station/remote/automatic commands and confirm priority.
  6. Inject bad/stale position, failed interlock, no synchrocheck, lockout and DC/mechanism failure.
  7. Fail IED, station HMI, LAN, gateway, WAN and redundant master during control.
  8. Restart devices and confirm no latent selection/output/queued command survives.
  9. Verify audit/event timestamps, HMI indications and precise rejection reasons.
  10. Attempt unauthorized user/client commands and configuration changes.
  11. At SAT, confirm physical selector/wiring and actual breaker/disconnector/earthing-switch behavior.
  12. Witness operations procedure for local maintenance, authority transfer and communication outage.

14. Common unsafe patterns

  • One raw “remote” bit interpreted differently by IED, HMI and control center.
  • Station and control center both active because gateway redundancy duplicated authority.
  • Mode change only hides an HMI button while the IED still accepts the command.
  • Pending SBO selection remains after authority transfers.
  • SCADA communication loss automatically grants local/remote permission without indication.
  • Interlock bypass embedded in the same selector as control authority.
  • Remote close accepted with stale/invalid switch position.
  • Automatic reclose/transfer continues during maintenance-local mode.

15. Design deliverables

  • Control-origin and authority matrix for each primary device/action.
  • Selector/wiring schematic and evaluated logic/state diagram.
  • Protection/interlock/synchrocheck/automatic priority matrix.
  • IEC 61850 control models, SCL and telecontrol mapping.
  • Point list/HMI indications, alarm text and operating procedures.
  • Failure-mode analysis for contacts, IED, networks, clients and DC.
  • Cyber roles, allowed clients, audit and incident local-control procedure.
  • FAT/SAT evidence and as-built configuration with change control.

References and further reading

Engineering note: The safest default on invalid authority is normally to block remote closing, preserve independent protection tripping and make the degraded condition immediately visible locally and remotely.

LearnSwitchgear

Search the engineering library