Safe control authority means one clearly identified source can command a device while every other source is predictably blocked and informed. “Local/remote” is often too vague for modern MV switchgear because commands may originate at the breaker mechanism, bay panel, station HMI, control center, maintenance tool or automatic scheme. A mode selector must define authority, not merely change an HMI label.
This article develops a fail-safe authority matrix, logic allocation, transition rules, cybersecurity and FAT/SAT for local, station/supervisory and remote control.
1. Define the control origins
| Origin | Examples | Design concern |
|---|---|---|
| Mechanical/device local | Breaker fascia/mechanism buttons or manual operation | Personnel proximity and maintenance safety |
| Bay/panel local | Panel pushbuttons, bay controller HMI | Wiring/IED availability and bay interlocks |
| Station supervisory | Station HMI or station controller | Station-wide topology and operator authority |
| Remote | Control-center SCADA/dispatcher | WAN delay, stale data, cyber and responsibility |
| Automatic | ATS, bus transfer, load shedding/restoration | Priority and coexistence with manual modes |
| Engineering/test | IED tool, test client or commissioning controls | Production isolation, role and audit |
2. Use precise mode names
A two-position LOCAL/REMOTE selector may mean local panel versus station HMI in one project and station versus control center in another. Define the physical device, selector contacts, logic and permitted origins in the drawings and operating procedure. Useful states may include DEVICE LOCAL, BAY LOCAL, STATION, REMOTE and MAINTENANCE; not every project needs all states.
- Use mutually exclusive, positively indicated selector states.
- Where consequence requires it, use a key-operated or access-controlled selector.
- Indicate the actual evaluated authority at all HMI levels, not only raw selector contacts.
- Treat invalid/disagreeing selector contacts as a defined safe degraded state.
- Separate authority from interlock bypass, protection blocking and test mode.
- Define whether trip/open is permitted from more origins than close.
3. Example authority matrix
| Evaluated mode | Bay panel | Station HMI | Remote SCADA | Automatic scheme |
|---|---|---|---|---|
| Bay local | Permitted with checks | Blocked | Blocked | Blocked or trip-only by philosophy |
| Station | Optional emergency trip; close blocked | Permitted with checks | Blocked | As specifically enabled |
| Remote | Optional emergency trip; close blocked | Monitor/authorized takeover only | Permitted with checks | As specifically enabled |
| Maintenance/test | Test procedure only | Blocked/clearly test | Blocked | Blocked |
| Invalid/no DC | Defined local/manual safe path | Blocked | Blocked | Blocked except independent protection |
This is an example, not a universal rule. Protection trips and emergency opening are separate safety functions and may remain effective in every mode. Remote closing generally deserves stricter gating than tripping.
4. Authority versus protection and interlocking
- Mode selection determines who may request operation.
- Interlocking determines whether the present topology permits the requested operation.
- Synchrocheck determines whether electrical closing conditions are acceptable.
- Protection blocking/test determines how protection functions behave.
- Breaker readiness determines whether the mechanism/DC/coil can act.
- Cyber authorization determines whether the user/client is entitled to issue a request.
- All required gates must pass; no one gate substitutes for another.
5. Where the authoritative logic should reside
The final close/open permissive should normally be enforced in the bay IED/control circuit close to the equipment so loss of station HMI, gateway or WAN cannot accidentally enable control. The station and remote systems also pre-check and present conditions, but their decision is advisory unless explicitly part of a validated distributed interlock.
- Hardwire critical selector and emergency-trip paths where the safety philosophy requires independence.
- Debounce/supervise selector contacts and detect impossible combinations.
- Expose evaluated mode and raw input disagreement for diagnostics.
- Do not depend on SCADA database state to enforce local maintenance safety.
- Automatic functions must enter through a named, gated authority path.
- Document every distributed GOOSE/remote interlock dependency and failure state.
6. Mode transition rules
- Detect and debounce the physical/logical mode change.
- Cancel outstanding select-before-operate reservations and pending commands.
- Block new commands during a short, defined transition state if necessary.
- Evaluate the new authority and all current interlock/process quality.
- Report the evaluated mode with source time and audit origin.
- Require a fresh operator command; never continue a command queued under the old mode.
- Alarm invalid/disagreeing mode and state the allowed degraded behavior.
Test a selector change at every point in a control sequence: before select, after select, during operate/output pulse and before feedback. The outcome must be deterministic and must not produce an unintended second operation.
7. Fail-safe behavior
| Failure | Safe expected behavior |
|---|---|
| One selector contact open/broken | Invalid/disagreement; remote close blocked and alarmed |
| Bay IED reboot | No retained output/pending command; authority re-evaluated |
| Station LAN/HMI loss | Local protection/control philosophy remains; station/remote quality bad |
| WAN/control-center loss | Remote control unavailable; station/local mode unchanged |
| Gateway failover | No duplicate command or implicit authority transfer |
| Stale/invalid breaker position | Remote close normally rejected; diagnostic alarm |
| Loss of DC control power | Commands fail safe; loss alarm; manual/mechanical behavior documented |
8. Local control and personnel safety
- Define whether “local” means at the breaker or safely outside the arc-flash boundary.
- Coordinate racking/earthing/door interlocks with the authority mode; a mode switch must not defeat mechanical safety interlocks.
- Provide lockout/tagout and test/maintenance procedures independent of software authority.
- Prevent remote reclosing when personnel have placed the bay in local/maintenance.
- Make mode/remote-enable status visible at the point of work.
- Use mechanical key/interlock systems where the risk assessment requires them.
- Test loss of auxiliary power and manual operating capability.
9. Station and remote supervisory control
- Station HMI should show topology, authority, fresh quality, interlocks and command result before/after operation.
- Remote SCADA should not assume the gateway’s TCP connection proves bay data is current.
- Use select-before-operate and enhanced result handling where justified by consequence.
- Define which station operator may transfer authority to/from remote and whether physical selector action is required.
- Prevent simultaneous station and remote active masters.
- Record takeover/return of authority and any failed command during transition.
- Include procedures for WAN outage, station evacuation and emergency local operation.
10. Automatic schemes and priority
Automatic transfer, load shedding and restoration may need to operate while manual authority is station or remote—but only if this is an explicit design rule. Define priority among protection trip, breaker failure, emergency trip, automatic open/close and manual command. Closing logic should normally be inhibited by active lockout/protection and maintenance/local conditions.
- Use explicit auto enable/disable with visible status and authorization.
- Cancel/lock automatic sequences on mode change according to a documented state machine.
- Do not let an automatic retry conflict with an operator command.
- Limit and alarm unsuccessful close attempts.
- Record sequence state, trigger, each command and abort reason.
- Test manual takeover at every sequence state.
11. Cybersecurity and identity
- A physical REMOTE selector enables a source class; it does not authenticate a specific user.
- Use unique user identities, role-based authorization and controlled privileged access.
- Restrict command clients/network paths; monitor unexpected associations and mode changes.
- Protect IED logic, SCL, gateway/HMI databases and selector wiring drawings.
- Audit physical mode change where observable plus user/client command origin and result.
- Apply IEC 62351 mechanisms supported for IEC 61850/telecontrol links and test lifecycle/failover.
- Define incident response that can isolate remote access while preserving local protection/control.
12. Point-list and HMI requirements
- Raw selector contacts, evaluated authority mode and invalid/disagreement alarm.
- Control enabled/blocked indication per origin where operationally useful.
- Current selection owner/pending command state and timeout.
- Interlock/synchrocheck/readiness summary with drill-down cause.
- Last command origin, user/client, desired action, time and result.
- Bad/stale quality and communication-source distinction.
- Mode change and command SOE with reliable source timestamps.
- Consistent color/symbol policy that does not confuse authority with primary position.
13. FAT/SAT test matrix
- Verify every matrix cell for open and close at each origin/mode.
- Test protection trip and emergency trip in every mode.
- Operate the selector through all valid/invalid contact combinations and contact bounce.
- Change mode during select, operate, output pulse, mechanism travel and feedback timeout.
- Try simultaneous bay/station/remote/automatic commands and confirm priority.
- Inject bad/stale position, failed interlock, no synchrocheck, lockout and DC/mechanism failure.
- Fail IED, station HMI, LAN, gateway, WAN and redundant master during control.
- Restart devices and confirm no latent selection/output/queued command survives.
- Verify audit/event timestamps, HMI indications and precise rejection reasons.
- Attempt unauthorized user/client commands and configuration changes.
- At SAT, confirm physical selector/wiring and actual breaker/disconnector/earthing-switch behavior.
- Witness operations procedure for local maintenance, authority transfer and communication outage.
14. Common unsafe patterns
- One raw “remote” bit interpreted differently by IED, HMI and control center.
- Station and control center both active because gateway redundancy duplicated authority.
- Mode change only hides an HMI button while the IED still accepts the command.
- Pending SBO selection remains after authority transfers.
- SCADA communication loss automatically grants local/remote permission without indication.
- Interlock bypass embedded in the same selector as control authority.
- Remote close accepted with stale/invalid switch position.
- Automatic reclose/transfer continues during maintenance-local mode.
15. Design deliverables
- Control-origin and authority matrix for each primary device/action.
- Selector/wiring schematic and evaluated logic/state diagram.
- Protection/interlock/synchrocheck/automatic priority matrix.
- IEC 61850 control models, SCL and telecontrol mapping.
- Point list/HMI indications, alarm text and operating procedures.
- Failure-mode analysis for contacts, IED, networks, clients and DC.
- Cyber roles, allowed clients, audit and incident local-control procedure.
- FAT/SAT evidence and as-built configuration with change control.
References and further reading
- IEC 61850-8-1 consolidated edition — MMS controls and reporting
- IEC 61850-7-2 consolidated edition — Control services and origin
- IEC 61850-7-4 consolidated edition — Switchgear logical-node models
- IEC 61850-6 edition 2.2 — SCL engineering
- IEC 60870-5-104 consolidated edition — Remote telecontrol
- IEC 62351-6:2020 — IEC 61850 security
- IEC 62443-3-3:2013 — System security requirements
Engineering note: The safest default on invalid authority is normally to block remote closing, preserve independent protection tripping and make the degraded condition immediately visible locally and remotely.