CCAMTG-2500 A04 — Safety Case & Hazard Controls
Volume 19 defines the integrated process-safety and hazard-control architecture for the complete
CCAMTG-2500 A04 dual-mode compressed-air energy-storage and recovery machine. It brings together
high-pressure compressed-air safety, high-speed rotor protection, active magnetic-bearing and
touchdown-bearing fault response, electrical and DC safety, BESS and grid hazards, thermal and
cooling protection, fire response, controls and SIS integration, maintenance isolation and
emergency-response requirements.
Main Public Safety Baseline
- Machine Class: 2.5 MW-Class Dual-Mode Compressed-Air Energy Storage / Recovery Magnetic Motor-Generator Machine
- Net AC Generation Target: 2.50 MW
- Nominal Rotor Speed: 12,000 rpm
- Master Air Mass Flow: 12.2 kg/s
- Compression Range: 1.20 bara → ~31 bara
- Expansion Range: ~31 bara → 1.20 bara
- DC Bus: 1,500 VDC
- BESS Energy Capacity: ~5 MWh LFP
A04 Safety Status:
V19 defines the concept-engineering safety architecture but does not present preliminary values as
certified safety limits. Final SIL targets, relief sizing, trip setpoints, rotor burst margins,
arc-flash values, BESS fire-system details and site-specific emergency criteria remain governed by
approved hazard studies, calculation volumes, supplier data and jurisdictional approval.
Safety Case Scope
- Integrated machine safety case
- HAZOP hazard review
- System FMEA / FMECA
- LOPA / SIL determination basis
- Emergency response procedure
- Safety-function architecture
- Safe-state definition
- Safety verification and proof
- Cross-volume safety traceability
- Residual-risk and action closeout
Primary Hazard Energy Sources
- High-pressure compressed air
- Stored pneumatic energy
- High-speed rotating energy
- Rotor and coupling kinetic energy
- High-power electrical energy
- Stored DC-bus energy
- Battery energy storage
- Thermal energy
- Hot and cold process surfaces
- Stored mechanical energy during maintenance
Master Safety Design Principles
- Independent mechanical overpressure protection for blocked-in pressure volumes
- Fail-closed external high-pressure storage isolation
- Fail-closed turbine inlet isolation
- Fail-open compressor anti-surge recycle where loss of actuation must protect the compressor
- Dual-channel rotor-speed sensing for overspeed protection
- AMB fault management separated from normal machine sequencing where practicable
- Independent touchdown-bearing support for defined levitation-loss events
- Fire detection for BESS and electrical enclosures
- Earthing, insulation monitoring and lockout/tagout protection
- Guarding and containment for high-energy rotating and pressure equipment
- Controlled depressurization before maintenance access
- Emergency shutdown designed to remove or isolate stored energy safely
High-Pressure Air Safety
- Rated pressure boundaries throughout the compressed-air system
- Independent mechanical pressure relief
- Redundant buffer-pressure monitoring
- Fail-safe high-pressure isolation
- Passive reverse-flow prevention
- Controlled blowdown and depressurization
- Pressure-zero verification before intrusive access
- Pressure-boundary inspection and certification before operation
Compressor Surge Protection
- Compressor operating-map supervision
- Corrected-flow and pressure monitoring
- Rotor-speed and temperature inputs
- Protective anti-surge controller
- Fail-open anti-surge recycle architecture
- Transient protection verified against the approved compressor analysis
- Damaging surge is treated as an unacceptable operating condition
Turbine Overspeed Protection
- Dual-channel rotor-speed sensing
- Turbine inlet isolation
- Removal of motoring torque
- Controlled electrical braking where approved and safe
- Rotor and wheel stress protection tied to approved analysis
- Containment and guarding requirements tied to released rotor-energy studies
- Physical overspeed testing only when separately engineered and approved
Rotor & Coupling Safety
- High-speed rotor integrity
- Coupling integrity
- Rotor balance and vibration monitoring
- Rub and contact detection
- Torsional and critical-speed analysis
- Overspeed and separation protection
- Fixed or interlocked guarding as required by the released design
- Zero-speed verification before intrusive access
Active Magnetic Bearing Safety
- Continuous radial and axial rotor-position monitoring
- AMB controller diagnostics
- Amplifier and coil health monitoring
- Fault detection independent of ordinary operator supervision
- High-pressure energy isolation during severe AMB fault conditions
- Controlled rotor coast-down strategy
- Fault acceptance tied to approved magnetic-bearing analysis and supplier limits
Touchdown Bearing Safety
- Independent mechanical backup support
- Defined fault coast-down capability
- Touchdown-bearing readiness verified before high-speed operation
- Post-touchdown inspection required before restart
- Repeated touchdown events require engineering review
- No high-speed operation with unavailable or damaged touchdown support
Electrical & DC Safety
- High-voltage DC isolation
- Continuous insulation monitoring
- Protective earthing and bonding
- Service disconnect architecture
- Electrical protection and converter isolation
- Arc-flash controls governed by the approved electrical study
- Stored electrical energy verified discharged before access
- Lockout/tagout and prove-dead procedures
BESS Safety
- BMS protection authority
- Battery thermal monitoring
- Fire detection
- Electrical isolation
- Site-specific fire suppression
- Supplier and site thermal-event response
- Controlled re-entry criteria after battery incidents
- Final BESS fire and ventilation design remains supplier and site controlled
Cooling-System Safety
- Redundant cooling-pump architecture
- Cooling-flow monitoring
- Temperature and pressure monitoring
- Standby pump transfer
- Controlled unloading on loss of cooling
- Machine shutdown before thermal limits are exceeded
- Temperature monitoring continues during coast-down where safe power remains available
Thermal & TES Hazards
- Hot compressor discharge conditions
- Cold turbine exhaust conditions
- Thermal stress
- Icing and condensation
- Heat-exchanger cross-leakage
- Blocked drains
- Loss of thermal circulation
- Material compatibility across the approved temperature envelope
Controls & SIS Safety
- Safety functions separated from ordinary machine sequencing where required
- Critical trips trace through sensor, logic and final element
- Watchdog and communications diagnostics
- Common-cause power and network faults considered
- Maintenance bypasses require controlled authorization
- Safety software is version-controlled
- Safety-function regression testing follows approved changes
- Loss of HMI or SCADA does not defeat local machine protection
Fail-Safe Final Element Philosophy
- External storage isolation — fail closed
- Turbine inlet control — fail closed
- Compressor discharge isolation — fail closed
- Compressor anti-surge recycle — fail open
- Reheater isolation — safe state defined by hazard review
- Buffer overpressure relief — mechanically independent
- Controlled blowdown — safe philosophy defined by hazard study
- Reverse-flow protection — passive where applicable
HAZOP Study Areas
- Air intake and inlet guide vane system
- Three-stage compressor
- Intercoolers and TES charge side
- HP buffer vessel
- External compressed-air storage interface
- Turbine preheat, reheat and expansion train
- Common rotor and couplings
- AMB and touchdown-bearing systems
- PMG, DC bus, PCS and grid interface
- BESS
- Cooling system
- Controls, SIS and HMI
- Structural skid, foundation and guarding
- Maintenance and isolation state
Representative HAZOP Deviations
- High pressure
- Low or no compressor flow
- High rotor speed
- Loss of magnetic levitation
- High vibration
- Cooling failure
- Electrical insulation fault
- Fire or emergency stop
- Reverse flow
- Maintenance access with trapped energy
FMEA / FMECA Failure Families
- Rotor-speed sensor failure or bias
- Buffer-pressure sensor failure
- Turbine inlet valve fails open
- Anti-surge valve fails closed
- External HP isolation fails open
- Mechanical relief unavailable
- AMB amplifier or coil failure
- Touchdown bearing damaged or unavailable
- Cooling duty pump failure
- DC contactor fails to isolate
- BMS fault
- PLC or control-network failure
LOPA / SIL Determination Basis
- Buffer and blocked-in overpressure scenarios
- Turbine overspeed scenarios
- Compressor surge scenarios
- AMB levitation-loss scenarios
- BESS fire and thermal-event scenarios
- Electrical arc and fault scenarios
- Independent protection layers identified for quantitative assessment
- Final SIL ratings are not assigned without approved project and site risk data
Emergency Shutdown Philosophy
- Remove or isolate pneumatic energy input
- Remove motoring torque where required
- Maintain controlled rotor coast-down
- Preserve independent pressure relief
- Isolate affected electrical converter paths
- Initiate controlled depressurization where approved
- Maintain event-specific exclusion zones
- Prevent restart until the initiating cause has been inspected and resolved
Overspeed Emergency Response
- Close turbine inlet
- Remove motoring torque
- Use controlled braking only where approved and safe
- Maintain personnel exclusion
- Monitor coast-down and pressure conditions
- Inspect rotor, protection and containment systems before restart
AMB or High-Vibration Emergency Response
- Close high-pressure energy sources
- Initiate controlled coast-down
- Use touchdown-bearing strategy where required
- Maintain guarding and exclusion until zero speed
- Inspect rotor, couplings, AMBs and touchdown bearings
- No restart until fault cause and machine condition are resolved
High-Pressure Leak or Rupture Response
- Isolate the high-pressure source
- Stop compressor and turbine energy input
- Depressurize only through the approved path
- Evacuate the jet, noise and debris hazard area
- Do not approach until pressure is positively confirmed at zero
- Inspect, NDE, repair and retest the affected pressure boundary before return to service
Electrical Fault Response
- Open the affected converter path
- Preserve safe rotor control where possible
- Apply electrical lockout/tagout
- Verify zero energy before access
- Inspect insulation and earthing systems
- Restore approved electrical protection before restart
Fire & BESS Emergency Response
- Raise alarm and initiate the approved emergency response
- Isolate electrical and pneumatic energy where safe
- Maintain personnel exclusion
- Follow the approved site and supplier fire strategy
- Use approved suppression and ventilation strategy
- Re-entry occurs only under approved site emergency criteria
Personnel Access & Guarding
- Fixed or interlocked guarding for high-speed rotating equipment
- High-energy testing exclusion zones
- Pressure-rated containment for compressed-air systems
- Personnel protection from hot and cold surfaces
- Electrical enclosure and arc-flash controls
- BESS access governed by supplier and site safety requirements
- Zero-speed proof before rotor access
- Controlled maintenance bypass authorization
Zero-Energy Maintenance State
- Rotor proven stopped
- High-pressure sources isolated
- Trapped pressure depressurized
- Pressure zero positively verified
- AC and DC supplies isolated
- Stored DC energy discharged
- BESS safe state established
- Unexpected torque commands prevented
- Lockout/tagout applied
- Thermal energy allowed to reach a safe access condition
Safety-Critical Instrumentation
- Compressor inlet and stage pressure monitoring
- Redundant HP buffer pressure monitoring
- Redundant master airflow monitoring
- Compressor discharge temperature monitoring
- Turbine preheat and reheat temperature monitoring
- Cold turbine outlet monitoring
- AMB rotor-position and vibration monitoring
- Redundant rotor-speed sensing
- Filter differential-pressure monitoring
- Drain and condensate monitoring
Safety Verification Requirements
- Overpressure protection verified by certified calculation, relief certification and functional testing
- Overspeed protection verified against approved rotor limits and control cause-and-effect
- Anti-surge protection verified against compressor transient analysis
- AMB/TDB fault response verified through approved stability and coast-down evidence
- Electrical protection verified through approved fault, grounding and functional tests
- BESS safety verified through supplier and site thermal/fire evidence
- Fire and emergency-stop functions verified through integrated testing
- Isolation and depressurization verified through valve and zero-energy tests
- Guarding and containment verified against released mechanical design
- Safety software and configuration remain revision-controlled
Safety Design Dependencies
- Compressor surge and anti-surge transient analysis
- Turbine flow and valve transient analysis
- Thermal and cooling design
- Critical-speed and torsional analysis
- Rotor and wheel stress analysis
- AMB force and stability analysis
- PMSM/PMG electrical and thermal design
- Pressure-vessel and relief calculations
- Electrical fault and protection studies
- BESS thermal and fire studies
- Reliability and FMECA data
Safety Action Register
- Unique safety-action identifier
- Hazard-review source
- Affected scenario and subsystem
- Required engineered or administrative action
- Responsible owner
- Required closure gate
- Closure evidence
- Residual-risk disposition
- Engineering-change or NCR reference where required
Cross-Volume Safety Traceability
- High-pressure overpressure and release
- Overspeed and rotor-burst protection
- Compressor surge protection
- AMB loss and touchdown response
- Electrical and DC faults
- BESS fire and thermal events
- Cooling loss
- Maintenance trapped-energy hazards
- Every hazard traces through design, protection, test and emergency response
Safety Case Acceptance Gates
- Concept safety basis established
- HAZOP completed
- FMEA / FMECA completed
- LOPA / SIL decisions completed where applicable
- Approved actions incorporated into the design
- Pre-FAT safety verification completed
- FAT / SAT safety proof completed
- Operational safety handover completed
V19 Safety Package
- Integrated Safety Case
- HAZOP Report
- System FMEA / FMECA
- LOPA / SIL Determination Basis
- Emergency Response Procedure
- Safety Action / Recommendation Register
- Safe-State Matrix
- Safety Verification Requirements
- Cross-Volume Safety Traceability
- Safety Case Acceptance Gates
Safety Case Release Philosophy
- No final SIL rating is invented without approved LOPA inputs
- No final relief setting or pressure-test value is invented
- No final rotor overspeed or containment limit is invented
- No final AMB or touchdown-bearing fault limit is invented
- No final electrical or arc-flash value is invented
- No final BESS suppression or re-entry criterion is invented
- No universal emergency exclusion distance is assumed
- Safety-critical changes are propagated through controlled engineering change management
- Every final safety value remains tied to its approved analysis, supplier data or site requirement