Prevent
Remove the ignition source, reduce the inventory, change the arrangement. Or: remove the step that creates the error.

Home · Method
The same discipline runs through both practices. What changes is the scale of the system being read — a process plant, or the company that operates one.
The failure mode
On an industrial facility it looks like this: a code is opened, a table is read, a system is specified. The result satisfies the regulation and protects the wrong thing, because nobody established what was actually at risk before the equipment was chosen.
Inside a company it looks identical: a tool is bought, a process is bent to fit it, and a year later the work is done twice — once in the tool and once the way people actually work. In both cases the error is the same and it happens before any implementation: nobody read the system.
Step one
On a plant: every medium and where it sits. The state each substance is in — liquid, vapour, heated above its flash point, held under pressure, cryogenic, two-phase. Its fire and explosion properties. The volumes held, the transfer rates, the loading and unloading operations.
In a company: how work actually moves rather than how the org chart says it does. Where a document is created, who touches it, where it waits, which decisions require which people, and what is held in someone’s head rather than in a system.
This is not a formality before the real work. This is the real work. A facility where the same hydrocarbon sits cold in a tank and hot under pressure in a column has two entirely different fire problems, and no code table will tell you that.
Step two
Protection never exists on its own. It sits on top of layers that already exist and that either help it or defeat it.
A fire strategy written without knowing what the shutdown system does on high level in a vessel is a strategy written blind. The same is true of an automation plan written without knowing who quietly fixes the data every Friday.
Step three
With the inventory and the existing layers understood, credible scenarios can be constructed rather than guessed: what releases, from where, in what quantity, ignited when, escalating how far. This is where the analysis lives — consequence modelling, thermal radiation, blast overpressure, dispersion, escalation to adjacent equipment.
In the corporate case the equivalent is just as concrete: where the process actually breaks, what an error propagates into, what a delay costs, and which of those failures are worth engineering against at all.
Step four
Remove the ignition source, reduce the inventory, change the arrangement. Or: remove the step that creates the error.
Limit what a release can reach before it becomes a fire. Or: catch the fault where it is cheap to correct.
Systems sized for the scenario that governs, not for the table. Or: automation scoped to the loop that actually costs.
To people, to the asset, to production and to the environment. Environmental consequence is decided in the strategy or it is not decided at all.
Not a template. An engineering answer to a specific system.
Why it travels
A hydrocracker, an ethylene cracker, a polyolefin line, an LNG train — these are licensed packages, and the licensors are the same worldwide. The plant read in one jurisdiction is the same plant in another: the same process scheme, the same media, the same operating regimes, the same failure modes. What changes at the border is the normative base, not the physics.
The fastest way to judge an engineering firm is to give it a real problem. Send us one unit and its inventory — or one process in your company that costs more than it should.
Contact