Chapter 32 / 36

Project: a batch tank

Combine measurements, valves, recipes and fault handling into a batch design.

Batch skid with cutaway tank, inlet and outlet valves, mixer motor and instruments
The second complete machine. Identify what can keep changing after a request is removed: liquid already in the pipe, a rotating mixer, a drifting measurement, and the material already in the vessel.
Recipe snapshot separated from a fill, mix and drain sequence, with a retained batch identity during held recovery
Mark the evidence on each arrow. Filled is a measurement decision. Mixed-for-time is an elapsed-time decision. Empty needs the project's declared drain criterion. They are different kinds of proof.

Before reading the solution, make two lists: what the controller remembers, and what the tank physically contains. Interrupt the imagined fill halfway through and compare the lists. If pressing Reset erases the only record of the material, your recovery design has lost the batch. A useful design must explain whether that material can continue, needs a controlled disposition, or requires another procedure.

The liquid remembers what the program forgets

A conveyor model can reset by moving a tray back to its start. A tank makes the weakness of that shortcut obvious. If a batch stops halfway through filling, clearing a state variable does not empty the vessel. It also does not identify the material already inside.

Our training tank receives water, mixes for a specified time, then drains to a receiving vessel. The purpose is to design ordinary sequencing and measurement handling. This is not a chemical-process safety design, and the model does not authorize real valves, pumps, heaters, or pressure equipment.

We will target 120 litres, mix for twenty seconds, and drain to a declared empty threshold. Those are exercise values, not universal settings.

Clarify the batch contract

The operator selects a recipe before starting. At acceptance, the program copies approved recipe values into an active batch record. Later HMI edits affect the next batch, not the batch already running. This prevents a moving target from changing the meaning of “filled.”

Acceptance requires a valid level measurement, an empty vessel according to the agreed threshold, receiving capacity, and production permission. The model checks that target volume and times lie within its configured operating envelope. Invalid recipe data is rejected with a reason; it is not silently clamped into a different recipe.

Completion means the drain criterion was met and the batch record was finalized. An interrupted batch has a disposition decision. It does not become a fresh batch merely because the Start button is pressed again.

Scale with units and validity

Suppose the model transmitter maps 4–20 mA to 0–200 litres. For an input current I_mA, the nominal conversion is:

Volume_L = (I_mA - 4.0) × 200.0 / 16.0

At 13.6 mA, the result is 120 litres. At 12 mA, it is 100 litres. These are useful hand checks because an inverted range or integer-division error becomes obvious.

Measurement validity is a separate value. A number slightly below 4 mA may be legitimate calibrated underrange or a diagnostic condition, depending on the transmitter, input module, configuration, and application. Use their documentation to define validity thresholds. Do not invent a universal wire-break rule from the scaling equation.

For this model, the harness supplies both current and LevelValid. Preserve the unbounded engineering conversion for diagnostics; any display limiting should not hide an invalid input from control logic. Define units in names such as TargetVolume_L and MixDuration, not in somebody's memory.

State the physical assumptions

The model treats volume as proportional to transmitter current and assumes a vessel geometry consistent with that calibration. Real level-to-volume conversion may require a geometry calculation or calibration table. It assumes no leakage during mixing, a separately observed valve state only where provided, and a finite inlet flow delay.

That last assumption matters. Closing the inlet request at 120 litres may produce more than 120 litres because liquid continues arriving. A model that stops flow instantly conceals this issue. Add a configurable closing delay and observe overshoot before proposing a control improvement.

A first correction might be a reviewed cutoff allowance based on measured behavior. More demanding accuracy may need flow measurement, staged filling, or a different actuator. Do not promise that one compensating constant solves every pressure and material condition.

Design outputs from states

Use Idle, Filling, Mixing, Draining, Complete, and Interrupted. Inlet and drain requests must never be true together. Mixing is permitted only in its specified process envelope. A state table gives an auditable ownership rule:

StateInletMixerDrainExit evidence
IdleOffOffOffAccepted valid batch
FillingOnOffOffTarget reached with valid measurement
MixingOffOnOffActive recipe duration elapsed
DrainingOffOffOnEmpty criterion confirmed
CompleteOffOffOffCompletion acknowledged
InterruptedOffOffOffBatch disposition and permitted recovery

All three final requests are assigned in one arbitration section. Missing permission removes ordinary requests. The model still lets a simulated stuck valve pass liquid, because command and physical behavior are different.

Supervise progress, not just elapsed time

A fill timeout catches missing completion but gives little diagnosis. Add a progress observation: while filling, does measured volume increase plausibly over a declared observation window? A flat trace could mean unavailable supply, a closed physical valve, or a failed measurement. An implausibly fast rise could mean a scaling or sensor problem.

Keep these checks separate from the main target transition. Specify startup allowance, window length, and thresholds based on process knowledge. Otherwise normal valve delay becomes a nuisance alarm. In the model, choose transparent values and let learners vary flow so they can see the relationship.

Call phase timers consistently with explicit activation conditions. When a phase ends, its timer must receive the reset condition required by the selected implementation. Do not carry a completed mixing timer into the next batch accidentally.

A focused code fragment

This fragment illustrates the filling decision after recipe acceptance; it is not the complete tank application:

IF State = FILLING THEN
    IF NOT ProductionPermission OR CancelRequest THEN
        InterruptReason := PROCESS_INTERRUPTED;
        State := INTERRUPTED;
    ELSIF NOT LevelValid THEN
        InterruptReason := LEVEL_UNAVAILABLE;
        State := INTERRUPTED;
    ELSIF Volume_L >= ActiveTarget_L THEN
        State := MIXING;
    ELSIF FillTimer.Q THEN
        InterruptReason := FILL_TIMEOUT;
        State := INTERRUPTED;
    END_IF;
END_IF;

InletRequest := (State = FILLING)
                AND LevelValid AND ProductionPermission;

The ordering documents priority. Invalid measurement prevents declaring fill completion even if the last numeric value exceeds target. A timeout does not identify the failed component. The active target remains the accepted recipe value throughout the batch.

Build acceptance around material history

Test target scaling at several known currents. Test invalid measurement before start and during every active phase. Test recipe edits during filling and confirm that the active batch remains unchanged. Test a stuck inlet valve: the output may be off while level continues increasing, so the model must show that discrepancy rather than freeze the liquid.

Interrupt at several volumes. The recovery screen should preserve batch identity, phase, last valid measurements, and reason. Any real disposition procedure belongs to the process owner; our water model uses an explicitly selected drain-and-restart exercise.

Try it

During filling, the transmitter reports an invalid status while its numeric value remains at 121 litres. The target is 120 litres. A colleague proposes accepting fill completion because the displayed number is high enough. Explain the flaw, then define a test that catches it.

Work through the answer

The value may be stale or otherwise unreliable. Comparing it with the target does not restore its validity. The requirement must say how control responds to unavailable measurement; in this model it interrupts and withdraws the ordinary inlet request.

Set valid volume below target, begin filling, then simultaneously mark the measurement invalid and change its numeric field above target. Assert Interrupted, inlet request false, and no transition to Mixing. Repeat with a stale unchanged value. Preserve the last trustworthy reading separately for diagnostics, clearly labelled as historical.

The next project, an inspection cell, extends this same principle: a result needs validity and identity, not merely a plausible value.

Now make the decision yourself

Use the chapter’s model on a fresh question, then compare your reasoning with the worked decision.

How this becomes a program

What stops filling when the level signal lies?

A batch tank has filling, mixing and transfer phases. A stuck measurement can make a perfectly plausible ‘not full’ value persist forever.

Fill / observeMix / proveTransfer / account

Your first artifact

Write separate evidence and limits for each phase. Set an independent maximum fill duration and define the disposition of an interrupted batch.

Open the worked decision
FillRequest := State = FillingState
               AND LevelValid AND NOT FillLimitExceeded;

Why this line belongs here

A value and its validity are separate. A watchdog bounds exposure to missing completion; it does not prove the physical level is safe. Real overfill protection is a separate engineering responsibility.

Change the task

A batch is partly filled when the operator requests a new recipe. Decide how it is completed, rejected or reconciled before another batch is accepted.