Arc flash on generator power: why less fault current means more energy
On a generator-fed bus the protective device sees a fraction of the utility fault current and clears much more slowly. The label shows the utility number.
A turnaround is usually treated as the lower-risk part of the year. The unit is down, the process is off, and most of the plant is de-energized. What is easy to miss is that the electrical system spends that period in a configuration nobody studied.
Temporary generators go in to keep instrumentation, lighting and selected loads alive. Tie-breakers get closed to feed a bus from an adjacent substation. Cables get run to backfeed a motor control centre so a crew can finish commissioning. Each of those is a real operating mode with its own fault current, its own protection behaviour and its own incident energy. The label on the door reflects one of them: the one the plant runs in for the other fifty weeks of the year.
What actually changes when the source changes
The common shorthand is that a generator is "lower voltage" and therefore safer. That is the wrong mechanism, and it points people in the wrong direction.
Voltage is not what drives the difference. Available fault current is.
A utility-fed bus might see 25 kA or more into a bolted fault. The upstream breaker's instantaneous element picks up immediately and clears in a few cycles. A portable generator on the same bus cannot supply anything close to that. Its contribution is bounded by the machine's own reactance, and it does not stay constant. The subtransient period gives the highest current for the first cycle or two, then the current decays through the transient period toward a sustained value that, on a machine without field forcing, can fall below the generator's own rated current.
Many gensets include a regulator specifically to prevent that collapse. Cummins publishes the behaviour of its AmpSentry function, which holds fault current at 300 percent of rated during the sustained period so that downstream devices still have something to trip on.
Three hundred percent of rated is a great deal better than nothing. It is also nowhere near what the protective device was coordinated against. At that current the breaker is no longer on its instantaneous element. It is out on the long-time band, where clearing is measured in seconds rather than cycles. In some cases the arcing current, which is lower again than the bolted fault current, sits below the instantaneous pickup entirely and the device never sees a fault at all.
Incident energy is directly proportional to arc duration. Stretch the clearing time from three cycles to two seconds and the energy at the working distance goes up by roughly the same factor.
The numbers are not subtle. In the worked example Cummins published, a generator-fed system limited by the IEEE 1584 two-second maximum arc duration produced 75.2 cal/cm². Constraining the same fault to 0.263 seconds brought it to 19.5 cal/cm². Same equipment, same generator, same working distance. The only variable was how long the arc was allowed to burn.
Neither of those numbers looks anything like the utility-mode value that is probably printed on the door, and the difference between them is not a property of the equipment. It is a property of the protection.
So the correct statement is not that lower voltage is more dangerous. It is that a source with low available fault current takes the protective device off its fast element, and a slow clear is what produces a large arc flash. All else equal, IEEE 1584 gives less incident energy at lower voltage. The voltage is a distraction. The clearing time is the whole story.
The gap starts in the study scope
Most arc flash studies model the plant as it normally runs. Utility source, normal alignment, tie-breakers in their usual positions. That is the right base case and it is the one the labels come from.
It is not the only case that needs a number.
Permanent alternate sources are the easy ones to fix, because they are engineered and they are not going anywhere. An emergency bus, a standby diesel, a UPS-backed distribution panel: each of those is a defined operating mode that exists in the drawings. A study can and should produce incident energy and boundary values for each of them. Where a facility has an emergency system that is designed to pick up load on a utility outage, the hazard values for the generator-fed alignment are as legitimate a study deliverable as the utility-fed ones. They are simply another normal state.
Temporary sources are harder, because they are procured by the turnaround team rather than the engineering team, and they arrive with a schedule rather than a model. A 2 MW rental unit tied into a bus is an engineering change to the electrical system. NFPA 70E 130.5 requires the arc flash risk assessment to be updated when a major modification takes place, and reviewed at intervals not exceeding five years; CSA Z462 carries the equivalent requirement in Canada. The five-year clock is the part everyone remembers. The modification trigger is the part that matters during an outage.
This is a specific instance of a broader pattern in label currency. At one large Alberta fertilizer facility, roughly 1,700 arc flash labels are under active management and about a third of them require updating in a given year, because the plant keeps changing between studies. Alternate source configurations are the sharpest version of that: the change is deliberate, it is documented somewhere, and it is reversed a few weeks later, which is exactly why it rarely reaches the label.
Why one conservative label is not the answer
The obvious response to two operating modes is to print the worse of the two numbers and be done with it.
That has a cost, and it is not a paperwork cost.
If the generator-mode value is 35 cal/cm² and the utility-mode value is 8, a single worst-case label puts a crew into arc-rated gear appropriate to the generator case every day of the year, including the fifty weeks when the plant is on utility power. That means heat stress in summer, restricted mobility in tight cabinets, reduced peripheral vision through a hood, and a slower job. Every one of those is its own hazard, and workers who believe a requirement is disproportionate to the actual condition tend to find ways around it.
Over-protection and under-protection are both failures of the same thing. The objective is not the highest number. It is the correct number for the mode the system is actually in when the work is done.
That is a hard requirement to satisfy with a printed sticker, which is why sites that take it seriously usually end up with either two physical labels and a procedural rule about which one applies, or a label that resolves to a live record.
The second question: what stays energized
Mode-aware hazard values solve the PPE question. There is a separate question that alternate sources introduce, and it is the one with the worse failure mode.
Outage planning is normally framed as what goes dark. Open this breaker, lose these loads, notify these operators. With an alternate source in the system the more important question inverts: when that breaker opens, what stays alive, and by what path.
A backfeed that was installed to keep a control room powered can energize a section of switchgear that everyone on the job believes is isolated. The single line diagram shows the normal alignment. The temporary cable does not appear on it. Confirmation that the section is dead comes down to somebody remembering, which is the least reliable control in the hierarchy and the one being relied on at the exact moment precision matters.
Any credible treatment of alternate sources has to answer both questions: which equipment is energized right now and by which source, and what hazard values apply to it in that state.
What a mode-aware label programme looks like
Five things, in order of how much they cost to do:
- Enumerate the credible operating modes for each bus. Normal utility, emergency bus, each engineered alternate alignment. Most facilities have fewer than they fear.
- Get study values for each of them. Ask for it at the scoping stage of the next study rather than as a change order during the outage.
- Treat temporary generator connections as engineering changes. A rental unit above a threshold your engineering group sets gets modelled before it is energized, not after.
- Decide how the field sees the right number. Two physical labels with a clear rule, or a QR label that resolves to a record that knows the active source. What does not work is one label plus a verbal briefing.
- Log the state changes. When the alternate source went live, which equipment it fed, and when it came off. If an incident happens during an outage, the question asked afterwards is what information was in front of the worker at the time, and that question is answerable only if somebody recorded it.
The first three of those are engineering work. The last two are a records problem.
It is the records half that we spend our time on at Aasgard. TagSafety already treats the physical label as a pointer rather than a document: the sticker is printed once, and the engineering record it resolves to is the thing that changes when the plant does. Extending that idea to alternate sources, so that a defined AES configuration can be switched on and the equipment attached to it presents its generator-mode values for as long as that source is live, is the direction we are working in. It is not something we are claiming as finished today.
What is worth saying now is the part that does not depend on any software. The engineering has to exist first. A study that models only the utility-fed case cannot produce a correct generator-mode number no matter what system stores it. The value of a live record is that it closes the distance between engineering that already exists and the person standing in front of the cabinet at two in the morning during a turnaround. It is not a substitute for the engineering, and any vendor who suggests otherwise is selling you the wrong thing.