An alarm needs a named owner, not just anyone who happens to see the screen
Aliases: alarm ownership · alarm owner
What it is
An alarm owner is a role accountable for the first assessment, response, or escalation of a given class of alarm — not simply "anyone who can see it." Putting the same alarm view in front of several workstations solves visibility; it does not answer who acts first. Shared visibility without a named owner tends to make everyone assume someone else has it.
Why it happens
The path from an alarm firing to it being handled needs an explicit commitment point: who accepts it, who executes, who it escalates to on timeout. If that commitment point is left to rest on "the alarm display is on a shared screen everyone on shift can see," responsibility gets diluted rather than reinforced as the number of people who can see it grows. This mirrors the pattern social psychology describes as diffusion of responsibility: when several people are simultaneously capable of responding with no assigned division of labor, each observes the same signal and estimates the same probability that "someone else is handling it," and the net effect is that everyone waits for confirmation before acting, which lengthens the overall response rather than shortening it. That is also why broadcasting an alarm to more people does not by itself speed up response — only defining who currently owns it does. The condition reverses when a role is already narrowly specialized and only one position can act on a given alarm class (only the electrical desk can operate a certain interlock, say); single-role visibility is not a risk there, because the division of labor has already answered the ownership question implicitly.
Studying it
Delays caused by unclear alarm ownership are hard to reproduce directly in a lab; the more common evidence comes from reviewing past incidents and near-misses — checking shift logs, alarm acknowledgement timestamps, and operator interviews to establish whether a delayed response happened because several people on duty each saw the same alarm and assumed the other would act, or because the alarm itself crossed a shift or discipline boundary and was dropped at handover. This kind of review depends on a plant's own incident investigation record rather than a general experimental paradigm, so conclusions have to be scoped to the specific control-room configuration and crew structure investigated and should not be assumed to transfer to a site organized differently.
Where it stops holding
- Ownership should not be hard-coded to a named individual regardless of shift roster, leave, or temporary absence; if it is, the alarm becomes effectively unowned the moment that person is off duty.
- Assigning a single owner should not be used to eliminate mutual monitoring altogether — a backup role is still needed for the case where the owner is incapacitated or occupied elsewhere.
- Compound faults spanning disciplines or areas may require the primary role to shift mid-response; a fixed assignment table does not cover this, and an explicit hand-off confirmation is needed rather than assuming the original owner keeps carrying it.
- In a single-operator control room, "who handles it" was never ambiguous, and layering acceptance, transfer, and escalation logic onto that setting just adds workload. The whole criterion only matters when more than one role capable of responding is on duty at the same time.
Applying it
Pre-assign a primary and backup role for each alarm class by operating mode (startup/shutdown, steady state, maintenance) instead of negotiating it after the alarm fires; the display should show whether the alarm has been accepted, by whom, and how much time remains before timeout escalation. The escalation target cannot be a vague title like "the shift lead" — it has to resolve to a specific next role and contact path, or the escalation itself reproduces the same ownership ambiguity it was meant to fix. At shift handover, unresolved alarms should be a mandatory line item on the handover checklist rather than something the next shift discovers on its own. How to check: run joint exercises with scenarios such as an absent role, simultaneous alarms, or a cross-area fault, and verify that a specific role takes clear ownership within the response window without ad hoc human coordination — rather than everyone present watching to see who moves first.