How a Strained Grid Decides Who Loses Power, and Which Circuits It Cannot Touch

On a grid running short of supply, some customers lose power and others do not, and the boundary between them is not drawn where most people assume. It is not drawn by neighborhood, by how much anyone pays, or by who called the utility first. It is drawn by which distribution circuit an address happens to sit on, and by which of two entirely separate mechanisms is doing the shedding at that moment.

Those two mechanisms are worth separating carefully, because coverage of any given shortage tends to blur them into one event. One of them is a chain of declarations made by people, ending in a utility opening breakers it selected in advance. The other is a set of relays that watch system frequency and act without asking anyone. They produce a similar outcome — load disconnected — through completely different logic, on completely different timescales, and with completely different rules about who is spared.

The directed path runs on definitions

The escalation is not improvised. It follows a reliability standard, EOP-011-4, written by the North American Electric Reliability Corporation and enforceable across the interconnections. The standard defines three Energy Emergency Alert levels, and each one is a statement about reserves rather than about how hot it is outside.

EEA 1 is declared when all available generation resources are committed to meet firm load, firm transactions, and reserve commitments, and the balancing authority is concerned about maintaining required contingency reserves. Nothing has been disconnected. The system is simply out of spare capacity to commit.

EEA 2 is declared when the balancing authority cannot provide its expected energy requirements and has become energy-deficient. It has implemented its operating plans to mitigate the emergency, and is still holding minimum contingency reserves. The operating plans referenced here are the ones each balancing authority is separately required to maintain; the conservation appeals and demand response calls familiar from news coverage live in those plans rather than in the alert definition itself.

EEA 3 is declared when firm load interruption is imminent or in progress, and the energy-deficient balancing authority is unable to meet minimum contingency reserve requirements. The standard directs that the balancing authority immediately take whatever actions are necessary to mitigate undue risk to the interconnection, and states plainly that those actions may include load shedding.

The word firm is doing heavy work in that definition. Firm load means ordinary customers who bought ordinary service, as distinct from interruptible load, which is service sold on the understanding that it can be cut. The standard does not rank the two against each other directly, but it does require that before requesting an EEA 3 the energy-deficient balancing authority make use of all available resources, a list that expressly includes activating demand-side management within the provisions of any applicable agreements. What EEA 3 records, then, is that those resources have been drawn on and firm load interruption has become imminent or has already begun.

Two ways load leaves a strained gridOne path runs through people and paperwork. The other runs through relays.DIRECTED — humans decideEEA 1All available generation committed. Reserves at risk.EEA 2Energy-deficient. Load management in effect.EEA 3Firm load interruption imminent or in progress.Rotating outages beginUtility opens pre-assigned distribution circuitsAUTOMATIC — frequency decides60.0 HzNominal. Relays armed, nothing acts.59.3 HzFirst stage trips. 5 percent of load.58.9 HzSecond stage. A further 10 percent.58.5 HzThird stage. A further 10 percent.No operator is consulted at any step on this side.Alert definitions: NERC Reliability Standard EOP-011-4, Attachment 1.Frequency stages: ERCOT, Maintaining Grid Security.

The automatic path runs on frequency, and does not wait

Running underneath the alert ladder is a second system that has no interest in alert levels. Alternating-current grids in North America run at a nominal 60 hertz. Frequency is the running record of whether generation matches demand: when demand exceeds generation, the spinning machines that make the power slow down, and frequency falls.

Under-frequency load shedding relays are installed at substations and armed continuously. They are set to trip at specific frequencies, and when frequency crosses a setpoint the relay opens and load is disconnected. In the ERCOT interconnection, the published stages are five percent of load at 59.3 hertz, a further ten percent at 58.9 hertz, and a further ten percent at 58.5 hertz — up to twenty-five percent of system load, disconnected automatically.

Two figures are worth pulling out of that table, because they are not printed alongside it.

The first is how narrow the band is. The first stage trips 0.7 hertz below nominal, a little over one percent off frequency. The whole span from first stage to last is 0.8 hertz — about 1.3 percent of nominal. Everything the automatic system will ever do, it does inside a window barely more than one percent wide.

The second is that the band resists being averaged. It is tempting to divide load shed by frequency span and quote a rate — so many percent of load per hertz — but the answer depends on two separate choices, and neither is obvious. Measuring from nominal down to the last stage gives 25 percent over 1.5 hertz, or about 16.7 percent per hertz. Measuring from just above the first setpoint gives 25 percent over 0.8 hertz, or about 31.3 percent. Measuring between the first and last stages, which excludes the five percent already shed at the top, gives 20 percent over the same 0.8 hertz, or 25 percent per hertz. The span moved in one comparison and the numerator moved in the other, and the spread between the extremes is close to twofold.

None of those rates describes the mechanism, because it is a staircase rather than a ramp. Nothing at all happens between 59.3 and 58.9 hertz, and then ten percent of system load goes at once. A rate implies that a small additional decline costs a small additional amount of load, and that is precisely what a step function does not do.

Frequency is useful as a control signal precisely because it is not local. Voltage sags near the problem; frequency is a property of the whole synchronous interconnection at once. Every large generator on it is mechanically locked to the same rhythm, and the energy stored in those spinning masses is what absorbs a sudden imbalance in the first instants. When demand exceeds what is being generated, that stored rotational energy is drawn down to cover the difference, and drawing it down is the same thing as slowing the machines. A falling frequency is therefore not a warning that a shortage might develop somewhere. It is a measurement that a shortage exists right now, across the entire interconnection, and that it is being paid for out of inertia.

ERCOT automatic load shedding, by frequencyCumulative share of system load disconnected as frequency falls. A staircase, not a ramp.0%5%10%15%20%25%30%60.059.559.358.958.5System frequency (Hz)5% cumulative15% cumulative25% cumulative60.0 Hz nominalSource: ERCOT, Maintaining Grid Security.Stages: 5 percent at 59.3 Hz, 10 percent at 58.9 Hz, 10 percent at 58.5 Hz.

The purpose of this system is not fairness and not customer service. ERCOT describes under-frequency load shedding as the final tool to balance the available generation and load in order to avoid a total system collapse or widespread blackout. Losing up to a quarter of the load is the cheaper failure, and the relays are configured to take it without consulting anyone.

What rotates is a circuit, not a household

When the directed path reaches EEA 3 and a utility begins rotating outages, the unit it operates on is a distribution circuit. Southern California Edison notes that a single circuit can serve up to about 2,000 customers, and that customers are assigned to rotating outage groups identified by an alphanumeric code printed on the bill — a code that does not necessarily follow streets or neighborhoods.

This is the source of a common and reasonable confusion. Two houses across a street from each other can sit on different circuits and therefore in different groups, and one will go dark while the other does not. Nothing about the two addresses differs in any way a resident can see. The relevant fact is buried in distribution topology decided years earlier.

The timing is also tighter than the alert ladder suggests. Southern California Edison states it may have as little as ten minutes after an Energy Emergency Alert Level 3 is declared before rotating outages begin, and that a mandated rotation lasts approximately one hour depending on circumstances. The escalation through EEA 1 and EEA 2 may run for hours; the last step happens faster than most notification systems can reach the people it affects.

The circuits that cannot be touched

The part of this that produces the most durable inequity is not the rotation. It is the exemption.

Essential customers — hospitals, prisons, national defense facilities and similar — are exempt from rotating outages, for reasons nobody disputes. But the exemption is granted to a customer, while the outage is applied to a circuit. A breaker that would drop a circuit is a single device. It cannot skip one address on the line.

So the exemption spreads to everything the essential customer shares a circuit with. The California Public Utilities Commission, examining rotating outage programs, recorded the scale of this: at Pacific Gas and Electric, approximately 2.0 million customers received service on a circuit exempt from rotating outage, even though fewer than 1,700 were essential customers.

Dividing two million by seventeen hundred gives about 1,176. That figure should be read as an order of magnitude and not as a measured ratio: the numerator is stated as approximate and the denominator only as an upper bound, so the arithmetic fixes neither a floor nor a ceiling. What it does establish is the shape of the thing. For every customer the exemption was written for, something on the order of a thousand others inherited it by sharing a wire.

Why exemption spreads past the customer it was written forRotation is applied to circuits. Exemption is granted to customers. Figures below come from two different utilities.ONE DISTRIBUTION CIRCUIT — up to about 2,000 customers (SCE)one essential customerThe breaker that would drop this circuit is a single device. It cannot skip one address.The entire circuit is exempt.Separately, at PG&E (CPUC): about 2,000,000 customers on exempt circuits, fewer than 1,700 of them essential.Customer and essential-customer counts: California Public Utilities Commission, Rotating Outage Programs decision.Circuit size: Southern California Edison.

The same proceeding notes a standard of keeping at least forty percent of available load available for rotating outages, which implies the remainder may sit outside the pool. Both facts point the same direction: the population that actually absorbs a rotation is considerably smaller than the population being served, so each rotation falls harder on the circuits that remain eligible.

Coming back runs on a different test

The condition that opens EEA 3 and the condition that closes it are not the same measurement. Entry is defined by reserves — the balancing authority is unable to meet minimum contingency reserve requirements. Exit is defined by energy and by operating limits. Downgrading is written into the same standard, and its trigger is a pair of conditions rather than one. EOP-011-4 provides that whenever energy is made available to an energy-deficient balancing authority such that its systems can be returned to their pre-emergency SOL or IROL condition — the system operating limits and interconnection reliability operating limits it is required to respect — the balancing authority requests that the alert level be downgraded. Energy has to arrive, and the operating limits have to be able to come back inside their normal envelope. Neither alone is the test, and note that the standard asks whether they can be returned, not whether they already have been.

What is absent from that trigger is any reference to a clock. Nothing ties the downgrade to the passing of peak demand or to a particular hour of the evening. A shortage can outlast the peak and keep its alert level. And while the alert level stands, the rotation stands with it: a circuit restored after its hour remains eligible to be taken again in a later round.

The Chain

Laid out in order, on a grid moving from tight to short:

  1. Reserves thin. All available generation is committed. EEA 1 is declared. Nothing is disconnected.
  2. The deficiency becomes real. The balancing authority cannot meet expected energy requirements. EEA 2. Operating plans run, interruptible contracts are called, conservation appeals go out.
  3. Reserves fall below minimum. EEA 3 is declared. Firm load interruption is imminent or already under way.
  4. The utility opens circuits. Pre-assigned rotating outage groups. In Southern California Edison's published procedure, roughly an hour each, potentially beginning within ten minutes of the declaration.
  5. Exempt circuits are skipped in full. Not the exempt customers — the entire circuits carrying them.
  6. In parallel, frequency is watched. If the imbalance drives frequency down regardless, under-frequency relays trip without reference to any of the steps above — in ERCOT, at 59.3, 58.9 and 58.5 hertz.

Steps one through five are a decision process. Step six is a physical protection scheme. A shortage severe enough to reach step six has, by definition, outrun the decision process.

Where This Doesn't Apply

Several boundaries limit how far this account travels.

Frequency setpoints are regional. The 59.3 / 58.9 / 58.5 hertz stages cited here are ERCOT's published values. Under-frequency load shedding programs are designed regionally, and other interconnections use different setpoints and different load percentages. The structure is general; the numbers are not.

The exemption figures are from one commission and one utility. The two-million-to-seventeen-hundred comparison describes Pacific Gas and Electric as recorded in a California proceeding. Other states define essential customers differently, and other utilities have different circuit topologies. The mechanism — exemption granted per customer, outage applied per circuit — is structural and travels; the ratio does not.

Most outages are not this at all. The overwhelming majority of power interruptions are local faults: equipment failure, weather damage, a vehicle striking a pole. Those have nothing to do with alert levels or load shedding, and are restored by repair rather than by rotation.

Not every shortage reaches load shedding. EEA declarations are considerably more common than firm load interruption. Reaching EEA 2 is not a signal that outages follow.

This is an explanation, not guidance. Nothing here describes what to do during an outage or how to prepare for one. That guidance is issued by agencies with the authority and responsibility to issue it — in the United States, Ready.gov, the Centers for Disease Control and Prevention, state and local emergency management, and the serving utility.

Sources

Alert level definitions: North American Electric Reliability Corporation, Reliability Standard EOP-011-4, Emergency Operations, including its restoration and downgrade provisions. Under-frequency load shedding stages: ERCOT, Maintaining Grid Security. Rotating outage group structure, circuit size, block duration and notification timing: Southern California Edison. Essential customer exemption counts and the load-availability standard: California Public Utilities Commission, decision on rotating outage programs.

Figures reflect the cited documents as published. Regional programs are revised periodically; the setpoints and counts above should be checked against current filings before being relied on.

Comments

Popular posts from this blog

Twenty-Three Days Before an Outbreak Is Visible, and Longer Before a Recall Notice