Retiring the inspection workbook at a combined-cycle plant
A combined-cycle inspection workbook stops being trustworthy the moment two people edit it and a typed constant appears in a formula column. Replacing it means moving the calculation, not just the list: readings stored immutably, minimum thickness and remaining life computed from a versioned rule, overrides recorded with a reason and an owner, and any past number re-derivable exactly as it stood on the day the decision was made.
Combined-cycle plants sit under a different code family than refineries, and the workbook usually does not know it. Power piping is ASME B31.1 and the boiler and HRSG pressure parts are ASME Section I, with in-service repairs and alterations administered through the National Board Inspection Code and a jurisdictional inspector, not through API 510 or 570 unless the owner has voluntarily adopted them. The damage mechanisms are cycling mechanisms: flow-accelerated corrosion thinning LP economiser and evaporator tubing, thermal fatigue at harp tube-to-header attachment welds, attemperator liner damage and downstream pipe cracking after spray events, creep and dissimilar-metal-weld degradation at Grade 91 to Grade 22 transitions. Major inspection intervals are counted in equivalent operating hours and factored starts rather than calendar years, and a two-shifting unit accumulates them in a pattern a date column cannot express. Findings are executed in a short outage window months after they are raised.
Source: Written against ASME B31.1 power piping, ASME Boiler and Pressure Vessel Code Sections I, V, VIII and IX, the National Board Inspection Code NB-23 for in-service repairs and alterations, OSHA 29 CFR 1910.119 process safety management including the mechanical integrity requirement to correct equipment deficiencies before further use or in a safe and timely manner, API RP 571 damage mechanisms, and API 579-1/ASME FFS-1 fitness-for-service.
| Failure in the workbook | How it looks on screen | What it does to the number | What to ask for in the demo |
|---|---|---|---|
| Typed constant sitting in a formula column | A plausible value, formatted exactly like its neighbours | Remaining life stops responding to new readings; the row freezes at a comfortable answer | Highlight every value in this calculation that was entered rather than derived |
| Approximate-match lookup against a re-sorted tab | A minimum thickness appears; it is simply the wrong one | Margin is over- or under-stated by a whole pipe schedule, consistently and invisibly | Change one component's material or size and show every downstream number that moves |
| Drawing nominal used as the corrosion baseline | A clean rate column with no baseline shown | Overstates loss on mill-tolerance-heavy pipe and understates it on anything replaced mid-life | Show the baseline reading, its date and who set it, for a component replaced last outage |
| One corrosion rate maintained instead of two | A single rate, almost always long-term | A recent step change in an economiser circuit is averaged away across ten years of history | Show long-term and short-term rate side by side, and which one drove the interval |
| Four copies of the workbook on the share drive | Filenames ending rev2, JS, final | Two engineers quote different remaining life for the same panel in the same meeting | Re-derive last year's interval decision exactly as it stood on the date it was made |
| Silent overwrite in a co-authored file | No visible change whatsoever | A reading is replaced with no record that the original ever existed | Edit a stored reading and show the prior value, the timestamp and the reason captured |
The workbook is not a list, it is a calculator
Almost every plant that describes itself as outgrowing spreadsheets is describing two different artefacts at once. There is a list of findings, which a spreadsheet handles badly but survivably, and there is a calculation, which a spreadsheet handles in a way that is quietly unsafe. The list is what people complain about. The calculation is what actually breaks.
The workbook takes thickness readings, subtracts them from something, divides by an elapsed time to get a rate, compares the result with a minimum thickness looked up from another tab, and produces a remaining life and a next examination date. Those numbers then drive outage scope, spare purchasing and, on occasion, a decision to run a unit through another summer. They are engineering outputs presented as spreadsheet cells.
Once more than one person edits the file, the calculation loses the property that made it acceptable: you can no longer state, with evidence, how any given number was produced. That is the real threshold being crossed, and it is why moving the list into a database while leaving the calculation in Excel solves the visible problem and none of the important one.
Where the numbers actually go wrong
The failures are specific and repetitive. Someone types a value over a formula, usually for a good reason at the time, and the cell keeps its formatting so nothing looks unusual; from that moment the row is frozen and no longer responds to new readings. A lookup against a nominal-thickness tab uses approximate match, someone re-sorts the tab, and every minimum thickness shifts to the adjacent size without a single error appearing.
The baseline is the other reliable source of error. Corrosion rate computed from drawing nominal minus current reading overstates loss on pipe that was delivered at the thick end of mill tolerance, and understates it badly on anything replaced mid-life, because the replacement's real starting thickness never entered the sheet. Both errors are invisible in the output and only surface when someone cuts a component out and measures it.
Then there is the version problem, which is not a calculation error at all but produces the same result. Four files on a share drive, distinguishable only by a suffix somebody added in a hurry, and two engineers in the same meeting quoting different remaining life for the same tube panel. Nobody is wrong; they are reading different files, and there is no mechanism that could tell them so.
Long-term and short-term rates, and the one the workbook forgets
In-service inspection practice expects two corrosion rates: a long-term rate from the original or baseline reading, and a short-term rate from the most recent previous reading, with the more conservative of the two governing. Spreadsheets almost always maintain one, and it is almost always the long-term rate because it is the easier formula to write once and copy down.
In combined-cycle service that omission has a name. Flow-accelerated corrosion in LP economiser and evaporator circuits is strongly sensitive to chemistry, temperature and velocity, and a change in any of those, a switch in amine, a modification to feedwater treatment, a change in dispatch pattern that alters flow, can move the rate by a large factor within a single year. Averaged across ten years of history, that step change disappears completely.
The system should compute both rates from stored readings, show which one governed the interval, and flag divergence between them as a condition worth an engineer's attention. That flag is one of the few genuinely predictive outputs available from routine thickness data, and it is exactly the output a single-rate spreadsheet is structurally incapable of producing.
Which code owns your piping, and why it changes the rule
Power plants routinely import refinery inspection habits along with the engineers who learned them, and the workbook inherits assumptions that do not apply. Power piping is designed and built to ASME B31.1, not B31.3. Boiler and HRSG pressure parts fall under ASME Section I, and their in-service repairs and alterations run through the National Board Inspection Code with a commissioned jurisdictional inspector, an R-stamp holder and a documented repair plan.
B31.1 does not carry the in-service interval framework that API 570 provides for process piping. Where a plant applies API 510 or 570 methodology to balance-of-plant equipment, it is doing so as an owner decision, and that decision has scope boundaries which people forget within about two years of making it. A system that records which regime governs each equipment class removes an argument that otherwise recurs at every outage.
This matters to the deficiency register concretely, because the disposition path differs. A finding on a Section I pressure part heads toward a repair plan and an inspector sign-off; a finding on a non-code service line heads toward maintenance. Recording the governing code on the asset means the workflow routes itself, instead of relying on someone recognising which kind of pipe they are looking at.
Cycling duty means the clock is not a calendar
A combined-cycle unit that two-shifts accumulates damage in a pattern that annual thinking cannot represent. Gas turbine inspection intervals are counted in equivalent operating hours and factored starts, with starts weighted heavily because the thermal transient does the damage. A unit dispatched for short peaking runs reaches a hot gas path inspection on starts long before it approaches it on hours, and a register keyed to a calendar date will be wrong in both directions across a fleet with mixed duty.
The damage mechanisms follow the same logic. Thermal fatigue cracking at HRSG harp tube-to-header attachment welds is driven by ramp rates and start counts. Attemperator damage, liner cracking and downstream pipe fatigue arise from spray events during transients rather than from steady operation. Creep in HP superheater and reheater tubing accumulates with hours at temperature, so a unit that runs hard in summer and sits in spring has two mechanisms advancing on two different clocks simultaneously.
The register should accept an interval expressed in hours, starts or calendar time, read the operating counters, and forecast the due date rather than storing one. That single capability changes the outage planning conversation, because the forecast moves when dispatch changes, and the change is visible months before it becomes a surprise.
The register is really the outage scope document
Findings at a power plant are not closed continuously. They are closed in a defined window that arrives once a year or once every few years, and between raising and closing there may be ten months in which the only thing preserving the finding is the register. A workbook that nobody trusts loses items in that interval, and the loss is discovered during the outage when a scope item that everyone remembers discussing turns out never to have made it onto the list.
That reframes what good looks like. The register's job is not primarily to report a backlog number; it is to accumulate a defensible scope, with each finding carrying the evidence, the assessment, the parts required, the access required and the estimated duration. When scope freeze arrives, the outage list should be generated from the register rather than assembled from it, and items deferred out of scope should be deferred as recorded decisions with a named approver.
The follow-through matters equally. Work executed during an outage generates repair records, replacement components with new baselines, and re-examination results, and all of those have to land back on the finding before the plant returns to service. A system where post-outage close-out is a separate spreadsheet has simply moved the original problem two months later in the year.
The ammonia system quietly changes the compliance picture
Many combined-cycle plants hold aqueous ammonia on site for selective catalytic reduction, and at typical inventories that can bring the plant within the scope of the OSHA process safety management standard. Plants that fall in scope frequently do not think of themselves as process safety sites, and their inspection practice reflects that until an audit says otherwise.
The relevant consequence for a deficiency register is direct. Under the mechanical integrity provisions, equipment found to be outside acceptable limits must be corrected before further use, or in a safe and timely manner where interim measures assure safe operation. That converts a deferral from an operational judgement into a documented determination: what the acceptable limit was, why continued operation is safe, what interim measures apply and who authorised them.
A spreadsheet status of deferred does not meet that expectation and cannot be made to. The system needs a deferral record on covered equipment that requires an engineering basis, an interim-measures statement and an approver, and it needs to be able to produce those records for a nominated date range on request. This is a small amount of configuration that removes an entire category of audit finding.
Keeping what the engineers liked about Excel
Spreadsheet replacements fail for a predictable reason. The workbook was not only a record, it was a thinking tool, and an engineer who could answer a novel question in fifteen minutes on a Tuesday will not accept a system that requires a change request to add a column. If the replacement removes that capability, a shadow workbook appears within a quarter, and the plant is back where it started with an extra licence.
The resolution is to separate authority from analysis. The system holds the readings, the calculations, the versions and the audit trail, and it is the only place a number becomes official. Alongside it, engineers get a live export or a query view they can pull into whatever tool they like, for scenario work, one-off correlations and the pattern-hunting that no product roadmap anticipates.
What changes is the direction of flow. Analysis reads from the system rather than the system reading from analysis, and nothing computed in a personal workbook can become the authoritative answer without being written back through a recorded, attributed action. Engineers keep their Tuesday afternoon; the plant stops inheriting it.
How to evaluate the replacement
Do the evaluation on your own data and run the six tests in the table above. Five of them take a minute each, and together they separate a product that owns the calculation from a product that owns a list and calls the calculation an integration. The one that takes longer, re-deriving a past number as it stood on a past date, is the one worth insisting on, because a system that cannot do it has not really replaced the workbook.
Bring the awkward cases too. A component replaced mid-life with a new baseline. A circuit whose short-term rate diverges from its long-term rate. A finding on a Section I pressure part that needs a repair plan and an inspector. An interval expressed in factored starts. Those four cover most of what a combined-cycle plant does that a generic inspection module was not designed for.
Atlantis builds this module on Odoo from an operating NDT and integrity practice, so the calculation rules are inspectable configuration rather than a sealed black box, and existing workbooks are migrated with their history and baselines intact rather than restarted. Atlantis NDT is affordable, accessible and fully customisable; send a sanitised copy of the workbook you want to retire to info@atlantisndt.com and ask for the six tests to be run against it.
Why is a typed constant in a formula column so much worse than a wrong formula?
A wrong formula is wrong everywhere and gets caught. A typed constant is wrong in exactly one row and looks identical to its neighbours, so it survives review indefinitely. It also breaks the feedback loop: the cell no longer responds to new readings, so the component appears stable precisely because nobody is calculating it any more. In inspection workbooks this is the most common integrity failure, and the hardest to find by eye.
Does ASME B31.1 change how intervals are set compared with refinery practice?
It changes who sets them. B31.1 is a construction and design code for power piping; it does not contain the in-service inspection interval machinery that API 570 provides for process piping. Jurisdictional oversight of the boiler and HRSG pressure parts runs through Section I and the National Board Inspection Code with a commissioned inspector. Many owners adopt API practice voluntarily for balance-of-plant piping, but that is an owner decision the system must record, not a regulatory default.
What does re-deriving a past number actually require?
Three things the workbook does not have. Readings must be immutable, so the values that existed on that date are still recoverable. The calculation must be versioned, so the rule applied then is distinguishable from the rule applied now. And overrides must be events with timestamps rather than edits. With those, the system answers what the remaining life was on a stated date and why, which is the question that arrives in a dispute or an audit.
How do equivalent operating hours and factored starts fit into a deficiency register?
They become an alternative clock. A cycling unit accrues turbine inspection liability by starts far faster than by hours, and a finding whose next examination is due at a factored-hours milestone cannot be tracked by a calendar date without constantly being wrong. The register should accept an interval expressed in hours, starts or calendar time, take the operating counters as an input, and forecast the due date rather than storing a static one.
Why does the aqueous ammonia system matter to inspection tracking?
Because it can bring the plant within process safety management scope, and PSM treats deficiency correction as a compliance obligation rather than a good practice. Equipment found outside acceptable limits must be corrected before further use, or in a safe and timely manner where interim measures assure safe operation. That means a deferred finding on covered equipment needs a documented basis and documented interim measures, which a spreadsheet status column does not provide.
What replaces the flexibility engineers liked about the workbook?
Read access and export, deliberately. Engineers used Excel because it let them ask an unplanned question on a Tuesday afternoon, and taking that away is how a replacement gets abandoned. The system owns the record of truth and the calculation; the engineer keeps a live export or API view for ad-hoc analysis. What changes is that nobody's Tuesday afternoon workbook becomes next year's authoritative source.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.