Deriving the next API 570 date on a midstream system, without the workbook
A remaining life and interval engine derives the next API 570 date for each midstream circuit from stored data: corrosion rate per CML, remaining life against a defined t-min, then one-half that life capped by the class maximum. The planner approves rather than types. Every input, exclusion and override is versioned, so any date can be reproduced years later.
Midstream piping is where derived intervals earn their keep, because the population is large, the corrosion rates are small, and the consequence of a wrong t-min is a release into a watercourse rather than a leak onto a bund. API 570 asks for one-half remaining life, capped by the class maximum in its interval table, with a separate provision when remaining life falls under four years. That is arithmetic a spreadsheet can do. What a spreadsheet cannot do is tell you, three years later, which readings fed the rate, which were excluded as datum errors, what t-min was in force at the time, and who approved the override. A gathering system with 4,000 CMLs across 300 circuits accumulates every one of those questions before its first serious audit. The engine has to answer them from stored state, not from a formula rebuilt on the morning it is asked.
Source: Calculation logic follows API 570 (Piping Inspection Code) for thickness measurement intervals, remaining life and t-min; API 574 for inspection practices and CML placement; API 571 for damage mechanism identification; ASME B31.3 for process piping pressure design thickness and B31.4 / B31.8 for liquid and gas transmission; API RP 580 and 581 for risk-based interval setting; and 49 CFR Parts 192 and 195 where a line is jurisdictional transmission or hazardous liquid service.
| Decision point | Shared spreadsheet behaviour | Derived interval engine behaviour |
|---|---|---|
| Corrosion rate selection | Whichever of short-term or long-term the last editor left in the cell; often overwritten with a typed constant | Both rates computed and stored; the governing rate selected by a stated rule, with the non-governing rate retained for review |
| Reading rejected as a datum error | Deleted, or the row hidden; no trace of why | Flagged as excluded with reason code, author and timestamp; the reading stays in the record and can be reinstated |
| t-min in force | One column, edited in place when a re-rate happens; history lost | Versioned with an effective date, so a 2023 interval recomputes against the 2023 t-min |
| Interval shorter than the code cap | Manually shortened, basis in an email | Shortened by rule or by a recorded engineering decision that names the mechanism and the approver |
| Reproducing a past due date | Impossible once the file has been saved over | Recomputed from the data and rule set as they stood on that date |
| Two people editing at once | Last save wins; a formula silently becomes a value | Field-level change history; concurrent edits reconciled, not overwritten |
The workbook fails at the second editor, not the thousandth row
A thickness workbook is stable for as long as one person owns it. That person remembers that column AJ is a typed override rather than a formula, that the three rows shaded amber were excluded because the technician measured a fitting instead of the pipe, and that the tab named FINAL_v3_rev2 is the one the schedule is built from. None of that knowledge is in the file. It is in one head, and it leaves when that person does.
The moment a second planner opens the same file, the arithmetic starts to drift in ways nobody detects. A formula gets pasted over with the value it happened to produce, so the cell stops responding to new readings. An autofilter is left on, and a summary below it silently excludes half the circuits. Someone sorts a block of readings without extending the selection, and CML identities detach from their measurements. The file still opens, still calculates, and still produces a plausible date.
What breaks first is not the number, it is the ability to explain the number. The question that arrives from a client integrity manager, an insurer or a regulator is rarely "what is the interval". It is "show me how you got there". A shared workbook has no answer to that question because it stores only its final state, and its final state was produced by an unrecorded sequence of human edits.
What API 570 actually asks you to compute
The code does not hand you an interval. It hands you a procedure. You establish a corrosion rate for the condition monitoring location, on both a short-term and a long-term basis. You compute remaining life as the difference between the current thickness and the required minimum thickness, divided by that rate. You then set the thickness measurement interval at one-half remaining life, subject to the maximum for that piping class, and you apply the code's separate provision for circuits whose remaining life has fallen below four years.
Each step contains a choice the code deliberately leaves to the owner-user. Which rate governs when short-term and long-term disagree. Whether the long-term rate is anchored on nominal thickness or on the first reliable measurement. Whether a CML's remaining life or the circuit's most limiting CML sets the circuit interval. Whether a corrosion rate can be carried across from a similar circuit when no history exists. These are all legitimate positions, and an engine has to let you configure them once, apply them everywhere, and show which one was in force.
The consequence of leaving those choices implicit is that they get made differently on every circuit, by whoever was working that week. That is not a compliance problem in the abstract. It is the reason two circuits in identical service on the same skid end up with a four-year and a ten-year interval, with nothing on file that explains the difference.
Midstream constraints that change the calculation
Midstream is not a refinery with longer pipe. The population is dispersed across gathering lines, compressor and pump stations, meter runs, tank farms, truck racks and pig traps, most of it unmanned and visited on a route. Corrosion rates are generally low and the mechanisms are localised: water hold-up at low points and long sags, top-of-line corrosion in wet gas where condensation forms, microbiologically influenced attack in produced water and hydrotest residue, under-deposit corrosion at dead legs, and soil-side loss at the air-to-soil interface where an above-ground line enters grade.
Low general rates make the arithmetic fragile. When true wall loss is 1 to 2 mpy, measurement uncertainty is the same size as the signal, and every reading has to be trusted before it is allowed to move a date. High-consequence localised loss means that a circuit average is actively misleading; the engine has to hold remaining life at the CML level and let the most limiting location drive the circuit, rather than reporting a comfortable mean.
The jurisdictional split is the constraint most likely to be mishandled in software built for plant piping. On the same station site you can have Part 192 or 195 regulated line pipe, whose reassessment intervals come from an integrity management programme and in-line inspection, sitting immediately upstream of station piping that is out of that scope and governed by API 570. An interval engine that does not model which rule applies to which segment will confidently apply the wrong one, and the record will look tidy while it does so.
The arithmetic traps that survive a migration
Moving off a spreadsheet does not, by itself, fix the arithmetic. Most of the traps travel with the data, and some become harder to see once they are behind a user interface. The most common is averaging: a CML measured at four clock positions is reduced to a mean, which hides the one grid point losing metal three times faster than its neighbours. The mean is the number that gets stored, and the localised loss disappears permanently on the day of import.
The second is the baseline. Long-term rate anchored on nominal thickness assumes the pipe was delivered at nominal, which mill tolerance says it was not; on thin-wall gathering pipe, a permitted 12.5 percent under-tolerance is larger than a decade of corrosion. Anchoring on the first measured reading is usually more honest but hides any loss that occurred before that reading. Whichever you choose, the engine must record which, because the two produce materially different lives.
The third is precision loss on import. Contractor data reported to two decimal places in millimetres cannot resolve a 1 mpy rate over a five-year interval. Rounding at the point of ingest is irreversible, and no amount of subsequent processing recovers the resolution. Any system that stores the accepted value without also storing the raw submission has thrown away the only evidence that would let you re-examine the decision later.
t-min is not one number, and it moves
Remaining life is a subtraction, and the term most often wrong is the one being subtracted. Required minimum thickness can be the pressure design thickness from the applicable code, a structural minimum for the diameter and support span, a value derived from a re-rated MAWP, or a retirement thickness set by owner-user policy above all of them. These are not interchangeable, and on small-bore lines the structural minimum routinely governs over the pressure calculation, which many workbooks never compute at all.
t-min also changes over the life of the circuit. A line is re-rated, a support is removed and the span grows, a branch is added, service changes from sweet to sour, or a temporary repair becomes permanent. Each of those events changes the target of the subtraction, and therefore every remaining life and every interval computed against it. A workbook edits the number in place and loses the previous value. That makes historic intervals unverifiable, because you can no longer show what the calculation was aiming at.
An engine has to hold t-min as a versioned attribute with an effective date and a stated basis, and it has to recompute forward when a new version is issued, flagging any circuit whose interval shortens as a result. The recomputation is the point. A re-rate that quietly leaves 200 old due dates in place is the single most common way a compliant-looking plan becomes non-compliant without anyone touching it.
What the record has to hold to be reproducible
Reproducibility has a precise technical meaning here, and it is stronger than an audit log. It means the system can be asked what the next inspection date for a circuit was on a given past date, and can answer using the data that existed then and the rules that were in force then, not today's data run through today's rules. Systems that store only current state can show you what changed; they cannot show you what you believed at the time, which is exactly what a dispute turns on.
That requires the engine to version four separate things: the readings, with their exclusions and reasons; the asset attributes including t-min and piping class; the rule set that selects rates and caps intervals; and the human decisions, each carrying an identity, a timestamp and a stated basis. Any override that shortens or extends an interval should be a first-class record with an expiry, not a free-text note in a comment field that no report ever reads.
The practical test is simple to run and hard to fake. Pick a circuit with a re-rate and an excluded reading in its history. Ask the system for its due date as of two years ago, then ask it to show the readings and the t-min that produced that date. If the answer requires someone to open a spreadsheet, restore a backup, or reason about it, the system is storing outcomes rather than derivations, and it will fail the same question in front of an auditor.
Evaluating a vendor when the workbook is the incumbent
Demonstrations are usually run on clean sample data, which is where every product looks the same. Insist instead on a loaded demonstration using two or three of your own circuits, chosen for their mess: one with a re-rate, one with a suspected datum error, and one with a short-term rate that disagrees violently with its long-term rate. What you are testing is not whether the software can divide, it is how it behaves when the inputs are contradictory.
Ask what the system does the moment it disagrees with your current plan. A credible engine surfaces every circuit whose derived date is earlier than the planned date, quantifies the exposure, and requires a recorded decision on each rather than silently adopting the safer or the more convenient number. Ask what happens when a corrosion rate cannot be computed at all, because a CML has only one reading. If the answer is a blank date rather than a code-maximum default with a flag, it will populate your plan with holes.
Then test migration honestly. Import a circuit and reconcile the derived interval against the workbook's number circuit by circuit, expecting differences and requiring an explanation for each. The differences are the value of the exercise; they are the accumulated undocumented decisions in your current file made visible. A vendor who wants those differences suppressed to make the migration look clean is selling you the same problem in a nicer window.
Why does one-half remaining life produce different answers in two spreadsheets built from the same readings?
Because the divisor is a choice, not a constant. One workbook anchors the long-term rate on nominal thickness, the other on the first measured reading. One uses the greater of short-term and long-term rate, the other averages them. One computes remaining life to pressure design thickness, the other to nominal minus corrosion allowance. Each choice is defensible in isolation, and together they can move a due date by five years on the same circuit.
How should the engine treat a negative corrosion rate on a midstream CML?
It should never silently take zero and grant an unlimited life. A wall reading thicker than the last one usually means the probe landed off datum, the coating was included, or a different instrument was used. The correct handling is to flag the pair, fall back to the long-term rate anchored on the earliest reliable reading, and raise a data query against the CML. What matters for audit is that the rule is stated, applied uniformly, and recorded on the record it affected.
Does a jurisdictional transmission line get its interval from API 570?
No. A line under 49 CFR Part 192 or 195 takes its reassessment intervals from the integrity management rule and the operator's written programme, driven by in-line inspection, pressure test or direct assessment. API 570 governs the process piping that is out of that scope: station, terminal, meter and manifold piping. The trap is a pump station where both live inside the same fence, and one interval rule gets applied to all of it.
What does measurement noise do to a two-point short-term corrosion rate?
It manufactures corrosion that is not there. If instrument and operator repeatability is around 0.005 in and two inspections are two years apart, the arithmetic alone can produce roughly 2.5 mpy of pure noise before any metal is lost. On a midstream circuit whose real rate is 1 to 3 mpy, that noise dominates the signal. The engine has to hold a repeatability threshold per CML and refuse to shorten an interval on a change smaller than it.
How are injection points and dead legs handled differently?
They are treated as their own circuits, not averaged into the parent. Injection points concentrate localised attack downstream of the quill, and dead legs collect water and solids where flow does not reach, so both corrode at rates that bear no relation to the circuit's general wall loss. Rolling them into a circuit average is the mechanism by which a spreadsheet reports healthy remaining life on a system that is about to leak at a low-point drain.
Is API 510, 570 or 653 inspector certification training part of this offer?
No. Atlantis does not deliver API inspector certification training, and the interval engine does not substitute for a certified inspector's judgement. What Atlantis provides is NDT training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD, ASNT Level III consulting, inspection management and reporting software, digital twins, 3D laser scanning and report validation. API certification stays with an accredited API training provider.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.