When the thickness workbook has two editors and nobody can reproduce the number

An offshore thickness history must store each reading as an immutable fact — date, technician, instrument, probe mode and method — never a running cell that the next campaign overwrites. Spreadsheets fail because the previous value is destroyed, so long-term corrosion rate cannot be rebuilt, a biased campaign cannot be recalled, and no two engineers reproduce the same remaining life.

Upstream and offshore intervals are set by access, not by risk. A CML behind scaffolding or on a riser reachable only by rope access may be gauged once every five or six years, so the corrosion rate is computed from two numbers separated by a long gap and burdened by measurement uncertainty. Manual pulse-echo on a rough, pitted back wall repeats to roughly plus or minus 0.1 to 0.2 mm in good hands. Sweet CO2 corrosion offshore commonly runs 0.05 to 0.3 mm per year. On a two-year interval the noise band is the same size as the signal, which is why API 570 asks for both a short-term and a long-term rate and why the long-term rate must reach back to the original construction thickness. A spreadsheet that overwrites last campaign's value deletes the only stabiliser you had.

Source: Sources: API 570 for in-service piping inspection, corrosion rate determination and the short-term versus long-term rate; API RP 574 for piping inspection practices and minimum structural thickness; API 510 for pressure vessels; API RP 580 and 581 for risk-based inspection; ASME B31.3 for process piping pressure design; NACE MR0175 / ISO 15156 for materials in H2S service; NORSOK M-506 for CO2 corrosion rate modelling; DNV-RP-G101 for risk-based inspection of offshore topsides; 30 CFR 250 Subpart S (SEMS) for US OCS facilities; ASME Section V Article 23 for ultrasonic thickness practice.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
Spreadsheet habits, what each one destroys, and the record behaviour that replaces it
Spreadsheet habitWhat it destroysWhat the record must do instead
One thickness cell per CML, updated each campaignEvery previous value, and with them the long-term corrosion rateAppend a new immutable reading row; the current value is a query result, never a stored cell
Corrosion rate as a live formula between two cellsThe ability to see which two readings the rate came from once rows moveStore the rate as a derived quantity that names its inputs by reading identity, not by cell reference
A single t-min typed at the top of the circuit sheetThe distinction between pressure design thickness and structural minimum, and between straight pipe and fittingsHold a required thickness per component with its basis, revision date and the calculation that produced it
Negative loss clamped to zero or deletedThe signal that a technician, probe mode or CML location changedRetain the negative result, flag it, and route it to review rather than hiding it
Inspector name in the sheet tab or the file namePer-reading attribution needed to isolate a biased campaignAttach technician, certification level and instrument serial to every individual reading
Rev 12 final v3 JS.xlsx saved to a local driveAny single source of truth; two engineers now hold different historiesOne record with concurrent access, per-field change history and a named author on every edit

The workbook stopped being a record the day it got a second editor

A thickness workbook usually starts as one engineer's private tool and works well for years, because that engineer holds the missing context in their head: which columns are trustworthy, which rows were re-shot, why the elbow on that flowline has a manual override. The system fails not when the data grows but when the context stops being held by one person. A second editor arrives, then a contractor, then a replacement for the original author, and the tacit knowledge that made the file work is gone.

The mechanics of the failure are unglamorous and universal. Someone inserts a row and a SUM range no longer covers the last CML. Someone sorts by circuit and a VLOOKUP against an unsorted reference table starts returning the wrong nominal thickness. Someone types a value over a formula because the formula was giving an odd answer, and the override survives for six years. A date column formatted as text reads 03/12/24 differently on a North Sea asset and at a Houston head office. None of these produce an error message.

What replaces the workbook is not simply a bigger workbook. It is a different data shape. In a record, a thickness reading is an event with an author, a timestamp, an instrument and a method, and it is never modified. Everything else — the current minimum, the short-term rate, the long-term rate, the remaining life, the next inspection date — is computed from those events on demand. When the inputs are immutable and the outputs are derived, two engineers asking the same question get the same answer, and if they do not, the difference is traceable.

Offshore intervals are set by access, not by risk

Onshore, an inspection interval is largely a risk decision. Offshore it is a logistics decision wearing a risk decision's clothes. Persons-on-board limits cap how many technicians can mobilise. Helicopter availability and weather decide whether they arrive. Scaffolding or rope access for a single high-level CML can cost more than the entire ultrasonic campaign around it. The result is that the inspection plan you wrote and the inspection plan you executed are different documents, and the difference lands in the thickness history as gaps.

This makes the record of what was not done as important as the record of what was. A CML deferred because the scaffold was reallocated to a shutdown job is a different integrity position from a CML deferred because RBI said it could wait. Both look identical in a workbook, where the row is simply blank for that campaign. In a proper history, each is a deferral event with a reason, an approver and a new due date, and the outstanding deferrals are a report the integrity engineer can put in front of the offshore installation manager.

The access constraint also shapes the arithmetic. Long, irregular intervals mean the corrosion rate for a given CML is often derived from readings six years apart, then applied forward as if it were a steady process. Where the mechanism is not steady — an intermittent water breakthrough, a period of sand production, a coating failure that began at a known date — the calendar average is misleading in both directions. Storing the operating history alongside the readings is what lets an engineer segment the interval rather than smear it.

Short-term and long-term rate are two different numbers and you need both

API 570 asks for a corrosion rate determined from the most recent readings and one determined over the long term, and expects engineering judgement about which governs. The reason is measurement uncertainty. Manual pulse-echo thickness on a corroded, pitted back wall is not a precision measurement. Surface preparation, couplant, probe wear, back-wall roughness and operator technique all contribute, and repeatability of plus or minus 0.1 to 0.2 mm is a fair working expectation on real offshore pipework, not a laboratory figure.

Now do the arithmetic. Sweet CO2 corrosion on an offshore flowline often runs 0.05 to 0.3 mm per year. Over a two-year interval, real loss is 0.1 to 0.6 mm and measurement noise is up to 0.4 mm on the difference of two readings. On the low end of that range the short-term rate is essentially noise, and on a short interval it can easily come out negative. Over twelve years, real loss is 0.6 to 3.6 mm against the same noise band, and the long-term rate is comparatively stable.

This is why destroying the reading history is not a housekeeping inconvenience but a technical loss. The long-term rate is the noise-suppressed estimate, and it requires the oldest reading and the construction thickness to still exist. A workbook with one live cell per CML can only ever compute a short-term rate between the current campaign and whatever was there before, and on a slow-corroding circuit that number is close to meaningless while looking entirely authoritative.

One instrument, one campaign, one systematic error

The most expensive data problem an offshore integrity team encounters is not a wrong reading; it is a wrong campaign. A technician sets a velocity for carbon steel and gauges a run of duplex. A dual-element probe with a worn delay line drifts on zero. A single-element probe measures interface to first back-wall on a coated topsides line, including three hundred microns of coating in every reading, while the previous campaign used echo-to-echo and excluded it. Every CML that technician touched now carries a consistent offset.

Discovering that two years later is the normal case, usually because one CML gets re-shot for an unrelated reason and the number does not fit. At that moment the only question that matters is scope: which readings share the same instrument, the same technician, the same probe mode and the same date window, so they can be quarantined and re-examined together. In a spreadsheet that question is unanswerable, because none of those attributes were ever recorded against individual values.

In a record they are answered in seconds, and the quarantine is a state rather than a deletion. The affected readings stay in the history, marked suspect with the reason, excluded from rate calculations, and available if a later investigation clears them. The circuits they belong to get flagged for re-measurement. The relevant point is that this is a routine, recoverable event when attribution exists and an unrecoverable one when it does not.

The mechanism decides where the reading has to be

Upstream and offshore damage is directional and local in ways that defeat evenly spaced grids. Sweet CO2 corrosion concentrates where water wets the wall and where flow is disturbed. Top-of-line corrosion in a wet gas line attacks the twelve o'clock position while the bottom of the pipe stays sound, so a CML placed at six o'clock will report a healthy line indefinitely. Sand erosion attacks the outer radius of elbows and the downstream side of tees, and API RP 14E's erosional velocity C-factor is a design rule of thumb, not a wear model that tells you where to gauge.

Water injection and produced water systems add microbiologically influenced corrosion and under-deposit attack, both of which produce discrete, deep pits rather than general wastage. A grid minimum tells you a pit exists somewhere; per-point history tells you whether the pit is growing, whether a new one appeared, or whether the technician simply found a different pit this time. That distinction changes the response, and it only exists if every point in the grid retains its own coordinate and its own series.

Sour service brings a different requirement again. Under NACE MR0175 and ISO 15156, materials selection and hardness control govern susceptibility to sulphide stress cracking, and the relevant damage is cracking rather than wall loss. A thickness history has to be able to hold the fact that a given circuit's dominant threat is not thinning at all, and to link to the crack-detection inspections that actually manage it, rather than letting an untroubled thickness trend imply the circuit is fine.

Reproducing a number you have already published

The moment that usually triggers the move off spreadsheets is not a data loss. It is someone asking why the remaining life on a riser is eleven years in this month's report and seven years in the report issued last quarter, and nobody being able to answer. In a workbook, the past is not stored; only the present is. Reconstructing last quarter's answer means finding last quarter's file, and even then it will not tell you which cell changed or who changed it.

A thickness history that supports this has to distinguish when something was true from when it was recorded. A reading taken in March and entered in June is a March fact recorded in June. If it is later corrected, both the original and the correction exist, with authors and timestamps. That structure lets the system answer a genuinely different question: not what is the remaining life today, but what was the remaining life on 30 June using only what was known then. That is the question a regulator, an insurer or a joint venture partner actually asks.

It also protects the engineer. When a number changes, the record shows whether it changed because new metal loss was found, because an error was corrected, or because a t-min was revised after a re-rate. Without that, every change looks like either incompetence or concealment, and the integrity team spends its time defending arithmetic instead of managing corrosion.

Migrating the workbook without cleaning it first

Teams often delay the move because they believe the workbook has to be cleaned before it can be imported. That sequencing is backwards and it is the main reason these projects stall for years. Cleaning inside the spreadsheet has no audit trail, no way to mark a value as questioned rather than fixed, and no way for a second engineer to review what the first one decided. You end up doing the hardest data work in the least suitable tool.

Import first, in a state that preserves the mess honestly. Every row comes in with a source reference to the workbook, the sheet and the cell it came from. Values that fail validation come in flagged rather than rejected. Cells that held a hard-coded override rather than a formula are marked as overrides. Ambiguous dates are flagged as ambiguous instead of being silently resolved. The result is an ugly but truthful starting record, and from there every correction is an auditable act by a named person.

The cleanup then becomes a normal integrity workload rather than a migration blocker. Prioritise by consequence: circuits with the shortest remaining life, highest-risk service and most imminent inspection dates get their history reconciled first, and low-consequence utility circuits can carry flags for a year without harming anyone. Nothing is deleted at any point, which matters both technically and politically, since the original workbook stays available as the cited source for every migrated value.

What to test in a trial before you commit

Run the trial on one real circuit that you already argue about internally. Load its full history, then ask the system to produce the short-term rate, the long-term rate, the governing rate and the next inspection date, and check that each one shows the specific readings it used. If the system gives you a number without letting you click through to its inputs, it is a prettier spreadsheet.

Then attack it. Enter a reading that is thicker than the last one and confirm it is flagged rather than accepted or discarded. Enter a reading with a probe mode that differs from the circuit's history and confirm the system says so. Have two people edit the same circuit simultaneously and confirm the second write is refused with a visible difference rather than silently winning. Correct a reading from six months ago and confirm the original survives and the change is attributed.

Finally, test the boundary with the field. Most bad data is created at the point of capture, on a deck, in weather, on a device with gloves on. Ask how readings arrive: whether the technician's certification and the instrument's identity are captured automatically from the assignment rather than typed, whether the app works with no connectivity and reconciles later, and whether a reading captured offline that conflicts with one entered onshore is surfaced rather than merged. A record is only as good as the discipline at its edge, and offshore the edge is the hardest part.

Why does a workbook stop working once a second person edits it?

Because a spreadsheet has no concept of a conflicting edit. Two engineers open the file, both save, and one set of changes vanishes silently. Nothing records that it happened. Inserted rows shift the ranges that formulas point at, sorting breaks lookups that were never anchored, and a pasted block of readings can land one row off without any visible error. The file still opens, still calculates, and is now quietly wrong.

How do you recover a long-term corrosion rate that a spreadsheet overwrote?

Usually you cannot, which is why this matters. Recovery depends on finding the original field reports, the contractor's raw data files or an old emailed copy of the workbook, then re-entering readings against dates. On an offshore asset with fifteen years of campaigns by four different service companies, that reconstruction is a project in itself. The practical answer is to stop the loss now by freezing every future reading as its own row.

What makes a negative corrosion rate worth keeping rather than deleting?

A negative result means the second reading was thicker than the first, which is physically impossible for the same metal. It therefore tells you something real about the measurement: the probe mode changed, the coating was included one time and excluded the next, the CML was relocated, the instrument velocity was set wrong, or the two readings are simply within repeatability. Deleting it discards a diagnostic. Flagging it turns it into an investigation.

How do you detect that one whole campaign of readings was biased?

By grouping readings on technician, instrument and date and looking at the distribution rather than individual values. A campaign where nearly every CML jumps in the same direction by a similar amount is almost never real metal loss; it is a calibration velocity, a zero offset, a coating subtraction setting or a probe change. You can only make that grouping if instrument and technician live on each reading, which is exactly what a workbook does not hold.

Can two inspectors work the same circuit at the same time without one overwriting the other?

In a proper record, yes, because each reading is a separate row keyed to a CML, a date and an author. Concurrency conflicts only arise when two people edit the same field of the same reading, and then the system should refuse the second write and show the difference. Offshore this matters during a campaign, when a technician is entering data on the deck and an engineer is reviewing the same circuit onshore.

Does one t-min per circuit ever give the right answer?

Rarely. Pressure design thickness under ASME B31.3 differs between straight pipe, elbows and branch connections at the same design conditions, and on small-bore lines a structural minimum from API RP 574 practice will often govern over the pressure calculation entirely. A single circuit-level t-min will be conservative on some components and non-conservative on others, and the workbook gives no clue which is which.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.