OIL & GAS EQUIPMENT | Updated May 2026 | 8 min read
What You’ll Learn in This Guide
- What flare pilot monitoring instrumentation actually does and what OOOOb requires of it
- How auto-relight logic restores pilot ignition after loss-of-flame events
- The three main pilot monitoring architectures and their reliability trade-offs
- How redundant pilot configurations integrate with monitoring and auto-relight
- What detection thresholds, attempt counts, and event logging the OOOOb-grade systems use
- How to verify pilot monitoring and auto-relight performance during commissioning and annual testing
- Common pilot monitoring and auto-relight specification mistakes
A flare pilot is the smallest, simplest, and most critical component on any continuous-pilot flare system. When the pilot goes out, the flare loses its ability to ignite the next relief event — a failure mode that converts an EPA OOOOb-compliant control device into an uncontrolled methane release source within seconds of the next PSV lift. Pilot monitoring and auto-relight systems exist to detect pilot loss the instant it happens, attempt automatic relight, and alert operators if relight fails. This guide walks through what OOOOb-grade monitoring and auto-relight actually require, and what the engineering choices look like across air-assisted, sonic, gas-assisted, utility, and emergency flare configurations.
Hero Process Solutions, founded in 2011 and headquartered in Kellyville, Oklahoma with operations in Midland, Texas, manufactures flare ignition systems with pilot monitoring and auto-relight logic across the full range of flare applications.
DIRECT ANSWER: Flare pilot monitoring uses redundant thermocouple and flame ionization rod sensors at each pilot to verify continuous flame presence. Auto-relight logic detects loss-of-flame within a defined threshold (typically 2 to 5 seconds), attempts ignition through a high-energy spark transformer 2 to 4 times spaced 10 to 30 seconds apart, and raises a critical alarm if all attempts fail. EPA 40 CFR 60 Subpart OOOOb requires continuous pilot monitoring on affected flares with data logging at 15-second to 1-minute intervals and five-year retention. For high-reliability OOOOb-grade service, redundant pilots with independent fuel, ignition, and detection eliminate single-point failure modes.
1. What Flare Pilot Monitoring Does
Flare pilot monitoring is the instrumentation and control system that continuously verifies the pilot flame is present and operating. It serves three functions.
First, it detects loss-of-flame events the instant they happen and triggers auto-relight logic. Second, it logs continuous pilot status data for OOOOb compliance recordkeeping. Third, it provides operator visibility into pilot health over time — declining detector signal strength or rising loss-of-flame event frequency are leading indicators of pilot maintenance issues that should be addressed at scheduled outages.
The instrumentation typically consists of a thermocouple at the pilot tip (detecting flame heat), a flame ionization rod in the combustion zone (detecting flame chemistry), control logic that combines both signals to declare flame status, and a data historian that logs status at 15-second to 1-minute intervals for compliance.
2. The Three Main Pilot Monitoring Architectures
Single-Sensor Pilot Monitoring (Legacy)
Single-sensor monitoring uses one thermocouple or one ionization rod per pilot. The architecture is simple and inexpensive but creates a single-point failure mode: a sensor failure indistinguishable from a real pilot loss-of-flame event. Single-sensor monitoring is acceptable for legacy non-OOOOb service but increasingly inadequate for affected facility service where every false loss-of-flame event creates compliance documentation overhead.
Redundant Sensor Pilot Monitoring (OOOOb-Grade)
Redundant sensor monitoring uses both thermocouple and flame ionization rod per pilot, with control logic that requires both signals to agree before declaring flame loss. Single-sensor failures no longer create false loss-of-flame events. This is the OOOOb-grade architecture standard.
Redundant Pilot with Redundant Sensing (High-Reliability)
For high-stakes utility, refinery, and petrochemical service, two or more independent pilots each with redundant sensors deliver the highest reliability. Each pilot has its own fuel supply, ignition transformer, and flame detection. Loss of one pilot leaves the flare functional on the remaining pilot while maintenance restores the failed one. This is the standard for high-stakes OOOOb-affected emergency relief duty.
KEY INSIGHT: Redundant sensing on a single pilot eliminates false loss-of-flame events but does not eliminate pilot failure as a system risk. For high-stakes service, the next reliability tier is redundant pilots — each with its own redundant sensing, fuel supply, and ignition system. The two reliability investments solve different problems and both have a place in OOOOb-grade flare design.
3. How Auto-Relight Logic Works
Auto-relight logic detects pilot loss-of-flame, attempts ignition through a high-energy spark transformer, and verifies relight success through the monitoring sensors. Four control parameters define how the logic responds.
Detection threshold is the period of confirmed flame absence required before declaring loss-of-flame. Too short produces nuisance relights from routine flame fluctuations; too long delays response. Typical threshold is 2 to 5 seconds.
Relight attempt count is the number of ignition attempts before raising a critical alarm. Two to four attempts is standard. Each attempt energizes the ignition transformer for a brief period (1 to 3 seconds typically).
Inter-attempt delay is the wait between attempts. Ten to 30 seconds allows pilot fuel to flow and dissipate any accumulated combustion products before the next ignition attempt. Too short risks ignition failure from rich-mixture conditions; too long extends total relight time.
Event logging captures every detection event, every attempt, and the outcome. This data is required for OOOOb recordkeeping and is the diagnostic basis for root-cause analysis of recurring pilot issues.
4. OOOOb Monitoring Requirements
EPA 40 CFR 60 Subpart OOOOb requires continuous parametric monitoring of pilot flame presence (or combustion zone presence for non-pilot systems) on flares used as control devices at affected facilities. Data must be logged at 15-second to 1-minute intervals and retained for five years. Visit our EPA OOOOb compliance resource for the complete monitoring framework.
For pilot monitoring on OOOOb-affected service, redundant sensor architectures are effectively required because single-sensor architectures create routine deviation events that consume disproportionate compliance documentation effort. Single-sensor monitoring is legal but operationally unsustainable.
5. Pilot Architecture Comparison Across Flare Types
| Flare Type | Typical Pilot Architecture | Why |
|---|---|---|
| Air-Assist Flare (continuous service) | Redundant pilots, redundant sensing | Continuous duty makes pilot reliability critical |
| Sonic Flare (continuous service) | Redundant pilots, redundant sensing | Same reliability profile as air-assist |
| Gas-Assist Flare | Redundant pilots, redundant sensing | Pilot fuel often shared with assist gas, requires careful design |
| Utility Flare (emergency relief) | Redundant pilots, redundant sensing, plus backup ignition | Single relief event reliability is the design priority |
| Low Flow Flare (unmanned upstream) | Battery/solar spark ignition (no continuous pilot) | Eliminates pilot-loss failure mode at unmanned sites |
| Portable/Trailer-Mounted Flare | Single pilot with redundant sensing (typical) | Temporary service; full redundancy CAPEX not justified |
The right pilot architecture depends on service profile and reliability requirements. For high-stakes continuous OOOOb-affected service, redundant pilots with redundant sensing are the standard. For unmanned upstream service, battery/solar spark ignition eliminates the pilot architecture decision entirely.
6. Verifying Pilot Monitoring and Auto-Relight Performance
Three verification activities ensure pilot monitoring and auto-relight perform as designed.
Commissioning test verifies sensor calibration, control logic behavior, ignition transformer output, and auto-relight sequence under simulated loss-of-flame conditions. The test should include intentional pilot extinction and verification that auto-relight restores ignition within the design response time.
Monthly functional test verifies the redundant pilot (if equipped), redundant sensor signals, and ignition transformer pulse strength. Catching declining performance early prevents loss-of-flame events from becoming actual extinction events.
Annual recertification (for OOOOb-affected service) verifies the complete pilot monitoring and auto-relight system as part of the annual performance test. The verification documents that the system continues to perform within OOOOb compliance limits.
7. Pilot Monitoring Integration with Combustion Zone Monitoring
OOOOb requires continuous monitoring of both pilot flame presence and combustion zone presence during waste-gas flow. Pilot monitoring covers periods when the flare is idle (no waste-gas flow); combustion zone monitoring covers periods when waste-gas flow is being actively combusted.
Integration of the two systems requires careful control logic. During idle periods, only pilot status is logged. When vent-gas flow begins, combustion zone monitoring activates to verify ignition success and continued combustion. The transition between the two states must be handled cleanly so that the data record never has a gap.
For combined air-assist, sonic, gas-assist, and utility flares, this integration is part of the standard OOOOb-grade controls package. For specialty configurations (multi-tip staged sonic, variable exit area tips), the integration is application-specific.
8. Common Pilot Monitoring Specification Mistakes
| Mistake | Why It Hurts | Fix |
|---|---|---|
| Specifying single-sensor pilot monitoring for OOOOb-affected service | Routine sensor noise creates false loss-of-flame events and documentation overhead | Specify redundant thermocouple and ionization rod sensing |
| Setting detection threshold too aggressively | Nuisance relights from flame fluctuations | Tune detection to 2 to 5 seconds confirmed absence |
| Limiting auto-relight attempts to one | Single failed ignition becomes flare-out | Specify 2 to 4 attempts spaced 10 to 30 seconds apart |
| Not documenting auto-relight tuning in OOOOb compliance file | Audit risk on controls behavior justification | Document threshold, attempt count, and inter-attempt delay |
| Missing combustion zone integration during waste-gas flow periods | Data record gaps during active flow | Specify integrated pilot plus combustion zone monitoring |
| Skipping commissioning auto-relight verification | System may not perform as designed under real conditions | Run intentional extinction test during commissioning |
Article Summary
- Flare pilot monitoring continuously verifies pilot flame presence using redundant thermocouple and flame ionization rod sensors.
- Auto-relight logic detects loss-of-flame, attempts ignition through a spark transformer, and raises critical alarm if relight fails.
- Three main pilot monitoring architectures: single-sensor (legacy), redundant sensors per pilot (OOOOb-grade), and redundant pilots with redundant sensing (high-reliability).
- Detection threshold of 2 to 5 seconds, 2 to 4 relight attempts spaced 10 to 30 seconds apart, and event logging are the standard auto-relight tuning parameters.
- EPA OOOOb requires continuous pilot monitoring with 15-second to 1-minute logging intervals and five-year retention.
- Pilot architecture varies by flare type: continuous-service flares use redundant pilots; unmanned upstream flares use battery/solar spark ignition.
- Verification through commissioning test, monthly functional test, and annual OOOOb recertification ensures performance.
- Hero Process Solutions manufactures flare pilot monitoring and auto-relight systems across the full range of flare configurations.
Frequently Asked Questions
What sensors does flare pilot monitoring use?
OOOOb-grade pilot monitoring uses redundant thermocouple plus flame ionization rod per pilot. The thermocouple detects flame heat; the ionization rod detects flame chemistry. Control logic requires both signals to agree before declaring loss-of-flame, eliminating single-sensor failure modes that create false deviation events.
How does flare pilot auto-relight work?
Auto-relight detects loss-of-flame within the detection threshold (2 to 5 seconds), then energizes a high-energy ignition transformer to spark at the pilot location. The system makes 2 to 4 ignition attempts spaced 10 to 30 seconds apart, verifying success through the redundant sensor signals after each attempt. If all attempts fail, a critical alarm is raised for operator response.
What does EPA OOOOb require for pilot monitoring?
OOOOb requires continuous monitoring of pilot flame presence on flares used as control devices at affected facilities. Data must be logged at 15-second to 1-minute intervals and retained for five years. The rule does not specify single vs redundant sensor architectures, but redundant sensing is effectively required because single-sensor architectures generate routine false deviation events that consume disproportionate compliance documentation effort.
When is redundant pilot architecture required?
For high-stakes OOOOb-affected continuous service (air-assist, sonic, gas-assist, utility flares in refining, midstream, and petrochemical applications), redundant pilots with redundant sensing are the standard. Each pilot has independent fuel supply, ignition transformer, and flame detection. Loss of one pilot leaves the flare functional on the remaining pilot. For unmanned upstream low flow service, battery/solar spark ignition replaces the redundant pilot architecture entirely.
How often should pilot monitoring be tested?
Three test intervals are standard. Commissioning test (one-time at startup) verifies all components and the auto-relight sequence under simulated loss-of-flame. Monthly functional test verifies redundant pilots, sensor signals, and ignition transformer pulse strength. Annual recertification (for OOOOb-affected service) verifies the complete system as part of the annual performance test.
Can Hero Process Solutions supply pilot monitoring across all flare types?
Yes. Hero manufactures flare pilot monitoring and auto-relight systems for air-assist, sonic, gas-assist, utility, low flow, portable, and emergency utility flare configurations. The selection between single-sensor, redundant-sensor, and redundant-pilot architectures is supported by Hero’s engineering team during project assessment based on service profile, OOOOb applicability, and reliability requirements.




