Every engineer working on a process plant encounters forms that can feel remote from the job at hand. A management-of-change request for a pipe that is “only temporary”. A permit for equipment that was isolated earlier in the day. A proof test on a level switch that has never tripped. A siting study for a portable cabin. On an uneventful day, it is easy to see only the paperwork.
Behind many of those requirements are investigations into events in which ordinary work became a major accident. Rules evolve through accumulated experience, engineering analysis and hard lessons. Understanding that history helps us see what a check is meant to protect, and what might happen if its purpose is lost.
Season 1, Production Facilities, followed the equipment from wellhead to sales meter. Season 2 follows the disciplines used to change, isolate, protect, locate and operate that equipment. Each episode examines one accident, explains the technical and organisational failure chain, and connects the findings to decisions engineers still make today.
What this season helps you understand
- Connect everyday safety requirements to the hazards they address.
- Recognise technical and organisational weaknesses in the same failure chain.
- Ask better questions about changes, isolation, protection and operating knowledge.
Start with Season 1 if the production-facility equipment is new to you. Videos are planned to run 9–13 minutes each, with time to pause and reflect.
How this season is made
The series draws on official inquiries, accident investigations and regulator publications. These include the Flixborough Court of Inquiry, Lord Cullen’s inquiry into Piper Alpha, the Buncefield investigations, the US Chemical Safety Board, the Longford Royal Commission and the French ministry’s report on Feyzin. Links beside each episode provide a starting point for further reading.
The focus is on evidence and transferable lessons. There are no dramatised final moments or speculation about individuals. Where the evidence leaves uncertainty about a failure sequence, that uncertainty matters. Technical failures are examined alongside the organisational conditions that allowed them to develop.
The illustrations explain equipment and failure mechanisms. They are learning aids, not exact reconstructions or operating instructions.
Six episodes. One connected argument.
The order moves from a temporary pipe modification to the protection and design of an entire site. Each episode stands on its own while adding another part of the picture.
/nicky-leonard-nasution--engineering-portfolio/images/hero-s2-01-flixborough.png)
Episode 01
Flixborough, 1974
Scheduled release: · 10:00 WIB
A damaged reactor at a chemical works in England was removed and replaced with a temporary 20-inch bypass. The modification had not received a full assessment of its mechanical behaviour, and the installed pipework was not pressure-tested. On 1 June 1974, a major cyclohexane release and explosion killed 28 workers. This episode examines the bypass geometry, the gaps in technical review and the purpose of management-of-change checks. It also distinguishes established findings from debate about the initiating failure sequence.
Open YouTube episode ↗Reflect on the lesson
What engineering review should a temporary modification receive before it is put into service?
/nicky-leonard-nasution--engineering-portfolio/images/hero-s2-02-piper-alpha.png)
Episode 02
Piper Alpha, 1988
Scheduled release: · 10:00 WIB
Separate maintenance tasks on a condensate pump and its pressure-relief valve were not brought together into a clear picture for the incoming shift. The Cullen inquiry identified a likely initial release associated with equipment returned to service while the relief valve was absent. The disaster on 6 July 1988 killed 167 people. This episode connects permit control, isolation and shift handover with the wider organisational lessons behind Cullen’s recommendations and the offshore Safety Case regime.
Open YouTube episode ↗Reflect on the lesson
Can the next shift see every outstanding task and isolation affecting the same equipment?
/nicky-leonard-nasution--engineering-portfolio/images/hero-s2-03-buncefield.png)
Episode 03
Buncefield, 2005
Scheduled release: · 10:00 WIB
Tank 912 overfilled on 11 December 2005 after its level indication and independent high-level protection failed to prevent the release. Petrol formed a large vapour cloud that ignited. More than 40 people were injured; there were no fatalities. The investigation exposed weaknesses in maintenance, testing and the installation of the high-level switch. This episode asks what independence and proof testing mean in practice, including why a successful test is not enough if a device is left unable to operate afterward.
Open YouTube episode ↗Reflect on the lesson
Does the test demonstrate that the complete protection function will work in its normal operating state?
HSE: Buncefield investigation and reports ↗
HSE: Level-switch installation and testing alert ↗
/nicky-leonard-nasution--engineering-portfolio/images/hero-s2-04-texas-city.png)
Episode 04
Texas City, 2005
Scheduled release: · 10:00 WIB
During start-up on 23 March 2005, a refinery distillation tower overfilled. Hydrocarbons passed through the relief system into an atmospheric blowdown drum and stack, producing a major flammable release. Fifteen workers were killed, many in or around nearby trailers. This episode follows the disposal route and the siting of occupied buildings, then examines a wider lesson: a low personal-injury rate does not establish that major-accident risks are under control.
Open YouTube episode ↗Reflect on the lesson
Where does the relieved material go, and who could be exposed along that route?
/nicky-leonard-nasution--engineering-portfolio/images/hero-s2-05-longford.png)
Episode 05
Longford, 1998
Scheduled release: · 10:00 WIB
A process upset at the Longford gas plant in Victoria caused equipment to become severely cold. Reintroducing warmer oil was followed by brittle fracture of a heat exchanger, a hydrocarbon release and fire on 25 September 1998. Two workers died. The Royal Commission identified deficiencies in hazard assessment, procedures, training and supervision, alongside the transfer of experienced engineers off site. This episode connects material behaviour with operating knowledge and the consequences of organisational change.
Open YouTube episode ↗Reflect on the lesson
When people or reporting lines change, who checks that essential process knowledge remains available?
/nicky-leonard-nasution--engineering-portfolio/images/hero-s2-06-feyzin.png)
Episode 06 · Season finale
Feyzin, 1966
Scheduled release: · 10:00 WIB
A propane release during a drain and sampling operation at Feyzin, near Lyon, ignited on 4 January 1966. Fire exposed the storage spheres to intense heat. A sphere ruptured despite pressure relief, and another exploded later. Eighteen people died, including 11 firefighters. The finale examines why pressure relief alone cannot prevent every fire-exposed vessel failure, then connects passive protection, emergency planning and inherently safer design with the rest of the season.
Open YouTube episode ↗Reflect on the lesson
Which hazards can be reduced at the source before relying on alarms, procedures or emergency response?
The season at a glance.
A new episode every Wednesday from 14 October to 18 November 2026, at 10:00 WIB (03:00 UTC). YouTube links are provided in advance; videos may not be available before their scheduled release.
| Release | Episode | Discipline |
|---|---|---|
| 14 October 2026 | Flixborough, 1974 | Management of change |
| 21 October 2026 | Piper Alpha, 1988 | Permit to work and isolation |
| 28 October 2026 | Buncefield, 2005 | Overfill protection and independent layers |
| 4 November 2026 | Texas City, 2005 | Relief routing, siting and process safety indicators |
| 11 November 2026 | Longford, 1998 | Hazard studies and operator knowledge |
| 18 November 2026 | Feyzin, 1966 | Passive protection and inherently safer design |
Each episode is planned to be followed by two short vertical videos on the channel. The full series is planned for a single playlist in release order.
Begin with the equipment.
Season 1 provides the foundation: separation, compression, treatment, flow assurance, and relief and flare systems. The relief-system discussion is especially useful before Texas City and Feyzin; the pressure and temperature concepts help prepare for Longford.
Season 1’s final episode, Relief & Flare: The System That Exists to Be Unused, is scheduled for 7 October. Season 2 starts the following Wednesday.
I am a practising oil and gas facilities engineer. If you work with one of these disciplines and know a part of its history that deserves more attention, I would like to hear from you.







/nicky-leonard-nasution--engineering-portfolio/images/hero-s2-sheet.png)