On March 23, 2005, fifteen people died at the BP refinery in Texas City. The company had a safety record it was proud of, right up until the tower blew.
The investigation said plenty about the operators who overfilled that tower that morning. I want to talk about the number the company had been staring at for years and reading backward. Every one of the dead was inside or beside a work trailer that had no business sitting where it sat.
How the unit worked.
Raffinate is what is left of a stream of gasoline-range hydrocarbons after the valuable aromatics, benzene and the like, have been pulled out of it. What is left is mostly paraffins, and the refinery splits that into a light cut and a heavy cut to blend into gasoline. The splitting happens by distillation, in a tall column called the raffinate splitter. At Texas City that column stood 170 feet.
During a startup you fill the bottom of the column with raffinate and heat it until it begins to boil and separate. The procedure is strict about how. Establish a liquid level in the bottom of the tower, about six and a half feet. Put the level control on automatic so heavy raffinate flows out to storage as fast as it comes in. Then bring the heat up slowly, which raises the pressure and starts the separation. The whole job is holding that level steady while the tower warms. Overfill a hot column and the expanding liquid has nowhere to go.
Before I sign off on a startup, I want to know what the crew can actually see. At Texas City the answer was almost nothing. The only level instrument the board operator had read just the bottom few feet of a 170-foot tower. It topped out around nine feet. Above that it showed nothing, and it was not calibrated right anyway. A sight glass could have given a second opinion, but it was caked with dark residue and had been unreadable for years.
If the level climbed past safe, the tower's last defense was three relief valves that dumped to a blowdown drum and a 113-foot stack installed in the 1950s. It vented to open air. No flare. Those valves had been de-rated from 70 psi to about 40. Hold onto the blind gauge and that 1950s drum. The morning of the explosion is a story about both.

What happened.
Here is the part that gets me. The gauge did not simply fail. It lied, and it lied in the one direction that kept the crew feeding the tower.
At 3:09 that morning the high-level alarm went off at 7.6 feet. Somebody acknowledged it and moved on. The backup alarm, the one hard-wired to catch exactly this, never made a sound. So the feed kept coming and the furnaces stayed lit.
Then the instrument did the cruel thing. The real level climbed, and the reading on the panel went the other way. It fell. The tower filled and the needle dropped, telling a tired crew there was less in the column than there had been.
By 1:04 in the afternoon the liquid stood at 158 feet in a 170-foot tower, better than nine tenths full. The gauge read 7.9 feet and still falling. Nobody in that control room knew they were nine tenths of the way to a disaster, because the one number they had to trust was pointed at the floor.
Then the physics took over. The liquid backed up into the overhead piping, and the weight of it drove the tower pressure up. At 1:13 p.m. the three relief valves opened and the pressure spiked to about 64 psi. They stayed open six minutes and pushed 51,900 gallons of hot hydrocarbon into that undersized 1950s drum. The drum filled and threw raffinate out the top of the stack like a geyser.
A diesel pickup sat idling about 25 feet away. The vapor cloud reached its air intake and the engine raced. It backfired, and at 1:20 p.m. the cloud lit. The trailers, 121 feet away, took the full blast.

The easy story.
Operators overfilled the tower and did not follow the startup procedure. Some were disciplined for it. It is true, as far as it goes. I have watched investigations stop right there, and it is the least useful true thing in the file.
What actually set it up.
The decisions that killed those fifteen people were made long before startup, by people who never touched a valve. BP had targeted a 25 percent budget cut in 1999 and another 25 percent in 2005, while the CSB found much of the refinery's infrastructure and equipment in disrepair. A required safety study of that tower's relief system had never been completed, and the blowdown drum was too small to hold what the valves could send it. The blind transmitter and the dead backup alarm were known problems, and the startup got authorized anyway. The 1950s blowdown drum stayed in service. The trailers got parked 121 feet from it through a change process that never asked the obvious question.
Every one of those was a gate, and the people who opened them did not work in safety. Finance set the budgets. Facilities sited the trailers. Engineering left the relief study undone and signed off a startup with a gauge that could not see. By the time an operator was watching a bad reading, the risk was already inside, through four different doors.
Walk it back up the chain with me. A cost culture set the budgets. The budgets shaped the decisions. The decisions let the risk in. Then the risk sat there for years, waiting for a bad startup to spend it. The operator was the last domino to fall, not the first. Peter Susca calls the people who open those doors hazard gatekeepers, the managers outside safety who decide what risk gets to walk in.
How they got past human error.
None of the tools that got the investigators there are exotic, and I would bet you already have every one of them.
Read the instrument before you read the operator. Pull the transmitter's range and you find a gauge that showed only the bottom nine feet of a 170-foot tower. That turns the operator ignored the level into the operator was never shown the level.
Pull the recorded level, temperature, and pressure. The runaway is right there in the trend, building for hours before anyone in the trailers was in danger. Do the hydraulics. A tower filled to 158 feet backs liquid into the overhead and lifts a valve set at 40 psi. It was always going to open.
Ask the design question the easy story skips. When those valves open, where do 51,900 gallons go. The answer, a 1950s drum venting to the sky, is the whole problem in one line. Then look at the man running the startup after 29 straight days of 12-hour shifts, with no supervisor in the room. I have felt a fraction of that fatigue on a hard week. I would not have caught it either.
The gap.
BP thought Texas City was safe, and it had a number to prove it. The personal-injury rate was low. The company had put real effort into slips, trips, hand injuries, and driving, and it graded itself on that and felt good.
A low injury rate tells you people are not getting hurt doing the ordinary work. It tells you nothing about the extraordinary failure building in a tower nobody could see into. They were reading the easy gauge, the one that is simple and almost always looks fine, and calling it the health of the process. The Baker Panel said it straight afterward. BP's reliance on injury rates blinded it to process risk, and its safety system did not really measure process safety at all.
You cannot wait for the outcome to tell you the process was sick. When the outcome finally shows up in a place like this, it is fifteen caskets.
Monday morning.
- Sort your safety numbers into two piles, personal injury and process safety. If you cannot name one process-safety number you watch every week, you are flying the wrong gauge.
- Pull your overdue studies. A relief-system review that is years late is not a backlog item. It is a decision somebody made.
- Walk up to your critical level and pressure instruments and ask what each one is actually calibrated to see, and what it is blind to. A gauge with the wrong range is worse than none. It lies with a straight face.
- Name the people outside safety who can let risk in with a routine call, in finance, maintenance, and facilities. Those are your real gatekeepers.
- Walk your occupied buildings and trailers and ask why each one sits where it does.
The operators overfilled the tower. That is the sentence everyone remembers. The one I want you to keep is that the company felt safe right up to the blast, because the only number it trusted was pointed at the floor. Fifteen people paid for the reading.

One question before you go.
What number does your site call "safe" — the TRIR, the days-without-an-incident board, something else? Drop it in the comments, and tell me what it can't see. I read every one.
Before Human Error is a teardown of industrial incidents for EHS and operations leaders. I take apart one industrial incident a week, the real cause, plus a few checks you can run on your own site Monday. Subscribe here on LinkedIn so the next one lands in your notifications.
Save this one while you are here, the five checks run in a ten-minute toolbox talk. And if you would rather read it in your inbox a day early, the link is in the first comment.
Sources:
- U.S. Chemical Safety Board, Investigation Report 2005-04-I-TX (2007) + CSB animation. [PRIMARY — every technical figure verified against it]
- The Report of the BP U.S. Refineries Independent Safety Review Panel (the Baker Panel), January 2007.
- Peter T. Susca, "It's Always Bigger Than Safety" (Professional Safety / ASSP, Jan 2018, Fig. 1) and "Business Class" (Mar 2018, Hazard Gatekeepers).

