Substation Automation Firmware Deployment Checklist
Systematic verification checklist for updating critical IED and RTU firmware across high-voltage substation networks.
Use this template before executing scheduled operational technology maintenance in electrical substations. It helps automation engineers ensure zero uncommanded breaker trips and complete communication redundancy during firmware flashes.
Role: Senior Power Systems Automation Engineer specializing in substation operational technology and IEC 61850 networks.
Context
- Utility Operator: {{utility_provider}}
- Target Location: {{substation_node}}
- Target Firmware Build: {{target_firmware_version}}
- Hardware Scope: {{ied_device_models}}
- Permitted Maintenance Window: {{maintenance_window_duration}}
- Contingency Strategy: {{rollback_procedure}}
Task
Generate an actionable, sequential engineering deployment checklist to safely update substation intelligent electronic devices (IEDs) and remote terminal units (RTUs), ensuring continuous grid reliability, data integrity, and strict adherence to safety interlocks.
Method
- Review the operational topology of {{substation_node}} and flag all protective relays associated with {{ied_device_models}}.
- Detail isolation steps for primary protection trip outputs to prevent nuisance tripping during updates.
- Establish baseline telemetry and communication link states across the station bus prior to execution.
- Formulate sequential firmware staging and flashing steps compatible with {{target_firmware_version}}.
- Structure validation checks for Goose messaging, sampled values, and SCADA gateway polling post-flash.
- Incorporate time-budgeted go/no-go gates aligned with {{maintenance_window_duration}}.
- Detail step-by-step restoration of trip circuits and interlocks.
- Embed trigger conditions for executing {{rollback_procedure}} if validation tests fail.
Constraints
- Every checklist item MUST include a checkbox
[ ], a clear operational action, and a verifiable pass/fail condition. - MUST NOT require manual configuration edits during live protection loop closures.
- Group checks logically into Pre-Deployment, Execution, Post-Flash Validation, and Normalization phases.
- Keep instructions concise, imperative, and field-engineer-ready.
Output format
- Phase 1: Pre-Maintenance Isolation & Baseline Verification (4-6 checklist items)
- Phase 2: Staged Firmware Installation & Gateway Reboot (3-5 checklist items)
- Phase 3: Telemetry & Protection Loop Validation (4-6 checklist items)
- Phase 4: Restoration & Sign-off (3-4 checklist items)
- Contingency: Abort & Rollback Triggers (3 actionable criteria)
Self-review
- Are all {{ied_device_models}} trip circuits isolated before flashing starts?
- Is {{rollback_procedure}} clearly referenced with immediate fallback thresholds?
- Does the execution timeline strictly fit within {{maintenance_window_duration}}?
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.