Drawing No. EH–902 // Energy Systems
You are the control room. Demand changes every second and the weather does what it likes. Switch generators on and off to keep the grid balanced — and keep frequency at 50 Hz, or the whole system trips.
Start synchronises a unit — it takes real time and contributes nothing until it is on the bars. Stop unloads it gracefully. Trip opens the breaker instantly, which is how you test whether you would survive losing it. Use each slider to set output incrementally; the marker on the bar shows where the governor and AGC are actually asking the unit to go.
Optional reading — open any section below.
A control room operator is not switching things on and off at random. The job is to keep generation matched to demand continuously, while holding enough margin to survive the sudden loss of the largest thing on the system. Frequency is the scoreboard: it rises when there is too much generation and falls when there is too little.
Three timescales run at once, and this simulator models all three.
Seconds — primary control. Governor droop on every synchronised unit responds automatically to frequency, with no instruction from anyone. It arrests a deviation but leaves a residual offset, because droop is proportional control.
Minutes — secondary control (AGC). A slow integral loop nudges setpoints until frequency returns to exactly 50 Hz and primary reserve is released for the next event. Toggle AGC off and you will see frequency settle slightly off-nominal and stay there.
Tens of minutes — unit commitment. Deciding what to start and stop. This is the part you cannot rush: a biomass boiler needs about a minute and a half, a nuclear unit far longer. Watch the demand forecast and start plant before you need it.
Some units are tagged with a MW·s inertia figure and some say NO INERTIA. This decides how much time you get to react to anything.
Nuclear, hydro and biomass drive heavy synchronous generators locked to grid frequency. Their rotating mass stores kinetic energy that is released automatically the instant demand exceeds supply — no controller, no delay, just physics resisting change. Wind, solar and batteries connect through power electronics that decouple them from frequency entirely. They can be excellent generators and still contribute nothing to slowing an excursion.
df/dt = f₀ · (Pgen − Pload) / (2H)
The imbalance sets the numerator; inertia sets the denominator. In this model, running with nuclear and hydro online gives roughly 2,900 MW·s and a 60 MW loss moves frequency at about 0.5 Hz/s. Strip the synchronous plant out and the same disturbance moves it several times faster, leaving no time for anything to respond.
Inertia only counts once a unit is actually synchronised. Press Start on the biomass unit and watch the inertia figure: it does not move for ninety seconds, then jumps the moment the unit comes on the bars. A plant that is warming up is not helping you.
This is a live engineering problem. As synchronous plant retires, system inertia falls, and operators are procuring synthetic inertia, grid-forming inverters and synchronous condensers specifically to buy back what those machines used to provide for free.
The Start button is the least forgiving control in this simulator, because start-up time is the one constraint you cannot argue with. A plant that is warming up produces nothing, contributes no inertia, and cannot be hurried. Every commitment decision has to be made before you need the capacity, using the demand forecast rather than the frequency trace.
Hot versus cold starts. The times quoted on the cards are hot starts: the plant has been running recently, the metal is still near operating temperature, and the boiler or steam generator is pressurised. A cold start — from ambient after a prolonged outage — is a completely different proposition, typically several times longer. The limit is rarely the fuel or the control system; it is thermal stress. Thick-walled components like steam drums, headers and turbine rotors can only be heated so fast before differential expansion threatens their fatigue life, so start-up is governed by permitted temperature ramp rates measured in kelvin per minute. Warm starts, after an overnight shutdown, sit somewhere between the two.
Biomass. The 90 minutes modelled here is a hot start. From cold, a biomass-fired steam plant realistically needs the better part of a day: the boiler must be brought up steadily, the fuel bed established, steam raised, drains cleared, and the turbine rolled and soaked before it can be synchronised and loaded. Solid fuel makes this worse than a gas-fired equivalent, because fuel handling, drying and combustion stability all take time to settle. It is genuinely mid-merit plant — useful for carrying load you have planned for, close to useless as a response to something that has already happened.
Nuclear. The twelve simulated hours in this model represent a hot start, and even that is optimistic in places. A large reactor is limited by reactor physics as much as by metal temperature: power must be raised slowly enough to manage xenon transients and to keep fuel and cladding within their thermal limits, and the whole sequence is bounded by technical specifications and approvals rather than by how fast the operator would like to go. A cold start, from a refuelling outage, is measured in days, not hours.
There is a further trap unique to reactors. After a scram, decaying fission products build up xenon-135, a powerful neutron absorber, which peaks several hours later. If the reactor is not restarted promptly it can enter a xenon dead time during which restart is simply not possible until the xenon decays away — potentially a day or more. This simulator models a minimum down time after a trip, but the real constraint is stiffer and less negotiable than a cooling-off period. It is the clearest illustration of why tripping a large unit is never a reversible action on the timescale of the event you are managing.
Might small modular reactors change this? That is one of the arguments made for them, and the reasoning is at least plausible. Smaller cores have less stored thermal energy and thinner pressure boundaries, so permitted heat-up rates can be higher. Factory-built standardised modules should behave more predictably. Several designs are explicitly marketed on load-following capability, with claims of ramping far faster than conventional plant, and a multi-module station can in principle stagger its units so some are always available to manoeuvre while others sit at base load.
It is worth being careful here. These are design intentions and vendor projections, not demonstrated operating experience: very few SMRs are operating anywhere, fewer still on a load-following duty, and none with the decades of data that underpin the figures quoted for conventional plant. The underlying physics does not disappear either — xenon behaves the same way in a small core as a large one, and economics may still favour running a capital-intensive reactor flat out regardless of what it is technically capable of. The potential is real and worth taking seriously. Whether it materialises is genuinely not yet known.
Spinning reserve is the headroom you have on plant that is already synchronised — megawatts you could call on within seconds. Largest infeed is the biggest single unit currently generating.
The classic security rule is N-1: you should survive losing any single element without shedding load. In practice that means spinning reserve must exceed your largest infeed. The dashboard checks this continuously and tells you whether you are SECURE or NOT SECURE.
Here is the tension that makes the job interesting: the cheapest, cleanest way to run is to load your biggest units heavily and shut everything else down. That maximises your largest infeed and minimises your reserve — exactly the wrong direction for security. Running more units at partial load is less efficient but far more robust.
Test it honestly with the Trip button, which opens a breaker instantly rather than unloading gracefully. If you were genuinely N-1 secure, frequency dips and recovers. If you were not, you will watch load shedding engage.
If frequency keeps falling, the grid does not simply collapse — it starts disconnecting customers to save itself. This is under-frequency load shedding, and it is automatic, pre-programmed, and deliberately brutal.
Three stages are modelled here: 6% of load at 49.0 Hz, 14% at 48.7 Hz, and 24% at 48.4 Hz. Each stage removes demand instantly, which reduces the imbalance and arrests the fall. Once frequency recovers above 49.85 Hz the load is reconnected.
Load shedding is a success, not a failure — it is the mechanism that prevents a regional disturbance becoming a national blackout. But it means real customers losing supply, so an operator plans to never reach it. If you see the amber banner, your reserve was inadequate for the event that just happened.
Below 48.0 Hz, shedding has failed to arrest the fall and the system trips completely.
There is a second way to lose the system, and it is faster. Distributed generation is protected by RoCoF relays that disconnect when frequency moves faster than a set rate. In this model, sustaining more than 2 Hz/s trips the system regardless of where frequency actually is. On a low-inertia grid you can therefore fail while still sitting near 49.5 Hz — not because the deviation was large, but because it arrived too quickly for anything to respond.
Survive an N-1 event. Get frequency steady, check you are showing SECURE, then Trip your largest unit. Now do the same while NOT SECURE and compare.
Turn AGC off. Change demand and watch frequency settle just off 50 Hz and stay there. That residual offset is what secondary control exists to remove.
Try to start nuclear during an event. You cannot — it needs twelve simulated hours, by which time the outcome was decided many times over. Commitment decisions are made in advance or not at all.
Trip a thermal unit and try to restart it. You will find it locked out. A unit that has tripped must cool and be checked before it can be resynchronised, which is modelled here as a minimum down time of roughly 40% of its start-up time. Tripping plant is not reversible on the timescale of the event you are managing.
Ride through sunset. Let the clock reach evening. Solar decays to zero while demand climbs to the daily peak. Use the +15 and +60 minute forecast and start plant early.
Run inverter-only. Unload and stop nuclear, hydro and biomass, leaving wind, solar and battery. Inertia collapses and the smallest disturbance becomes unmanageable.
Curtail deliberately. On a windy, sunny, low-demand hour you may have too much generation. Pull the wind and solar curtailment sliders down, or charge the battery by setting it negative.
This is a teaching model and omits a great deal:
One node. The whole grid is a single busbar — no network, no power flows, no transmission constraints, no voltage or reactive power, all of which constrain real operation as much as frequency does.
Simplified plant. One lumped inertia constant and one droop setting per technology. No turbine or boiler dynamics, no governor deadband, no start-up fuel costs, no minimum up and down times.
No markets. Real dispatch is set by economics as well as physics. There are no prices, bids or costs anywhere in this model.
Two timescales at once. This is the model's most significant simplification and it is worth being explicit about. Frequency dynamics run in real time, because that is the only way you can watch and react to them. The clock, demand profile and unit start-up sequences run sixty times faster, so a full day passes in twenty-four minutes and a start-up quoted as "90 min" occupies ninety real seconds. Ramp rates are set in real seconds, which makes the fast plant realistic during a frequency event but leaves the slow plant faster in clock terms than its real counterpart. The ordering between technologies is right; the absolute values are a compromise.
Synthetic conditions. Demand, wind and solar come from smooth analytical profiles with added noise, not measured data.
Use it to build intuition about balance, inertia, reserve and response speed. Do not read the numbers as engineering results.
Why does frequency fall after a generator trip?
Frequency is the running scoreboard of the balance between generation and demand. The instant a
generator trips, the megawatts it was supplying vanish, but demand does not fall with them. The
shortfall is drawn from the kinetic energy of every other spinning generator on the system, which
slows down as a result — and grid frequency is directly tied to that spinning speed. Frequency
keeps falling until either governors and reserve bring on enough replacement generation, or, if
they cannot keep up, until load shedding removes enough demand to rebalance the books.
What is spinning reserve?
Spinning reserve is generating capacity that is already synchronised to the grid and running, but
not loaded to its maximum — headroom that can be called on within seconds simply by opening a
valve or a throttle further, with no start-up delay. It is the margin that determines whether losing
your largest generator is a survivable dip or a cascading failure, which is exactly what the N-1
security check in this simulator is testing.
What is inertia?
Inertia is the kinetic energy stored in the rotating mass of synchronous generators — turbines,
rotors, everything physically spinning in step with grid frequency. It matters because that stored
energy is released or absorbed automatically the instant generation and demand fall out of balance,
buying time for slower control systems to react. More inertia means a given imbalance moves frequency
more slowly; less inertia means the same imbalance moves it faster, giving operators less time to
respond before limits are breached.
Why do synchronous generators stabilise frequency?
A synchronous generator's rotor is physically locked in step with grid frequency by the magnetic
field linking it to the network, so its rotating mass respond to a frequency change immediately and
automatically — no controller or communication required. If frequency starts to fall, that
rotor gives up stored kinetic energy and helps arrest the fall the instant it begins, purely through
physics. This automatic response is what the inertia and governor droop in this simulator represent.
Why don't solar panels provide inertia?
Solar panels generate direct current and have no rotating machinery at all, so they connect to the
grid through a power electronic inverter that synthesises an alternating current output. That
inverter electrically decouples the panel from grid frequency: nothing physical is spinning in step
with the network, so there is no stored kinetic energy to release when frequency changes. The same is
true of wind turbines and batteries in this simulator, which is why they are tagged "NO INERTIA"
regardless of how much power they can supply.
Why is 50 Hz important?
50 Hz (or 60 Hz in North America and parts of Asia) is the frequency the whole synchronous grid is
designed and protected around, and it is not just a nominal target — it is the direct,
real-time measurement of whether generation and demand are in balance. Equipment across the system,
from turbine blades to protection relays to industrial motors, is built to tolerate only a narrow
band around that frequency. Stray far enough from it and protection automatically starts
disconnecting plant and load to protect the equipment, which is the mechanism behind both load
shedding and full blackouts.
What is RoCoF?
RoCoF, rate of change of frequency, measures how fast frequency is moving, in hertz per
second, as distinct from how far it has moved. A small, slow deviation and a small, fast one can
reach the same frequency, but the fast one is far more dangerous, because it gives protection
systems and operators less time to respond. Low-inertia systems are especially exposed to high
RoCoF: the same size of imbalance moves frequency more abruptly when there is less stored kinetic
energy to cushion it, which is exactly what you can reproduce by running this simulator on
inverter-only generation.
Found something wrong with this calculator? Let us know and we'll take a look.