Skip to main content

Project management

Maintenance Shutdown Planning Guide

12 Jun · 11 min read · by the Phaselo team

Most planned shutdowns are tracked across three Excel files, a WhatsApp group, and someone's notebook. The shutdown itself might run for 48 hours, but maintenance shutdown planning starts months earlier, involves a dozen trades, and the cost of overrunning is measured in lost production per hour. On a line that earns $20,000 an hour, a single extra shift of overrun is $160,000. That is the number your plan exists to protect. Here is a planning structure that holds up under that pressure, with a worked phase breakdown, a realistic timeline, the failure modes that cause overruns, and an honest look at the tools.

Why spreadsheets break down for shutdown planning

A spreadsheet is fine for a task list. A shutdown is not a task list. It is a hierarchy: the shutdown has phases (pre-shutdown, isolation and access, mechanical, electrical and controls, recommissioning), each phase has work packages, and each work package has tasks owned by different people, often different companies. The moment two people edit the same sheet, or a contractor emails through a revised scope, your single source of truth splits into five versions and nobody can say which one is current.

  • No rollup: you cannot see at a glance whether the electrical phase is 40% or 80% done.
  • No ownership: a cell with initials in it is not an assignment anyone gets notified about.
  • No dates that move together: when isolation slips a day, every downstream row is wrong and stays wrong until someone hand-edits it.
  • No critical path: a flat list cannot tell you which late task actually pushes the restart and which has slack to absorb it.
  • No history: nobody knows who changed the scope, when, or what the budget was before the variation landed.

The result is familiar. The plan looks healthy on Tuesday, the shutdown starts Friday, and by Saturday morning the spreadsheet is fiction. What you need is a structure that keeps the plan honest while the floor moves faster than any human can retype rows.

Step 1: Structure the shutdown as a work breakdown

Start with the phases as top-level items, then break each phase into work packages, then tasks. This is a work breakdown structure, and it is the single most important decision in maintenance shutdown planning because everything else (progress rollup, the critical path, the budget) hangs off it. A typical structure looks like this:

  1. Pre-shutdown: scope freeze, long-lead parts ordered and confirmed, contractor inductions booked, isolation plans approved, permits drafted.
  2. Isolation and access: lockout-tagout, blinding and de-energising, scaffolding erected, confined space permits issued.
  3. Mechanical works: each major equipment item (pump, gearbox, heat exchanger, valve train) is its own work package with its own tasks.
  4. Electrical and controls: switchboard work, motor changeouts, instrument calibration, loop checks, control system updates.
  5. Recommissioning: de-isolation, function tests, safety system proofs, performance run, formal handover to production.

The discipline that matters: every task has one owner and one due date. Work packages roll their progress up to phases, and phases roll up to the shutdown. When the plant manager asks how it is going, the answer is a number, not a feeling. A real tree with rollup is the difference between reporting and guessing, and it is why operations teams reach for a proper WBS tree instead of another tab.

How deep should the breakdown go

Stop breaking a work package into smaller tasks when the smallest task is something one crew does in one shift and you can mark done in one update. Going finer than that creates admin nobody maintains. Going coarser hides slip: if a three-day work package is a single line, you only learn it is late on day three. One shift of granularity on the things that sit on the critical path, coarser elsewhere, is the balance most planners settle on.

Step 2: Schedule backwards from production restart

Shutdowns are scheduled backwards. Production needs the line back at a fixed time, so recommissioning gets a fixed window, which fixes the end of electrical works, which fixes the end of mechanical, and so on back to day one. Build the schedule on the Gantt view so every phase is visible against the calendar, and so that when one bar moves you can see exactly what it collides with downstream.

Find the longest pole: the critical path

Not every task matters equally. The critical path is the longest chain of dependent work from start to restart, and it is the only chain where a one-day slip becomes a one-day overrun. Everything off the critical path has total float: hours or days of slack it can lose before it hurts. If your big gearbox rebuild is the longest pole, a late delivery on a non-critical valve is noise, and a half-day slip on the gearbox is a crisis. A real critical-path engine tells you which is which automatically, instead of you tracing dependencies by eye at 2am. It computes the projected finish, marks the critical path, and shows the float on everything else.

Put a buffer before recommissioning

Put a buffer between mechanical completion and recommissioning. Every experienced shutdown planner does this, and every overrun report says the same thing: the buffer was consumed by discovery work, the extra scope you find once equipment is opened up and you can finally see the wear. A sensible figure is 10 to 20 percent of the mechanical phase duration, parked as an explicit buffer task on the timeline, not hidden as padding inside other estimates. When you can see the buffer as its own bar, you can watch it shrink in real time and react before it hits zero.

A realistic timeline example

Take a 72-hour shutdown on a packaging line, with the restart fixed for 06:00 Monday. Scheduled backwards, it looks roughly like this:

  • Weeks minus 12 to minus 2 (pre-shutdown): scope frozen by week minus 6, long-lead parts ordered by week minus 8 with delivery confirmed by week minus 2, contractors inducted, permits drafted.
  • Friday 18:00, line stops. Isolation and access, 4 hours: lockout-tagout, blinding, scaffolding up.
  • Friday 22:00 to Sunday 10:00, mechanical works, 36 hours: gearbox rebuild on the critical path, exchanger clean and pump overhaul running in parallel.
  • Sunday 10:00 to Sunday 22:00, electrical and controls, 12 hours: motor changeout, instrument calibration, loop checks.
  • Sunday 22:00 to Monday 04:00, a 6-hour buffer for discovery work.
  • Monday 04:00 to 06:00, recommissioning, 2 hours: de-isolation, function tests, safety proofs, handover.

The gearbox rebuild is the longest pole. If it finishes at Sunday 12:00 instead of 10:00, that two hours eats into electrical start, and the only thing standing between you and a late restart is the buffer. That is the entire game: protect the critical path, watch the buffer, and react to slip the hour it appears, not the morning of the restart.

Step 3: Coordinate contractors with one shared plan

The riskiest interfaces in a shutdown are between companies, not within them. Your electrical contractor finishing late delays your instrument techs, who belong to a different company and have other jobs to get to. The fix is unglamorous: one shared plan that everyone can see, with statuses updated from the floor, on a phone, the moment work completes. A board view that works at the equipment means a task gets marked done at the equipment, not back at a desk three hours later. If status updates wait for the evening toolbox meeting, your plan is always half a day stale, and on a 72-hour shutdown half a day is a quarter of your visibility gone.

Give every contractor their own owned tasks inside the same tree, so each company sees its work in context but the planner sees the whole. This is the same reason operations teams move off generalist developer tools: a shutdown has trades and handoffs, not sprints. If you have ever tried to run site works in a sprint board, the case for an operations-first alternative to Jira will read like your own notes.

Step 4: Track quotes, scope, and budget on the work packages

Attach contractor quotes, scope documents, and isolation drawings to the work packages they belong to. Each work package carries its own cost: budget, what is committed against it, and the exposure you can see coming. When a variation comes in, it lands on the item it affects, with a note saying who approved it. Six months later, when finance asks why the shutdown cost 12 percent over budget, the answer is in the plan, not in an inbox.

If the shutdown includes a genuine capital item (a new exchanger, a control system upgrade), generate a capex request that freezes its figures at the moment you create it. The plan keeps moving, but the document you send for sign-off shows the numbers as they stood when you asked. That is how you keep an audit trail clean: the request is fixed, the plan is live, and nobody argues later about which figure was approved.

How slip and baseline tracking catch overrun early

Here is the part spreadsheets cannot do at all. When your plan goes live, capture a baseline: a frozen snapshot of every planned date. From then on, the tool compares live progress against that baseline and tells you, before the restart, that the projected finish has moved. That is slip detection, and it is the early-warning system a static plan never gives you.

  • Baseline at go-live: the planned dates are frozen so you always have a reference, not just whatever the plan says today.
  • Projected finish recalculates as work completes, so a slow gearbox rebuild shows a late restart on day one of the shutdown, not on the morning of the restart.
  • Overdue and slip alerts fire in-app and by email, so the planner is told the critical path moved instead of discovering it at the next meeting.
  • Re-baselining requires a recorded reason and lands in an append-only audit trail, so a quietly moved deadline is impossible to hide.

The point is not blame. The point is that you find out you are 6 hours behind on Saturday afternoon, when you can still bring in a second crew or de-scope a non-critical job, instead of finding out at 05:00 Monday when production is waiting at the gate. Baseline plus slip is the difference between managing the shutdown and being managed by it.

Common failure modes (and how to catch them)

Scope creep

Every job you add after the scope freeze competes for the same fixed window. The fix is a hard scope-freeze date in the pre-shutdown phase and a rule that anything added after it is a variation: a new work package, with its own owner, cost, and a recorded reason. If it is not on the plan, it does not happen during the shutdown.

Late long-lead parts

The number one cause of a shutdown that cannot finish is a part that did not arrive. Put long-lead items on the timeline as tasks with delivery dates, not as a buried purchase order. When a forging is quoted at a 10-week lead time and your shutdown is in 9 weeks, you want that conflict screaming at you in the Gantt view in week one, not discovered in week eight.

Stale status

A plan that is updated once a day is a plan that is wrong for most of the day. During the shutdown itself, status has to come from the floor in near real time, which is why a phone-friendly board beats a desktop spreadsheet every hour of every shift. Stale status is worse than no status because it gives false confidence: the plan says you are fine right up until it says you are not.

No buffer, or a buffer that was already spent

Planners who skip the discovery buffer overrun on the first surprise. Planners who hide the buffer inside other estimates spend it without noticing. Make it an explicit bar, watch it, and treat the moment it drops below a shift as a trigger to act.

Excel vs MS Project vs Phaselo

Three tools get used for shutdowns. They are not equal.

Excel

Free, everyone has it, and it is genuinely fine for the parts list and the contact sheet. It fails as the live plan: no rollup, no critical path, no dependencies that move together, no slip detection, no budget rollup, and it forks into multiple versions the moment more than one person touches it. Good for inputs, wrong for the schedule of record.

Microsoft Project

It has a real critical-path engine and a proper Gantt, and for a planner who lives in it, it is powerful. The problem on a shutdown is the floor: nobody updates MS Project from the equipment with gloves on, so it drifts from reality within a day, and it is desktop-heavy, licence-heavy, and contractors will not log in. The schedule is excellent and the status is fiction.

Phaselo

Phaselo is built for exactly this: a WBS tree with progress rollup, a real critical-path engine with projected finish and float, baseline governance with slip alerts, cost and capex on every work package, and a phone-friendly board so status comes from the floor. Five views (Tree, Gantt, Board, Report, People) on one plan, at $8 per user per month with a 14-day free trial and no credit card. It does not pretend to be sprint software or resource-levelling software. It runs phased, budgeted, contractor-heavy work, which is what a shutdown is.

The same structure works for the project that follows a shutdown: bringing new gear online. If your next job is installing and proving equipment, the equipment commissioning project checklist lays out the five phases to copy straight into a plan.

Set up your next shutdown as a real plan

You do not need enterprise maintenance software for this. You need a hierarchical plan, a Gantt view with a real critical path, a board for the floor, a baseline that catches slip, and budget fields on each work package. That is exactly what Phaselo does. Start a free trial, build your next shutdown as a WBS tree scheduled backwards from restart, and retire the spreadsheet before it retires your restart time.

Frequently asked questions

How far in advance should you start planning a maintenance shutdown?

For a major turnaround, start maintenance shutdown planning 3 to 6 months out, driven by the longest lead time on the parts list. Freeze the scope around 6 weeks before the line stops, confirm long-lead deliveries 2 weeks out, and lock contractor inductions and permits in the pre-shutdown phase. The shutdown window itself is fixed by production, so all of this is scheduled backwards from the restart.

What is the critical path in a shutdown schedule?

The critical path is the longest chain of dependent work from the line stopping to the line restarting. A one-day slip on the critical path becomes a one-day overrun, while work off it has float (slack) it can lose without hurting the restart. A critical-path engine marks that chain automatically and shows the projected finish, so you protect the right jobs instead of chasing every late task equally.

How do you coordinate multiple contractors during a plant shutdown?

Put every contractor on one shared plan, give each company its own owned tasks inside the same WBS tree, and update status from the floor on a phone the moment work completes. The risky interfaces are the handoffs between companies, so a phone-friendly board that everyone can see beats emailed spreadsheets that go stale within hours. One live plan means the planner sees the whole shutdown while each trade sees its own work in context.

How do you stop a shutdown from running over budget?

Carry the budget on each work package, track committed cost and exposure against it, and attach every quote and variation to the item it affects with a recorded reason. For genuine capital items, generate a capex request that freezes its figures at creation for offline sign-off. When the numbers live on the plan instead of in an inbox, the over-budget reason is traceable to the exact work package six months later.

Is Excel or MS Project better for a planned shutdown?

Excel is fine for the parts list and contacts but fails as the live schedule: no rollup, no critical path, no slip detection, and it forks the moment two people edit it. MS Project has a real critical-path engine but nobody updates it from the plant floor, so it drifts from reality within a day. Purpose-built shutdown tools like Phaselo combine a real critical path and baseline with a phone-friendly board so status actually comes from the floor.

More guides

Maintenance Shutdown Planning Guide | Phaselo