TEST BUILD — an unstable work in progress, not the released simulator. Things here are half-finished on purpose. The stable version is at reactordynamics.com.

PWR Operator Manual · Open the simulator

02 — Simulator User Guide

Document: PWR-SIM-01
Title: Reactor⚛️Dynamics — PWR Trainer Operation
Revision: 24


1.0 Purpose

Provide step-by-step instructions to launch the simulator, navigate the human-machine interface (HMI), select plant modes and missions, and use trainer tools without modifying plant state incorrectly.


2.0 Starting the simulator

2.1 Requirements

2.2 Launch

  1. From the home page, open the PWR control room — or open the offline download, a single HTML file that runs with no internet connection.
  2. Confirm the board fills the plant area with its vital-parameter tiles across the top, and that the right column shows the Instructor, the tool tabs, and the System Scanner.
  3. The Main Menu opens on every load. If it is closed, press Main Menu in the tools row; the plant is the Pressurized Water Reactor.

2.3 First actions (recommended)

StepAction
1Press Main Menu in the tools row (it also opens on every load)
2Click Free Play
3Select the starting condition (or pick Walkthroughs or Lessons for a guided session)
4Starting conditions: Hot Full Power (Mode 1), 50 % Power (Mode 1), At Power — power ascension (Mode 1), Hot Standby (Mode 3), or Cold Shutdown (Mode 5)
5Press Play if paused; set speed 1× until familiar

3.0 Board layout (PWR)

The PWR uses a single full-plant synoptic board as the sole control surface — one stage carrying the plant mimic, its control cards, and the vital-parameter tiles. **There is no view switcher and no separate gauge strip**: the tiles are part of the board. The legacy multi-view plant display with its own gauge strip applies to RBMK/BWR only.

┌─ PWR BOARD (one stage) ─────────────────────────────────────┐┌ Sim clock / Play / Speed ─┐
│ [Power][Tavg][Subcool][Pressure][PZR Lvl][SG Lvl]  ← tiles  ││ 📖 Manual  ? Help         │
│                                                             │├ Instructor ───────────────┤
│              PLANT MIMIC + CONTROL CARDS                    ││ commentary / gates        │
│   (rod control, PZR, CVCS, ECCS/RHR/AFW, SG feed,           │├ Tools ────────────────────┤
│    steam dump, turbine-generator, condenser cooling …)      ││ Operate  Inject Failure   │
│                                                             ││ Graph  Physics  Settings  │
├──────────────────────────────┬──────────────────────────────┤├ System Scanner ───────────┤
│ Strip chart (trends)         │ Alarm panel                  ││ hover = name; click = full │
└──────────────────────────────┴──────────────────────────────┘└───────────────────────────┘

3.1 Vital-parameter tiles

Six tiles across the top of the board. Each shows the reading, a short trend trace, and the seven protection regions behind it — trip · alarm · acceptable · NORMAL · acceptable · alarm · trip — drawn from the plant's live protection tables, so a retune moves the tile with it. Always instrument readings, never truth (HR1).

TileMeaning
REACTOR POWERNeutron power, % rated
AVG COOLANT TEMPERATURETavg — the band tracks the sliding Tavg program
SUBCOOLING MARGINMargin to boiling — TMI truth-teller
PRIMARY PRESSURERCS pressure; the green band is the pressurizer's own control band
PRESSURIZER LEVELPressurizer water level, %
STEAM GENERATOR LEVELSG narrow-range level, %

Units follow Settings → Units (§7.6): US customary (psi / °F) or SI (MPa / °C), tiles and strip chart together.

3.2 Board cards (control homes)

The cards are laid out around the mimic. Nothing on the board is tabbed — every card is visible at once, which is the point of a single-stage board.

CardPrimary controls
REACTOR / ROD CONTROLControl bank Raise/Lower, rod speed, nudge, SCRAM (+ RPS reset)
CONTROL / SHUTDOWNControl-bank and shutdown-bank position, insertion limit
NUCLEAR INSTRUMENTATION (NIS)Source/intermediate range, SUR, reactivity, period, SR detector, trip blocks, 1/M plot
PRESSURIZER (+ HEATER, SPRAY)Pressure, Pressure SP, heaters, spray, level
CHARGING / LETDOWN / BORONCharging pump and flow, CVCS Inventory Control AUTO, letdown orifices, borate/dilute and boron target
ECCS (×2) / RHR / AFW / AUX FEED WATERHPI/LPI, RHR alignment and HX flow split, AFW pump and throttle, ESF AUTO re-arm
SITAccumulator status — passive, discharge indication only
STEAM GEN FEEDSG level, steam flow / feed flow matched pair, feed pump, MSIV
STEAM DUMPDump valve position, Dump SP, AUTO/MANUAL
TURBINE-GENERATORLoad mode (Follow / Manual / Off), Turbine Load MWe, main breaker, RPM/MWe
CONDENSER COOLINGCondenser vacuum, circulating-water inlet temperature

PORV, block valve, RCPs, MSIV and the safety valves live on the mimic itself rather than on a card — click the component. 03_CONTROLS_AND_INDICATIONS.md is the per-control reference.

3.3 Right column

RegionFunction
Sim controlsPlay/Pause, speed 1× / 5× / 10× / 60× and the two WARP rungs 600× / 3600× with the achieved-rate readout beside them, Manual, Help, Contact, and Board focus (⛶) — hides this column and enlarges the board
Main Menu buttonIn the tools row beside Settings: choose Free Play, a walkthrough or a lesson, and Reset (§5.0)
InstructorScenario commentary, gates, walkthrough step grading
ToolsOperate · Inject Failure · Graph · Physics · Settings (§7.0)
System ScannerThe inspection surface — hover anything to name it; click the block to expand it (§3.4)

3.4 System Scanner — the inspection surface

The Scanner answers "what is this?" in two tiers, and it covers the whole board: every card, control, component and indication, plus the shell chrome, the vital-parameter tiles and the active alarm tiles.

TierHowWhat you get
CollapsedPoint at anythingThe name and one sentence — what the thing does
ExpandedClick the Scanner block, then pointThe full account: how it behaves, what it is wired to, and the trap that catches people

Expanded entries carry a 📖 Manual link that opens the on-screen Operator's Manual **at the exact section documenting that item** — the fastest route from "what is this knob" to the procedure that uses it. The collapsed/expanded choice is remembered between sessions.

Alarm-tile detail is generated from the plant's own protection table, so it states the real setpoint in your selected units and cannot drift from a retune.

NOTE: hovering does not ring or highlight the element. The only glows on the board are the Instructor's (blue) and the walkthrough's step preview (green) — both of which point at something you did not choose to look at.


4.0 Sim controls and keyboard shortcuts

4.1 Time control

ControlEffect
Play / PauseStart or freeze simulated time (diagram freezes when paused)
SpeedTwo tiers. PLAY: 1×, 5×, 10×, 60× — the full physics at its 0.02 s step, identical at every rung. WARP: 600×, 3600× — the same physics at a coarser 0.5 s step, for the long quiet evolutions: xenon, decay heat, boron, a heatup or cooldown
Achieved rateThe badge beside the buttons reads actual N× — the plant-time actually passing per second of wall clock. Green: keeping up with the request. Amber: behind it — the physics cannot keep up with the request, which at 3600× is the ordinary state of most machines. Red: the page itself is stalling
NOTEOn PLAY the physics timestep stays 0.02 s and acceleration runs more steps per wall-clock second. On WARP the step is 0.5 s: over a sim hour every channel stays inside its own instrument noise of the 0.02 s plant (see 12 §2.1), and the buttons are dark while the plant is in a transient — WARP is refused then, and lets go on its own

CAUTION: High speed during approach to criticality or load rejection can leave you behind the plant. Use 1×–10× for startups and transients until proficient.

WARP lets go by itself. The moment the plant moves fast — a reactor trip, a new equipment failure, a first alarm on a quiet board, power moving faster than 2 %/s or pressure faster than 40 psi/s (0.276 MPa/s), or the loop asked for more sub-steps than it can give — WARP drops to 60× and a toast names the reason. The two WARP buttons stay dark for as long as the condition stands, and light again the moment it lifts — there is no timer. Asking for WARP while it is unavailable lands you at 60× with the same toast. A mission's own fast-forward never uses WARP.

The plant can hold the clock. Where the plant needs you and cannot let you skip past — today the accumulator arming window on a heatup, from the 665 psi (4.585 MPa) cover gas until the accumulator valve is open — the clock drops to 1× and every speed button above it is refused, with the reason in the scanner bar under the board. Opening the valve releases it. This hold ignores the fast-forward dropout setting, because the point of it is that the window cannot be recovered once passed.

A walkthrough drives the speed control for you. While a walkthrough is running, each step sets the clock to the rate that step should be played at: the rung named on its ⏩ wait line for a long wait, a slower rate where the step names its own — the four steps of the approach to criticality and the pull into Mode 1 run at 10× or 5× against the wait line's rule of thumb, because a rod step has to land while you can still read the rate — and 1× for everything else. It also comes back down to 1× the moment the step's check-off criterion is met, so a fast-forward cannot run the plant past the thing the next step is about. When it raises the clock for a long wait, the line under the speed buttons says so — Speeding up to N× — nothing to do for a while. You keep the bar: any rung you press stands for the rest of that step, and the walkthrough takes the clock again at the next one. The step's own rung stays marked on the strip throughout, and pulses only while the plant is not on it.

Fast-forward dropout. Acceleration snaps back to 1× when something arrives that you have to look at: a reactor trip, a new equipment failure, or the **first alarm on an otherwise quiet board**. A toast names the reason. Alarms that follow while the board is already lit do not drop the clock — inside a casualty those are the consequences you are already working, and stopping for each one would make fast-forward useless exactly when a long evolution (cooldown, boration, decay-heat wait) needs it. Standing alarms therefore suppress alarm dropouts for as long as they stand; a trip or a new failure still gets through. Turn the whole behavior off at Settings → Fast-forward dropout.

4.2 Keyboard (global)

KeyAction
SpacePlay / Pause (when not focused on a hold-button)
AAcknowledge all alarms
MOpen / close Operator’s Manual overlay
?Help overlay
EscClose overlays

4.3 Destructive control arming

SCRAM is the one control on the PWR board that arms. It is a two-press CONFIRM with a 3 s arm window: the first press reads CONFIRM, a second press inside the window trips the reactor, and letting the window expire disarms it with no action taken.

After the trip the same button becomes the RPS reset — it reads PRESS TO RESET, or names what is blocking the reset when the plant is not ready (see 03 §3.5.1). The reset is refused until the rods are seated.

NOTE: every other control on the board acts on a single press, including ones with real consequences — MSIV Close, PORV Block Valve Isolate, and taking the generator Off (the planned offline). Read the control before you click it; there is no second-chance prompt. Save first (§11.0) if you are experimenting.

The wider two-press convention belongs to the classic control-bar panels the RBMK and BWR still use, where breaker-open, PORV block close, ADS and SLC all arm. The PWR board replaced that bar, and only SCRAM carried the idiom across.


5.0 Main Menu

Entry: Main Menu, in the tools row beside Settings. The menu also opens on every load, with the plant paused until you close it or start something.

5.1 Selection order

  1. Continue — shown only when this browser holds an autosave; picks up where you left off.
  2. Category — Lessons (short guided sessions with the Instructor), Walkthroughs (a
  3. guided startup and shutdown) or Free Play. Clicking one moves the list to a narrow left column and shows that category's choices beside it; click another to switch.

  4. The choice inside it — for Lessons, the full-power opener (about 5 minutes); for
  5. Walkthroughs, a part of the Startup or Shutdown (Startup Part 1 to Part 3, each with its starting and ending Mode; the next one to do is tagged NEXT); for Free Play, the starting condition and Start Free Play.

Once the plant has run, every Start (and Reset) asks before it replaces the plant you have: a line reads This restarts the plant. Your current plant will be lost. with **Restart plant and Cancel** beside it. Nothing happens until you press one.

5.2 Free Play vs training

ModeUse
Free PlayOperator-driven; inject failures from the Inject Failure tab, which appears only in Free Play; the Instructor debriefs you after a trip or failure (§8.2)
WalkthroughsStep-graded Startup and Shutdown parts, run from authored procedures
LessonsShort guided sessions with the Instructor (the full-power opener)

Campaign missions and Scenarios are not offered in the Main Menu.

5.3 Initial conditions (PWR Free Play) and plant MODES

State IDLabelPlant MODEBoard meaning
hot_full_powerHot Full PowerMode 1, At PowerCritical ~100 %, ~100 MWe
50_percent50 % PowerMode 1, At PowerCritical, 50 % power, 50 MWe
low_powerAt Power — power ascensionMode 1, At PowerCritical, about 10 % power and 10 MWe — the hand-off point between the startup and the power ascension
hot_zero_powerHot StandbyMode 3, Hot StandbySubcritical, hot T/P, control bank in, SR on
cold_shutdownCold ShutdownMode 5, Cold ShutdownSubcritical, RCS 122 °F (50 °C) / 363 psi (2.50 MPa), RCPs secured, RHR in service, both banks in, the P-11 blocks taken, SR on, boron 918 ppm — the SG secondary rides at its own saturation, 1.8 psi (0.0127 MPa)

The cold end is Mode 5, Cold Shutdown. Take the plant up with PWR-T20, or run PWR-T21 down from power; both run end to end. These five states are the whole list — there is no Mode 4, Hot Shutdown start; you pass through Mode 4 on the way.


6.0 Display modes (Learning vs Realistic)

ModeWhat you see
LearningFull teaching visuals, SUR, deception duals (Indicated vs Actual on the PORV when relevant), contextual xenon/fuel chips. The strip chart traces the true physics
RealisticQuiet board — indications and status only, no teaching overlays. The strip chart traces the instruments, so a failed sensor lies on the trend exactly as it does on the gauge
Physics OverlayLearning only — reactivity (pcm), period, inventory, void, etc., drawn on the board. Not the same thing as the Physics tab (§7.5), which is always available and is a panel of its own

These are set by the CONTENT, not by you. There is no display-mode selector: the Settings tab holds units, fast-forward dropout and About, and nothing else. A scenario declares the mode it needs, and the TMI-2 module is the reason the mechanism exists — Parts 1 and 3 run Realistic, so the board and the trend both keep the deception, and Part 2 switches to Learning so the reveal can show you the physics underneath. Free Play always runs Learning.

Automatic protection and the alarms read the instruments in both modes (HR1). The mode changes what is drawn; it never changes what the plant decides.

WARNING: in Realistic mode the PORV indicator can lie with no dual Actual column and no relief animation — exactly as at TMI-2. The tailpipe temperature is your only honest tell. Run the TMI-2 module (campaign Act V, missions 27–29) to practise it — see 08_ACCIDENT_TMI.md. You cannot reach that board state from Free Play.


7.0 Tools tabs

The side panel's tabs are Instructor and Indications, plus Inject Failure in Free Play only — it is hidden while a walkthrough, lesson or mission runs. Settings, Help and Feedback sit in the top bar. Plant automation is not a tab — it lives on the board (§7.3).

7.1 Operate

7.2 Inject Failure

Free Play only. The tab is hidden during walkthroughs, lessons and missions.

See 07 for the response procedure for each failure.

7.3 Plant automation (board AUTO controls — not a tab)

Per-channel AUTO / MAN controllers that read instruments and issue plant commands. They live on the board's control cards (there is no separate tab): STEAM GEN FEED → AUTO (three-element SG level), BORON → ON (target ppm), STEAM DUMP → AUTO, CHARGING → AUTO. Rod control has no automatic channel on this plant, and since Rev 17 there is no button for one either (03 §14.3).

Channel (label)Holds / drives
Boron concentration (target)Batch-doses boron to a target ppm (metered, totalizer-stopped — see 03 §7.5)
Boron → rod position trimBang-bang boron trim
Pressurizer pressureHeaters + spray mode
CVCS make-upInventory make-up
Feed pump → SG level (three-element)SG level
Steam dumpBypass mode
Turbine / grid (load follow)Load follow mode

Rules:

7.4 Graph

Strip / multi-parameter trends for post-event review and slow transients (xenon, boron). Pick which parameters plot under Plot parameters.

What the trend traces depends on the display mode the content set (§6.0). In Learning it plots the true physics — sensor noise is not a lesson, and a clean trace is what makes a slow trend readable. In Realistic it plots the instruments, so a failed or drifting sensor shows up on the trend exactly as it does on the gauge, and must be caught by cross-checking diverse indications (see PWR-E20/E21/E22 in 07_ABNORMAL_EMERGENCY.md). Alarms and automatic protection read the instruments in both modes (HR1) — the mode changes what is drawn, never what the plant decides.

The vertical scale auto-ranges to round numbers and is then held: it re-scales only when a trace leaves the band, so a line does not change shape once it has been drawn. A trace brightens when its parameter is in an alarm band. Chart units follow Settings → Units, the same selection the board tiles use.

7.5 Physics

The true plant state, behind the instruments. Everything on this tab is what the simulator is actually computing — no lag, no noise, and a failed sensor does not change a single figure on it. It is an engineering display, not a second board: nothing here alarms, nothing here is what protection reads, and a real control room has none of it.

Rows are chosen for what the board cannot show — quantities with no instrument at all, or none wired to a readout — and are ordered along the energy path. Five groups:

GroupWhat is in it
ReactivityNet reactivity (pcm) · fuel temperature (the Doppler driver) · xenon (% eq) · true RCS boron
Core heatFission power · decay heat (% and MWt) · total core heat · peak clad temperature · core void fraction
Primary coolantCore ΔT (hot − cold) · true subcooling margin · heatup/cooldown rate · RCS inventory · loop void fraction · loop flow
Loop pressureHot leg (the pressurizer datum) · cold leg (pump discharge) · pump suction · suction subcooling · RCP cavitation · primary leak flow
Heat sink & outputSteam − feed mismatch · turbine steam demand · gross electrical · cycle efficiency

Three of those repay a second look:

Use it after a transient, not during one. Operating from the true values instead of the instruments teaches the wrong habit and skips the lesson the sensor-failure drills exist for (PWR-E20/E21/E22 in 07_ABNORMAL_EMERGENCY.md). Reading it afterwards to find out why the plant did what it did is the point.

Units follow Settings → Units (§7.6). RBMK and BWR have no physics panel authored yet.

7.6 Settings

There is no display-mode, terminology or physics-overlay selector here — see §6.0.


8.0 Alarms and Instructor

8.1 Alarm panel

Philosophy: Alarms read instruments. A stuck sensor can hide a real condition or create a false one.

8.2 Instructor panel

During missions:

NOTE: Rewind restores a checkpoint; use it after a failed recovery or softlock.

In Free Play the Instructor does not direct you, but after a reactor trip or an **injected failure it writes a debrief** in the Instructor tab, read off the instruments and alarms: what the board says happened (the trip and its recorded cause, the first alarms), the automatic actions with their times, five key readings and which way they are going, and whether the plant has held steady or is still changing. A toast points you at it. Retry rewinds the plant to the last checkpoint before the event — for a failure you injected or a trip you made by hand, that is the instant before it; Dismiss closes the debrief.

8.3 Walkthroughs and their prerequisite banner

A walkthrough is a live, self-checking procedure run against the plant. Start one from the Main Menu → Walkthroughs, which lists the operating cycle as Startup Part 1–3 and *Shutdown Part 1–3*; its Start button loads the procedure's own starting condition first. Lessons start the same way, from Main Menu → Lessons. A running walkthrough is drawn in the Instructor tab one step at a time, headed Step X of N, with the step's details open. Steps check themselves off the instruments while you operate; nothing is reset by starting one and no command is ever blocked. Every step waits for Continue, which is dark until the instruments say the step is done and lights when they do; **Rewind step** takes the plant and the walkthrough back to the start of the previous step (the chart's Rewind is off while a walkthrough runs).

Procedures also carry machine-checked prerequisites. From the moment a walkthrough starts, the Instructor grades each one against the live plant — reading the same indications you do — and if any does not match, the walkthrough shows a caution banner listing each failed item with what the procedure expects and what the plant actually reads (for example: boron at the estimated critical condition, ≈ 683 ppm — reads 857). The Instructor adds one comment pointing you at it.

Reading a step card

Every step card leads with its number and instruction. The card you are on adds a block underneath it:

LineWhat it is
Check-off criterionThe indication the step is graded on, in blue; it turns green when met.
Use …The board control this step drives, and the value to drive it to.
⏩ wait lineRoughly how long the step takes in plant time, and what the clock is doing about it — the walkthrough sets the rung itself, and the line reads set the speed control to N× only when you have taken the bar back (§4.1).
Hold progressOn a step that needs the plant to stay put for a while, a line counts it — Averaging… 13 of 30 plant-seconds — and says when a disturbance restarted the count.
Continue ▶On every step, and pinned to the bottom of the card so it never scrolls out of sight; a fade above it means there is more text to scroll. Dark until the instruments satisfy the step, lit when they do — press it to move on.
⏪ Rewind stepBeside Continue. Takes the plant and the walkthrough back to the start of the previous step. Off on the first step.
BackgroundThe step's reasoning, cautions and extra notes, drawn in full under the step.

When a step's text tells you an alarm is expected, that alarm's tile carries a small **predicted by step N** tag while the step is active. The alarm is still real — the tag tells you it is the one the procedure expected.

The wait line appears on steps that hold three plant-minutes or longer, and the walkthrough presses that rung itself (§4.1). The suggested rung is the lowest one that finishes the wait in about half a minute of real time, so three quarters of the waits stay on the full-fidelity 1× to 60× tier; the ones of about forty plant-minutes and up — the pressurization, the heatup ride, the cooldown legs, the boration — call for 600× or 3600×, which are WARP and will be refused while the plant is in a transient (§4.1). The plant-time figure is an upper bound taken from the procedure's own dwell: drive the plant harder and you will get there sooner. The rung is a request, not a rate — what your machine actually achieves is shown beside the speed buttons.


9.0 On-screen Operator’s Manual


10.0 Recommended first-session checklist

#TaskReference
1Launch PWR Free Play at Hot Full Power (Mode 1, At Power)§2, §5
2Identify Power, Pressure, Tavg, Subcool, SG level§3.1
3Practice SCRAM arming on Rod card (do not fire yet)§4.3
4Select MAN on the generator card → set load ≈ 90 MWe; observe steam flow / Tavg03, 05
5Restore Follow05
6Pause; open Manual (M); find trip setpoints09
7Load Hot Standby (Mode 3, Hot Standby); practice criticality → Mode 2, StartupPWR-N03, PWR-T03
8Raise above 5 % into Mode 1, At Power; then shut down to Mode 3, Hot StandbyPWR-N06, N14
9Read PWR-T20 / PWR-T21 for Mode 5, Cold Shutdown ↔ Mode 1, At Power full story05
10Inject Loss of Feedwater in Mode 1, At Power; practice AFWPWR-E01

11.0 Save, reset, and recovery

ActionWhen
SaveBefore risky free-play experiments
LoadRestore a saved JSON state
ResetReturn to selected initial condition (asks you to confirm: Restart plant / Cancel)
RewindMission checkpoint restore after failure
Clear failuresInject Failure tab (Free Play) — end a drill without a full reset

12.0 Training campaign overview (optional path)

Campaign “Zero to Operator” (six acts, 34 missions plus one bonus) takes a novice from board familiarization through TMI and a senior operator exam. Recommended order is the campaign list; Free Play is always available. The mission-by-mission map, with the procedure each one exercises, is chapter 11.

ActMissionsTheme
I3The Machine — energy path, chain reaction
II6The Physics — criticality, feedback, xenon, boron
III12The Controls — pressure, feed, rods AUTO, load follow, automation
IV8When Things Go Wrong — protection, LOFW, RCP, LOCA-class drills
V3Three Mile Island — the TMI-2 module (Parts 1–3)
VI2The Reckoning — compressed TMI + qualification exam

13.0 Related documents

These manuals are licensed CC BY 4.0 — see Legal. Training documents for an educational simulator, not licensing-basis documents for a real plant.