A thermal lockout on a motor protection relay is a deliberate inhibit, not a fault, and the decision to override it is governed by the relay's reset class, the motor's thermal model state, and the site's process-safety rules rather than by the operator's sense of urgency.
Industry guidance on thermal-element settings is anchored in the IEEE PCIC paper "Keep on Running: Select Motor Relay Settings to Balance Protection and Operation" (Payne, Miguel, Bhuvaneshwaran, Haas, 2022), which lays out a first-order thermal model used by microprocessor relays to calculate lockout time and inhibit new starts until thermal capacity drops below a settable threshold [S1].
What a thermal lockout actually is
A thermal overload relay is built to sense sustained overcurrent, not instantaneous faults; it disconnects the motor only when excess current persists long enough to threaten insulation, then it holds the trip state through a defined cool-down window [S2]. Built-in winding protection follows the TP designation scheme under IEC 60034-11, with codes such as TP 111 (slow overload, single level, category 1) and TP 211 (slow plus fast/blocked, category 1) defining how the device behaves once the trip threshold is crossed [S4]. After a trip, many overload relays cannot be reset until the thermal element has cooled sufficiently, which is the root mechanism behind the lockout [S3]. The IEEE PCIC paper makes the same point: the relay can prevent a new start until the motor has sufficient thermal capacity to start successfully, and that wait is calculated from the motor datasheet, not from operator judgement [S1].
Manual reset vs auto reset vs lockout: the three reset modes
Manual-reset thermal overload relays require a physical operator action after the bimetal strip or thermal model has cooled, which is the only path that lets a qualified person make a deliberate emergency-restart decision [S2]. Auto-reset relays close themselves after a cooling interval, so any "override" is actually a no-op, but the trade-off is loss of human verification of the fault cause [S2]. Electronic and microprocessor-based units add a third mode, a thermal-capacity lockout, where the relay blocks the start command until the calculated used thermal capacity falls below a programmed inhibit threshold, typically expressed as a percentage of the motor's thermal limit [S1]. For emergency work, the manual-reset path is the only legally clean option, because auto-reset removes the diagnostic checkpoint and the thermal lockout is computed from the same first-order model the protection is built on.
When a thermal lockout can be overridden, and when it cannot

An override is operationally defensible when four conditions line up: the relay is in a manual-reset configuration, the calculated or measured thermal capacity has dropped below the inhibit threshold, the cause of the original overload has been identified and addressed, and the restart is logged with a time-stamped operator or permit record [S1][S3]. It is not defensible when the relay is in auto-reset (no operator decision to make), when a built-in thermal protector is a snap-action bi-metallic disc (Klixon) wired in the control circuit with no external reset access [S4], or when the protection scheme includes an explicit restart-inhibit setpoint whose threshold has not yet been met [S1]. The IEEE PCIC authors warn that if the inhibit window is set too long the motor becomes unavailable, and if set too short the relay will trip on the inrush, so the correct override is to lower the inhibit threshold knowingly, not to bypass it blindly [S1].
Comparison: reset options against decision criteria
Four reset options line up against four decision criteria drawn from the references. Manual reset gives a human gate and a documented emergency restart, but requires an operator at the panel; auto-reset gives unmanned recovery but no fault-cause checkpoint, which is a poor fit for emergency-start discipline [S2]. A settable thermal-capacity inhibit (microprocessor relay) gives the most precise lockout, since the wait is computed from motor datasheet constants, and it can be adjusted in firmware rather than bypassed with a wire [S1]. A sealed bi-metallic thermal protector (TP 111 / TP 211 device mounted in the windings) cannot be overridden at all without replacing the device, because the snap-action disc resets only on temperature fall and the contacts are inside the motor [S4]. For emergency-restart duty, the hierarchy is therefore: microprocessor relay with manual reset and adjustable inhibit first, then manual-reset bimetallic relay, with auto-reset and sealed protectors last.
Procedure for a defensible emergency restart

Step 1, read the trip cause from the relay event record and confirm it is a thermal overload, not a short circuit; the two faults are not interchangeable and an overload relay is explicitly not a short-circuit device [S5]. Step 2, allow the relay's thermal model or the bimetal element to reach its reset threshold, which on bimetallic units is a physical cool-down of typically 1-3 minutes depending on ambient and prior heating [S3][S6]. Step 3, perform a visual and electrical check on the driven load (jam, bearing seizure, coupling, process valve) so the restart is not into the same fault [S5]. Step 4, execute the manual reset, start the motor, and log the event with motor nameplate data, ambient, prior lockout duration, and the signature of the person who authorized the override. A documented thermal relay override is an audit trail, not just a button press.
Standards, sourcing, and what the references actually cover
Built-in motor protection TP codes are defined in IEC 60034-11, which the EEP reference cites directly when mapping TP 111 to slow overload and TP 211 to slow plus blocked-rotor protection [S4]. The IEEE PCIC paper provides the calculation framework for thermal-element trip and reset settings used by microprocessor relays in petrochemical service [S1]. Vendor explainers from Schneider Electric, Eaton, and CHINT consistently describe thermal overload relays as sustained-overcurrent devices with distinct manual and auto reset paths, and explicitly exclude short-circuit protection from the relay's job [S2][S5][S6]. Two of the references, the Eandisales thermal overload article (2026-03-01) and the CHINT beginner's guide (2025-05-23), were published inside the six-month window for this review [S5][S6].
Limits, failure modes, and signals to track

The single biggest failure mode is the repeated-restart trap: if a motor is restarted several times within a short window, locked-rotor current keeps adding heat and the next trip arrives faster, even if each individual restart looked clean [S4]. A second failure mode is hidden cooling failure, where the relay resets but the motor windings have not, because ambient temperature is high or ventilation is blocked, and the TP 111 / TP 211 device does not see the same air the operator does [S4]. Trackable signals for the next planning cycle are: the fraction of motor trips with a recorded operator override in the past 90 days, the distribution of lockout durations against the calculated first-order thermal model, and any change in inhibit-threshold setpoints across the site's protection relay fleet.
For a deeper cross-domain read on decision-mapping under similar constraint logic, the spec-by-spec comparison in cable gland vs conduit fitting applies a similar override-versus-replace framework to enclosure entry choices. A complementary view on documentation discipline around equipment overrides is in how fabrication yards digitize weld tracking for offshore wind foundations, where the same audit-trail logic governs a different override event.