Pool Automation and Time Controls

Make sense of automation, schedules, mechanical timers, service modes, delays, freeze behavior, remote access, and reversible control changes.

Owner: BlueLux OperationsUpdated September 11, 2026

At a glance

A short orientation to the key ideas explained in the guide below.

Key points

  1. Scan electrical/control enclosures from outside for hazards.
  2. List every controller and manual override.
  3. Establish the hierarchy and schedule owner.
  4. Capture time, mode, schedules, setpoints, delays, protection and alerts.
  5. Map every circuit name to physical equipment.
  6. Use temporary service mode only with a defined exit.
  7. Test physical results and dependencies.
  8. Confirm next event and final AUTO/authorized state.
  9. Protect account ownership and credentials.

Done when

  • Control hierarchy and single source of schedule authority are documented, including every manual/app/cloud override that can alter operation.
  • Schedules, circuits, speeds, setpoints, delays, freeze behavior and pool or spa dependencies have been verified in the field or marked unverified.

Pool controls coordinate water paths, pump output, heating, sanitation, cleaners, lights, features, covers and protective behavior. A single button can therefore change several physical systems at once.

The central field question is not “Where is the schedule?” It is which control owns each action, what can override it, and what physically happens when the command runs?

Fast orientation

  1. Scan electrical/control enclosures from outside for hazards.
  2. List every controller and manual override.
  3. Establish the hierarchy and schedule owner.
  4. Capture time, mode, schedules, setpoints, delays, protection and alerts.
  5. Map every circuit name to physical equipment.
  6. Use temporary service mode only with a defined exit.
  7. Test physical results and dependencies.
  8. Confirm next event and final AUTO/authorized state.
  9. Protect account ownership and credentials.

1. Common control layers

A pool or spa system may include:

  • breaker/disconnect labels;
  • mechanical time switch;
  • digital timer;
  • relay/load center;
  • integrated automation controller;
  • pump's own keypad and schedule;
  • heater local controller;
  • salt cell/chemical controller;
  • valve actuators;
  • cleaner/booster timer;
  • cover controller/interlock;
  • indoor panel, handheld remote or wall switch;
  • mobile app/cloud service;
  • voice assistant or third-party home automation;
  • temporary manual override, egg timer or service mode.

Do not assume the newest app is the highest authority. A mechanical timer can remove power, a pump schedule can run under an idle automation display, and a local switch can leave equipment unavailable to the cloud.

2. Build the control hierarchy

For each device, record:

  1. Power source/control: what permits or removes power?
  2. Command source: what tells it to start, stop or change?
  3. Local state: auto, on, off, service, remote, schedule or lock?
  4. Protection/interlocks: what delays or inhibits operation?
  5. Physical outcome: what actually moves or runs?
  6. Fallback: what happens if network/cloud/automation fails?

Example:

Automation schedule → pump data command → RPM program → water flow → heater flow approval → salt-cell production eligibility

If the pump also has an internal schedule, decide under the exact manuals which layer should own routine timing. Two active schedule owners create confusing, hard-to-reproduce states.

3. Capture the as-found configuration

Before making changes, record/screenshoot:

  • controller clock, date, time zone and daylight-saving state;
  • AUTO, SERVICE, TIMEOUT or manual mode;
  • all schedules, including disabled/seasonal schedules;
  • days, start time, end time or duration;
  • priority/overlap behavior;
  • pump programs and speeds/flows;
  • pool or spa mode and valve assignments;
  • heater mode and setpoints;
  • sanitizer pool or spa output;
  • cleaner/booster dependencies;
  • feature/light groups;
  • egg timers/manual timeout;
  • freeze-protection circuits and threshold reading;
  • heater cool-down and valve/pump delays;
  • alerts, warnings and recent faults;
  • app/cloud connection and local display agreement;
  • next scheduled event.

Do not expose network, MAC/IP, serial, pairing, address or customer information in public feedback.

4. Circuit names are hypotheses until proven

Names like AUX 2, WATERFALL, CLEANER or SPA LIGHT may be stale or wrong.

Safely verify each authorized circuit by observing:

  • relay click is not enough;
  • pump display/output;
  • actuator travel and water response;
  • light/feature/device operation;
  • heater/sanitizer status;
  • current pool or spa water level;
  • any unexpected secondary equipment.

Relabel only after proof. Mark unknown circuits “UNVERIFIED, DO NOT OPERATE.”

Never energize an unknown circuit that could feed removed/damaged equipment, an open wire, drained pump, unsafe cover or inaccessible feature.

5. AUTO, SERVICE and TIMEOUT

Exact terms differ, but common behavior is:

AUTO

Normal schedules, sensors and remote commands operate.

SERVICE

Routine automation may be disabled so local manual control can test equipment. Some systems turn auxiliary circuits off immediately on entry and require each circuit to be enabled manually.

TIMEOUT / TIMER SERVICE

Manual service control returns automatically after a set duration. This reduces, but does not eliminate, the risk of leaving normal operation disabled.

Before entering service:

  • record running equipment and active heating/chemical states;
  • understand what stops immediately;
  • protect required heater cooldown;
  • know valve movement and pump delay behavior;
  • set a realistic return timer;
  • keep ownership of the site until AUTO is restored and verified.

Never leave indefinite SERVICE mode without explicit property protection and handoff.

6. Manual override and egg timers

A manual ON command can remain active until:

  • switched off;
  • an egg timer expires;
  • next schedule transition;
  • service timer expires;
  • automation changes mode;
  • power/network event occurs.

Record the exact exit condition. “It should turn off later” is not acceptable.

Beware settings such as DON'T STOP or unusually long default egg timers. Verify them against the intended device, continuous operation may be harmless for a light but damaging for a dry booster or overflowing feature.

7. Schedules and overlaps

For each schedule, verify:

  • correct controller time/date;
  • day selection;
  • start and end versus duration semantics;
  • midnight crossover;
  • priority when programs overlap;
  • pump speed/flow and dependent circuit;
  • pool versus spa allocation;
  • seasonal variants;
  • utility/time-of-use intention without compromising required operation;
  • what happens after power or network interruption.

Check the next event after saving. A schedule can look correct but be disabled, lower priority, assigned to the wrong circuit or already overridden.

8. Pump schedule coordination

A variable-speed pump can be:

  • scheduled internally;
  • commanded by automation over data connection;
  • started by relay/contact inputs;
  • manually timed at its keypad;
  • subject to priming/thermal behaviors.

Document one normal owner and any approved fallback. Confirm:

  • pump clock agrees when its scheduler is used;
  • external-control mode is correct;
  • program names map to purpose;
  • heater/salt/cleaner minimum operating needs are satisfied;
  • manual service does not leave an unexpected internal schedule active;
  • power is not being removed in a way prohibited by the pump/system design.

9. Pool and spa valves and delays

Shared systems may automatically:

  1. stop/reduce the pump;
  2. rotate suction and return valves;
  3. wait for valve travel;
  4. restart at a pool or spa speed;
  5. enable heating/sanitation setpoints.

Do not cancel valve delay merely because “nothing is happening.” Observe actuator travel and pool or spa levels. Confirm the spa is not draining/overflowing and the pump has safe suction/return before operation resumes.

10. Heater cooldown and fireman-style delay

Some heaters require circulation after heat demand ends to dissipate residual heat. Automation/time-control systems may keep the pump running or interrupt heater demand before pump shutdown.

Document:

  • exact heater requirement;
  • how the controller implements it;
  • timer/relay relationship;
  • whether a manual override can defeat it;
  • what a displayed delay badge means.

Do not override a cooldown to end a visit sooner. A generic delay duration cannot replace the exact heater/control manual.

11. Freeze protection

Freeze behavior can start pumps, rotate between pool or spa paths or enable selected circuits based on an air sensor and configuration.

Record:

  • sensor reading and plausible location;
  • activation threshold/logic as permitted;
  • protected circuits;
  • valve cycle behavior;
  • pump speed;
  • spa override behavior;
  • interaction with covers/features/solar;
  • alert/notification path;
  • power-outage limitation.

Freeze protection is not a guarantee against damage. It depends on power, sensor accuracy, water path, pump operation, weather and configuration. Do not enable a dry/damaged feature pump as a shortcut; use a property-specific freeze plan.

12. Mechanical time switches

From outside/authorized accessible controls, document:

  • exact model and circuit/load label;
  • dial time versus actual time;
  • ON/OFF trippers and secure placement;
  • manual override state;
  • motor/dial movement evidence;
  • enclosure, cover and moisture condition;
  • interaction with pump keypad or automation.

Do not open a powered enclosure, touch terminals, move wiring or select a model based only on appearance. Voltage, poles, load and enclosure suitability are qualified electrical decisions.

If adjusting trippers is within approved scope, preserve the old positions, prevent unsafe starts and verify an actual transition or controlled simulation under the exact manual.

13. App, cloud and offline behavior

Remote access improves monitoring but creates another control path.

Use:

  • property/customer-owned primary account;
  • named delegated professional access where supported;
  • least privilege;
  • no shared plaintext password in service notes;
  • removal of departed technicians/temporary access;
  • documented local fallback when internet/cloud is unavailable.

Compare app status with local controller and physical equipment. “Offline” can mean the cloud cannot see the system while local schedules continue normally, or that the controller itself has a power/communication failure.

Never factory reset or re-pair equipment during routine service without an approved ownership/recovery plan.

14. Safe change workflow

  1. State the field problem and intended outcome.
  2. Confirm authorization and control owner.
  3. Capture full as-found configuration.
  4. Identify every affected dependent device and safety delay.
  5. Make one bounded change.
  6. Save/apply as the exact interface requires.
  7. Verify display and physical outcome.
  8. Test pool, spa, or other affected modes.
  9. Confirm next scheduled event and timeout/override exit.
  10. Restore AUTO/authorized final state.
  11. Document rollback and customer-visible behavior.

Do not bundle unrelated cleanup changes into one visit; they become impossible to attribute or reverse.

15. Qualified-service boundary

This guide does not authorize:

  • opening load centers, time switches or electrical panels;
  • energized electrical testing;
  • breaker, relay, transformer, wiring or actuator rewiring;
  • disabling interlocks/protection/delays;
  • firmware update/downgrade without approved change/recovery plan;
  • factory reset or account takeover;
  • programming an unknown circuit by trial;
  • creating remote access without customer authorization;
  • changing protection logic beyond documented your authorized scope.

Common mistakes

  • Leaving SERVICE mode active.
  • Forgetting a manual override or DON'T STOP egg timer.
  • Running both pump internal and automation schedules unintentionally.
  • Editing a circuit name without proving the physical load.
  • Cancelling heater cooldown or valve delay.
  • Treating an app display as proof equipment moved.
  • Saving a schedule without checking the next event.
  • Enabling freeze protection on unsuitable/dry equipment.
  • Pairing a customer system to a technician's personal account.
  • Publishing network or pairing details in feedback.

Major stop conditions

Stop the task, leave the system safe, and escalate when any of these conditions apply.

  • Open/damaged/wet electrical enclosure, exposed conductor, arcing/burning odor, repeated trip, unknown voltage/circuit, missing deadfront, damaged time-clock mechanism or work requiring an enclosure to be opened.
  • Circuit/feature/valve consequence is unknown; activation could start dry equipment, energize a damaged appliance, drain/overflow a pool or spa, defeat a cover/interlock, create entrapment or expose a person to moving/high-voltage equipment.
  • Controller time, schedule owner or hierarchy cannot be established; two schedulers conflict; remote user is actively changing the system; or cloud/app state disagrees with local physical state.
  • Change would disable/override a heater cooldown, valve delay, freeze protection, flow/pressure protection, sanitizer-pump interlock, cover safeguard or other safety function.

For BlueLux technicians, contractors, and partners

What BlueLux does differently

  • We document a control hierarchy and designate one schedule owner so pump keypad, timer and automation do not fight each other.
  • We capture the next event and field-test physical outcomes, preventing a configuration that looks correct until the technician leaves.
  • We treat service mode, time-out, egg timers, manual overrides and safety delays as temporary state with an explicit exit condition.

Sources and authority

These are the regulations, official guidance, manufacturer instructions, industry references, and documented operating practices materially used for this entry.

  1. manufacturerPentair
    Representative current automation source for schedules, circuits, service/time-out/auto, valve and heater delays, freeze protection, pump/chemistry status and system configuration.Source checked August 26, 2026
  2. manufacturerPentair
    Representative field-facing source for service mode, timer return, manual circuits, badges, delays, schedules, alerts and status interpretation.Source checked August 26, 2026
  3. manufacturerJandy
    Alternate-manufacturer resource for integrated pump, valves, heating, sanitizer, schedules, auxiliaries and service control. Exact installed interface/manual controls.Source checked August 26, 2026
  4. manufacturerIntermatic
    Representative mechanical time-control source for 24-hour dial, ON/OFF trippers, manual override and model-specific electrical/load limits.Source checked August 26, 2026
  5. blue lux field practiceBlueLux Operations
    BlueLux automation audit and change practice (BlueLux Field Practice 1.0)
    The hierarchy map, next-event verification, account-ownership rules and completion criteria.

Related Playbook entries

Was this guide useful?

Every rating and note helps improve this exact version.