Manufacturing
Customer-owned designs in manufacturing records: how to exclude them
By SourceX Editorial · Updated
Short answer
To exclude customer-owned designs from manufacturing records, tag every part number by design owner, remove drawings, models, specifications and CNC programs for customer-owned parts, and keep only the process events around them with part identities masked. Done in that order, the exclusion protects customers without emptying the dataset of the operating history that makes it useful.
Key takeaways
- Tag design ownership at the part number level first, because every later exclusion step keys off that tag.
- Treat any part with unknown design ownership as customer-owned until someone confirms otherwise.
- Remove design artifacts by file type and by field, including drawing notes copied into NCR text.
- Keep process events such as routings, times, dispositions and corrective actions, with part and customer names masked.
- Jobs under export controls are excluded as whole jobs, not masked.
What counts as a customer-owned design in a plant's records?#
A customer-owned design is any drawing, model, specification or program that describes a part the customer designed and the plant only builds. Build-to-print work is the clearest case: the customer sends a drawing and a 3D model, and the plant quotes, programs and makes the part.
The design shows up in more places than the drawing file. CAM and CNC programs encode the geometry. CMM programs and first article inspection reports with ballooned drawings repeat every dimension. Inspection plans list critical characteristics and their tolerances. Even an NCR can quote a drawing note word for word.
Company-owned designs are not automatically in scope either. Your own fixture drawings or product models may be trade secrets you would rather keep, so the tag records ownership, and a separate decision records whether each owned design is licensed, held back or used only as context.
Where do customer designs hide in ERP, QMS and shared drives?#
Customer designs hide wherever a system lets someone attach a file or paste text, so the search covers every system that touches a job. Start with the places below, then ask programmers and quality engineers where else they keep prints.
| Location | What it may contain | Exclusion action |
|---|---|---|
| ERP item master attachments | Drawings, models, customer specs | Remove attachments for customer-owned parts |
| Quote packages and RFQ email | Full drawing sets, models, statements of work | Exclude the folders and mailboxes |
| CAM and CNC program library | Toolpaths that encode geometry | Exclude programs for customer-owned parts |
| CMM and inspection programs | Every dimension and tolerance | Exclude |
| QMS records: FAI, NCR, CAPA | Ballooned drawings, drawing notes in text | Strip attachments; scrub quoted notes |
| Shop-floor travelers and work instructions | Embedded prints and photos | Exclude images; keep operation steps if generic |
| Shared drives by customer | Everything above, in copies | Exclude by default |
Step one: tag every part by design owner#
Tagging every part by design owner is the foundation, because each later step filters on that tag. Export the item master, add a design owner field and fill it from the evidence you already have.
Unknown is a valid value. Parts marked unknown are handled exactly like customer-owned parts until someone with knowledge confirms otherwise.
- Customer-owned: built to the customer's drawing, often with a customer part number cross-reference.
- Company-owned: your own catalog products, standard components and designs your engineers created without assignment.
- Jointly developed: designs shaped by both sides, which need the contract checked before any use.
- Unknown: no clear evidence; treat as customer-owned.
- Evidence to use: drawing title blocks, quote type (build-to-print versus design-and-build), customer part number fields and the customer agreement.
Step two: strip the design artifacts#
Stripping design artifacts means removing every file and field that could reproduce a customer's part. Filter by file type first: drawing formats, 3D model formats, CNC and CAM files, CMM programs and image files attached to customer-owned parts.
Then scrub text. NCR descriptions, CAPA root cause statements and traveler notes sometimes copy dimensions, tolerances or drawing notes. A pattern search for tolerance formats and drawing references, followed by human review of the hits, catches most of them. Keep a log of what was removed and why.
Apply the same filters to exports, not just live systems. Old ERP backups, migrated archives and email exports often carry the attachments the live system no longer shows. Building the candidate dataset from a fresh, filtered export, rather than copying folders, keeps forgotten design files from slipping back in.
Step three: keep the process events, masked#
Process events are the records of what happened on the floor around a part: when it ran, on which work center, how long setup took, what was scrapped, what the NCR decided and what the CAPA changed. These events describe your operation, not the customer's design, and they carry most of the value in manufacturing records.
Mask part numbers and customer names with consistent codes so that every event for one part still links together. Generalize anything that drifts back toward design, such as measured values tied to a drawing characteristic.
| Field type | Treatment | Example |
|---|---|---|
| Part number and customer name | Replace with consistent codes | Part P-0412 for customer C-17 |
| Routing and operation codes | Keep | Saw, turn, mill, deburr, inspect |
| Setup, run and queue times | Keep | Actual versus standard hours |
| Scrap, rework and NCR disposition | Keep | Use as is, rework, scrap, return to supplier |
| Root cause and corrective action text | Keep after scrubbing design details | Fixture clamping changed |
| Measured dimensions against drawing | Generalize or remove | In tolerance or out of tolerance only |
| Material and heat lot | Keep or code | Supplier lot coded |
Export-controlled jobs are excluded whole#
Export-controlled jobs are excluded as complete jobs because masking does not solve the problem. The ITAR definition of technical data includes blueprints, drawings, photographs, plans, instructions and documentation required to design, build, operate or maintain defense articles. The EAR treats as technology any information necessary to develop, produce, use or maintain an item.
Process records for such work can themselves be controlled, and releasing controlled technology to a foreign person can count as an export. Flag export-controlled jobs by customer, contract and part in the design owner tag, and remove every record linked to them before any other preparation begins.
Illustrative: a precision machining company draws the line#
Illustrative: a fictional precision machining company makes parts for semiconductor equipment, packaging machinery and industrial pump customers, plus a small line of its own fixture components. Its ERP holds jobs and routings, its QMS holds NCRs and CAPAs, and a shared drive holds customer prints by customer name.
The COO has the quality team tag the item master. Most parts are build-to-print and tagged customer-owned. The fixture components are company-owned. A handful of parts have no clear owner and are treated as customer-owned. One customer's work is under export controls, so every job for that customer is removed.
The resulting candidate set keeps routings, actual times, scrap, NCR dispositions and CAPA reasoning for all remaining jobs, with codes in place of part and customer names. Drawings, programs, CMM files and the shared drive are excluded entirely, and the exclusion log goes to counsel for review.
How SourceX approaches design exclusions#
SourceX treats customer-owned designs as excluded by default. In the SourceX five-step transaction, the Rights step confirms which parts and customers are out of scope, and the Preparation step applies the tags, removals and masking described above.
The SourceX Evidence Packet records the exclusion rules, the privacy record and the release authorization, so the plant can show a customer or buyer exactly what was removed. The supplier approves the final scope before Delivery.
Frequently asked questions
Do customer NDAs restrict process data even after drawings are removed?
They can. Some NDAs and supply agreements define confidential information to include everything learned or generated while working for the customer. In those cases even masked process events may need the customer's consent or exclusion. Read the confidentiality definition for each major customer before including its jobs.
Can jointly developed designs be included?
Only after the contract is checked. Joint development often comes with split ownership, use limits or consent requirements. Many plants exclude jointly developed parts in a first package and revisit them once counsel has read the agreements.
How do we stop masked codes from being reversed?
Use random codes rather than shortened part numbers, keep the lookup table inside the company, and remove free-text fields that repeat the original identifiers. Check for indirect clues too, such as a unique material or a rare process that points to one customer.
How do we show the exclusion was done properly?
Keep an exclusion log listing each rule, the systems it was applied to, the categories of records removed and who reviewed the result. Spot-check a sample of the output by hand. The log becomes part of the evidence that the package respects customer rights.
Should we tell customers that their designs are excluded?
It often helps. A short note to major customers explaining that drawings, models and programs are excluded, and that any process records are masked, answers the first question most customers ask. Whether notice or consent is required depends on each agreement, so confirm with counsel before sending anything.
Sources
- 22 CFR 120.33(a)(1) defines ITAR technical data to include information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles, including blueprints, drawings, photographs, plans, instructions or documentation. Source
- BIS describes EAR technology (15 CFR 772.1) as information necessary for the development, production, use, operation, installation, maintenance, repair, overhaul, or refurbishing of an item. Source
- Under 15 CFR 734.13, export includes the release or transfer of technology or source code to a foreign person in the United States, deemed an export to that person's most recent country of citizenship or permanent residency. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.