The deviation, not the measurement Block before release Works offline

Custom app for deviations at a critical control point

Almost everyone records measurements. What happens once a critical limit is exceeded is a different matter: someone then has to decide what happens to the product, the batch has to be held back, and that decision has to be accountable afterwards. That moment falls in a production run that keeps going, and that is where it is recorded worst.

Why the deviation is the most serious step

A critical control point involves more than a measurement. There is a critical limit, there is a monitoring procedure, and there is a corrective action for when that limit is exceeded. In addition, verification and record-keeping belong to it, because without those two, control cannot be demonstrated.

The measurement is the simple part. It is a number, it repeats, and there is a system for it. The exceedance is not like that. Within minutes it must be determined which product was affected, that product must be held back before it leaves, and someone with the right authority must decide whether it can still be released.

In practice this happens verbally. An operator calls a team leader, something is decided, and the record follows later or not at all. In an audit or a complaint, this is exactly where the file breaks down: the measurement is there, the decision is not, and then the question of who released it cannot be answered.

This page is about what happens once a measurement falls outside the limit. Where that limit comes from, which step is a control point and why, is covered one layer up in software for the HACCP plan and control points.

How we build this

Here the exceedance is the unit, not the measurement. If a record with a block and a decision is created at that point, the accountability is a reflection rather than a reconstruction.

1
Retrieving the limits and measures

Which critical limit belongs to which point and which corrective action is set out in your plan. That is substantive work for your quality officer; we carry it out.

2
Establishing what was affected

When a limit is exceeded, the first question is which batch or time period is affected. That follows from the previous good measurement, and we build that link in.

3
Blocking before deciding

The block comes first and the assessment second. The other way round, the batch is already on its way before anyone has made a decision.

4
Release as an authorised action

Who may release, on what basis, and with what justification. That is the signature that is looked for in an audit.

What the app does in practice

The app starts where the measurement ends. Which components you need depends on your process and on how quickly products leave your site.

An exceedance immediately becomes a record

As soon as a value falls outside the critical limit, a case file is created with the time, control point, value and the operator who spotted it. Not just an alert, but a case with an owner.

Determining which product is affected

The time window between the last good measurement and the exceedance determines which lots are involved. Working that out by hand takes minutes you don't have.

Blocking with a single action

The affected lot is held before any decision is made. In practice this order is often reversed, which leads to a recall.

Corrective action from your own plan

The app shows what your HACCP plan requires at this control point, rather than leaving an operator to work it out from memory when they are under pressure.

Release by those authorised to do so

The decision to release after all, with justification and the person responsible. When a complaint or audit comes in, this is the question asked, and it is currently usually answered verbally.

Works offline

In a cold room or behind steel the network drops out. Blocking and recording carry on and synchronise later, with the actual time.

Who we build for

How quickly products leave your site determines how much this is worth. Four situations.

Short lead-time production

With fresh products the lorry is already waiting. Then the difference between blocking within two minutes and within twenty is the difference between an internal deviation and a recall.

Batch production

The batch boundary is clear, and the question is which time window within the batch was affected. That reduces how much you need to block, and therefore the cost.

Cooling and storage

A temperature excursion affects everything that was in that cell, which is rarely just one lot. Determining the scope is the real work here.

Private label with customer notification obligations

Your buyer expects to be told within an agreed timeframe that something has happened. That is only possible if the case file already exists at the moment you pick up the phone. The surrounding certification records sit in IFS software.

Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

Technology and integrations

The app executes your HACCP plan and does not replace it. Critical limits, control points and corrective actions are settings managed by your quality officer.

React Native or native iOS and Android Offline working with the actual time Critical limits and measures configurable Determining the affected time period Blocking by batch or location Release with authority and justification Photo on finding and remedy Integration with measuring equipment where possible Integration with stock or production system Tamper-proof recording of decisions Roles by line and by authority Export for audit and complaint handling Audit logging Hosting in the EU

Why Appfront

Blocking comes before deciding

We build that order in. In practice people first consult and then block, and in the meantime the consignment drives away.

Determining the scope is arithmetic, not memory

We derive the affected time window from the last good measurement. By hand this takes minutes and leads to debate.

Release is a signature, not a conversation

We record who decided and on what basis. That is the question asked in an audit and in a complaint, and it cannot be reconstructed afterwards.

The measurement comes from elsewhere

The monitoring and recording of CCP values runs through HACCP monitoring; we connect to it via integrations.

Security and privacy

A deviation file is commercially sensitive in a way that goes beyond ordinary production data: it contains the cases where things went wrong and the decisions to release products nonetheless. We therefore control access by role, separate recording a deviation from releasing product, and log every inspection. An operator sees their own reports; a quality officer sees the whole.

The evidentiary standard here is stricter than for any other record. A release decision that can be updated after the fact is not really a decision, and an auditor or regulator who finds that something was altered retrospectively has found a bigger problem than the excursion itself. We therefore record the finding, the block and the release as tamper-proof entries, with timestamp and person, and treat any correction as a visible correction alongside the original. How we handle security ourselves is set out in our information security policy; reports from outside go through our CVD policy.

Frequently asked questions about CCP deviations

Monitoring is about measuring and recording values at fixed moments; see HACCP monitoring and CCP recording. This app starts where that ends: at the excursion. Blocking, determining the scope, correcting and releasing are different actions with different authorities.

Technically it can, and with short lead times that is the core of the gain. Whether it is wise depends on your process and on which system manages dispatch. What you settle in advance is who may lift a block; that is an organisational choice, not a setting.

From the period between the last good measurement and the exceedance, linked to what was produced or stored during that period. How precise that can be depends on how granular your production records are; the coarser they are, the more you will need to block.

You determine that in your HACCP plan, and the app carries it out. What we build in is that release can only be done by someone with that authority, with a justification attached. Without both, the action may have happened but cannot be demonstrated.

Yes, and that is necessary in a cold store or a production hall. Blocking and recording continue and synchronise later with the actual time. We do agree in advance what happens if two people offline assess the same batch.

No. The plan with the hazard analysis, the critical control points and the limits remains the work of your quality officer. The app executes what is in it and holds those limits as settings, so a revision does not require a code change.

Especially with the question auditors most like to ask: show us a deviation from last quarter. If the finding, block, correction and release sit in one record with timestamps and names, that conversation is short. Otherwise a search begins, which is in itself a signal.

That depends on the number of control points, whether the block must also apply in your production system, and how granular the batch records are. The deviation file with release is usually quick to put to use; the blocking and integrations cost more. We give a reasoned estimate after the discovery phase.

Knowing who released the last batch?

Look up the last excursion and check whether it states who decided the product could leave anyway. If it doesn't, that is the work. We build this as a standalone app and as part of a wider custom app development or custom software development project.

Edit content