Contents
1. What is PPAP?2. The PPAP flow: draft → submitted → approved3. What is SPC? Tolerance and control limits are not the same thing4. For the operator: entering measurements5. Cp, Cpk, Pp, Ppk — what does each one say?6. What does the "stopping" flag do?7. FMEA: why RPN is gone and AP took its place8. Control Plan and special characteristics (CC / SC)9. The confirmation gate: were the CC and AP-High rows measured?10. MSA (Gage R&R): can we trust the measurement?11. Supplier audit (VDA 6.3) and the A/B/C class12. IMDS material declaration, 8D and EDI13. Multi-plant planning: plant-scoped MRP and e-Kanban14. Subcontractor portal (/fason)15. Time phasing and plant capacity: "when is it short?"Help › PPAP & SPC
Automotive Supply: PPAP and SPC
A workshop supplying a carmaker is asked two questions over and over: "are you approved to make this part?" (PPAP) and "can your process actually hold this tolerance?" (SPC). This guide explains both from scratch.
Twenty minutes in total for a quality officer. If you are an operator, section 4 (entering measurements) alone is enough: four minutes.
1. What is PPAP?
PPAP is the customer's approval saying "you may mass-produce this part". Producing without it means the whole shipment can be rejected. In HNR, PPAP is a file approval: documents such as the control plan, FMEA and measurement report are completed, and only then is a decision made.
If a part has no PPAP record at all, nothing is blocked. The lock only works once the company has opened a PPAP record for that part. Installing the module does not stop a workshop that does not use PPAP.
2. The PPAP flow: draft → submitted → approved
- Open a record — part code and revision are mandatory; PPAP is granted to one specific revision of a part.
- List the required documents — control plan, PFMEA, measurement report… Which ones are mandatory varies by customer, so the list is yours to set.
- As documents are completed, mark them "done".
- A manager makes the decision. If even one mandatory document is missing, approval is refused — approval granted with missing paperwork is the single most audited item.
While editing a PPAP record you cannot set the status to "approved" directly; approval only comes through the Decision step. Otherwise the lock would be meaningless. An expired approval also blocks — a PPAP past its validity means, to the customer, no approval at all.
3. What is SPC? Tolerance and control limits are not the same thing
This is what everybody new to SPC confuses:
- Tolerance is what the customer demands: "the diameter must be between 9.9 and 10.1 mm."
- Control limits are the process's own voice: "your machine naturally produces between 9.98 and 10.02."
- On the chart the tolerance is drawn red and the control limit dashed amber. A point past the amber means the process changed; past the red means the part is scrap.
4. For the operator: entering measurements
- Production window → SPC tab. Pick the characteristic you measured from the list (part + e.g. "Diameter").
- Type the values into one box, separated by spaces or commas:
9.98 9.99 10.01 10.00 10.02. All five are stored as one subgroup. - If the measurement belongs to a work order, fill in the Work order no box — only then does the stopping gate apply to that order.
- Save. If any value is out of tolerance, the warning turns red and tells you what to do next.
A bad measurement cannot be deleted; a decision is recorded instead (scrap / rework / concession / measurement error) and a reason is mandatory. A deleted measurement reads, in an audit, as "data was filtered". Once the decision is written — and no other open out-of-tolerance measurement remains on that order — the work order reopens by itself.
5. Cp, Cpk, Pp, Ppk — what does each one say?
| Figure | Meaning |
|---|---|
| Cp | The best the process could do. It ignores where the average sits. |
| Cpk | Capability plus off-centre shift. Automotive expects ≥ 1.33. |
| Pp / Ppk | What actually happens. Far below Cp means the process drifts over time (tool wear, setting slip). |
"Cpk 2.4" from five measurements means nothing. The screen does not hide the number but puts a red note above it: a capability study needs at least 25 measurements (at least 5 subgroups on an X̄-R chart). Hiding the number would only push the user to make one up elsewhere.
6. What does the "stopping" flag do?
There is a checkbox in the characteristic definition: Stopping. It is off by default and should stay off — until the customer declares that dimension critical.
- Off: an out-of-tolerance measurement is only recorded and shows up in reports. Production does not stop.
- On: if that order has an unresolved out-of-tolerance measurement, the work order moves to stopped and no confirmation can be written. Once the decision is recorded the order returns to its previous state by itself — nobody has to remember to "reopen the order".
- Not measuring at all is not a block. An unmeasured characteristic is only listed as a warning; making measurement mandatory would lock the line in a one-person shop.
7. FMEA: why RPN is gone and AP took its place
FMEA is the written form of "what can go wrong, how bad is it, will we catch it?". You give three numbers: S (severity — effect on the customer), O (occurrence — how often), D (detection — will we catch it). All three are 1-10.
The old method multiplied them (RPN = S×O×D). A safety failure with S=10 / O=1 / D=1 gives RPN 10 and looks "low". A cosmetic failure with S=4 / O=8 / D=8 gives RPN 256 and looks "high". Backwards. That is why AIAG-VDA 2019 dropped the product: Action Priority is a table, not a multiplication. HNR keeps that table in code and never lets you type AP — the same S/O/D cannot produce two different priorities on two rows.
- AP High (red): either write an improvement action or write down why no action is taken. HNR will not save a high-priority row with an empty action field.
- AP Medium (amber): an action is expected but not mandatory.
- AP Low (grey): action is optional.
- DFMEA / PFMEA are two different questions about the same part (design and process) and live in separate records; they cannot be mixed.
8. Control Plan and special characteristics (CC / SC)
FMEA says "what can fail"; the control plan says "where, with what, how many pieces, how often we catch it — and what we do when we do". Every row has a reaction plan — the field most often left empty and most often asked about in audits.
- CC (critical characteristic) — a dimension with safety or regulatory impact. HNR will not save a CC row without a link to an SPC characteristic: an unlinked CC is only a label, and the system cannot ask "was it measured?".
- SC (significant characteristic) — affects customer satisfaction or fit; linking is recommended but not required.
- Level: prototype · pre-launch · production. Three plans can sit side by side for one part; the gate only looks at the active one.
- The row list has a CSV button for the shop floor. The PDF design of the traveller card is not part of this round.
9. The confirmation gate: were the CC and AP-High rows measured?
This gate only runs when Settings › Production Preferences › SPC is set to "required". In the Level 1 template SPC is off, in the automotive template it is "advisory" — so the gate never opens by itself in any company.
When the gate is on: if the work order's part has an active control plan, the rows marked CC or linked to an AP-High FMEA row must have at least one measurement on that order. Otherwise the confirmation is refused and the message names the missing characteristic and its number. As soon as the measurement is entered the gate opens by itself.
When the gate is off the same list appears as an indicator: the "Order check" box on the Control Plan tab tells you which CC/AP-High rows are unmeasured, but stops nothing.
10. MSA (Gage R&R): can we trust the measurement?
An SPC chart assumes the measurement is right. MSA tests that assumption: does one operator get the same number twice on the same part (repeatability, EV), and do two operators get the same number (reproducibility, AV)?
- Open a study: device, characteristic, parts × operators × trials (AIAG suggests 10 × 3 × 3). If tolerance is left blank it is taken from the SPC characteristic.
- Fill the grid and press Calculate. The result box shows %EV, %AV, %GRR, %PV, ndc and which base (tolerance or total variation) the percentages used.
- Acceptance: %GRR < 10 accept · 10-30 conditional · > 30 reject, plus ndc ≥ 5. The thresholds are settings (kalite.msa_grr_esik / _iyi / _ndc_alt).
- A number from thin data is not hidden but not presented as reliable: a "LOW DATA" badge sits next to it.
- In an attribute study cells take 1/0; within- and between-appraiser agreement and kappa are computed (≥0.75 accept).
Calibration asks "is the device right"; MSA asks "can this device measure this tolerance". Measuring a 0.01 mm tolerance with a calibrated caliper passes calibration and fails MSA. A device with %GRR > 30 is flagged msa_gecersiz; to actually block it in confirmations you must turn on kalite.msa_zorunlu (off by default). The escape: run a new MSA, or have an administrator clear the flag with a written reason — clearing without a reason is refused.
11. Supplier audit (VDA 6.3) and the A/B/C class
The supplier scorecard measures what happened (documents, returns, NCRs). The audit judges the supplier's process — a bad process may not have produced a bad delivery yet. They are separate records and sit side by side on the scorecard.
- Scores follow the VDA scale: 0 · 4 · 6 · 8 · 10. There are no values in between; there is no such thing as "6.5 conformity".
- A 0 or 4 is a finding: it cannot be saved with an empty action field. A low score with no action is the easiest way to make an audit look "done".
- An unanswered question does NOT count as 0 — it stays out of the denominator. The percentage is the percentage of what was audited, and the number of blanks is reported separately.
- Class thresholds are parameters: A ≥ 90, B ≥ 80, below that C (kalite.denetim_sinif_a / _b). VDA's own downgrade rules depend on the customer specification and are not invented here — element percentages are shown separately and the decision is human.
- Question texts are not seeded: the VDA 6.3 catalogue is a copyrighted publication. The P1..P7 element structure is ready; the company enters its own questions.
- A closed audit cannot be edited. To correct it, open a new audit; the old report stays with its date.
When kalite.satinalma_sinif_kapisi is on, you cannot select the quote of a class C supplier or one whose audit has gone stale (12 months by default). The visible escape: add sinifOnay to the request; who approved it and which class/how stale is written into the request's justification as a trace. The subcontract dispatch gate is deliberately not part of this package.
12. IMDS material declaration, 8D and EDI
- IMDS — what the part is made of (material, CAS number, share, grams) is recorded. The CAS check digit is verified: a wrong CAS silently defeats the restricted-substance scan. For a part with a bill of materials the declaration is rolled up from the components; a component without a declaration is not hidden but listed as "missing declaration" — the number one reason IMDS submissions are rejected. When the ELV (2000/53/EC Annex II) lead/mercury/cadmium/hexavalent-chromium thresholds are exceeded a warning appears; production is not stopped, the exemption call belongs to the engineer. The official IMDS XML is out of scope for this round.
- 8D — no new table was created: the existing NCR/CAPA record already holds half of 8D (root cause = D4, corrective action = D5, closure = D8). The six missing steps were added as columns. An empty step is not hidden; in a report sent to the customer a missing step is the reason for rejection. An OEM-format PDF is for a later round.
- EDI — the customer's order/release message is received as JSON or CSV and its fields are bound to ours through a mapping table the company defines. The message is written to the existing integration ledger and an idempotency key prevents the same message being processed twice. Processing produces an order draft plus a production request; it does not open a work order and does not debit the customer — turning the draft into a real order is a human decision. A line whose part code cannot be resolved is not skipped; it stays as "unmatched". ⚠ The OEM's real EDIFACT/VDA segment schema is not invented before the customer specification arrives; the OFTP2/VAN transport layer is out of scope.
13. Multi-plant planning: plant-scoped MRP and e-Kanban
When pressing, welding, e-coat and assembly sit in different buildings, “we have 500 company-wide” is useless: the material can be short in assembly while sitting in pressing. MRP therefore gained a scope selector (Production › Planning bar): Company and Warehouse (both today's behaviour) and Plant.
- In plant scope, netting sums ALL warehouses mapped to that plant, and demand (open work orders and production requests) is filtered to the same plant. Every factory sees its own shortage.
- Plant membership is not copied anywhere new. It is derived from the warehouse mapping (Corporate › Plant / Warehouse). The only new field is the production request's target warehouse.
- Never a silent “nothing missing” over an empty set. If no warehouse is mapped the plan refuses to run and
MRP_TESIS_DEPOSUZtells you to map one. Sending warehouse and plant together returnsMRP_KAPSAM_CAKISMASI— there is no silent precedence rule. - Requests with no target warehouse belong to no plant; the plan header states how many were left out. You can map them in bulk from the multi-select list on the Corporate › Plant / Warehouse screen.
- Source-plant suggestion: when an item is short and another plant holds a surplus, that plant is shown on the row — an internal transfer is considered before purchasing.
e-Kanban. For a card (item + source warehouse + target warehouse) the card count is computed on the server: N = ⌈ daily demand × transit days × (1 + safety margin) ÷ bin quantity ⌉. The board lists cards whose available stock has fallen below the reorder point. Triggering goes through the existing transfer path: four-eyes approval, the plant wall and ownership gates all still apply — kanban skips none of them.
All three gates are off by default (Settings › Safety gates): depo.mrp_transit_arz (should goods on open transfers count as supply in MRP), depo.kanban_otomatik (should the board only suggest, or also create transfer orders) and depo.kanban_tesis_disi (may an inter-plant kanban carry the approval automatically). While the last is off, an inter-plant kanban stops with TESIS_TRANSFER_ONAY: an automatic trigger cannot punch through the plant wall on its own.
The warehouse replenishment screen counts goods on open transfer orders as “in transit”; MRP did not. The gap was large enough to open duplicate purchase orders. The depo.mrp_transit_arz gate closes it so both screens report the same figure. While the gate is off the MRP answer is byte-for-byte what it is today — turning it on is a deliberate decision because planning numbers change.
14. Subcontractor portal (/fason)
A subcontractor has no HNR account and should not have one: giving them an ERP user is wrong for both licensing and security. The same pattern as the staff and dealer portals is used instead — a separate identity table, a PIN and its own session. The address is /fason; the company defines the username and PIN.
- Only their own records. The supplier sees the subcontract packages, accreditation certificates and audit score tied to their own customer code. Asking for someone else's package returns 404 — a 403 would leak that the record exists.
- Identity is never read from the request. The customer code is stamped from the session on every call; writing a different one into the request body changes nothing.
- The portal creates no stock movement, issues no delivery note and does not change the shipment status. The supplier only reports (ASN number, lot, serial list, measurement report file). The dispatch decision belongs to the HNR user, because the accreditation gate runs there.
- The PIN lock is per user: five wrong attempts lock that account for 15 minutes and another supplier in the same office is unaffected. “No such user” and “wrong PIN” return the same message so account names cannot be probed, while the server log distinguishes them.
- Audit questions are never shared. The supplier sees the score, the A/B/C class and the number of open actions; the VDA 6.3 question catalogue stays with the company.
There are two gate levels and both are off by default: kalite.fason_portal opens the portal itself (login gets 403 PORTAL_KAPALI while closed) and kalite.fason_portal_asn opens writing (the portal is read-only while closed). Reading carries no risk; letting an outside user write rows into the ERP is a separate decision.
In automotive the ASN file format is EDIFACT DESADV or VDA 4913/4987, and those schemas are not freely published. An invented schema produces a file the carmaker's system rejects silently. The portal therefore records the ASN in HNR's own fields; when an outbound message is required the route is the EDI mapping layer (section 12), once the customer specification arrives.
Related guides: Production, Cutting, Rolls and Installation, Audit and Gates.
15. Time phasing and plant capacity: "when is it short?"
Until now MRP reported a single total shortage. An item needed six weeks from now and an item needed this week sat on the same row in the same red; the planner could not tell from the screen which to buy first. When the depo.mrp_zaman_fazlama gate is opened, demand and supply are spread into buckets by due date (weekly or monthly, 1–26 buckets), the cumulative balance of each bucket is computed, and the date of the first shortfall appears on the row. Clicking that date opens the bucket strip: demand, supply and balance bucket by bucket.
If an order or request has no due date, the bucket it belongs to is unknown. Putting it in the first bucket manufactures false urgency, putting it in the last manufactures false comfort, and dropping it breaks reconciliation with plain MRP. HNR does none of the three: the dated part goes into the buckets and the remainder is shown separately as “undated demand / undated supply”. The rule holds on every row: buckets + undated = the plain MRP total. So the shortfall in the strip and the total shortfall on the row may differ — the difference is exactly the undated part, and it closes by itself once due dates are entered.
Plant capacity. Next to the plant-scoped MRP there is a “Plant capacity” button (uretim.tesis_kapasite gate, off by default). The remaining quantity of open work orders is converted into routing minutes (for multi-cavity tools ⌈quantity/cavity⌉ × time), spread into buckets by the order due date and compared with the minute capacity of the machines attached to the plant. Which plant a machine belongs to is derived from URT_MAKINE.DEPO via the warehouse policy's plant; no separate plant field is added to the machine card, because writing the same fact in two places means the two will drift apart.
Sequence-dependent setup time, the shift calendar, operator and tooling constraints are not taken into account; a working month is taken as 22 days and a week as 5. The response says so explicitly via kabaPlan:true. The goal is not finite capacity scheduling (APS) but to make visible the imbalance of “we are overloaded this week and idle in two weeks”. If no active machine is attached to the plant, capacity shows as 0 while the load is real; the screen states this in a separate warning band — a silent zero would read as “plenty of capacity”.