Skip to content
HNROS Help Center
English
Start free
Contents1 · Raw material values — EN 10204 3.12 · Special processes and Nadcap accreditation3 · Operator competence4 · AS9102 First Article Inspection Report5 · Need to know — security classification6 · MIL-STD-130 UII and the 2D label8 · Aerospace chemicals — out-of-freezer time and pot-life9 · Importing a CMM measurement report10 · GQA — Government Quality Assurance (AQAP-2070)11 · Gate summary — what, where, is there an escape?

Help › Defence Traceability

Defence & Aerospace Traceability — A Guide from Scratch

This guide is written for a company supplying aerospace and defence customers. Every gate described here follows one logic: releasing anything depends on MEASURED evidence; with no evidence the program does not let it through. What counts is the NUMBER inside the certificate rather than its PDF, the ACCREDITATION CERTIFICATE rather than the supplier's word, and the SCOPE OF THE CERTIFICATE rather than the operator's experience.

No gate switches itself on. Every gate is OFF BY DEFAULT: if no limit is defined, if the special process is not marked, if the security class is empty, the program behaves exactly as it does today. A gate only becomes active once you fill in that field. Installing the module therefore never stops production.

1 · Raw material values — EN 10204 3.1

An EN 10204 3.1 certificate is not a PDF, it is a NUMERICAL commitment: it lists alloy element percentages and mechanical values. The program stores those numbers under Metal → Spectrum and compares them with the material specification. Specification limits are NOT hard-coded — you enter the limits for Ti-6Al-4V, Inconel 718 or 7075-T6 yourself; the program never assumes a standard's values.

How to set it up

The visible escape — deviation approval. If a value is out of bounds but engineering says "usable on this batch", you supply the number of an approved DEVIATION record. A deviation cannot be used without a lot/serial scope; a deviation that is unapproved or out of scope is refused, and every use is written to the access trail. The escape exists, but it is never silent.

2 · Special processes and Nadcap accreditation

Heat treating, coating and non-destructive testing (NDT) are special processes: you cannot see the result by looking at the part, so the company performing it must be accredited. The program sets this up in two steps: (1) you record on the routing operation which programme is required (AC7102 heat treating, AC7108 chemical processing, AC7114 NDT, or free text), (2) you register the supplier's accreditation with its number, issuer and EXPIRY DATE.

The gate sits on the "shipped" step of the subcontract package: goods do not leave for a supplier with no accreditation or an expired one. The error message names the company, the programme and the expiry date. If the operation carries no special process, the gate never runs and your current subcontracting flow is unchanged.

3 · Operator competence

The program has long checked the calibration of measuring instruments: you cannot record a confirmation with an out-of-calibration gauge. Yet a welder with an expired certificate, or an NDT operator qualified only up to 3 mm, could still sign off a 6 mm part. The auditor put it plainly: "You control the equipment, you do not control the person." This gate restores the symmetry.

The gate only READS the special-process certificates held in Human Resources — HR enters them, this module writes nothing. Four criteria are checked: is the certificate valid, is the material in scope, is the position in scope, is the thickness within range; plus continuity: if the process has not been performed for N months the qualification lapses and requalification is required. The visible escape is manager approval, which only a system administrator can give and which is written to the access trail.

4 · AS9102 First Article Inspection Report

The existing FAI record in the Quality window is a DECISION ("first article approved"). AS9102 asks for the FILE behind that decision and consists of three forms:

The gate: quality cannot approve the FAI while any balloon on Form 3 is undecided or non-conforming. The audit package: one click collects every form into a single JSON, Form 3 also downloads as CSV, and a manifest digest (SHA-256) is added — the same data always yields the same digest, so an auditor can verify for himself that the file was not altered afterwards. Paper output comes from the ready-made AS9102 design in Print Forms; there is no separate PDF engine.

5 · Need to know — security classification

In defence work the mere EXISTENCE of a document is information: "there is a drawing for that project but you may not see it" is itself intelligence. That is why the gate blocks not only downloading but listing — a user without the clearance never sees the record in the list at all.

6 · MIL-STD-130 UII and the 2D label

A UII is not a barcode, it is a COMMITMENT: for the life of the part that identity is never given to another part. It is built from three pieces — your enterprise identifier (CAGE/NCAGE code), the original part number and the serial number. You enter the CAGE code once in settings; the program never invents a serial number, you supply it.

The string printed on the label is an ISO/IEC 15434 Format 06 carrier, drawn as a 2D Data Matrix (ECC 200). The print designer gains a new object type: Data Matrix. Two ready-made designs ship with it — the UID part label and the case (shipping) label. A scanned code is decoded and its serial number matched against the traceability node; if there is no match the program says so plainly. Drivers for laser or dot-peen marking equipment are out of scope here: the output is the UII string and the label itself.

8 · Aerospace chemicals — out-of-freezer time and pot-life

For materials such as adhesives, resins and prepregs three separate clocks run, and confusing them makes the whole module wrong. The first is the shelf life (the lot expiry) — the system already knew this one. The second is out-of-freezer time: how long the material stays outside between removal and return. The third is pot-life: how long a two-component resin remains usable after mixing.

Out-of-freezer time is CUMULATIVE and never resets. This is the most commonly misunderstood point: putting the lot back in the freezer does not zero the counter, it only pauses it. On the next removal it continues from where it stopped. A material taken out four times for two hours each has been exposed for eight hours; if its budget is four hours it has reached the end of its life, and returning it to the freezer does not save it.

The time budget is not invented. There are no built-in values such as "30 days" or "21 days"; each material's budget is stated on the manufacturer's technical data sheet (TDS) and is entered per item under Quality → Pot-life → Material rules. If an item has no rule, none of this module's gates run — opening the screen stops no production.

The counter is tied to the lot number, not to the warehouse row. This was a deliberate choice: when a lot moves from the MAIN store to the SUBCONTRACT store the system opens a new row at the destination. Had the counter been tied to that row, the material's history would have been silently erased on the first transfer. As long as the lot number stays the same, so does the cumulative time.

There are two gates and both are off by default. With kalite.potlife_zorunlu on, a lot whose budget is exhausted is refused at production confirmation with POTLIFE_ASILDI; the visible escape is potlifeOnay and a potlife mark is written on the confirmation. With kalite.potlife_otomatik_bloke on, a lot that exhausts its budget is placed on quality hold at the moment of return — a held lot cannot be shipped and there is no escape from that; releasing it is a quality decision.

9 · Importing a CMM measurement report

Typing every balloon of an AS9102 Form 3 by hand is both slow and error-prone: the measurements already exist in the coordinate measuring machine's (CMM) report. This section reads that report and writes the measurements into SPC and, if you wish, into Form 3. It must be said up front: there is no single format called "Calypso CSV" or "PC-DMIS CSV". Those programs produce CSV from a template; column names, order, decimal separator and language vary from customer to customer. HNR is therefore not a "Calypso reader" but a parser and mapping engine.

Q-DAS ASCII is the exception: it has a published specification (Q-DAS ASCII Transfer Format V12/2015) and the program follows it literally — K-fields, the characteristic separator, the additional-data separator and the date format included. If you can use that format you need no mapping at all. In a PC-DMIS text report the column order depends on the report template; the program does not assume a fixed order but reads it from the header line of each block. For delimited text you define a mapping under Quality → CMM profile for any column it does not recognise.

Importing has two stages and the first cannot be skipped. First PREVIEW: the file is read, every row is matched against the characteristics in the ERP and the result is shown on screen — nothing is written at this stage. Then WRITE. On the write request the server demands the preview's signature; if the file, the item, the work order or the tolerance setting changed in between, the signature does not match and the request is refused. The reason is simple: measurement data is audit evidence, and a row the user has not seen cannot slip silently into SPC.

In the preview every row has a status and a reason: matched (found in the ERP), new (not in the ERP but the file carries a tolerance — created if "Create new characteristics" is ticked), uncertain (no tolerance, or the file and the ERP disagree about it) and invalid. No row is skipped silently; the reason is always written. "Create new characteristics" is off by default so that a typo in the file does not multiply your SPC definitions.

If tolerances disagree, the ERP wins. The tolerance inside the CMM program is often left over from an older drawing revision; the file is not allowed to overwrite the current ERP tolerance silently. This behaviour lives in the kalite.cmm_tolerans_kaynak setting and defaults to sistem. If dosya is chosen the conflicting row is marked "uncertain" and the decision is left to you — in no case is there an automatic overwrite. The same file cannot be imported twice into the same work order: writing the same measurements twice would falsely improve Cp/Cpk.

Two exclusions must be stated plainly: the QIF (ISO 23952) XML format and PC-DMIS's binary .DMO file are not read. The first is a schema tree larger than this whole package; the second has no published specification. In both cases export Q-DAS or text/CSV from the CMM program instead. The module itself is off by default; it is switched on from the ⚙ Settings section of the Quality → AS9102 → “Import CMM report” window (administrator) by setting kalite.cmm_ice_aktarim to “acik”. While it is off the preview and import endpoints return 403; the window says so and opens the settings section by itself.

10 · GQA — Government Quality Assurance (AQAP-2070)

In NATO contracts the acquiring state has the supplier's quality verified through its own representative. That process is called GQA (Government Quality Assurance) and the person who performs it is the GQAR. The rules live in NATO STANDARD AQAP-2070 Edition B Version 3 and HNR uses that document's terms literally: the request form is the RGQA, its answer the RGQAR, the closure report the GQACR, the risk communication the RIAC and the conformity document the CoC.

The CoC here is not the CoC the system already knew. The certificate you see at goods receipt is the document that COMES FROM THE SUPPLIER; the AQAP CoC is the document that GOES TO THE CUSTOMER. To keep the two apart this concept is kept separate and lives on screen under "Certificates of Conformity (CoC)". The document has two parts: Part I is the supplier's statement of conformity (AQAP Annex B, blocks 1-15) and Part II is the GQAR's "Statement of GQA" (blocks 1-6).

The GQAR's signature DOES NOT MEAN ACCEPTANCE. This is the caveat the AQAP document itself prints on the Part II form, and HNR carries it verbatim both on screen and in the generated package: the signature does not mean the supplies are accepted on behalf of the Acquirer and/or Delegator, nor that the individual items have been inspected. Removing that sentence would turn the document into something it is not.

The default route is the DOCUMENT route. The GQAR is not a user of your system, and in most installations you would not want to give them a screen. So the ordinary flow is: the Part II page is printed, the GQAR signs it by hand, the page is scanned and uploaded as an attachment, and the file's sha256 digest is written on the CoC record. A "granted" decision cannot be saved without the attachment — the GQAR signature lives on the document, not in the system; the system only records that the document exists and what its digest is.

Part I itself passes through four-eyes approval: once the CoC draft is written, an approval is started under Corporate → E-signature with the subject gqa and two different people sign it. Until the approval completes, "Publish" is refused. At the moment of publication a manifest digest is stamped on the record: an auditor can reproduce the same digest from the same data, and if the data changed later the digest will not match. GQA approval belongs to the quality family, so finance or operations users do not see the approval record.

The gate is NARROWLY SCOPED, and that is a deliberate decision. Even with kalite.gqa_zorunlu on, the gate applies only to a customer or project that has an active RGQA delegation. GQA is not asked for on a commercial order without a delegation — otherwise a single setting would stop all shipping. If you wish you can also set the scope by hand by listing customer/project codes, comma separated, in kalite.gqa_kapsam. The gate runs while a sales invoice is being written and refuses with GQA_BEKLIYOR; the visible escape is gqaMuaf, which is administrator-only, demands a reason and leaves both a deviation record and an access trail.

Finally, one boundary: AQAP defines no machine-readable file schema; it says the document may be prepared in Word or PDF. HNR therefore invents no XML/EDI format — what it produces is a RECORD, JSON and CSV, while paper output is printed through the single existing renderer in the print designer. Institution-specific portals and e-signature flows (such as those of national procurement agencies) are also out of scope: they have no published specification.

11 · Gate summary — what, where, is there an escape?