What Should AM Teams Do When Their Workflow System Is Unavailable?
When an AM workflow system becomes unavailable, establish which jobs and controls are affected, follow the site's approved criteria for continuing or pausing work, and record permitted activities through the agreed temporary process. Once access returns, reconcile those records with production and material status before treating the digital workflow as current.
The immediate difficulty may be surprisingly ordinary. An operator cannot open the next work instruction. Quality cannot update an inspection result. A material movement happens while the system used to record it is inaccessible.
Those situations need different responses. A useful continuity procedure identifies the information each activity depends on, how decisions will be made during the interruption, and how the production history will remain understandable afterwards.
Establish what is unavailable and which work it affects
Begin by identifying the interruption's scope through the site's support and incident process. Is one workstation affected, or can nobody access the platform? Can operators view records but not update them? Is the workflow application available while a machine connection or integration has stopped providing current information?
Record when the problem was detected and what the team knows. An unavailable screen is evidence of an access problem; it does not establish that every connected machine has stopped or that every production record has been lost.
The reverse also matters. A machine continuing to run does not prove that monitoring, recording or workflow controls remain available. Check the dependencies for the affected activities rather than drawing conclusions from one status display.
Give someone responsibility for coordinating updates between production, quality and system support. If the cause is unknown, state that clearly. Where there is suspected corruption or a security incident, follow the relevant incident procedure; an ordinary access workaround may be inappropriate.
The wider relationships between jobs, machines, materials and records are explained in Data, Software and Workflow in Additive Manufacturing: A Practical Guide. An interruption tests which of those relationships operators need at each production step.
Check whether each activity can continue under approved controls
An AM workflow system outage does not produce one universal answer about continuing production. The decision depends on the activity, system architecture, available evidence and applicable procedures.
Consider an inspection awaiting a controlled drawing, a build already executing, and a new job awaiting release. Each has different information requirements. Assess them separately through the authority defined in the continuity procedure.
Before an activity continues, the responsible person should establish whether operators have the applicable approved instructions, a reliable identification of the work, the required equipment and material status, and an authorised way to record what happens. Include any monitoring or approvals that the process requires.
Where a required control is unavailable, use the established escalation and pause criteria. A remembered instruction, an old download or an informal message should not become an assumed substitute for controlled information.
Avoid improvising a machine stop or restart to solve an information-system problem. Machine operation and interruption decisions need to follow the applicable equipment and process procedures. For an active build, assess those requirements alongside the information that has become unavailable.
The continuity procedure should also identify how long a temporary arrangement may remain in use and what conditions require another review. A workaround suitable for a brief interruption may become difficult to control across several shifts.
Keep temporary records connected to jobs, parts and materials
Where continued work is authorised, use the agreed temporary recording method. That might be a controlled paper form or another approved record accessible during the interruption. Establish this method before it is needed, including who maintains it and where supporting evidence belongs.
Retain the identifiers that connect the activity to the production workflow. Record the relevant job, build, part or material container, the operation performed, the person responsible and when it occurred. Where applicable, include the instruction revision, result, observation or decision reference.
Distinguish the time of the physical activity from the time someone later enters it into the system. Otherwise, recovery can create an apparently orderly history that misrepresents the sequence of work.
Material movements deserve particular attention. A powder container transferred to a machine or a quantity issued to a job may change the physical situation even though the digital stock record remains unchanged. Preserve the relevant container and batch references, quantities and destinations using the approved method.
Record uncertainties explicitly. An unclear quantity or missing result needs investigation; filling the gap from memory can conceal the very discrepancy that recovery needs to resolve.
If the interruption spans shifts, hand over the temporary records, active restrictions and outstanding actions. Keep one agreed method for the affected work so incoming teams can establish which record to use.
Reconcile production records when access returns
Restored access allows the team to begin checking the affected workflow. It does not establish that every activity performed during the interruption is already reflected in the system.
Follow the agreed recovery process with system support. Establish which records were saved, which information may still arrive from connected systems and which activities exist only in temporary records. Do not assume that machine data was buffered or will automatically reappear unless that behaviour has been verified for the deployment.
Compare the records with the current production situation. Check completed operations, part locations, material movements, inspection results and outstanding restrictions. Where an activity appears in both a temporary record and an electronic record, resolve the duplication before entering it again.
Preserve the original evidence and make later entry or correction identifiable under the site's record-control procedure. Avoid silently replacing uncertain information or assigning the recovery-entry time as though it were the event time.
Give unresolved discrepancies an owner and follow the applicable controls for affected work. Confirm which jobs and functions have been checked and who authorises their return to normal use. The timing can differ across activities; recovery need not be represented by one blanket status.
Two AM outage scenarios and the decisions they expose
The following examples are illustrative, rather than accounts of customer incidents.
A build is running when workflow access is lost
A metal AM build is executing when operators lose access to the workflow platform. The machine interface remains available, but the team cannot update the central job record.
The supervisor first establishes which required controls remain available and follows the approved procedure for the active build. The continuity plan identifies how permitted observations and actions should be recorded, and which conditions require escalation.
If the build completes during the interruption, record that event through the authorised method. Completion alone does not establish readiness for removal or the next operation. Those activities still depend on their applicable instructions and controls.
After access returns, the team checks whether the completion event reached the platform and compares it with the temporary record. This prevents assuming either that the event was lost or that another entry is necessary.
Material moves while an operation is recorded temporarily
During an authorised temporary operating period, an operator moves a tracked material container to a workstation. Another operator completes an inspection and records the result using the approved form.
When the platform becomes available, it still shows the earlier container location and an outstanding inspection. A planner looking only at those statuses would see a different situation from the production floor.
Recovery connects the movement to the correct container and destination, and the inspection to the correct part and operation. The team checks whether either event was already recorded electronically, retains the original evidence and resolves discrepancies before relying on the updated status.
Prepare and test a workflow continuity checklist
A practical plan should be usable without access to the system it covers. Store the procedure, contact information and approved temporary forms through an arrangement appropriate to the site's access and security requirements.
The NIST Contingency Planning Guide for Federal Information Systems provides broader background on contingency planning, recovery and reconstitution. Its scope is federal information systems; the checklist below is an editorial framework for AM teams, not a NIST-prescribed manufacturing procedure.
Stage | What to establish |
Preparation | Critical information dependencies, decision authority, accessible procedures and approved temporary records. |
Interruption assessment | Affected functions and jobs, detection time, known restrictions and the person coordinating the response. |
Temporary operation | Authorised activities, required controls, record identifiers, responsible operators and review conditions. |
Record reconciliation | Saved and pending data, temporary evidence, physical status, duplicates, gaps and correction ownership. |
Return to normal use | Checks completed for affected functions and jobs, remaining restrictions and the required authorisation. |
Test the plan against a realistic job, with production, quality and system support involved. Ask whether operators can find the necessary information, use the temporary method and explain how each record will be reconciled. Review the procedure when the workflow or system dependencies change.
What to agree with your workflow-system provider
Ask specific questions about the deployment: what remains accessible during different interruptions, what happens to data from connected equipment, how recovery handles delayed or duplicate events, and which responsibilities belong to the provider or the manufacturing team.
Document the answers. Offline access, buffering, synchronisation and recovery arrangements depend on the actual system and configuration; they should be verified rather than inferred from a general feature description.
Authentise FlowsAM connects production planning, tracking, traceability and reporting. These relationships provide a useful starting point for identifying information dependencies. They do not, by themselves, establish what any particular deployment can do during an outage.
The Authentise perspective is to examine continuity through the work being coordinated: which job, part, material and decision records must remain connected for that activity to be controlled? This gives production and suport teams a concrete basis for planning and testing recovery.
Start with one active job and identify what would become unavailable during an interruption. Test the agreed recording and reconciliation process with the people who would use it. If your team needs a clearer view of those dependencies, explore Authentise FlowsAM and discuss continuity arrangements for your production environment.




