When the thickness workbook has three editors and nobody can reproduce the number

A CML and TML registry for aerospace holds each monitored point in aircraft coordinates — zone, station, stringer and effectivity — with its original nominal thickness, every blend-out taken against it, and the remaining thickness after each. It replaces the shared workbook by making one nominal the source of record and every calculation reproducible, so a second blend is measured against original stock, not against as-found.

The aerospace difference is that the monitored point moves. A refinery CML sits on a fixed circuit; an aerospace TML sits on a serialized article that can be removed, overhauled and installed on another tail number, so the registry has to key on part serial and effectivity as well as ATA zone, frame and stringer. It also has to survive the arithmetic that governs the decision. Structural Repair Manual blend limits are usually expressed against original nominal thickness — for a chem-milled skin, the pocket nominal, not the land nominal — and blends are cumulative. A workbook that records only the as-found reading at the start of each visit loses the earlier removal and quietly approves a second blend that puts the location below the SRM limit. Recording to four decimal places while displaying three hides another 0.0005 inch. NAS 410 and EN 4179 certification status at the moment of the reading, and AS9100D clause 8.5.2 traceability, both attach to the point, not to the folder.

Source: Sources: manufacturer Structural Repair Manual allowable damage and blend limits; 14 CFR Part 43 and Part 145, including §145.219 record retention; 14 CFR 26.21 limit of validity and widespread fatigue damage; the operator's corrosion prevention and control program as approved through the maintenance review board process; NAS 410 Rev 5 and EN 4179 for NDT personnel qualification; AS9100D (clauses 7.1.5.2 and 8.5.2) and AS9110C; Nadcap AC7114 NDT audit criteria; ATA iSpec 2200 zoning conventions; ASTM E797 for contact pulse-echo thickness measurement.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
What an aerospace TML record has to carry that a refinery CML does not
FieldFixed-equipment practiceAerospace requirementWhat breaks without it
Location keyPlant, unit, line and CML number, fixed for the life of the assetTail number plus ATA zone, frame and stringer, and part serial for rotable hardwareA repaired panel installed on another airframe arrives with no history
Baseline thicknessOne nominal from the line listOriginal nominal by feature: chem-mill pocket, land, or bonded doubler stackBlend depth is judged against the wrong nominal, in the safe-looking direction
Loss mechanismUniform and localized corrosion accumulating over yearsDiscrete blend-out removals plus corrosion; event-based, not rate-basedA straight-line corrosion rate is computed for something that does not corrode linearly
Cumulative ruleCompare latest reading against retirement thicknessSum of all removals against original stock, across visits, stations and operatorsA second blend is approved that puts the location past the SRM limit
Personnel recordASNT SNT-TC-1A or ISO 9712 level held by the technicianNAS 410 or EN 4179 level, method and technique authorization current on the reading dateAn audit finding on a record that looked complete until dates were compared
Repeat findingsRate trend sets the next inspection due dateRecurrence count per location drives corrosion program level and escalationRepeat findings never join up, so the program is never escalated

The workbook stops being a record the moment two people open it

The corrosion and blend workbook usually survives one person. It has a column for nominal, a column for depth removed, a formula that subtracts, and a conditional format that turns a cell red. It works because one engineer holds the conventions in their head — which nominal came from the Structural Repair Manual and which from the drawing, whether the value in row 40 was measured or estimated, why one aircraft's tab has an extra column. The system of record is not the file. It is the person.

Then a second and third person start editing. Someone copies a block of rows from last year's aircraft to save typing and inherits its nominal along with the formatting. Someone else pastes values over a formula. A row gets sorted while a filter is active. Six months later a lead engineer is asked how a remaining thickness of 0.0318 inch was arrived at, and the honest answer is that nobody can reconstruct it, because the inputs that produced it were overwritten during the next visit.

That is the point at which the question stops being about software features and becomes one about evidentiary weight. Under 14 CFR Part 145 and AS9110, a repair station has to be able to show how a maintenance determination was made, not merely that it was made. A registry earns its place by making the calculation reproducible: fixed inputs, versioned edits, an identity attached to every change, and a stored result that can be recomputed from the record rather than accepted on assertion.

Why a monitored point on an aircraft will not stay still

In a refinery, CML-14 on circuit 3-P-102 is in the same place in twenty years. Aerospace does not offer that stability. A monitored location may sit on a skin panel that is removed, repaired in a shop two thousand miles away, and reinstalled on a different tail number. A rotable component carries its own history by serial number. A structural location is described by zone, frame, stringer, waterline or buttline — and by effectivity, because the same part number on two aircraft in the same fleet may sit at different stations.

The consequence is that a registry keyed only on aircraft registration will shed data every time hardware moves. It needs two keys: a position key expressed in aircraft coordinates, and a hardware key on the serialized article. Readings attach to the hardware; interval and program logic attach to the position. When a panel comes off and goes back on somewhere else, the thickness history travels with the metal while the zone retains its inspection obligation.

This also determines what fleet analysis is possible at all. If every reading is filed by tail number alone, the only trend you can build is per-aircraft. If readings carry part number, zone and effectivity, you can ask a far more useful question: is this lap joint thinning across the whole fleet, or is this one airframe an outlier? That question is the difference between fixing an aircraft and fixing a program.

The blend-out arithmetic a spreadsheet almost always gets wrong

Corrosion removal in aerospace is not a slow curve. It is a series of discrete events. A technician blends out a corroded area, measures what remains, and compares that against the allowable damage limit for that location. If it passes, the area is dressed and protected and the aircraft returns to service. If it fails, the escalation is a repair scheme or a query to the manufacturer. Between those events, nothing measurable changes at that point.

The trap is cumulative removal. The limit is written against original nominal thickness, not against whatever the material happened to be at the start of the current visit. A location blended 0.004 inch in 2021 and 0.005 inch in 2024 has lost 0.009 inch from original stock. A workbook that records only an as-found figure at the beginning of each visit treats the 2021 removal as the new baseline and reports the second blend as 0.005 inch against a limit written to cover the whole 0.009. Every individual entry looks compliant.

The registry fix is structural rather than clever. Original nominal is stored once and locked. Each removal is an immutable child event with its own date, depth, technique and technician. Remaining thickness is always derived, never typed. When someone needs the number, the system recomputes it from the events. When someone disputes it, the events are still there to be read.

Chem-milled pockets, bonded doublers and which nominal is the nominal

Ask three engineers for the nominal thickness at a given point on a chem-milled skin and you may get three answers, each defensible. There is the sheet nominal before machining, the pocket nominal after chem-milling, and the land thickness at the pocket boundary. Repair manual limits reference a specific one of these. A workbook with a single "nominal" column silently forces a choice that varies with whoever filled the row and what they had open at the time.

Ultrasonic measurement adds its own ambiguity. A contact pulse-echo gauge over a bonded doubler returns the full stack thickness unless the operator resolves the bondline, and a reading taken slightly off the pocket onto the land reads high by the machining depth. Both errors point in the reassuring direction. Both are completely invisible once they are a number in a cell.

A registry answers this by making the feature part of the location definition rather than a remark in a notes field. The point record states pocket, land, doubler stack or monolithic; it stores the applicable nominal for that feature; and it carries the measurement technique required to obtain a valid reading there, including any mandated delay line or echo-to-echo mode. The next technician does not have to reconstruct the intent of the last one.

Recurrence, not rate: what the corrosion program actually needs

A corrosion prevention and control program does not care very much about a single reading. It cares whether a location keeps coming back. Findings are categorized by severity and by whether they exceed allowable limits, and repeated findings at the same location within a defined window are what force a program change: an interval reduction, a task revision, or a referral to the manufacturer and the maintenance review board.

This is a counting problem, and counting is exactly what a shared spreadsheet fails at. The same physical location appears as "FS 620 LH lower lap" on one visit and "L/H fwd fuselage lap jt sta 620" on the next. Two rows, two apparently isolated findings, no recurrence detected. The program sees nothing worth escalating because the data never joined up in the first place.

A registry with a controlled location identifier makes recurrence a query rather than an act of recollection. It also makes the opposite case defensible. When an operator proposes to extend an interval, the supporting evidence is a location-level history showing no repeat findings across several visits, rather than a claim that nobody remembers a problem in that area.

What a Part 145 or Nadcap auditor pulls out of the record

Auditors do not audit the aircraft. They audit whether the record supports the decision. An NDT assessment against the Nadcap AC7114 criteria traces from a result back to the written procedure and its revision, the technique sheet, the equipment and its verification, the reference standard used, and the examiner's NAS 410 or EN 4179 certification — level, method and, where applicable, technique authorization — current on the date the reading was taken.

The most common failure is not a wrong reading. It is a record assembled after the fact that cannot demonstrate contemporaneity. A certificate scanned into a folder proves the person is certified today. It says nothing about whether they were certified in March of last year, which is when the reading in front of the auditor was taken. A registry that snapshots qualification state at capture converts a recurring argument into a stored field.

The same logic applies to instruments. AS9100D clause 7.1.5.2 requires identifiable calibration status and a defined response when equipment is found out of tolerance, which in practice means being able to list every reading taken by a specific gauge between its last good verification and the failed one. That query is trivial against a registry and effectively impossible against a folder tree of workbooks.

Migrating off the workbook without losing what is in it

The fear that keeps teams on the spreadsheet is that migration means retyping years of history, and that a half-migrated dataset is worse than none. In practice the workbook already holds most of what a registry needs. What it lacks is discipline about which column means what. The migration work is a mapping exercise: resolving nominal columns to a feature, resolving location names to a controlled identifier, and deciding what to do with rows whose provenance nobody can vouch for.

The honest approach is to import historical rows as evidence rather than as fact. A migrated reading carries a flag showing it came from the legacy workbook without the technician identity, equipment and technique a native record would have. It still supports trending and recurrence counting. It simply does not claim an audit weight it never possessed. Fabricating the missing metadata to make an import look tidy is the one action that genuinely damages the record.

From there, growth is forward-only. New readings are captured natively with full provenance, and legacy rows age out of relevance as locations are re-measured. Within one or two check cycles the registry holds a complete native history for the locations that matter, and the workbook becomes what it should have been from the start: an archive that nobody edits.

Evaluating a registry: the questions that separate real from demo-ware

Most demonstrations show a clean data-entry screen and a trend chart. Neither is where these systems fail. Ask instead to see an edit reversed. Change a stored nominal, then show the full history of that field: who changed it, when, and what the derived values were before and after. If the previous value is simply gone, the tool carries the same defect as the spreadsheet with a better interface on top.

Then run the awkward scenarios in front of the vendor. Move a serialized panel from one aircraft to another and ask where the thickness history went. Record a second blend at a location blended three years earlier and see what the system compares against. Enter a reading from a technician whose certificate expired last week and observe whether it warns, blocks or accepts silently. Create a location that already exists under a different name and see whether the duplicate is detected.

Finally, ask what leaves the system. The record is only useful if it can be produced in the form someone else demands: an auditor's sample, a manufacturer's query about a repeat finding, or a customer's own maintenance information system. Export fidelity, including the provenance fields rather than only the numbers, is the difference between a registry and one more silo.

How is a TML on an airframe different from a CML in a plant?

A plant CML is a fixed point on a fixed circuit, trended for a corrosion rate. An airframe TML sits on hardware that moves between aircraft, loses material in discrete blend-out events rather than continuously, and is judged against a manual limit that references original nominal thickness. So the registry must key on both position and serialized part, store removals as immutable events, and derive remaining thickness rather than store a typed number.

What actually breaks when three people share the thickness workbook?

Provenance. Values get pasted over formulas, rows get sorted while a filter is applied, and a block copied from another tail number brings its nominal with it. Nothing announces the damage, because the file still calculates. The failure surfaces months later when someone asks how a specific remaining thickness was produced and the inputs have already been overwritten by the next visit. What is lost is not the number but the ability to defend it.

How should cumulative blend-out be recorded across separate visits?

As immutable events against a locked original nominal. Each removal stores its own date, depth, technique, technician and resulting measured thickness, and the system derives cumulative loss by summing them. Recording only the as-found figure at the start of each visit silently resets the baseline and makes a second blend look small against a limit written for the total. That is how a location drops below manual limits with every individual entry appearing compliant.

Is API 510, 570 or 653 inspector training part of this offer?

No. Those inspector certifications are issued by API and sit outside what Atlantis provides. Atlantis delivers NDT training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD, plus ASNT Level III consulting, report validation, and the inspection management software described here. Where an aerospace program requires NAS 410 or EN 4179 qualification, that remains the responsibility of the employer's written practice and its approved Level 3 examiner.

Can the registry roll up findings by part number across a fleet?

Yes, provided readings carry part number, zone and effectivity rather than tail number alone. That is what makes fleet-level questions answerable: whether a lap joint is thinning across every airframe or one aircraft is an outlier with a drainage problem. Rolled-up recurrence also strengthens a case to the manufacturer or the maintenance review board, because the evidence is a location-level count across the fleet rather than a scattering of individual write-ups.

What does an auditor pull out of a thickness record first?

Traceability at the moment of capture. Which written procedure and revision, which technique sheet, which reference standard, which instrument and its verification status, and the examiner's certification level and method current on that date. A certificate filed today proves nothing about a reading taken last March. Systems that snapshot qualification and calibration state at the point of capture turn the most common audit finding into a stored field nobody has to reconstruct.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.