A plant sets a production plan freeze window, yet the next morning’s planning run changes today’s shop-floor instructions. Another plant locks the schedule so tightly that a machine breakdown or urgent customer order becomes impossible to handle. For a factory in Thailand buying APS or a production scheduler, the answer is more precise than choosing a number of days. Define what is frozen by plant, line and material; who can approve an exception; how order promising respects the boundary; and how ERP and MES receive the approved version. This guide turns those decisions into RFP requirements and FAT/SAT tests. It addresses change governance rather than repeating a general scheduler or finite-capacity comparison.
What does a production plan freeze window actually protect?
A freeze window is a period in which a planning run or manual edit should not move the near-term production plan without the agreed process. The protected object still needs a definition. Is it a manufacturing order’s start time, finish time, sequence, assigned line, quantity, allocated material, or the date promised to a customer? A useful requirement reads: “For orders starting within the next 48 hours, automatic replanning must preserve the assigned line and start time. Quantity and sequence changes require an approved exception.” Merely writing “two-day freeze” allows vendors to implement different things.
Product behavior differs. Microsoft Dynamics 365 documentation says its freeze time fence prevents changes to existing planned orders and new planned-order suggestions during a master schedule run. Oracle Fusion Cloud documentation describes a planning time fence that limits rescheduling and new orders, while noting that some excess supply can still be rescheduled out or cancelled. SAP documentation ties firming of planned orders within its planning time fence to settings such as the item’s MRP type. These are product-specific examples, not a universal definition. Demonstrate what the proposed product does with the buyer’s test data.
Also separate a frozen plan from a firmed order. Firming converts a planned order into an executable production, purchase or transfer order. Microsoft documents firming and freeze as separate time fences. A schedule can look stable even though material has not been purchased; an actual order can exist while its shop-floor sequence still changes. The RFP must identify both states and their owners.
Set the boundary from the cost of change
A single number for every site ignores imported versus local material, continuous processes versus assembly, and differing preparation times. Map when change begins to cause real rework: picking components, preheating a mould, cleaning equipment, assigning operators, informing a subcontractor, booking inspection or reserving a truck. Give each event a timestamp and cost or operational consequence. The window follows from those decisions.
One hypothetical factory might protect the moulding sequence before imported resin is dried, while allowing its general assembly line to change until staff availability is confirmed in the morning. If a bottleneck’s cleaning and changeover are expensive, freeze the order sequence earlier. If several equivalent machines are available, preserve the delivery date while allowing the line assignment to change. These are design examples, not recommended industry-wide day counts.
Think in three layers. At the plant layer, protect the promised supply site and shipment date. At the line layer, protect setup and staffing commitments. At the material layer, protect allocation, usable receipt date and approved lot. Different layers can have different boundaries. Instead of always applying the longest boundary, specify which type of change triggers which approval. When a frozen material is still missing, it may be more responsible to approve a substitute or re-promise the customer than to preserve an impossible-looking Gantt bar.
| Scope | Commitment to protect | Typical trigger | Example approver | Evidence to retain |
|---|---|---|---|---|
| Plant | Supply site and confirmed ship date | Demand spike or site transfer | Planning and sales heads | Old and new promise dates |
| Line | Near-term sequence, setup, start | Breakdown, absence, quality hold | Supervisor and planner | Stop time and affected orders |
| Material | Allocation, usable date, lot | Late delivery or failed inspection | Purchasing, quality, planning | PO, inspection and substitution approval |

Design an exception path for changes inside the freeze
“Never change anything” usually creates off-system workarounds. Breakdowns, shortages, scrap and genuine customer emergencies will occur. Provide a short path from request to impact calculation, approval, revised instruction, notification and audit record. The requester selects a reason and attaches evidence. The system shows the old and proposed schedules, affected customer orders, setup implications and material availability. An authorised approver accepts or rejects the change. Only an approved change becomes the next shop-floor instruction.
Authority should reflect impact. A planner may simulate alternatives immediately, but changing a released order requires approval. A sequence swap that preserves every customer promise can have a different approver from a change that delays another customer’s confirmed date. The latter also needs sales to re-promise. Name deputies and an escalation time for night shifts and holidays. A change with no valid approver must not silently become approved because a user has administrator access.
Retain who changed what, when, the prior and new values, reason, approver, approval time and version sent downstream. Store rejected and withdrawn requests too. Their patterns explain whether the policy is too restrictive or the master data is poor. The floor display must make the effective version unmistakable. A chat message may arrive before the system update, but the signed-off instruction remains identifiable.
For a Thailand plant, define time zones and shift boundaries explicitly. A “one-day” fence based on midnight may protect different jobs from a fence based on a 07:00 shift handover. Test working days, weekends and night shifts. The choice is a business rule; do not assume the software’s default calendar matches the factory.
Connect ATP and CTP to the freeze policy
Maximum schedule stability alone can slow customer responses. Promising every new order at the earliest imaginable date can destroy the locked schedule. The order-promising rule must respect the freeze.
Available-to-Promise (ATP) assesses supply that can be allocated from existing inventory and eligible scheduled supply. Capable-to-Promise (CTP) asks when new supply could be created using materials, production resources, suppliers or transfers. Oracle’s Global Order Promising documentation distinguishes existing available supply from capacity to build supply that does not yet exist. Precisely which supply qualifies, and how capacity is checked, depends on configuration. Ask vendors to show the promised date and its underlying supply for each sample order.
Do not let a new order consume a frozen production slot without the exception process. First examine uncommitted capacity, alternate lines, available inventory and usable material receipts. If meeting the customer’s requested date requires moving protected work, show a tentative date and the affected orders, then seek approval before issuing a firm promise. A purchase-order due date is not necessarily the material’s usable date; inbound transport, customs and inspection can matter. Hold tentative and confirmed promise dates in different states in ERP.
For make-to-stock products with ample finished inventory, ATP quality may be the first investment. For make-to-order products whose lead time depends on material and bottleneck capacity, CTP deserves deeper tests. In either case, track manual promise overrides and their downstream effect.

Measure schedule stability beside on-time delivery
A lower change count is not proof of success if lateness, overtime or work in process rises. An excellent delivery score can also hide a floor that replans every day. Use both types of measure. Define schedule stability, for example, as the proportion of orders whose line, start and sequence remain within agreed tolerance from the freeze snapshot to execution. Keep the size and reason of changes, not just a binary count. A five-minute adjustment and a move to another shift should not be treated as operationally equivalent.
Define on-time delivery against the last formally confirmed customer promise and state what completion means: production finish, inspection release, shipment readiness or receipt. Do not overwrite old promised dates and then claim an improved score. Preserve promise versions. Measure exception approval time separately for emergency and routine cases.
| Measure | Example definition | Common distortion |
|---|---|---|
| Change rate inside freeze | Share of approved instructions whose effective version changed within the protected window | Hidden verbal exceptions |
| Schedule stability | Share executed within tolerance of frozen line, start and sequence | Undefined tolerance and partial completion |
| Promise adherence | Share ready for shipment by the formally confirmed time | Replacing old promise dates |
| Exception lead time | Median and upper-tail time from request to decision | Mixing routine and urgent cases |
| Replanning effort | Time spent replacing instructions and contacting people | Counting computation time only |
For before-and-after analysis, compare comparable product mix, holidays and demand conditions. In a pilot, first replay the same disruptions in old and proposed workflows and confirm that change history and affected orders are visible. The numerical acceptance examples later in this article are hypothetical test criteria, not TOMAS TECH results or industry averages.
Define the data contract between ERP, APS and MES
The freeze cannot live only inside an APS screen. ERP usually holds orders, purchasing, inventory and customer promises. APS produces a constrained plan and its versions. MES returns starts, completions, good and scrap quantities, material consumption and stops. Product boundaries overlap, so choose one authoritative system per data element. Keep the ERP confirmed date separate from an APS tentative date, and the actual MES timestamp separate from the planned timestamp.
Microsoft’s MES integration documentation lists production-order release, start, produced and scrapped quantity, material consumption, time reporting and completion as integration processes. This is documentation for one product, but it provides a useful interface inventory. For freeze governance, identify the approved schedule version and the version the floor actually received. If APS changes the sequence while MES still displays an older order, staff need a clear rule for which instruction is effective.
Specify source, receiver, fields, event trigger, frequency, time zone, duplicate handling, retries, approval state and audit log for every interface. What happens when a night-shift completion reaches ERP after a plan was recalculated? Does the system automatically change protected work or hold a discrepancy for a planner? During an outage, the floor should see the last successfully received approved instruction. On reconnection, the same message must not create two jobs.
Map item, operation and equipment codes across systems. Align BOM revision effective dates, approved substitute material, quality holds and lot restrictions. An accurate freeze rule over stale material data only stabilises a plan the floor cannot run.

Put testable freeze requirements into the RFP
An RFP should describe inputs, actions and expected outcomes rather than asking whether a “freeze setting” exists. Ask every supplier to answer the same points:
- At which scope can boundaries be configured: site, line, operation, product family, item, material or customer order? Which rule wins when they overlap?
- Does a boundary use calendar days, working days, hours or shifts? How are holidays and time zones handled?
- What happens to existing orders, new demand, shortages, breakdowns and excess supply during an automatic run?
- Which roles can simulate, request, approve, reject or directly edit a protected instruction?
- How do ATP/CTP see reserved capacity, eligible supply and provisional versus confirmed dates?
- Can users inspect the prior and new plan, affected orders, approved version, MES receipt and rollback possibilities?
- How do ERP and MES interfaces report partial success, retry errors and audit events?
- Who can change rules after go-live, who tests them and which support languages are available locally?
Require each answer to be marked standard function, configuration, development or unsupported, with a demonstration or API evidence. Give suppliers the same anonymised 3–5 disruption scenarios. For the broader product-selection framework, see our production scheduler comparison for Thailand factories. The concern here is narrower: whether change authority and frozen boundaries work under disruption.
Score the existence of a feature separately from the effort needed to use it. An exception approval may exist, yet require the requester to search for every affected order across several screens. On the same test case, record steps to submit and assess the change, required fields, approver notification and proof of floor receipt. Test with actual planner, supervisor and sales permissions rather than administrator access. Check that Thai and English status names clearly distinguish tentative, pending and confirmed states. For custom development, include ownership, maintenance and upgrade regression tests in the estimate; freeze rules will change as products and machines change.
Test the policy at FAT and SAT
Use FAT to verify configured functions and interfaces before production use; use SAT to verify operations with the actual site, devices, shifts and permissions. Contract definitions may differ, so specify them explicitly. A clean initial planning run is not enough. Reproduce changes.
Build a compact dataset with two sites, three lines, a bottleneck machine, a delayed material, an urgent order, a quality hold and a night shift. As a hypothetical test, set Site A Line 1 to 48 hours, Line 2 to 24 hours and imported Material M to 72 hours. Those are example values, not recommended settings. Confirm the schedule on Monday at 09:00, then add an urgent order affecting Tuesday’s protected Line 1 work. Replanning should retain the approved instruction, show unallocated demand and propose alternatives. If Material M slips from Wednesday to Thursday, the system should flag infeasibility and route to substitute approval or re-promising rather than silently claim the frozen order remains feasible.
Record initial state, test action, expected result, actual result, evidence, pass or fail, and retest date. Include at least the following cases:
| Test | Action | Expected result |
|---|---|---|
| Replan | Add demand with protected orders present | Do not silently move protected line, start or sequence; explain unmet demand |
| Exception | Request an in-window change for material shortage | Show affected orders and versions; only authorised role can approve |
| ATP/CTP | New order needs protected capacity to meet requested date | Give a tentative or alternative date before approval, not a false firm promise |
| MES | Revise an approved instruction, then interrupt communication | Send one effective version after recovery, with receipt version and time |
| Shift boundary | Repeat a request across handover | Apply the configured plant calendar consistently |
During SAT, let actual supervisors and planners operate the flow. Confirm Thai-language state names, alerts and error messages convey the intended meaning. If the true stop reason is unavailable in the UI, users will select “other” and lose the feedback needed to improve rules. Timestamp the sequence from disruption to alternative, approval and floor receipt to locate delays in computation, decision or communication.
Hypothetical numerical acceptance criteria
Set targets from the plant’s measured baseline. The following figures illustrate how to write a test specification. They are neither measured benefits nor industry benchmarks.
- In a dataset of 100 manufacturing orders, zero protected line/start/sequence changes occur without an approval record.
- For ten urgent-order cases, the system outputs an alternative date, affected orders and traceable input evidence for every case.
- For ten approved changes, the effective version agrees across ERP, APS and MES.
- After five communication outages and five separate resend tests, there are zero duplicate or missing instructions.
- Measure response time using a fixed data volume and infrastructure, then compare it with the contractually agreed limit.
A short FAT cannot guarantee a business outcome such as 95% on-time delivery; demand mix and breakdowns affect it. Verify functions and evidence in FAT, real workflow in SAT, then assess delivery and stability together over a longer operating period. If no baseline exists, collect several weeks of version history and shipment results first.
Common implementation failures
The first failure is assuming a longer freeze means a more stable floor. If capacity and material receipts are wrong, only the screen looks stable. Count infeasible instructions before lengthening the boundary. A line with frequent material surprises may need better receipt and inspection timestamps before it needs a stricter freeze.
The second is blocking floor edits so thoroughly that administrators change data behind the process. Make frequent legitimate reasons quick to request, and delegate low-impact approvals to suitable roles. Review exception patterns monthly. An approval route too slow for a real breakdown is not a working route.
The third is using different capacity and calendars in ATP/CTP and APS. Sales may see a free machine while the floor has booked setup or maintenance. Align the resources and material definitions used for promises. Where they differ, document which answer takes precedence and why.
The fourth is inconsistent ERP and MES status semantics. “Complete” may mean last operation finished in MES but inspected inventory available in ERP. Specify each state transition and timestamp, including partial completion and scrap, then test them. For sequencing and finite-capacity data preparation, see our finite-capacity planning implementation guide. Capacity accuracy and freeze governance depend on each other but are separate requirements.
The fifth is letting rule ownership disappear after go-live. New products, machines, suppliers and shifts all change the right boundary. Name a proposer, approver and tester for configuration changes. Keep the representative FAT cases so upgrades and rule revisions can be regression-tested.
Three conflicts between overlapping freeze rules
First, an approved substitute material may appear to be a material-only change. If it requires extra drying or cleaning, the operation and every following order may move. Test whether the system traces substitution through routing time and sequence rather than merely changing a material code. Second, a transfer from Site A to Site B is more than a line change. Transport, inspection location, WIP ownership and customer promises can change. Preserve versions before and after the transfer and trace them by order number. Third, a rush customer order may meet its requested date only by delaying an existing confirmed order. Show all displaced promises and require sales to complete re-promising before the floor change is released. The RFP should show the wider impact of each apparently small edit.
Use historical changes during migration
Idealised sample orders miss real exceptions. Select past events that were common and events that caused large losses: expedited delivery, material delay, machine failure, quality hold, staff shortage and rework. Anonymise customers while preserving order sequence, inventory known at the time, machine calendar, approver and shipping outcome. Recreate what was known at order entry, plan confirmation and disruption separately; do not preload the finally known receipt time into the first state. The aim is to test whether a planner can see the evidence available at each decision, not whether software can magically predict the old outcome. During parallel operation, review disagreements between old and new processes as configuration, master-data, interface-delay, authority or tacit floor-rule issues before changing the fence length.
Checklist before choosing a supplier
Can the team explain which fields are protected at each plant? Has it identified change costs for each line? Does material availability use the date the material can actually be consumed, rather than only the PO due date? Are emergency approvers and deputies named? Does ATP/CTP avoid offering capacity already reserved by the frozen plan? Can ERP, APS and MES reconcile effective instruction versions? Have night shifts, holidays and time zones been tested? Can the plant measure stability and confirmed delivery performance together? Do FAT/SAT contracts specify evidence, failure criteria and retests? Questions the team cannot answer indicate business requirements to settle before a product demonstration.
Take one real historical schedule change into the procurement meeting and trace it from order receipt to floor instruction replacement. Identify when the material delay became known, who built an alternative, whether sales re-promised, and which version the floor received. Missing answers reveal where the operating process must be designed before software configuration.
Improve the rule after go-live
Review exceptions weekly during the first operating period. Separate unusual breakdowns from recurring issues such as late material availability data. If the latter is processed through emergency approval every day, the approver becomes the bottleneck and the floor follows obsolete instructions. Improve supplier date quality, receiving timestamps or inspection lead time before extending the freeze.
Plot exceptions against the boundary. A cluster immediately before it may reveal a mismatch with sales cutoff or purchasing confirmation. A cluster just after it may indicate stale inventory, machine or staffing data. Bring planning, purchasing, quality, sales, production and IT into a monthly review. Choose whether each frequent cause warrants master-data correction, interface repair or a simpler approval rule. Re-run the representative tests before changing live configuration.
FAQ
How many days should a production plan freeze window last?
There is no universal number. Work backwards from material readiness, setup preparation, labour assignment, subcontractor commitment and shipment booking. Define protected fields and distinct boundaries by site, line and item family, then adjust using observed changes and infeasible orders.
Is an APS freeze window the same as a firm ERP order?
Not necessarily. A freeze may protect planning results during a rerun; firming moves an order into execution. Test order creation, recalculation, change and cancellation in the specific products under consideration.
What if the scheduler must change a frozen plan?
Simulate alternatives, inspect affected orders, material and customer promises, obtain the authorised exception approval, then issue a new effective floor version and send it to ERP and MES. Do not turn an unapproved tentative date into a customer promise.
Which acceptance tests should come first?
Start with new demand against protected instructions, equipment breakdown, material delay, unauthorised edits and outage recovery. For each, compare old and new versions and the effective version received downstream.
Summary
A production plan freeze window is a decision about when change becomes costly and who may authorise it. Define protected fields at site, line and material level; keep exceptions visible; connect ATP/CTP promises; and measure schedule stability alongside delivery. Put real disruption cases into the RFP and FAT/SAT instead of accepting a feature checkbox.
If your Thailand plant is still defining its freeze rules or ERP–MES interfaces, contact TOMAS TECH with a few recent schedule-change examples. Requirement mapping can begin before a product is chosen.
References
- Microsoft Learn: Master plans overview, freeze and firming definitions; accessed 7 October 2026.
- Microsoft Learn: Firm planned orders, order firming; accessed 7 October 2026.
- Oracle Fusion Cloud SCM: Considerations for Configuring Supply Plan Attributes, product-specific fence behaviour; accessed 7 October 2026.
- SAP Help: Firming Planned Orders Using the Planning Time Fence, item MRP settings; accessed 7 October 2026.
- Oracle Fusion Cloud SCM: Overview of Global Order Promising, ATP/CTP; accessed 7 October 2026.
- Microsoft Learn: Integrate with third-party manufacturing execution systems, MES events; accessed 7 October 2026.
- Oracle: Overview of Time Fence Planning, distinct planning, demand and release fences; accessed 7 October 2026.