Manufacturing & Industrial Vision// diagnostic

The camera passed it and the customer found it: tracing an escape backwards

In short

Answer three questions in strict order before touching the model: was the part imaged, was the defective surface inside the image, and was the judgement wrong. Most escapes stop at the first or second — a missed trigger, a bypassed station, a face nobody inspects — and skipping to retraining adjusts a boundary that was never involved. The chain runs part, image, score, disposition, fate.

Key takeaways

  • Order matters: imaged, imaged well, judged wrongly. Skipping to the model is how escapes recur unchanged.
  • Without a key joining part identity to image, no escape can ever be investigated. Build the key first.
  • A score just under the threshold and a class never seen look identical in a report and need opposite fixes.
  • Check the disposition too: a part the system rejected can still ship if the divert or the bin fails.
  • Image retention has to outlast the customer's complaint horizon, or the evidence is gone before the question arrives.

Three questions, in this order. Was the part imaged at all? Was the defective surface actually inside the image? Was the judgement wrong? Each one is answerable from records you either have or should have, and each has a completely different fix — a trigger, a fixture, a threshold, a new class. Working them out of order is how a team spends a fortnight retraining a model that never received a picture of the face the customer complained about.

The investigation is a retrieval chain with five links: the part's identity, the image, the score, the disposition the system produced, and what physically happened to the part afterwards. Follow it link by link. The place it snaps is the finding.

The retrieval chain, and the link most plants are missing

The chain usually breaks at the first link, and it breaks in the same way everywhere: images are filed by camera and timestamp, parts are identified by serial or by a works order on a traveller, and nothing joins the two. The customer returns a part with a serial on it, quality asks for the image, and the answer is a folder of 90,000 files with no way in. That is not a vision failure. It is a missing key, and it is the cheapest thing on this page to fix and the most expensive to be without.

  • Write the identity into the record at capture. Serial, works order, lot, station, camera, model version and threshold version, all stamped on the image record the moment it is taken.
  • Where parts carry no serial, record position in sequence. Order number plus a monotonic count within the shift bounds the search to a handful of candidates rather than a day's production.
  • Keep the score with the image, not in a separate report. A score you cannot put next to the pixels that produced it settles nothing.
  • Version the configuration alongside it. An escape from March cannot be reasoned about with June's threshold, which is why the threshold has to be a governed setting rather than a slider — the argument in the anomaly score is a ranking and the threshold is a business decision.
  • Make the lookup a tool, not a query. If retrieving an image needs a database expert, escape analysis will happen twice and then stop happening — the class of small internal system described under internal tools and ops.

Question 1: was the part imaged at all?

More escapes than anyone expects end here. A station in monitor-only mode during a trial, a shift where the cell was bypassed for a changeover and not re-enabled, a rework loop that re-injects parts downstream of the camera, a trigger that missed because the part was translucent or badly presented. In every one of these the model performed perfectly on the parts it was given and the escape had nothing to do with it.

  1. Count images against parts produced for the shift in question. Any shortfall is your answer before you look at a single picture.
  2. Check the cell's operating mode log for that window: enforcing, monitor-only, bypassed, or stopped. If there is no mode log, that is finding number one.
  3. Trace the rework and repair paths on the physical line. A part that leaves for repair and rejoins after the station is invisible to it by design.
  4. Look for a trigger fault. Missing images cluster and have physical causes, which is the ground covered in half a part in frame: trigger and encoder faults.

Question 2: was the surface actually in the picture?

The second question splits into two. Was the defective face covered by any camera, and was it usable in the frame you have. The first is a design question that should have been settled at feasibility: a two-camera cell inspecting the top and one side has three uninspected faces, and everyone knows that until the day a complaint arrives about the underside. Write down which faces are inspected and get quality to sign it, because the alternative is discovering the coverage gap during a complaint.

The second is about the image itself. Retrieve it and look at it with a human eye before scoring anything. A part sitting 4 millimetres out of its nest, a smear of coolant on the window, a hand in shot, motion smear across the surface — these produce images in which the defect is genuinely invisible, and no threshold change will ever recover it. If the defect is not visible to you at full resolution, it was not available to the model either, and the fix is presentation or optics rather than data.

An image a competent inspector cannot make the call from is not evidence that the model failed. It is evidence that the model was asked a question the picture could not answer.

Question 3: was the judgement wrong, and in which way?

Only now does the model come into it, and there are two distinct verdicts that look identical in a summary report and demand opposite responses.

The first is a near miss: the defect was detected, the score landed just below the accept boundary, and the part passed by a margin. Pull the score and compare it against the distribution for that part number. A score sitting in the top few percent of passes is a threshold conversation, with a known and quantifiable cost in extra false rejects. The second is a genuine miss: the score is unremarkable, sitting in the middle of the pass population, which means the model saw nothing unusual. That is a class it does not know, and no threshold will find it — it needs examples, a class definition and a labelling standard that two inspectors agree on, which is the discipline in labelling defect images so two inspectors agree.

The branch nobody checks: the system called it and the part shipped anyway

Before concluding that the model missed anything, check what the system actually said. A surprising share of escapes turn out to be parts the cell correctly rejected. The blow-off fired late and the part carried on. The reject chute was full and backed up onto the belt. An operator, working through a spike of false rejects, re-checked a bin and put parts back. Or the cell flagged the part for review and the review queue was never worked because the shift was short.

Five findings, and what each one licenses you to change

FindingConfirming evidenceWhat you may changeWhat you must not change
Part never imagedImage count below part count; mode log shows bypass or monitor-onlyTrigger, interlocks, rework routing, mode governanceThe model — it never saw the part
Face not covered by any cameraCoverage drawing shows the defective face has no stationCell design, an added camera, or the written scope of what is inspectedThe threshold, which cannot see what is not imaged
Image unusableThe retrieved image is blurred, occluded or the part is out of positionFixturing, optics, exposure, cleaning scheduleThe training set — adding bad images makes it worse
Score just under thresholdScore sits in the top few percent of the pass distribution for that partThe threshold, with the false reject cost stated and signed offThe class list — the class already works
Class never seenScore is mid-population; no similar example exists in the training setThe defect class list, labelling standard and training dataThe threshold — lowering it buys overkill, not this defect
Correctly rejected, shipped anywayReject count exceeds parts found in the bin, or a review queue was unworkedActuator timing, chute capacity, the review queue and its staffingAnything in the vision system at all
Escape findings, their confirming evidence, and the permitted response

The retention window that decides whether any of this is possible

None of the above works if the evidence has already rolled off. Escapes surface on the customer's timescale, not yours — weeks in an assembly plant, months in a warranty channel — so an image retention of 7 or 14 days guarantees that every real investigation starts with 'we no longer have it'. Set the window from the complaint horizon of the parts you ship, and get that number from whoever handles returns rather than from IT.

One caveat on interpreting a cluster of escapes. If several arrive together and trace to parts made in the same few days, check the incoming material before the model — a coil, resin or component change shifts appearance in ways that move whole score distributions, and the signature is a goods-receipt date rather than a training gap. That path is rejects doubling the morning a new lot goes on. If the escapes instead cluster by time of day, the variable is the light, and the check is the model that finds the scratch on day shift.

Finally, decide in advance who runs this at 6am on a Tuesday. An escape investigation is a procedure a plant team should be able to complete without the people who built the cell, which means the retrieval tool, the mode log and the coverage drawing all have to exist before the first complaint — the working arrangement we set out in support when the builders are not on site. The surrounding decisions sit in visual inspection and defect detection, part of our manufacturing and industrial vision work.

Frequently asked questions

Short answers to the follow-ups this page tends to raise.

A customer found a defect our vision system passed. What do we check first?

Whether the part was imaged at all. Count images against parts produced for that shift and check the cell's operating mode log, because bypassed stations, monitor-only trials and rework loops that rejoin the line downstream all produce escapes with no model involvement. Only once you have the image in front of you does it make sense to ask whether the judgement was wrong.

How do we tell a threshold problem from a missing defect class?

Compare the escaped part's score against the distribution of passing scores for that part number. A score sitting near the top of the pass population means the model saw something and the boundary was set too loose, which is a threshold decision with a known false reject cost. A score sitting in the middle means the model saw nothing unusual at all, and that needs examples and a defined class rather than a boundary change.

How long should we keep inspection images?

Long enough to outlast the complaint horizon for the parts you ship, which is usually months rather than weeks. Because images dominate storage and scores do not, the practical shape is full-resolution frames for a stated window, downscaled copies for longer, and score, model version, threshold version and disposition retained for as long as anyone could raise a claim.

Can an escape happen even when the system correctly rejected the part?

Yes, and it is common enough to check every time. The cell can call a reject that never physically leaves the line — a late blow-off, a full chute, an operator returning parts from a bin during a false-reject spike, or a review queue nobody worked. Reconcile parts inspected, parts scored reject, parts in the bin and parts dispositioned; gaps between those four numbers are handling faults, not detection faults.

  • escape analysis
  • traceability
  • machine vision
  • quality
// shipped work

The work behind this page

Builds from our portfolio that this page draws on.

Read next

Working on something in this space?

Tell us where you are in a sentence or two. We'll tell you honestly whether we're the right team, and what a sensible first slice of the work looks like.

Start the conversation