Skip to main content
Stop information loss between cellar and packaging: a two-page shift-handoff SOP with mandatory photos

Stop information loss between cellar and packaging: a two-page shift-handoff SOP with mandatory photos

Why the gap between cellar and packaging is where your beer quietly goes wrong

The handoff is the weakest link in most brewery production days, and it almost never shows up on a report. A day shift cellar operator notices a tank fermenting a little slow, makes a mental note, figures they'll mention it when the night crew comes in. Then they get pulled into a keg wash, the shift ends, and the mental note walks out the door.

Two days later packaging pulls that tank and the gravity is off. Now someone's asking why nobody flagged it, and the honest answer is: somebody did notice, they just never wrote it down in a way the next person could act on. A brewery shift handoff SOP exists to kill that failure mode. Not with a longer meeting, not with a group chat that scrolls away by lunch — with a structured two-page form that forces the right information out of one person's head and into the next person's hands. The trick is making it short enough that operators actually fill it out, and strict enough that it can't be filled out halfway. Below is the form structure worth stealing, plus the escalation logic and anomaly examples that make it work on the floor.

The three ways handoffs actually fail

Before getting into the form, it helps to be honest about how information disappears — because a good handoff SOP is really just a set of countermeasures against these three patterns.

The verbal handoff that never happened. Shifts overlap by fifteen minutes if you're lucky. Sometimes the outgoing person leaves before the incoming person arrives. Anything that lived only in conversation is now gone. This is the most common failure mode, and it's completely silent — nobody knows information was lost because nobody knew it existed.

The vague note. "Watch FV4" written on a whiteboard. Watch it for what? High krausen? A leaking sample valve? Blow-off slowing down? The note technically exists but carries zero actionable content. The next operator either ignores it or wastes twenty minutes figuring out what they're supposed to be looking at.

The buried detail. Someone writes a thorough paragraph, but the one line that mattered — "airlock activity dropped hard between 2 and 4pm" — is sitting in the middle of four other observations about routine stuff. This usually happens when there's no separation between "FYI" and "you need to act on this."

A form that works has to defend against all three at once: mandatory fields defeat the missing handoff, forced specificity defeats the vague note, and a clear escalation flag keeps the critical detail from getting buried.

Why photos change the whole thing

Text describes. Photos prove.

The single biggest upgrade you can make to a handoff isn't better wording — it's requiring a photo for specific conditions. When an operator writes "some foam around the manway gasket," the next person has to interpret that. Is it a smear or a steady weep? With a timestamped photo, interpretation disappears. The incoming operator sees exactly what the outgoing operator saw, at that moment, and can compare it to current state.

Photos also do something written notes can't: they create an accountability trail that isn't about blame. When a gravity reading photo shows the hydrometer at 1.014 at shift change and packaging later disputes the number, there's no argument. A lot of handoff tension comes from he-said-she-said about what condition a tank was in — photos cut that off entirely.

The rule worth pushing for: any anomaly that gets escalated must include at least one photo. Routine handoff items don't need them. Anomalies do. That keeps the photo requirement from becoming busywork.

The two-page form structure

Two pages is deliberate. One page forces you to cut things that matter. Three pages guarantees nobody finishes it. Page one is the standard shift snapshot. Page two is the anomaly and escalation section that only gets filled when something's off.

Page one — the shift snapshot (mandatory fields)

Every field here is required. If it's blank, the handoff isn't complete. That's a hard rule, not a suggestion.

  1. Shift date, time, outgoing operator, incoming operator — signatures or initials on both sides
  2. Tank-by-tank status line for every active FV and BBT — tank ID, batch/lot, current gravity or pressure, temp setpoint vs actual
  3. CIP/sanitation status — what was cleaned, what's still dirty, what's mid-cycle
  4. Transfers in progress or scheduled — source, destination, volume, expected completion
  5. Open valves / active processes — anything left running that the next shift now owns
  6. Consumables low or out — CO2, sanitizer, DE, whatever you're about to run short on

The tank status line is where most breweries under-build this. A single "all tanks nominal" checkbox is worthless. You want a forced entry per tank so the operator has to physically look at each one before signing out. That act of looking is half the value of the form.

Page two — anomalies and escalation

This page stays empty on a normal day. When something's off, each anomaly gets its own block:

  1. What — the specific observation, not a category
  2. Where — exact tank/line/equipment ID
  3. When noticed — timestamp, because rate of change matters
  4. Photo — mandatory, attached or referenced by file number
  5. Action taken — what the outgoing operator already did, if anything
  6. Escalation level — 1, 2, or 3 (defined below)

The escalation level field is what separates a useful anomaly log from a wall of undifferentiated notes. Without it, everything gets treated the same, and the thing that actually needed a phone call gets read the next morning alongside a note about low CO2.

Here's a simple workflow for filling page one, recording an anomaly on page two, attaching a photo, and routing notifications based on escalation level.

Process diagram

The diagram shows where photos attach and who gets notified at each escalation level.

The 3-step escalation rule

Escalation is where most handoff forms fall apart. Operators don't know when to bump something up versus just note it, so you have to define it by consequence, not gut feel.

LevelTriggerWho gets notifiedTimeframe
Level 1 — Log & monitorDeviation inside acceptable range, no immediate riskIncoming operator only, via the formNext shift checks it
Level 2 — Notify leadDeviation trending wrong or outside spec but recoverableShift lead or head brewer, same dayWithin the shift
Level 3 — Stop & escalateContamination risk, safety issue, or product-loss riskHead brewer / owner immediately, by phoneNow — don't wait for handoff

The key point: Level 3 items don't wait for the form. The form documents them after the fact, but the phone call happens first. Where breweries get burned is treating the handoff document as the notification channel for emergencies. It isn't. It's the record. Anything that can ruin a batch overnight needs a human contacted in real time.

Level 1 and 2 are where the form does its heavy lifting, because those are the ambiguous middle cases that operators tend to sit on.

Anomaly examples that make the levels concrete

Abstract rules don't survive contact with a night shift. Operators need worked examples for the three anomaly types they actually run into: fermentation, sanitation, and transfer.

Fermentation anomalies

  1. Level 1 example. FV6, day two of primary, gravity dropping on schedule but temp reading 1.5°F above setpoint. Glycol's keeping up, no off-gassing concern. Log it, photo the panel, tell the next shift to confirm it holds.
  2. Level 2 example. FV3 gravity has barely moved in 18 hours when it should be dropping steadily. Could be a stalled fermentation, could be a stuck reading — either way it's outside expected behavior and needs a judgment call above operator level. Notify the head brewer same shift, photo the hydrometer sample and the fermentation log.
  3. Level 3 example. Krausen collapse plus a sour or sulfury note that shouldn't be there, or a pressure spike on a tank that should be venting freely. Possible contamination or a blocked blow-off. Phone the head brewer now, then document. If you're building out your detection habits here, it pairs directly with a real microbial and sensory sampling plan so these catches aren't purely reactive.

Sanitation anomalies

  1. Level 1 example. Sanitizer concentration tested slightly low but still in range, topped off during shift. Log the reading and the correction, photo the test strip.
  2. Level 2 example. A CIP cycle on BBT2 didn't hit target temperature and the operator isn't sure the caustic step ran full duration. Tank can't be trusted for filling until verified. Flag to lead, hold the tank, note it so nobody transfers into it. This is exactly the kind of gap a disciplined CIP scheduling SOP is supposed to prevent — but when it slips through, the handoff form is your backstop.
  3. Level 3 example. Visible biofilm or residue in a supposedly clean tank, or a sanitizer line found disconnected mid-cycle. Contamination risk to anything that touches that vessel. Stop, call, quarantine.

Transfer anomalies

  1. Level 1 example. A transfer ran slightly slower than usual but completed clean, volumes reconciled. Note it in case it signals a partially fouled line next time.
  2. Level 2 example. Transfer from FV5 to BBT1 stopped short — receiving tank shows less volume than expected and the operator can't account for 3–4 gallons. Could be a measurement error, could be a leak. Notify lead, photo both tank levels and any pooling on the floor.
  3. Level 3 example. Beer visibly leaking from a fitting mid-transfer, or a wrong-tank transfer caught in progress. Product loss and cross-contamination risk. Kill the transfer, call immediately.

Kill the transfer, call immediately.

A real scenario

A production-focused brewery running around 4,500 barrels a year kept losing information across a day/night split on their cellar crew. Over roughly a quarter they traced three separate quality holds back to handoff gaps — a stalled fermentation nobody flagged for two days, a tank filled after an incomplete CIP, and a transfer discrepancy that wasn't investigated until packaging came up short.

They rolled out a two-page form almost identical to the structure above. Nothing fancy — printed on a clipboard at first, later moved to a shared tablet form so photos attached automatically. The mandatory tank-by-tank status line was the piece that actually stuck, because it forced operators to physically walk the cellar before signing out.

Over the next few months, escalated-but-caught-early anomalies went up while product holds traced to handoffs dropped significantly. The photo requirement resolved two disputes between cellar and packaging that previously would've turned into a half-hour argument and a guess. No dramatic revenue story here, just fewer dumped batches and a lot less finger-pointing.

Where a shared system beats paper

Starting on a clipboard is fine. But two problems show up as you scale.

First, paper forms don't enforce mandatory fields — an operator can leave the gravity line blank and nobody notices until it's too late. Second, photos and paper don't live together, so the image that proves the anomaly ends up on someone's phone, disconnected from the record.

Moving the handoff into a shared operational platform fixes both. A digital form can hard-block submission until required fields are filled, attach the timestamped photo directly to the anomaly block, and route a Level 3 flag to the head brewer's phone automatically instead of relying on someone remembering to call. AI-assisted checks can also flag when a tank's gravity readings across consecutive handoffs stop trending the way they should — catching a stalling fermentation before an operator would've spotted it manually.

Require photo attachments only for escalated anomalies so operators don't treat photos as busywork on routine entries.

The point isn't the software for its own sake. It's that the discipline the form demands is much easier to hold when the system won't let you skip a step.

When this is worth building — and when it isn't

If you run a single shift with a two-person crew who overlap every day and talk constantly, a formal two-page SOP might be more overhead than it's worth. A short verbal handoff plus a whiteboard may genuinely be enough at that scale.

The moment you split shifts, add a night crew, or grow past the point where everyone sees every tank every day, information starts falling through the cracks whether you notice or not. That's when this form pays for itself. It's also worth building earlier if you've already had one quality hold trace back to a missed handoff — that's your signal the informal system already broke.

The form isn't about distrust or bureaucracy. It's about making sure the thing one operator noticed doesn't leave the building when they do. Get the mandatory fields, the photo rule for anomalies, and the three-level escalation right, and the cellar-to-packaging gap stops being the place your beer quietly goes wrong.

The form isn't about distrust or bureaucracy. It's about making sure the thing one operator noticed doesn't leave the building when they do. Get the mandatory fields, the photo rule for anomalies, and the three-level escalation right, and the cellar-to-packaging gap stops being the place your beer quietly goes wrong.

Built for Breweries Tailored to craft brewery production and sales workflows
Save Time Automate scheduling, inventory, and quality control tasks
Optimize Quality Maintain consistent brews with streamlined quality checks
Grow Sales Track and expand distribution channels effectively