Most people never think about a serial number, even on products that rely on serialization. It is a short string of characters inside a QR code, printed on a box in a fraction of a second. Yet a single serial passes through a database, a line computer, a printer, a camera, a carton, a pallet, a warehouse, a shop and a phone, and at any of those steps a small mistake can create two products with one identity, or one product with none.
This story follows one serial, A7K29Q, through its whole life. It belongs to a box of Ambre Nuit 100 ml, a fictional perfume from the fictional house Maison Ardent. The timeline above gives the steps; below, we explain what is happening and why each one matters.
Birth: a value in a list
A7K29Q begins as a row in a database. The ERP (or a dedicated serial-management system) creates it, together with 4,999 others, and reserves them for one production order: Ambre Nuit 100 ml, batch L2609.
On its own, A7K29Q means nothing. A serial number identifies one unit only together with the product's GTIN. GS1 allows serials of up to 20 letters and digits; Maison Ardent uses six random-looking characters so that knowing one serial does not let anyone guess the next. Why the pairing matters is explained in GTIN + serial: how an individual product gets its identity.
The list is copied down to the packaging line's local software, so the printer never has to wait for the ERP or the internet in the middle of a print cycle. What happens next is covered in detail in what happens after an ERP creates a serial number.
The point of no return
When box number 1,842 approaches the printer, the line software picks A7K29Q and does something subtle but important: it writes down "sent to print" before it sends the serial to the coder.
From this moment, A7K29Q can never go back to "available". Even if the PC crashes a millisecond later, it might already be on a box. A serial that may exist on a physical pack must never be given to a second one. This one-way rule is the core of exactly-once serialization.
The coder prints a QR code carrying a GS1 Digital Link:
https://id.maisonardent.example/01/09501101530003/10/L2609/21/A7K29Q?17=271231
and reports that the job was sent.
The fork: verified or voided
That report proves very little. The printer knows it was asked to print; it does not know whether the ink landed cleanly, whether the box was skewed, or whether the right box was under the head.
A few centimetres downstream, an inline camera reads the code and compares it with the serial the software expected at that position. This is verification in the line sense: the right identity, readable, on the right pack. The difference is explained in why "printed" is not the same as "verified".
The happy path. The camera reads A7K29Q. It matches. The serial moves to "verified" and the box is eligible to be packed. In supply-chain event terms, this is the moment the unit's identity is commissioned: the physical object and its serial now exist together. See what is a commissioning event?
The reject path. The box behind it was meant to carry A7K29R. The camera cannot read it; the code is smudged. Several things now have to happen, in order:
- The box is tracked to the reject station and pushed off the line.
- A sensor confirms it actually landed in the reject bin.
A7K29Ris marked void, permanently.- The next box gets a fresh serial.
A7K29Ris never reprinted.
Why not simply reprint A7K29R? Because the smudged box still exists in a bin, carrying a partly readable copy of it. If someone fishes it out, or if the "rejected" box actually slipped through, two packs would share one identity. Voiding costs one serial; reuse risks a duplicate in the market.
If the reject cannot be confirmed, because the sensor did not see the box fall, the line stops the conveyor or holds the next case for a person to check. A rejected box that sneaks into a case is the most common way bad data enters a carton record.
Into the box, out of sight
Verified A7K29Q reaches the case packer with eleven others. A camera reads all twelve through the open case, the case is sealed and labelled with its own SSCC, 395011010000004574, and the line records the link. That parent-child record is aggregation, explained in what is aggregation in traceability?
From here, nobody scans A7K29Q directly for a long time. The case goes onto a pallet with its own SSCC. The pallet is scanned onto a truck, scanned off at the distributor, and broken down. The case is scanned onto a store delivery. At every step, the serial travels inside the records of its carton and pallet. If any of those records is wrong, A7K29Q is in the wrong place on paper even though it is in the right place in reality. How individual products become cartons and pallets shows why.
At the checkout, the scanner reads the GTIN from the box and the till prices it. The serial plays no part in the sale.
First scan
At home, the new owner scans the QR code. The phone opens the web address, and Maison Ardent's service looks up A7K29Q:
- Is this serial one we issued? Yes.
- Was it verified on the line? Yes, not voided.
- Was it shipped to this market? Yes, inside case
…4574. - Has it been scanned before? No.
The page shows the product, confirms the serial is known and that this is its first check, and offers loyalty points for registering the purchase. The points are credited once per serial, whoever scans it later. The whole consumer side is in what happens when a consumer scans a connected product.
The clone
Weeks later, something odd happens. A7K29Q is scanned 140 times in three cities in another country, by dozens of different phones, over a single weekend.
A counterfeiter has bought one genuine bottle, photographed its QR code, and printed it on hundreds of fake boxes. Every copy opens the same web page. Copying a QR code is trivial; no printed code can prevent it.
What the serial makes possible is noticing. A single genuine bottle does not get scanned in three cities at once, and this one was shipped to a different market. Maison Ardent's rules flag the serial: new scans see a warning rather than a reassuring message, loyalty redemptions are blocked, and the brand protection team gets an alert listing where and when the scans happened. This is where serialization becomes a tool for authentication programmes, not a guarantee in itself. See why a QR code does not automatically prove authenticity.
There is a subtlety: the genuine owner's bottle now carries a flagged serial too. Good programmes handle this with care, for example by trusting the first scan's location and history, rather than treating every scan of a flagged serial as fake.
What one serial teaches
Follow A7K29Q from start to finish and a few lessons stand out:
- It is only an identity once it is printed and read back. Before that, it is a reservation.
- States move one way. Available, sent, verified or void, packed, shipped. Never backwards.
- The reject path is part of the design, not an exception to it.
- Packing records carry the serial through the supply chain. Their accuracy decides whether the serial can be found.
- The consumer's scan is both a service and a signal. It helps the owner, and it helps the brand see what is happening to its products.
For the full journey of the bottle around this serial, read the journey of a perfume bottle, from brand to consumer.
See how AIQR supports product authentication programmes