Delivery manifest template for licensed records
A data delivery manifest is a one-page-per-delivery record the licensing company keeps, listing what was handed over: systems, date ranges, file counts, checksums, exclusions applied, delivery method, recipient and date. It lets the company prove later exactly what was delivered and what was withheld.
Why keep a delivery manifest?
A manifest answers one question quickly: what exactly did we hand over, to whom and when? Without one, a company relying on memory and email threads will struggle during an audit, a dispute with the buyer or an end-of-term certification.
The company licenses data and keeps ownership, so it is the company's record to hold. SourceX handles the licensing process, but the manifest is yours. Partners do not create or see it; they only make the introduction.
When do you fill it in?
Create the manifest after the agreement is executed and the company has authorized delivery, and complete one for every delivery event. A single license can involve several deliveries, for example one per system or one per date-range tranche.
| Moment | Action |
|---|---|
| Before delivery | Draft the manifest header and scope from the agreed inventory |
| At packaging | Record file counts, sizes and checksums |
| At handover | Record method, recipient, date and who authorized it |
| After receipt | Obtain the recipient's acknowledgement of counts |
| At term end | Attach any deletion or return certification |
The template
Copy the block below into a document or spreadsheet. Each field has a plain-language purpose.
What do the fields mean in practice?
| Field | Why it matters | Common mistake |
|---|---|---|
| Agreement reference | Ties the delivery to the contract scope | Leaving it blank, so the scope is unclear |
| Date range | Proves nothing beyond the agreed period went out | Writing "all history" |
| Counts and size | Lets both sides reconcile quickly | Counting at the wrong stage, before redaction |
| Checksum | Shows files were not altered in transit | Recording a checksum for the folder, not each file |
| Exclusions | Evidence that agreed redactions were applied | Describing them vaguely |
| Method | Shows the data stayed within agreed channels | Forgetting to note if it stayed in your own storage |
| Acknowledgement | Prevents later disputes about receipt | Never asking for it |
For very large datasets, delivery may stay in the seller's own storage or ship on encrypted drives; record the method and who held access. See encrypted drives vs seller-hosted access for how those options differ.
Illustrative filled example
Illustrative and fictional. A 200-person engineering services company delivers its support tickets in the second of three tranches.
| Field | Entry |
|---|---|
| Delivery number | 2 of 3 |
| Source system | Support ticketing, 2016 to 2023 |
| Records delivered | 41,200 tickets with attachments removed |
| Exclusions applied | Customer names and contact details redacted per the agreed rules |
| Items withheld | Tickets tagged legal hold |
| Method | Encrypted drive couriered to the named recipient |
| Acknowledgement | Counts confirmed by the recipient the day after receipt |
Pre-delivery checklist
- The agreement is executed and the sponsor has authorized this delivery in writing.
- The scope on the manifest matches the agreed inventory, system by system.
- Redaction rules were applied and spot-checked by someone other than the preparer.
- Checksums were generated after the final processing step.
- The recipient and method match the contract.
Who should be able to open the manifest?
Treat the manifest as a controlled document. It shows system names, record types and exclusions, which are themselves sensitive. Limit access to the sponsor, counsel and the person running delivery, and log who views it. The guide to internal access controls while preparing records covers the permissions side.
How does a manifest help in a dispute or subpoena?
If a buyer says it never received a system, or a third party asks what was disclosed, the manifest is the first document counsel will request. It also supports a clean answer when a stakeholder asks what left the building; the stakeholder objection map lists who tends to ask. For legal process questions, read whether licensed data can be subpoenaed from the buyer. Manifests also help when you must decide who to inform; see who to notify before licensing data.
What should never go in a manifest?
- Any actual content from the records, including sample text or subject lines.
- Personal data about individuals in the dataset.
- Passwords, keys or links that grant access.
- Promises about price, reward or outcome.
A manifest describes the data; it never reproduces it.
Next step
Save the template, fill the header from your agreement and use one copy per delivery. If you advise a company that may license records, register as a partner and make the introduction; the manifest is something the company keeps, not something you handle.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Who is responsible for keeping the manifest?
The licensing company, because it owns the data and signs the agreement. SourceX manages the licensing process and delivery steps, but the company should hold its own copy of every manifest. Partners who made the introduction do not create, receive or review it.
Do I need a separate manifest for each delivery?
Yes. One manifest per delivery event keeps counts, checksums and recipients clean. If a license involves several tranches or systems, number them and reference the same agreement, so you can reconcile the whole license against the agreed scope.
What is a checksum and do I really need one?
A checksum is a short value computed from a file's contents; if the file changes, the value changes. Recording one per file lets both sides confirm that nothing was altered or corrupted in transit. For large datasets, a hash list in a separate file is enough.
Should the manifest list what was redacted?
It should describe the redaction rules applied and the categories withheld, not the redacted content itself. Rules are agreed with the company before any work begins, so the manifest should reference them and record that they were applied before delivery.
How long should we keep the manifest?
Keep it at least for the license term and any period your counsel or auditors require after it. Retention rules vary by company and industry, so ask your counsel. Store it with the agreement, and keep access limited to people who need it.
Related pages
- Encrypted drives vs seller-hosted access for large dataset delivery
- How to control internal access while preparing records for licensing
- Stakeholder objection map for a data licensing decision
- Can data licensed to an AI buyer be subpoenaed from the buyer?
- Who outside the company should be told before it licenses its data?
Free resources
- Enterprise value calculator — Enterprise value from equity value, debt and cash.
- Earnout scenario calculator — Probability-weighted earnout value and its present value.
- Profit margin calculator — Profit and margin across three scenarios.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment