Delivery manifest template for licensed records

A data delivery manifest is a one-page-per-delivery record the licensing company keeps, listing what was handed over: systems, date ranges, file counts, checksums, exclusions applied, delivery method, recipient and date. It lets the company prove later exactly what was delivered and what was withheld.

Why keep a delivery manifest?

A manifest answers one question quickly: what exactly did we hand over, to whom and when? Without one, a company relying on memory and email threads will struggle during an audit, a dispute with the buyer or an end-of-term certification.

The company licenses data and keeps ownership, so it is the company's record to hold. SourceX handles the licensing process, but the manifest is yours. Partners do not create or see it; they only make the introduction.

When do you fill it in?

Create the manifest after the agreement is executed and the company has authorized delivery, and complete one for every delivery event. A single license can involve several deliveries, for example one per system or one per date-range tranche.

MomentAction
Before deliveryDraft the manifest header and scope from the agreed inventory
At packagingRecord file counts, sizes and checksums
At handoverRecord method, recipient, date and who authorized it
After receiptObtain the recipient's acknowledgement of counts
At term endAttach any deletion or return certification

The template

Copy the block below into a document or spreadsheet. Each field has a plain-language purpose.

What do the fields mean in practice?

FieldWhy it mattersCommon mistake
Agreement referenceTies the delivery to the contract scopeLeaving it blank, so the scope is unclear
Date rangeProves nothing beyond the agreed period went outWriting "all history"
Counts and sizeLets both sides reconcile quicklyCounting at the wrong stage, before redaction
ChecksumShows files were not altered in transitRecording a checksum for the folder, not each file
ExclusionsEvidence that agreed redactions were appliedDescribing them vaguely
MethodShows the data stayed within agreed channelsForgetting to note if it stayed in your own storage
AcknowledgementPrevents later disputes about receiptNever asking for it

For very large datasets, delivery may stay in the seller's own storage or ship on encrypted drives; record the method and who held access. See encrypted drives vs seller-hosted access for how those options differ.

Illustrative filled example

Illustrative and fictional. A 200-person engineering services company delivers its support tickets in the second of three tranches.

FieldEntry
Delivery number2 of 3
Source systemSupport ticketing, 2016 to 2023
Records delivered41,200 tickets with attachments removed
Exclusions appliedCustomer names and contact details redacted per the agreed rules
Items withheldTickets tagged legal hold
MethodEncrypted drive couriered to the named recipient
AcknowledgementCounts confirmed by the recipient the day after receipt

Pre-delivery checklist

  • The agreement is executed and the sponsor has authorized this delivery in writing.
  • The scope on the manifest matches the agreed inventory, system by system.
  • Redaction rules were applied and spot-checked by someone other than the preparer.
  • Checksums were generated after the final processing step.
  • The recipient and method match the contract.

Who should be able to open the manifest?

Treat the manifest as a controlled document. It shows system names, record types and exclusions, which are themselves sensitive. Limit access to the sponsor, counsel and the person running delivery, and log who views it. The guide to internal access controls while preparing records covers the permissions side.

How does a manifest help in a dispute or subpoena?

If a buyer says it never received a system, or a third party asks what was disclosed, the manifest is the first document counsel will request. It also supports a clean answer when a stakeholder asks what left the building; the stakeholder objection map lists who tends to ask. For legal process questions, read whether licensed data can be subpoenaed from the buyer. Manifests also help when you must decide who to inform; see who to notify before licensing data.

What should never go in a manifest?

  • Any actual content from the records, including sample text or subject lines.
  • Personal data about individuals in the dataset.
  • Passwords, keys or links that grant access.
  • Promises about price, reward or outcome.

A manifest describes the data; it never reproduces it.

Next step

Save the template, fill the header from your agreement and use one copy per delivery. If you advise a company that may license records, register as a partner and make the introduction; the manifest is something the company keeps, not something you handle.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Who is responsible for keeping the manifest?

The licensing company, because it owns the data and signs the agreement. SourceX manages the licensing process and delivery steps, but the company should hold its own copy of every manifest. Partners who made the introduction do not create, receive or review it.

Do I need a separate manifest for each delivery?

Yes. One manifest per delivery event keeps counts, checksums and recipients clean. If a license involves several tranches or systems, number them and reference the same agreement, so you can reconcile the whole license against the agreed scope.

What is a checksum and do I really need one?

A checksum is a short value computed from a file's contents; if the file changes, the value changes. Recording one per file lets both sides confirm that nothing was altered or corrupted in transit. For large datasets, a hash list in a separate file is enough.

Should the manifest list what was redacted?

It should describe the redaction rules applied and the categories withheld, not the redacted content itself. Rules are agreed with the company before any work begins, so the manifest should reference them and record that they were applied before delivery.

How long should we keep the manifest?

Keep it at least for the license term and any period your counsel or auditors require after it. Retention rules vary by company and industry, so ask your counsel. Store it with the agreement, and keep access limited to people who need it.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment