In short: The release date under drum buffer rope is the constraint's start time minus the constraint buffer, which usually falls a week or more later than the date an ERP planned start would have produced. Buffer penetration, meaning the share of the buffer already consumed when a job reaches the constraint queue, replaces the expeditor's list as the daily control signal, and the distribution of penetration across a month tells you whether the buffer is the right size. Little's law is the whole reason the method works: with throughput fixed by the constraint, cutting released work in process cuts flow time in direct proportion. The method needs protective capacity at non-constraints and a constraint that holds still long enough to schedule against, and when neither holds, a work in process cap is the honest fallback.
A machine shop I know had 240 open works orders on the floor and finished about twenty a day. Somebody had computed that as twelve days of flow time and quoted four weeks to customers, which felt generous. Jobs were still late, so the planned lead times on the item master had been padded again the previous year, which pushed release dates earlier, which put more work on the floor, which made the queues longer. The carburising furnace, which everything went through, never starved once in that period. It also never went a shift without a supervisor changing its sequence for someone.
That loop is the problem drum buffer rope was built to break, and the fix sits almost entirely at the point where work is released rather than at the point where it is scheduled.
The three objects and what each one does
Goldratt and Cox set out the underlying logic in 1984 and Goldratt gave the scheduling mechanics their operational form in 1990. Schragenheim and Ronen described the shop floor version in the Production and Inventory Management Journal the same year, and that paper is still the clearest short statement of the mechanism.
The drum is the schedule at the constraint. One resource, sequenced properly, with setups grouped and the order book loaded against its real available hours. Everything else on the site takes its timing from that sequence.
The buffer is time, held in front of the constraint so that ordinary upstream variation does not stop it. Its size is a statement about how unreliable the feeding operations are, and it gets sized from evidence rather than from comfort.
The rope is the release rule. Work enters the floor at the constraint's start time minus the buffer, and at no other moment. That single rule is what converts the other two objects into a working system, and it is the one most implementations quietly abandon.
Working the release date backwards from the drum
Take the furnace above. It runs 20 hours a day, six days a week, so 120 hours a week are available after planned maintenance. Next week's order book asks for 138 furnace hours. That gap is visible before a single job is released, and deciding which 18 hours do not happen is a conversation at the drum with the commercial team, held once, on Friday.
Now take one job in that book. Order 4471 has a furnace slot at 08:00 on Thursday. Its route to the furnace is saw, turn, mill, with 4.2 hours of touch time between them. The constraint buffer is three days. So the rope releases the raw bar to the saw at 08:00 on Monday, giving 4.2 hours of work 72 hours to get 72 hours of runway.
The ERP would have released the same job on a fixed twelve day planned lead time computed from the promise date, which lands eleven working days earlier. Those eleven days are queue time, spent on the floor competing with other work for the same non-constraint machines and the same supervisor's attention, and they protect the furnace slot no better than the three days do.
Two other buffers sit alongside the constraint buffer. A shipping buffer covers the route from the constraint to the promise date, typically shorter because there is less to go wrong downstream. An assembly buffer covers parts that never touch the constraint but have to meet one that did, and it exists because a constrained part waiting on an unconstrained one is the most expensive thing that can happen on the site.
Buffer penetration as the daily control signal
Buffer penetration is the share of the buffer already used up when a job arrives at the constraint queue. Express it as a percentage and read it every morning.
The three day constraint buffer above is 72 hours. A job that reaches the furnace queue 54 hours before its drum slot has consumed 25 per cent, which is green. One arriving with 18 hours left has consumed 75 per cent, which is red. Anything past 100 per cent means the drum slot itself is now at risk and the sequence has to change. Zones by thirds are the usual convention and the boundaries are arbitrary, which matters less than applying them consistently.
The operational rule is that you expedite red and you leave green alone. That sounds trivial and it is the largest behavioural change the method asks for, because the expeditor's list is currently sorted by customer name and due date, and buffer penetration will disagree with it most days. A job for your largest account, due in three days, sitting in green, needs nothing done to it. Convincing people of that takes a quarter.
The distribution across a month is the second signal, and it is the one that sizes the buffer. If 90 per cent of jobs stay green for four weeks running, the buffer is larger than the variation it is absorbing, and cutting it by a day takes a day off quoted lead time at no risk. If red is routine and the same three work centres keep appearing upstream of the red jobs, the buffer is compensating for a capacity or reliability problem that has a cheaper fix than holding more time.
Why holding work back shortens the queue
The mechanism underneath is Little's law, published by Little in 1961. Work in process equals throughput multiplied by flow time. On the shop above, 240 orders divided by twenty completions a day gives twelve days.
Throughput is set by the constraint, so as long as the furnace never starves, releasing less does not reduce output. Cut released work in process to 100 orders and flow time falls to five days at the same twenty a day. The whole promise of the method is that arithmetic: same output, less on the floor, shorter and more predictable elapsed time, and the buffer is what makes the "as long as the furnace never starves" clause hold.
Kingman's 1961 approximation explains why the non-constraints matter here. Queue time scales roughly with utilisation divided by one minus utilisation. At 85 per cent that ratio is 5.7; at 95 per cent it is 19. A feeding work centre loaded to 95 per cent contributes more than three times the queueing delay of the same machine at 85 per cent, and it will contribute it erratically. This is what protective capacity means in practice, and it is the condition most sites fail without knowing they have failed.
Mabin and Balderstone collected around eighty published applications of the approach in 2003 and reported mean lead time reductions of roughly two thirds and inventory reductions of about half. They were explicit that the sample is self selected published successes, so treat those as the top of a range rather than an expectation. The direction is well supported; the magnitude in your plant depends on how much of your current lead time is queue, which you can measure directly.
The day the constraint moves
Everything above assumes one resource is the constraint and stays that way long enough to schedule against. Sometimes it does. In a plant with a single expensive furnace, a single test cell, or a single accredited line, the constraint is a physical fact and it will be there next year.
Elsewhere the constraint is a property of the mix. Lawrence and Buss documented shifting bottlenecks in Production and Operations Management in 1994, and their point holds anywhere product families load work centres differently: the bottleneck moves when the order book changes, and it can move week to week.
When the constraint moves, four things have to happen and only the first is obvious. The drum schedule moves to the new resource. The constraint buffer has to be resized, because the new drum has a different set of feeding operations with different reliability. The rope offsets change for every route, which means every open order's release date is now wrong. And the old constraint, which has been sequenced carefully for two years and has the best data on the site, becomes an ordinary work centre whose queue nobody watches.
Two responses are reasonable. Simplified drum buffer rope, described by Schragenheim and Dettmer in 2001, drops the internal constraint schedule altogether when the market rather than a machine is the binding limit, and plans against a shipping buffer with a load check on whichever resource is currently tightest. The other is to stop electing a constraint at all and cap total released work instead, which is CONWIP as Spearman, Woodruff and Hopp set it out in 1990. A work in process cap captures most of the Little's law benefit and needs no bottleneck identification, at the cost of the constraint sequencing that made the drum valuable. On a genuinely high mix job shop, the cap is usually the better trade.
Where this stops
The method assumes routings and process times good enough to compute a drum schedule. If standard times at the constraint are 30 per cent optimistic, the drum is loaded to 130 per cent of reality every week, buffers get eaten systematically rather than randomly, and the buffer penetration report tells you the shop is failing when the data is. Check the constraint's standard times against a fortnight of actual run data before anything else. That is one resource and a few dozen operations, which is an afternoon of work.
It also assumes protective capacity that many sites have deliberately removed. If every work centre is loaded above 90 per cent because a previous programme took out the spare machines, releasing by the rope will not save you. The queues will form upstream of the constraint instead of at it, and the constraint buffer will need to grow until it is holding weeks. The honest reading of that situation is that you have a capacity problem, and the buffer penetration data makes the case for fixing it better than an opinion did.
The last obstacle is a measure rather than a method. A machine idling because the rope has not released work will report 62 per cent utilisation, and somebody will be asked to explain it in a meeting where 62 sounds like waste. Unless that measure changes at the same time as the release rule, supervisors will release work to keep their numbers up and the system reverts within two months. How utilisation gets read at non-constraints is a separate argument worth having first, and schedule adherence (BB9) is where the reporting side of it belongs.
None of this creates capacity. If the constraint is genuinely short against the order book, drum buffer rope gives you a truthful and much earlier version of the same shortfall, which is worth having and is not the same as solving it.
Start by standing on the floor at the same time every morning for two weeks and writing down the queue in front of each work centre. The constraint is the one whose queue never reaches zero, and if two of them qualify, you have a mix question to settle before any release rule will help.