A dispensary chain operating in three states can end up running three different compliance realities at once. One license reports to Metrc, another to BioTrack, and each system has its own rules for sales reporting, transfers, and inventory adjustment. Corporate wants a single operating model; regulators want every transaction tied to the correct jurisdiction. Both demands are legitimate, and reconciling them is quietly one of the hardest problems in multi-state cannabis retail.
Why One Traceability System Can't Fake Another
Metrc and BioTrack both perform seed-to-sale tracking, but that surface similarity hides real differences underneath. Metrc configures itself to each state's specific regulatory requirements; BioTrack runs as a government traceability system in its own set of jurisdictions. The workflows for receiving inventory, correcting a package error, or reporting a return are not the same across the two platforms. Treating them as interchangeable is where operational trouble tends to start - a procedure that works cleanly in a Metrc market can behave unpredictably once applied in a BioTrack one.
The fix isn't forcing uniformity. It's building a management layer that sits above both systems while leaving each one as the authoritative compliance record for its own market. The point-of-sale system can own the retail transaction. The state traceability platform owns the regulated history. Corporate business intelligence aggregates normalized figures on top of both, without ever becoming the system of record for a regulated event.
Standardize the Business Layer, Not the Regulatory One
There's a useful distinction multi-state operators need to internalize early: brand names, SKUs, merchandising categories, and vendor identities can be standardized across every store in the portfolio. Package IDs, regulated product categories, lab testing status (as reflected on the COA), and facility identifiers cannot. A shared product catalog is fine. A shared package identity across state lines is not - the compliance history behind that package belongs to one jurisdiction and cannot be merged into another's.
- State and license number for every facility
- Required traceability platform and responsible local users
- POS integration method and sales/transfer workflows
- Package IDs and regulated categories kept local, never cross-mapped
Exceptions, Access, and the Cost of Getting It Wrong
A single exception queue - surfacing failed sales reporting, quantity mismatches, unresolved transfers, unusual adjustments - saves regional managers from logging into separate state systems every morning. But the queue only works if each exception keeps its state, facility, and source system attached. Strip that context out and you've just built a faster way to make the wrong correction.
Access control deserves the same scrutiny. Metrc, BioTrack, and the POS each run their own permission models, and gaps appear fast: an employee with narrow rights in the POS but broad adjustment rights in the state system is a real risk, not a hypothetical one. Least-privilege access has to be checked across all three systems together, not just the retail front end.
Provider Transitions Are a Controlled Event, Not a Reset
States do change traceability providers. New York's move from BioTrack to Metrc is the clearest recent example, and it required operators to reconcile physical counts, credential users in the new system, and reconnect POS workflows before go-live. Historical records need to carry forward; opening inventory in the new system should be validated against a defined cutoff in the old one. A migration that produces an unexplained starting balance is a compliance problem waiting to surface at audit, not a clean break from the old system.
None of this is about forcing two platforms to act alike. It's about accepting that they won't, and designing the enterprise layer - product standards, KPI definitions, access rules, exception handling - so that every regulated transaction still has exactly one system that legally owns it.