The Compliance Problem Isn't Always in Your Software. Sometimes It's Between Your Systems
By Drew Duffy, MHA, FACHE · CannaPath Regulatory Solutions · About 8 minutes
There is something happening in cannabis compliance software and cannabis technology that I find genuinely interesting.. The industry has more software than it did a few years ago, and much of that software is quite good. There are companies building very capable point-of-sale systems, inventory platforms, seed-to-sale integrations, ecommerce tools, employee management systems, training platforms, accounting software and security technology. There are also companies doing some very good work specifically around cannabis compliance.
So why does it still seem so difficult for an operator to get a clear picture of what is happening inside the business?
I think part of the answer is that we have spent a lot of time making individual systems better, but we haven't spent nearly as much time asking what happens when all of those systems must work together. And in cannabis, that matters more than it does in a lot of industries.
A transaction isn't just a transaction.
Someone placed an order. A POS system records it. Inventory changes. That information may need to move into a state track-and-trace system. An employee performed the transaction, and that employee has training requirements. The business has procedures governing how the transaction should have been handled. Security cameras may have captured what happened. Someone will eventually reconcile the financial side of it, and if something goes wrong, somebody has to figure out what happened and document what was done about it.
There may be six or seven different systems involved in something that, from the customer's perspective, took thirty seconds.

And here's the strange part. None of those systems necessarily must be broken for the business to have a compliance problem.
The ecommerce system can function exactly as designed while the POS reflects something different. The POS can be correct while inventory is out of balance. Inventory can reconcile while an employee's required training has expired. The training record can be perfect while the employee isn't following the procedure in the SOP. The security system may have exactly the footage needed to investigate an incident, but nobody knows which camera to pull or where that information belongs in the larger record.
Every individual system can tell you that it is working. The business can still have a problem. That's the part I think we sometimes miss when we talk about cannabis technology.
Integration is progress. It isn't the finish line.
The industry is already moving in the right direction. Metrc has built a significant ecosystem around integrations with POS, ERP and other business systems, in part to reduce duplicate data entry and improve consistency between operational and regulatory records. Metrc says more than 500 software providers have integrated with its platform across the cannabis industry. That is a good thing. Nobody wants an employee entering the same information into three different systems simply because the systems refuse to talk to one another.
But getting systems to exchange information is only part of the problem. Once the information is moving, someone still must understand what it means.
Suppose a dispensary notices an inventory discrepancy. The inventory system can tell you that the numbers don't match. Metrc can tell you what was reported. The POS can tell you what transactions occurred. None of them can tell you which employee handled the relevant transactions, whether that employee was properly trained at the time, whether they were following the company's procedure, whether the discrepancy was investigated, whether a corrective action was created, or whether the underlying problem actually got fixed instead of happening again two weeks later.

At that point we have moved well beyond the question of whether two systems successfully exchanged data. We are asking whether the organization itself operated the way it was supposed to operate.
That is a compliance question.
The operators are starting to describe the same problem
This isn't something I think consultants should simply declare from a conference room. You can see pieces of it in what operators are asking.
Not long ago, a cannabis operator on Reddit was looking for an ERP system capable of handling production, inventory and compliance. The problem wasn't that there were no products available. The problem was that the available choices seemed to solve different pieces of the puzzle or were designed around businesses much larger than the operator's own organization.
That is a remarkably ordinary technology problem. It is also a remarkably important one.
A large organization can afford to have a technology department whose job is keeping five, six or ten systems connected. A smaller cannabis business may have an owner, a general manager and a handful of employees trying to do the same thing while also dealing with customers, vendors, taxes, licensing, staffing, inventory and everything else that comes with running the business.
The owner doesn't care that the inventory software is technically performing correctly if the information they need is scattered across four different screens. They care whether the business is working.
That distinction is becoming more important as cannabis businesses become more dependent on technology. We're already seeing companies move further into integrations between ecommerce, POS, inventory and regulatory systems. We're seeing video systems connect to transaction data. We're seeing compliance software become more sophisticated. All of that is useful. But every new integration also creates another question.
Who is looking across the whole thing?
Maybe the missing system isn't another system
This is where my thinking about CannaPath Sentinel began. The more I looked at the problem, the less interested I became in building yet another piece of software that an operator must log into. A cannabis business already has systems. The question became whether there was a way to build something that understood the business those systems collectively represent.
Think about what that would look like in practice. An employee has a particular role. That role has training requirements, and those requirements relate to the company's procedures. The procedures relate to regulatory requirements. The employee performs an action in the business, and that action affects inventory. The transaction is recorded by the POS and ultimately by the regulatory tracking system. A security system may provide another piece of evidence about what occurred.
Those aren't separate events. They are different parts of the same event. So why should the software treat them as completely separate? That is the idea behind Sentinel. We're not trying to build another POS, because there are already companies doing that very well. We're not trying to replace Metrc. And we're not assuming an operator wants to throw away every system they've already invested in. We're asking whether compliance can become the layer that connects the business together.

That means Sentinel can eventually understand the relationship between people, training, procedures, documents, inventory, POS activity, Metrc, security and the other operational information a business already depends upon. The goal isn't simply to tell an owner that something went wrong. The goal is to help them see the relationship between what was supposed to happen and what happened.
That's a very different kind of software.
Compliance must live where the business lives
I've spent much of my career in healthcare compliance, and one thing has always seemed obvious to me: compliance doesn't happen in a binder. It doesn't happen because somebody wrote a beautiful policy, and it doesn't happen because an employee clicked through a training course. It happens in the middle of the work.
Someone receives inventory. Someone checks it in. Someone stores it. Someone sells it. Someone reconciles it. Someone notices something doesn't look right, investigates it, documents it, and changes the process so it doesn't happen again.
That is the actual compliance environment.
Cannabis businesses aren't fundamentally different in that respect. They're simply operating in a regulatory environment where the consequences of disconnected information can become particularly visible. That's why I don't think the answer is necessarily to keep giving operators another compliance application, another dashboard or another subscription. At some point the software must become part of the way the business operates.
That is what we're trying to do with Sentinel.
And we don't think essential services should automatically cost more
There is another part of this that matters to me personally.
There are some very good cannabis technology companies and compliance firms out there. Minnesota's cannabis industry is fortunate to have people who are taking the work seriously, and I have no interest in building CannaPath by pretending everyone else is doing it wrong. We simply have a different philosophy.
We listen to our clients. We pay attention to the things that make running their businesses harder. And when we build something intended to make their lives easier, we don't believe that something should automatically become expensive simply because it is essential.
I have made my money already. I'm not here to get rich from this. I'm here to provide a service that makes the lives of my clients significantly better, with software that supports their actual day-to-day operations. That's a big part of why we're taking the approach we are with Sentinel.
That doesn't mean we're trying to build the cheapest software in cannabis. I don't want Sentinel to be perceived as cheap, and I certainly don't want it to be built cheaply. It means we want the core product to be good enough to become part of an operator's everyday business, without creating a price barrier that keeps smaller businesses from using it.
The future may be less about replacing systems and more about connecting them
I don't know that the eventual answer for cannabis technology will be one giant platform that replaces everything. Maybe it will be for some businesses. But I don't think it has to be.
An operator may already have a POS they like. They may have a security system that works, an accounting platform they trust, a particular inventory solution or ecommerce provider they prefer. I don't think they should have to start over simply because they want better visibility into compliance.
What I would like to see instead is software that understands that all of those things are part of one business. That's the bridge we're trying to build with Sentinel. Not another silo. Not another tool that asks an owner to remember one more password and check one more dashboard. A compliance-centered operating layer that can look across the business and help the people running it understand what is happening.
Because that's what compliance is supposed to do. It isn't supposed to make running the business harder. It is supposed to help the business run correctly.
And if we can build software that makes that easier, gives an operator a clearer picture of what is happening, and does it without requiring them to spend a fortune just to get the basic tools they need, then I think we've built something worth having.
That's why Sentinel exists. Not because cannabis needs another software platform. Because cannabis businesses need their existing business to work more like one business.
Where this stands right now
Sentinel isn't open yet, and I'm not going to pretend otherwise. We're building it deliberately, and it will stay off the public internet until we're satisfied that it is ready to do what we designed it to do. But the first piece is already here. Scout is the beginning of that work: a practical compliance gap analysis that looks at the documents, procedures and supporting evidence together rather than treating each one as an isolated file. It is available now at cannapath.org/sentinel.
The rest of Sentinel is being built around the same idea. The technology should not create more work for the people running the business. It should help them see the business more clearly, understand where something has gone off track, and make it easier to correct before a small problem becomes a much bigger one.
That's the direction we're heading. Not toward another piece of software that cannabis operators have to manage, but toward software that helps the systems they already depend on finally work more like one business.
-Drew



