Platform overview
One transaction architecture, from manifest to audit evidence.
Smoke Alarm is one identifier that follows a transaction through every subsystem, one operational inventory state reconciled to Metrc, a dedicated Metrc service with a durable queue, and Audit Shield as the control layer across all of it. This page shows the design and, beside each part, what exists today.
One identifier, carried through every record.
A Smoke Alarm transaction never spawns an unrelated identifier. The order, the sale, the payment, the inventory change, the package and its Retail ID, the Metrc submission, the receipt, the employee, the terminal and the audit event all carry the same id, so any one of them leads to all the others. Dispatch, driver and delivery join the chain when Smoke Alarm Delivery ships.
- 01OrderPreview
- 02SalePreview
- 03PaymentPreview
- 04Inventory change
- 05Package / Retail ID
- 06Metrc submissionPreview
- 07ReceiptPreview
- 08EmployeePreview
- 09TerminalPreview
- 10DispatchPlanned
- 11DriverPlanned
- 12DeliveryPlanned
- 13Audit event
Relationships are kept
A return or refund points at the sale it reverses; a void points at the receipt it cancels; a discrepancy case points at the manifest line and the package it concerns.
Events, not overwrites
Every state change is an appended event with who, when and why. Nothing is rewritten; a correction is a new entry that references the one it corrects.
Statuses are recorded, not inferred
Audit Shield writes a status at every stage of the lifecycle: verified, review, blocked or pending. An inspector's question is answered from the record, not reconstructed.
Application → engine → durable queue → connector → Metrc → confirmation.
Metrc writes are not idempotent, so Smoke Alarm treats the state system as a dedicated service. No screen calls Metrc directly; every significant write is traceable, retry-aware, reconciled and auditable. The design is on the left; what runs today is on the right.
| Stage | The design | What exists today | Status |
|---|---|---|---|
| 01 Application | The register, receiving and the assistant never call Metrc themselves; they write a transaction. | The register and receiving write transactions and inventory events; no UI component holds a Metrc call. | Preview |
| 02 Transaction / event engine | One identifier per transaction; every state change is an event on the inventory ledger. | Twenty-five inventory lifecycle events and an append-only movement ledger, attributed and timestamped. | Available |
| 03 Durable queue | Every Metrc write waits in a durable queue with an idempotency key, a lease and a retry schedule. | The sales-reporting queue claims rows under a lease, counts the attempt before the request leaves, and never sends a receipt twice without reading Metrc back first. | Preview |
| 04 Metrc connector | One adapter per destination, with host guards so a sandbox item can never reach production. | Reads for packages, incoming transfers, lab results and receipts against the v2 API; one write, the package adjustment, through the write-operation ledger (proposed, approved, preflight, dispatch, read-back). | Requires setup |
| 05 Metrc | The state system of record. Smoke Alarm reconciles to it; it does not replace it. | Production connections are switched off until Metrc grants New York integrator access; simulated and sandbox destinations run today. | Requires setup |
| 06 Confirmation / retry / exception | A receipt is treated as reported only once Metrc confirms it; anything uncertain becomes an exception for a person. | Confirmed with Metrc's receipt id, retried with backoff on definite failures, or parked as Requires review when Metrc cannot say; failures escalate after the attempt limit. | Preview |
The write-operation ledger
Every mutation Smoke Alarm sends to an outside system is a row with a state: proposed, approved, preflight, ready, dispatching, then confirmed, requires review or failed. A person approves; a person decides any retry. Today one Metrc write, the package adjustment, runs through it.
Verify before retry
An answer that might mean recorded is read back from Metrc before anything is re-sent. If Metrc cannot say, the item waits for a person rather than being sent again. Production sales reporting also waits on Metrc's confirmation of New York's payload fields.
Built on the Metrc third-party API. Smoke Alarm never accepts a transfer in Metrc, because the state’s API offers that to no integrator, and writes nothing to Metrc without a named person’s approval.
No website, POS or delivery inventory silos.
One inventory, synchronised and reconciled with Metrc, that every product line reads and writes. Each package carries one of 12 compliance states and each unit one status; the table maps the designed operational states to the machines that exist today.
| Operational state | Package compliance state | Unit status | Exists today |
|---|---|---|---|
| Available The only sellable state; every other one is a reason the package cannot be sold. |
|
| In the ledgerAvailable |
| Reserved Arrives with storefront and pickup orders; the kiosk's in-store order queue is the nearest thing built. | none yet | none yet | DesignedPlanned |
| Sold |
|
| In the ledgerAvailable |
| Delivery assigned | none yet | none yet | DesignedPlanned |
| Driver custody | none yet | none yet | DesignedPlanned |
| Quarantined |
|
| In the ledgerAvailable |
| Return pending |
| none yet | In the ledgerAvailable |
| Returned |
|
| In the ledgerAvailable |
| Recalled |
| none yet | In the ledgerAvailable |
| Expired |
| none yet | In the ledgerAvailable |
| Destroyed |
|
| In the ledgerAvailable |
Package states also include pending_receipt for a manifested package that has not arrived. Unit statuses also include transferred, in_transit, unaccounted and adjusted_out, which the reconciliation rules use to explain a variance rather than to sell.
Twelve stages, one record, a status at each.
The same lifecycle the homepage shows, with what Audit Shield records at every stage and the honest status of the capability behind it.
- Verified
- Checked and agreed at this stage.
- Review
- A person needs to decide.
- Blocked
- The workflow stops here until it is resolved.
- Pending
- Waiting on a step that has not happened yet.
- 01 · MANIFESTVerified
Manifest
The supplier's manifest arrives before the truck does.
Audit Shield: Manifest lines are imported and checked for duplicates, missing lab results and mismatched packages.
AvailableReceiving firewall - 02 · RECEIVEReview
Receiving
Every package is scanned at the dock against the manifest.
Audit Shield: Short, extra and wrong packages become discrepancy cases; nothing enters inventory until a person decides.
AvailableReceiving firewall - 03 · INVENTORYVerified
Inventory
Accepted packages carry a state and a Retail ID.
Audit Shield: One operational inventory state, reconciled against Metrc; every movement attributed and timestamped.
AvailableInventory ledger - 04 · STOREFRONTPending
Storefront
The customer orders from the same inventory the register sells.
Audit Shield: The order reserves inventory instead of promising stock the shelf does not hold.
PlannedOnline storefront - 05 · POSVerified
Point of sale
The register is the last gate before a sale exists.
Audit Shield: Age verification, package state, quantity and price are checked before the sale can complete.
PreviewSmoke Alarm POS register - 06 · PAYMENTVerified
Payment
Tender is recorded against the sale, never beside it.
Audit Shield: Payment amount is matched to the sale; the Compliance Technology Fee is disclosed before completion.
PreviewCash payments - 07 · METRCPending
Metrc reporting
The sale is queued for the state system of record.
Audit Shield: A durable queue with retries and read-back; a receipt is confirmed before it is treated as reported.
PreviewMetrc sales reporting queue - 08 · DISPATCHPending
Dispatch
A prepaid order is picked, packed and assigned to a run.
Audit Shield: Only products on prepaid orders leave the store; each is manifested before it moves.
PlannedSmoke Alarm Delivery - 09 · DRIVERPending
Driver custody
The driver takes custody, one scan per package.
Audit Shield: Custody transitions are events; a failed delivery returns to the store and is reconciled, never lost.
PlannedSmoke Alarm Delivery - 10 · CUSTOMERPending
Customer
The customer receives the order and a verified handoff is recorded.
Audit Shield: Identity verification is an event, not a stored image; the minimum is kept.
PlannedSmoke Alarm Delivery - 11 · RECONCILEVerified
Reconciliation
Metrc, POS, ledger and shelf are compared package by package.
Audit Shield: Every mismatch is a finding with an owner, an explanation and evidence; the report is reproducible.
AvailableAudit Shield Reconcile - 12 · EVIDENCEVerified
Audit evidence
The record an inspector asks for already exists.
Audit Shield: An append-only audit log and a dated binder with its SHA-256 fingerprint.
AvailableAudit trail and binder
Sell. Protect. Move. Deploy. Intelligence.
Every destination on the platform, grouped the way the navigation groups them, with each page's honest status beside it.
Sell
The register, the storefront and the payment layer, on one inventory.
- Smoke Alarm POS
The register with the compliance gate at checkout.
Preview - Storefront
Your branded online store, sharing the register's inventory.
Planned - Payments
Cash today; certified terminals through provider adapters.
PreviewRequires setup - Kiosk
Self-service ordering that hands the order to the counter.
Preview
Protect
Audit Shield: the control and exception layer across the whole lifecycle.
- Audit Shield Reconcile
Metrc, POS, ledger and physical count compared package by package.
Available - Fix Me
Reconcile Pro with Autopilot investigates, prepares the correction and runs it only after a person approves.
- Receiving
Every manifest verified at the dock before it becomes inventory.
Available - Inventory
One operational inventory state, every movement attributed.
Available - Vendor protection
Refusals, short deliveries, buybacks and returns with evidence.
Available - Audit trail
The append-only record and the binder an inspector asks for.
Available
Move
Prepaid orders from the shelf to the front door, in custody the whole way.
- Smoke Alarm Delivery
Dispatch board, driver workflow, verified handoff. In development.
Planned - Smoke Alarm Switch
Migration from your incumbent POS, with shadow mode and a Green Light cutover.
AvailableRequires setup
Deploy
Hardware, installation and the audit that starts most engagements.
- Integrated Store
Register, receiving and kiosk kits from certified third-party hardware.
Requires setup - Implementation
Professional deployment from discovery to launch support.
Available - NYS Systems & Compliance Audit
Fifteen categories, graded findings, a fingerprinted report.
Available
Intelligence
Connections and the assistant that turns a question into a reviewed action.
- Integrations
Metrc, incumbent POS connectors, scanners and printers.
Requires setupRequires setup - Ivory
Ask Ivory: natural language in, a reviewed, audited action out.
Available - Platform story
The operating system behind the sale.
What is live today.
Every capability the site describes, grouped by its status. This table is generated from the same register every badge on the site reads, so a page cannot describe a roadmap item as live.
- Available
- Available features still require store setup and authorized data. This is not a connected-account status.
- Preview
- Explore with illustrative data. Not generally released for customer use.
- Requires setup
- Provider credentials, a partner agreement or approval may be needed before use.
- Planned
- Not available yet.
AvailableLive: 13 capabilities
| Capability | What it is |
|---|---|
| Audit Shield Reconcile | Metrc, the point of sale, Smoke Alarm's ledger and the physical count compared package by package, with reproducible reports and discrepancy cases. |
| Receiving firewall | Manifests imported, scanned at the dock, checked against New York's receiving rules and held until a person decides each discrepancy. COD transfers are flagged from the payment terms Metrc carries, the verified payment is recorded, and a COD transfer received in Metrc unpaid raises a finding. |
| Inventory ledger | Every package and unit carries a state; every movement is an attributed, timestamped entry that is never rewritten. |
| Discrepancy cases | Seven categories of receiving discrepancy, each a case with an owner, evidence, a human decision and the final inventory state. |
| Vendor protection | Refusals, short deliveries, buybacks and expiration returns tracked with evidence and a secure vendor link. |
| Audit trail and binder | An append-only audit log with before and after on every decision, and a dated evidence binder with its SHA-256 fingerprint. |
| NYS Systems & Compliance Audit | A person-led audit across fifteen categories, findings graded red, amber, green and blue, delivered as a fingerprinted report. |
| Multi-location oversight | Each licence keeps its own inventory and findings; owners see every location, staff only the ones they are given. |
| Switch: import and normalise | Inventory imported from a CSV export with package tags and SKUs preserved; products mapped to Smoke Alarm's catalogue with every legacy identifier kept as an alias. |
| Switch: shadow mode and pilot measurement | Smoke Alarm watches receiving and reconciliation beside the current system, holding every outward action, and measures its own precision before it is trusted. |
| Switch: readiness checklist and go-live | A fourteen-step implementation and a fourteen-item go-live checklist; only an owner with an authenticator can activate, pause or resume live sales. |
| Professional deployment | Discovery, mapping, Metrc connection, migration, hardware setup, shadow operation, reconciliation and a controlled cutover, delivered by the team. |
| Ivory (Ask Ivory) | A conversational interface over the operation's own records; anything that would change data waits on a card for a person's approval, and nothing it does can write to Metrc. |
PreviewPilot: 11 capabilities
| Capability | What it is | Waiting on |
|---|---|---|
| Metrc sales reporting queue | Every sale queued to Metrc with verify-before-retry so nothing is sent twice; New York's sales payload fields are still being confirmed with Metrc. | Metrc's written confirmation of the New York sales report fields; production API access. |
| Smoke Alarm POS register | Register, cart, compliance rules at the sale, statutory New York receipts, shifts with blind close, voids and returns; live sales open only after the go-live checklist. | Go-live: confirmed tax rates per location, Metrc sales authorization and payload mapping. |
| Cash payments | Cash tender, change, drawer events and blind shift close. | Same go-live gate as the register. |
| Cannabis tax configuration | New York's state and local adult-use taxes as versioned, per-location rules that a person confirms before a live sale. | A person confirms each location's rates. |
| ID verification at the register | A scanned ID (PDF417 parsed on the device) or a manually inspected government ID; a glance is never accepted, and only the method and result are stored. | — |
| Self-service kiosk | A paired kiosk where a customer builds an order to pay for at the counter, through the same compliance rules as the register. | Same go-live gate as the register. |
| Devices: printers, scanners, drawers, ID scanners | ESC/POS receipt printing and drawer kick over Web Serial or WebUSB, keyboard-wedge and camera barcode scanning, PDF417 ID parsing, ZPL labels, and a bench test that records each device's result. | Chromium on HTTPS; each store's device models verified on site. |
| Ivory: dictation | Speak instead of type, through the browser's own speech recognition; the words are shown before anything is sent. | — |
| Autopilot remediation engine | Smoke Alarm investigates a discrepancy, determines the safest correction, prepares it, explains exactly what it intends to change, and executes only after a named person's approval, with six records kept for every fix. | Running on test and pilot locations; no customer location has used it yet. |
| Fix Inventory | A scan the register cannot resolve is investigated, the cause classified, the local correction prepared and applied after the tap the policy requires, then verified and recorded on an AI case. | Running on test and pilot locations; no customer location has used it yet. |
| Fix Me | On a discrepancy case: a planner model proposes the correction, a second model verifies it, a person approves it, and the approved actions run through the write ledger and are read back. | Running on test and pilot locations; no customer location has used it yet. |
Requires setupIntegration: 4 capabilities
| Capability | What it is | Waiting on |
|---|---|---|
| Metrc connection (reads) | Packages, incoming transfers and lab results read through Metrc's third-party API with the licensee's own key; nothing is written without a named person's approval. | Metrc integrator access for New York (Metrc case 02448265) and each licensee's user API key. |
| Electronic payments | A payment boundary that refuses any processor not lawfully able to accept cannabis sales; debit, pay-by-bank and ACH are added through a contracted provider's adapter. | A contracted, cannabis-lawful pay-by-bank partner chosen with counsel, its adapter under src/integrations/payments/smokepay/partners/, and its credentials. |
| Integrated Store hardware kits | Commercial off-the-shelf registers, scanners, printers, drawers and displays configured for Smoke Alarm and installed on site; sourced per deployment, priced as ranges. | Supplier pricing at the time of order; the store's site survey. |
| Switch: read from the current POS | A read-only connector contract; Dutchie is built against its published API, other systems arrive through the same contract or a CSV export. | The POS vendor's partner credentials. |
PlannedRoadmap: 13 capabilities
| Capability | What it is |
|---|---|
| Online storefront | A branded online store on the same inventory and transaction engine as the register. Designed; not built. |
| Pickup orders | Order online, pay, collect at the counter. Follows the storefront. |
| Smoke Alarm Delivery | Dispatch, driver custody, identity verification at the door, failed-delivery returns and reconciliation as one transaction. Designed and priced; not built. |
| Customer-facing display | A second screen at the register showing the cart, taxes and disclosed fees to the customer. |
| E-mailed receipts | The setting exists; the sending does not yet. |
| Switch: vendor exit, contract and equipment return tracking | Tracking the incumbent vendor's notice period, cancellation, RMA and equipment returns as part of the migration record. |
| Plant and batch tracking | Plant tags, stage moves, harvests and transformations. Smoke Alarm works at the package level today. |
| Outbound manifests and transfers | Creating and verifying outbound transfers. Smoke Alarm reads incoming transfers today. |
| Customer API | A public API for customers' own systems. Not built. |
| AI-guided returns | A return investigated and prepared the way a discrepancy is, with the refund or reversal held for elevated approval. Designed; not built. |
| AI-guided receiving | The receiving firewall's discrepancies investigated and the correction prepared for the receiving manager. Designed; not built. |
| Proactive problem detection | The engine watching for the conditions that precede a discrepancy and opening a case before the reconciliation run finds it. Designed; not built. |
| Reconcile Enterprise with Autopilot | Batch fix review, multi-location remediation, custom approval rules and dual approval on top of Reconcile Pro with Autopilot. The policy record exists; the batch, multi-location and second-approver workflows are designed and not yet built. |
Walk the architecture with the people who built it.
Twenty minutes with Ken and Charles. Bring one manifest and one register close and we will follow them through every record on this page.