Skip to content
Available

Audit Shield · Audit trail

The record already exists when someone asks for it.

Every finding, decision and correction is recorded the moment it happens, with the record before and after, and is never silently rewritten. When an inspector, an auditor or your own accountant asks how a discrepancy was found and resolved, the answer is a document, not a recollection.

Audit Shield records a status at every stage. The chips above follow one example transaction from the dock to the audit log.
Audit log · Evergreen Dispensary (simulated)
Simulated
  1. investigation.correction_approvedWed 09:20:14
    M. Chen (manager) · before on_hand: 57 → after on_hand: 54
    Three damaged units found in back stock; photos attached.
  2. inventory.adjustedWed 09:20:15
    system · before 57 → after 54
    From INV-118; approval by M. Chen.
  3. evidence.attachedWed 09:21:02
    M. Chen (manager) · before — → after backstock-2.jpg · SHA-256 9f2c…e41a
    Recount evidence.
  4. reconciliation.run_storedThu 06:00:00
    system · before — → after inputs SHA-256 3b7d…c0f9
    Hourly run; 1 finding open, 1 reconciled.

Illustrative logFictional entries in the shape the audit log stores them: actor, action, before, after, reason.

The audit log

Append-only, with before and after.

Every consequential action writes an entry: who, when, what, the record before, the record after, the reason given and any external reference (a Metrc submission id, a provider's answer). No entry is deleted; things are resolved and closed.

  • Every decision, attributed

    Receipts approved, cases resolved, corrections proposed and approved, roles changed, connections stored: each with the person who did it.

  • Who approved what

    An external write (today, a Metrc package adjustment) sits on the write-operation ledger: proposed, approved by a named person, preflighted, sent once, read back. The provider's answer is stored beside the request.

  • Fingerprints, not promises

    Evidence files are stored with their SHA-256; a replaced file stays on record. Reconciliation runs are stored with the SHA-256 of their inputs.

The reproducible report

The same facts give the same report.

A reconciliation run is stored with the hash of everything it read. Its printable report and its CSV carry that hash in an X-Inputs-SHA256 header and print it on the page; the download itself carries X-Content-SHA256. Every download is audited.

HTML and CSV

One row per package: tag, product, SKU, the Metrc, POS, ledger and physical quantities, the variances and the status. Simulated runs say SIMULATED in the data itself, on every row.

Checkable later

Anyone holding a copy can compute its hash and compare it with the one Smoke Alarm recorded for that run. A report cannot be quietly regenerated with different numbers under the same fingerprint.

The audit binder

One licence, one period, one document.

A dated, page-numbered document of everything on record for a location over a period of up to 366 days (30 by default): findings and what was done about each, who approved what, the evidence, every external write and what the provider answered, the counts and transfers of the period, and the audit history. Its manifest lists the fingerprint of every record it prints.

Nothing written for the binder

This binder assembles what Smoke Alarm has on record for one licensed location over one period: the findings its reconciliation raised, what was done about each, who approved what, the evidence attached, every external write that was proposed and what the provider answered, the physical counts and transfers of the period, and the audit history. Nothing in it was written for this document. Every line is a record that already existed, printed with the timestamp and the person it was recorded with.

Nothing asserted about a regulator's view

Smoke Alarm does not decide whether a discrepancy is reportable, does not file anything with any regulator, and is not a system of record. Where a rule is cited, the threshold shown is the product's reading of that rule, flagged for human review. The applicable rule and any reporting duty must be verified against the current authoritative text.

Simulated stays marked

Records marked SIMULATED were produced by the product's simulated data sources. No state system, point of sale or laboratory was read or written for them. They show the workflow and the arithmetic, not the inventory of a licensed facility.

Audit trail and binderAvailable

An append-only audit log with before and after on every decision, and a dated evidence binder with its SHA-256 fingerprint.

Beyond the software

Want a person to review your current exposure?

The audit trail is part of every plan. The NYS Systems & Compliance Audit is a separate, person-led review of your systems and records across fifteen categories, graded and delivered as a fingerprinted report. It is not an OCM inspection and not legal advice.

Smoke Alarm does not decide whether a discrepancy is reportable and does not file anything with any regulator. Where a rule is cited, the threshold shown is the product’s reading of that rule, flagged for human review.

Ask for last month's binder.

On the simulated store we generate the binder for a period, open the manifest of fingerprints, and show you what an inspector would be handed.