Audit Shield · Inventory
One operational inventory state. Never competing truths.
No website inventory, POS inventory and delivery inventory that drift apart. Every package carries one state, every unit one status, and every movement is an attributed, timestamped entry that is never rewritten. Metrc is the regulatory system of record; Smoke Alarm's ledger is reconciled against it, never assumed to match it.
| When | Event | Quantity | Recorded by · reason |
|---|---|---|---|
| Mon 08:12 | Manifest received | +60 | R. Ortiz (receiver) Manifest 0000112233, line 2; manager confirmation recorded for a 5.00% variance on another line. |
| Mon 08:14 | Accepted | 60 on hand | M. Chen (manager) Receiving rules ALLOW; lab passed in the state system; packaging checked. |
| Tue 14:03 | Sold | −1 | Register 2 · shift 41 Sale S-20931; age verified by scanned ID; compliance gate passed. |
| Tue 14:41 | Sold | −2 | Register 1 · shift 40 Sale S-20957. |
| Wed 06:00 | Counted | 54 counted | J. Walker (inventory) Cycle count, vapes. Ledger expected 57: variance −3 → finding SA-002. |
| Wed 09:20 | Adjusted | −3 | M. Chen (manager) Investigation INV-118 approved: three units found damaged in the back stock and written off with photos (SHA-256 on file). |
Illustrative ledgerA fictional package on a fictional dispensary. The event names are the 25 the ledger records; the people, sales and quantities are made up.
The states a package can be in.
The target lifecycle the platform is built toward, and where each state stands in the code today. Storefront and delivery states arrive with those modules; until then they are shown as roadmap, never as live.
Available
AvailableAccepted at the dock and sellable; a unit on hand.
In the code today as: Accepted — sellable, unit on hand
Reserved
PlannedHeld for an order placed on the storefront, so the shelf never promises stock twice.
Arrives with Smoke Alarm Storefront; no state exists for it yet.
Sold
AvailableA completed sale at the register; the package is depleted when its last unit goes.
In the code today as: Sold out
Delivery assigned
PlannedA prepaid order picked, packed and put on a run.
Arrives with Smoke Alarm Delivery; no state exists for it yet.
Driver custody
PlannedThe driver has scanned the package out; a failed delivery returns it, reconciled.
Arrives with Smoke Alarm Delivery; no state exists for it yet.
Quarantined
AvailableIn inventory, not sellable, with the warning that put it there; on hold while a person inspects it.
In the code today as: Quarantined, On hold, unit quarantined
Return pending
AvailableA vendor return has been requested and the package waits to leave.
In the code today as: Return to vendor pending
Returned
AvailableBack with the vendor, the claim recorded.
In the code today as: Returned to vendor
Recalled
AvailableA recall or a failed lab test blocks the package from sale.
In the code today as: Recalled, Failed lab test
Expired
AvailablePast the expiration date the label, the vendor document or the state system gave.
In the code today as: Expired
Destroyed
AvailableDestruction requested, then recorded, with its reason.
In the code today as: Destruction pending, Destroyed
Also carried today, before a package becomes inventory: Awaiting receipt.
- Available
- Available features still require store setup and authorized data. This is not a connected-account status.
- Planned
- Not available yet.
Append-only, attributed, timestamped.
A movement is never edited. A corrected count is a new line that points at the one it corrects; a write-off carries the approval that allowed it; a sale carries the transaction that caused it.
Who, when, why
Every entry names the person or the register that recorded it, the moment, and the reason. Nothing is deducted from inventory automatically without a record saying why.
Approvals attached
An adjustment with no approved correction behind it is itself a finding (SA-018). The investigation that approved a write-off is linked from the line.
Reconciled against Metrc
Expected on hand from receipts, sales and movements is one of the four sources Audit Shield Reconcile compares. The ledger is checked, not trusted.
The 25 events the ledger records.
From the manifest to destruction, each event is a named type with its own meaning, so a report can be read without a glossary and a filter never guesses.
- 01Manifest createdMANIFEST_CREATED
- 02Manifest receivedMANIFEST_RECEIVED
- 03ScannedPACKAGE_SCANNED
- 04AcceptedPACKAGE_ACCEPTED
- 05Partially acceptedPACKAGE_PARTIALLY_ACCEPTED
- 06RejectedPACKAGE_REJECTED
- 07QuarantinedPACKAGE_QUARANTINED
- 08Put on holdPACKAGE_ON_HOLD
- 09ReleasedPACKAGE_RELEASED
- 10RecalledPACKAGE_RECALLED
- 11ExpiredPACKAGE_EXPIRED
- 12Failed lab testLAB_FAILED
- 13SoldSOLD
- 14Sale voidedSALE_VOIDED
- 15Returned by customerRETURNED
- 16AdjustedADJUSTED
- 17TransferredTRANSFERRED
- 18Destruction requestedDESTRUCTION_REQUESTED
- 19DestroyedPACKAGE_DESTROYED
- 20Vendor return requestedVENDOR_RETURN_REQUESTED
- 21Returned to vendorVENDOR_RETURNED
- 22Sold outPACKAGE_DEPLETED
- 23CountedPHYSICAL_COUNT
- 24Reported to MetrcMETRC_REPORTED
- 25Metrc report failedMETRC_REPORT_FAILED
Full counts set the baseline. Cycle counts keep it honest.
This is how a store actually counts: one full count to set the baseline, then category-by-category cycle counts and recounts in between. Smoke Alarm reads them the same way.
Full count
Every package at the location. It becomes the anchor: the latest full count and everything after it speak for the shelf.
Cycle count
A category or an area. For each package the most recent count that covered it wins, so a small cycle count never erases the figure for the packages it did not touch.
Recount
One package, checked again during an investigation. A recount that matches clears the finding; one that does not sharpens it.
Counts are scanned with a phone camera, a USB or Bluetooth scanner, or entered by hand. A count is a ledger event with the counter’s name; it never changes a quantity by itself. A variance becomes a finding for a person to resolve.
The identifier on the shelf is checked against the record.
A Metrc Retail ID QR code or a package tag scanned at the dock, the count or the register must resolve to the package the record names. One that does not is an identifier mismatch, one of the seven discrepancy categories, and never a silent match.
One package, one tag, one product
A tag listed twice, a tag already in inventory, or a tag the POS files under a different product than the ledger does, are each their own rule (SA-005, SA-019, SA-020) and their own finding.
Every licence, its own inventory
AvailableEach licensed location keeps its own packages, counts and findings. Owners see the whole operation; staff see only the locations they are given.
Every package and unit carries a state; every movement is an attributed, timestamped entry that is never rewritten.
The four-source comparison that checks all of this is on Audit Shield Reconcile.
Bring one register close.
We compare your ledger with your POS export and your latest count on the simulated store, and show you where the states disagree.