Multi-location operations
Compliance evidence infrastructure for operators with more than one shelf.
One location can hold its compliance record in a binder and a good memory. Ten cannot. HempDash keeps the evidence behind every product, lot and certificate connected, so the answer to a regulator's question does not depend on which store was asked.
Check. Prove. Respond. At every location.
The operating model does not change with scale. What changes is that no single person can hold it in their head any more, and the cost of a gap moves from one shelf to all of them.
- 01
Check
Evidence is reviewed against dated requirements before a product reaches a shelf or an online catalogue — the same requirements, applied the same way, whichever location received the shipment.
- 02
Prove
Which product, which lot, which certificate, which record, and what was associated with what at the time. Reconstructing that months later from invoices and inboxes is where multi-location operators actually lose.
- 03
Respond
When a notice arrives or a lot is recalled, the question is which locations are affected and what evidence supports the answer. That is a query against a connected record, not a phone tree.
Others store compliance files. The chain is what makes them answerable.
A folder of PDFs is not an evidence chain. The distinction is whether each link knows the next one, so that a question entering anywhere can be followed to the end.
- 01
Vendor
Who supplied it, and under what licence.
- 02
Product
The item as you catalogue and sell it.
- 03
Lot
The specific batch that arrived, kept distinct from the product.
- 04
COA
The certificate covering that lot, with its own dates.
- 05
Requirement
The dated rule the certificate is read against.
- 06
Finding
What the review concluded, per requirement, at that time.
- 07
Record
The retained result, still readable when the question is old.
- 08
Response
The notice, recall or audit answer assembled from all of it.
Every link is a real relationship in the data model rather than a naming convention — a lot points at its certificate, not at a filename that resembles one.
Controls
What the platform enforces
The detail behind each of these, and the questions a security review asks next, are on the security page.
Read the security and procurement record →- Defined roles, one source of truth
- Access is governed by defined roles rather than per-user toggles. The specifics render here once the current evidence for them is on record.
- Your records stay yours
- Records are scoped to the organization that owns them. The specific enforcement statement renders here once it has been observed in production.
- Nothing deletes the evidence
- Compliance evidence is kept rather than rotated away. The retention schedule renders here once the current evidence for it is on record.
It goes beside your point of sale, not through it
HempDash does not replace your point of sale and does not integrate with one. There is no Cova, Dutchie or Shopify connector — a rollout does not touch the system your staff ring sales on, and does not wait on an integration project before it is useful.
Your systems
- Point of sale
- Ecommerce
- Spreadsheets
- Lab portals
HempDash
- Products and lots
- Certificates and findings
- Retained records
- Notices and recalls
Who asks
- Inspectors
- Buyers and partners
- Your own compliance lead
How a rollout actually goes
This is the sequence, not a timeline. Anyone quoting you a go-live date before seeing your records is guessing, and the number of locations matters less than the state of the paperwork behind them.
- 01
Scope against your own records
One real product, one real certificate, one real gap. Before anything is configured, both sides find out whether the evidence you hold is in a state the system can work from.
- 02
Set the policy centrally
Which requirements apply, who reviews what, and which roles exist. Decided once, for the organization, rather than negotiated per store.
- 03
Bring locations on in waves
Locations are added in groups rather than all at once, so a problem in the record-keeping surfaces on the first wave instead of across the estate.
- 04
Let the locations operate
Day-to-day work stays local. What is centralised is the policy and the record, not the operating.
- 05
Rehearse the bad day
A recall drill and a notice walkthrough, before you need either. The point of the record is what it does under pressure.
Before you go further
What HempDash does not do at enterprise scale
If any single line below is disqualifying for you, it is better learned here than in a security review. None of it is on a promised roadmap date, because publishing a date we have not committed to would be the same failure as publishing a capability we do not have.
- No single sign-on
- No SAML, no OIDC federation, no SCIM provisioning. Accounts are managed in HempDash. For an organization that provisions everything through its identity provider, this is a real gap today.
- No security certification
- No SOC 2, no ISO 27001, no third-party attestation to send with a questionnaire.
- No portfolio rollup view
- Locations, products, lots and certificates are records you work with. There is no executive dashboard aggregating them across an estate.
- No point-of-sale integration
- Nothing connects to Cova, Dutchie, Shopify, Treez, BioTrack or LeafLogix today.
- No published availability target
- Scale and Enterprise carry contractual service terms. A live service-status page exists for the vendor platform, but it reports current health only — there is no uptime figure, no incident history, and no availability target, so none is implied.
- No customer references yet
- HempDash has not yet run a full compliance cycle with a live retailer. There are no case studies, no logos and no customer metrics on this site, because there are none to report.
Bring one real product and one real certificate.
A scoping session works from your records rather than a slide. Thirty minutes is usually enough to tell whether this is worth either side's time — including when the answer is no.