METRC User Access and Permissions Management — Questions and Answers
Question 1: In METRC, who has the authority to create new employee user accounts for a licensed facility?
- The facility administrator assigned to that license in METRC (Correct answer)
- Any employee who has passed the METRC certification exam
- The state cannabis regulatory agency upon written request from the owner
- The METRC helpdesk after the employee passes an identity verification check
Correct answer: The facility administrator assigned to that license in METRC
Facility administrators are responsible for managing user accounts within their licensed facility in METRC. This includes creating new accounts, assigning roles, and deactivating accounts for departed employees.
Question 2: An employee leaves a cannabis company. What must the facility do in METRC?
- Immediately deactivate the former employee's METRC account to prevent unauthorized access (Correct answer)
- Transfer the employee's account to a new name and reassign it to the replacement hire
- Archive the account and retain it for 2 years in case of audit questions
- Notify the state regulatory agency and wait for official instruction before removing access
Correct answer: Immediately deactivate the former employee's METRC account to prevent unauthorized access
Prompt deactivation of departing employees' METRC accounts is a critical security and compliance requirement. Failure to do so leaves the facility vulnerable to unauthorized transactions and creates liability for actions taken using the former employee's credentials.
Question 3: Which METRC user role typically has view-only access and cannot create, edit, or delete records?
- A 'Viewer' or read-only user role assigned by the facility administrator (Correct answer)
- A newly certified employee who has not yet completed their first 90-day probationary period
- Any user who logs in from an unregistered IP address
- The state regulatory auditor account assigned to monitor the facility
Correct answer: A 'Viewer' or read-only user role assigned by the facility administrator
METRC supports role-based access levels, including view-only access for users who need to see records for reporting or oversight purposes but should not be able to modify any inventory, transfer, or plant data.
Question 4: Why is it a compliance risk for multiple employees to share a single METRC login?
- It prevents the system from creating an accurate audit trail linking specific transactions to the individual who performed them (Correct answer)
- METRC's software detects shared logins and automatically locks the account after the second user signs in
- Shared logins cause inventory reconciliation errors because METRC calculates stock levels per user
- State regulations require that login credentials be printed on the facility's posted license
Correct answer: It prevents the system from creating an accurate audit trail linking specific transactions to the individual who performed them
METRC maintains a transaction log that attributes every action to a specific user account. When employees share credentials, regulators cannot determine who performed a given action, undermining accountability and making audit responses very difficult.
Question 5: A METRC facility administrator wants to allow a new budtender to process retail sales but NOT create or modify packages. What should they do?
- Assign the employee a role with sales permissions only, limiting their access to the retail/sales module (Correct answer)
- Create the account with full permissions and instruct the employee verbally not to touch the package module
- Create a shared 'sales staff' login used by all budtenders to streamline the process
- Contact the state regulatory agency to request a restricted user license for the employee
Correct answer: Assign the employee a role with sales permissions only, limiting their access to the retail/sales module
METRC's role-based access system allows administrators to grant granular permissions. Assigning a role scoped to sales functions prevents accidental or unauthorized changes to inventory packages while allowing the employee to do their job.
Question 6: What is the consequence of a facility failing to maintain accurate and current user access records in METRC?
- The facility may face regulatory violations during an audit, as inactive or unauthorized accounts indicate a breakdown in internal controls (Correct answer)
- METRC will automatically suspend the facility's license until the user list is corrected
- The facility loses access to METRC reporting features until user records are reconciled
- There is no regulatory consequence for user management issues, as they are considered an IT matter
Correct answer: The facility may face regulatory violations during an audit, as inactive or unauthorized accounts indicate a breakdown in internal controls
State regulators treat user access management as a compliance matter, not just an IT issue. Active accounts for former employees or uncredentialed individuals can indicate control failures and result in warnings, fines, or license sanctions.
In METRC, who has the authority to create new employee user accounts for a licensed facility?