Compliance explainer
WSLCB compliance: coded gates vs operator-handed
WSLCB compliance is the term every cannabis-POS website uses. It means two different things depending on who's saying it. Either the platform refuses the action when the rule is broken — or the platform documents the rule and hands enforcement back to the operator. Both can technically be called 'compliant.' Only one keeps you from a $5,000 fine when a budtender forgets at 9:55pm on a Saturday.
The two definitions, side by side
| Approach | What it does | Risk model |
|---|---|---|
| Documentation-only | Lists the rule in a manual / training module / KB article | Operator carries 100% of enforcement risk |
| Coded gate | Refuses the action at the platform level | Platform carries the enforcement load; operator carries the audit trail |
Both call themselves 'WSLCB-compliant' on the website. Both are technically truthful. The difference shows up at 9:55pm on Saturday when a budtender about to ring up an under-21 sale either gets an audit-logged refusal-screen — or doesn't.
Five gates that should be coded, with WAC citations
Not every WSLCB rule needs a gate — some are operator-side judgment calls (advertising decisions, hiring criteria, security planning). But the five below are mechanical enforcement points where a coded gate is straightforward and documentation-only is a known failure mode.
- Sale-to-minor (WAC 314-55-079). The age-21 verification has to fire on every transaction with no soft-fail path. Manager override exists, requires PIN + reason + audit-log row. Coded gate refuses to add a flagged item to cart until ID is scanned + birth-date computed + 21+ confirmed.
- Industry-discount re-verify (WAC 314-55-095). Industry-discount eligibility lapses every 90 days. Documentation-only puts the burden on the budtender to remember. Coded gate refuses the discount until the customer's last-verified date is < 90 days old.
- Lab-test passthrough (WAC 314-55-079 5% rule). Retailers can pass through 5% of lab-test cost to consumers. Documentation-only says 'set this on each product.' Coded gate computes the passthrough at line-item time, validates the 5% ceiling, refuses any markup beyond it.
- Surveillance retention (WAC 314-55-082). 30+ days of video retention required. Documentation-only puts a manager's spreadsheet between you and an inspection. Coded gate runs a nightly probe of the DVR/NVR retention window, writes an incident the moment retention drops below threshold.
- Manager-override audit (WAC 314-55-095 record-keeping). Any manager-PIN override on a coded gate must write an audit-log row with actor + timestamp + reason. Documentation-only says 'managers should document overrides.' Coded gate refuses the override until the reason field is filled in — no shortcut path, no 'reason: see notes.'
What 'documentation-only' looks like — when it fails
Documentation-only compliance fails in predictable patterns. Across operator forums and years of WSLCB inspection experience, the patterns are remarkably consistent.
- The new-hire pattern. A budtender who started 3 weeks ago hasn't internalized rule X yet. The training module exists; the rule was covered in onboarding; the actual enforcement at the register is muscle memory the new hire hasn't built. A coded gate works on day 1; documentation only works on day 91.
- The end-of-shift pattern. Last sale of the night, manager already in the office counting cash. Budtender takes a shortcut they wouldn't take at 2pm. Documentation says 'no shortcuts.' Coded gate doesn't permit the shortcut.
- The relationship pattern. Customer is a regular. Budtender wants to do them a favor — skip the ID re-check, apply a discount that's 95 days old. Documentation says 'no exceptions.' Coded gate refuses the exception.
- The rule-change pattern. WSLCB updates a rule via Implementation Letter (IL). Documentation update has to land in the SOP binder + the training module + the operator chat group. Coded gate updates once, ships once, applies everywhere.
When documentation IS the right answer
Not everything should be a coded gate. Some rules are inherently operator-judgment. Trying to code those creates platform brittleness without a compliance gain.
- WAC 314-55-155 advertising rules. Advertising decisions involve content judgment. The platform can flag risky language (efficacy claims, medical-advice language) but can't make the final call.
- Premise-security planning. WAC 314-55-082 requires the operator to have a security plan; the platform can hold the plan + verify retention windows, but the security framework itself is human-designed.
- Hiring + termination decisions. Manager-write-up assistant (per the v0.38 guide) helps document — but the decision to hire, write up, or terminate is a human responsibility.
- Customer service exception calls. When a customer has a legitimate edge case the rule doesn't anticipate, the operator handles it. The platform should make the exception easy to log; the platform should not pretend it can decide.
The audit-trail compromise
The cleanest line: code the gate where the rule is mechanical, document where it's judgment-based, and audit-log everything either way. WSLCB inspectors aren't asking 'did you have a manual.' They're asking 'show me the trail of every override in the past 36 months.' If you can produce that in 30 seconds, you pass; if you can't, you don't.
Takeaways
- 'WSLCB-compliant' means two different things: documentation-only (operator carries enforcement risk) vs coded gate (platform refuses the action)
- Five gates that should be coded: sale-to-minor / industry-discount re-verify / lab-test passthrough / surveillance retention / manager-override audit
- Documentation-only fails in 4 predictable patterns: new-hire muscle memory / end-of-shift shortcuts / relationship favors / rule-change propagation lag
- Documentation IS right for judgment-based rules: advertising content, security framework, hiring decisions, customer-service exceptions
- The audit trail is the unifying answer — code where mechanical, document where judgment, log everything either way
Frequently asked
- When a POS says it's 'WSLCB-compliant,' what am I actually getting?
- That phrase means one of two different things. Documentation-only compliance lists the rule in a manual, training module, or KB article and leaves the operator carrying all the enforcement risk. A coded gate refuses the action at the platform level when the rule is broken, so the platform carries the enforcement load while you carry the audit trail. Both can truthfully call themselves compliant, but only the coded gate stops a budtender from ringing up an under-21 sale at 9:55pm on a Saturday.
- Which compliance rules should actually be coded into the platform versus left to staff to enforce?
- Five mechanical enforcement points should be coded gates: sale-to-minor (WAC 314-55-079), industry-discount re-verify every 90 days (WAC 314-55-095), lab-test passthrough at the 5% ceiling (WAC 314-55-079), surveillance retention of 30-plus days (WAC 314-55-082), and manager-override audit logging (WAC 314-55-095). Rules that involve human judgment should stay documentation-based instead: advertising content decisions (WAC 314-55-155), the premise-security framework, hiring and termination calls, and customer-service exception cases. Trying to code judgment-based rules creates platform brittleness without a compliance gain.
- Why does documentation-only compliance keep failing in practice?
- It fails in four predictable patterns. A new hire hasn't built the register muscle memory yet, so a coded gate works on day 1 while documentation only works on day 91. At end of shift a budtender takes a shortcut they wouldn't take at 2pm, and with a regular customer they want to do a favor and skip a re-check or apply a stale discount. And when WSLCB updates a rule via Implementation Letter, a documentation change has to land in the SOP binder, the training module, and the operator chat, whereas a coded gate updates once and applies everywhere.
Related guides
Ready to talk through your migration?
30-minute demo. We end by quoting the cutover from your current setup — fixed scope, no hourly games.