METRC Ghost Inventory: Why Your POS and the State Disagree

Amelia Gagne · · 9 min read
Dispensary inventory counter with POS tablet, RFID scanner, tagged jars, and reconciliation paperwork under gold and magenta light

TL;DR: "Ghost inventory" is what operators call product that exists in one system but not the other: stock your POS shows that METRC does not, or physical product that no longer matches the state's tag records. Regulators call it a discrepancy, and most of the time it is an innocent operational artifact: a sale that failed to sync, an unlogged sample, a moisture-weight change, an untagged package. The state does not grade on intent. An unexplained gap between your physical count and METRC is treated as a possible diversion until you prove otherwise. The fix is not fear. It is process: daily reconciliation, the correct METRC adjustment mechanism, and an authorized, well-built integration engineered to sync reliably.

Seeing numbers that do not line up between your POS and METRC? Kief Studio is a Metrc-authorized integrator. Talk to our team and we will help you find where the drift starts and close it.

The U.S. legal cannabis industry sold roughly $30 billion in 2024 (Vangst / Whitney Economics; corroborated by the MJBiz Factbook), and nearly every one of those transactions had to be mirrored, within hours, into a state track-and-trace system called METRC. Run a licensed operation and you effectively keep two sets of books that are supposed to agree: the POS you use all day, and METRC, the state's system of record. When they stop agreeing, you get ghost inventory. Here is exactly why the two drift apart, what it risks, and how to stop it, without the doom pitch.

In this article

What "ghost inventory" actually means

METRC (Marijuana Enforcement Tracking Reporting and Compliance) is the government-mandated seed-to-sale track-and-trace system that state regulators contract with. Metrc built the country's first cannabis track-and-trace system with Colorado regulators, and today it is the mandated platform in more than 20 states and roughly 29 jurisdictions (Metrc), which makes it the compliance backbone for most of that $30 billion market. It uses RFID tags where "each tag is embedded with a unique chip that carries coded regulatory information" (Metrc).

You do not work inside METRC all day. You work inside your POS, and it syncs to METRC in the background. "Ghost inventory" is the industry term for what happens when those two records, plus the physical product in your building, stop matching. Regulators do not use that phrase. They call it a discrepancy: any unexplained difference between your physical inventory and your track-and-trace records, whether that is missing units, extra units, mismatched weights, or product that was received but never tagged. A compliant operation keeps three numbers aligned every day.

Mermaid diagram: physical count, POS, and METRC feed daily reconciliation; match is compliant; gap is ghost inventory fixed with package adjustment
The three ledgers a compliant cannabis operation must keep aligned every day: physical count, POS, and METRC. A gap is ghost inventory until you correct it at the source.

Why your POS and METRC drift apart

Almost every discrepancy comes from one of a few ordinary causes. METRC's own adjustment reason codes are the clearest evidence of what regulators formally recognize (Ohio DCC guidance):

  • Manual re-entry error. METRC has a "Data Entry Error" reason code specifically to correct records that conflict with the physical package. Hand-keyed counts and data-entry lag are a leading source.
  • POS to METRC sync failures. A single sale or transfer fails to post, nobody catches it, and within a week there are several more. Operations that rely on periodic syncs or manual reconciliation are the most exposed.
  • Unreported adjustments. Waste, samples, spoilage, and moisture gain or loss all change your real count. METRC has reason codes for each. If it is not logged, the systems diverge.
  • Untagged or mis-tagged packages. Product received but never entered, or tagged incorrectly, is a discrepancy the moment it hits your shelf.
  • Unit-of-measure mismatches. METRC records weight, volume, or count depending on the activity (4 CCR 15049). A 700mg item that rings out as a 590mg item is a real, documented dispensing mismatch.
  • Latency, throttling, and outages. METRC's v2 API enforces rate limiting and object limiting, so aggressive polling gets throttled (Metrc API docs). When METRC itself is slow or down, you are still responsible for reporting, so your software has to queue and catch up.

Notice what is not on this list: intent. The state does not distinguish an honest sync gap from deliberate wrongdoing until an investigation says so, and the license holder is responsible for accuracy even when a third-party POS did the work.

That same "two systems that must agree" pattern shows up far beyond cannabis. It is the core of compliance data integrity across regulated industries, from pharma serialization to food traceability to device UDI databases. Ghost inventory is simply the cannabis face of a universal integration problem.

Kief Studio brand card: custom builds for websites, apps, and the systems your business runs on
Authorized integrations are custom systems work, not a checkbox plugin. Kief Studio builds the POS-to-state sync so the operator keeps the keys and the numbers stay boring.

What is actually at stake

Here is the part that makes ghost inventory more than a bookkeeping nuisance. An unexplained physical-versus-METRC gap can be read as possible diversion to the illegal market, which turns a routine audit into a citation or a hold. The recording rules are strict and specific, and they vary by state. In California, activities such as receiving, destruction, packaging, testing, and sale must be recorded in track-and-trace within 24 hours of occurrence, and any package adjustment must include a written description explaining the reason (4 CCR 15049). Colorado goes further, requiring licensees to reconcile all on-premises and in-transit inventory in METRC at the close of business every day (1 CCR 212-3, Rule 3-805).

Regulators actively police adjustments. Ohio's Division of Cannabis Control states plainly that it "will monitor Metrc to ensure licensees comply," and that misusing a package adjustment "may result in retesting, administrative hold, destruction of product, or further action" (Ohio DCC). The takeaway is not to be afraid. It is to be accurate: an unresolved discrepancy is a compliance failure on its own, so you want to catch and correct it before an inspector does.

Accuracy is also a growth lever. When inventory and compliance data are trustworthy, the rest of the digital stack can do its job: SEO that actually reflects what you sell, local search that matches real stock, and marketing that does not promise product the state does not show. That is the same discipline behind our MetroWest contractor growth work and the broader LTFI "get found, get chosen" playbook for regulated and home-services operators.

Kief Studio brand card highlighting 400 percent client-reported revenue growth after ERP SEO and digital strategy work
Client-reported 400% revenue growth after ERP, SEO, and digital strategy work. Clean operational data is what makes growth numbers defensible, not decorative.

How to fix a discrepancy the right way

When you find a gap, matching the mechanism to the situation matters (Ohio DCC guidance):

  • Package Adjustment. Use it when a transaction already occurred or you find a discrepancy during an audit. Always select the correct Reason code and write a Notes entry explaining what happened, referencing any external waste or dispensing log.
  • Inventory Reconciliation reason code. Use it when an audit surfaces a discrepancy and the package needs adjusting to match reality.
  • Discontinue. Use it only for a package created in error that has no transactions yet. It is permanent, and discontinued tags cannot be recovered.

Just as important is what not to do: do not use a package adjustment to move product between packages, to re-package, to add plant material, or to transfer to another facility. Those have their own correct paths, and misusing an adjustment is exactly what regulators watch for.

How to stop ghost inventory before it starts

Prevention is a process problem and an engineering problem. On the process side:

  • Reconcile daily. Your physical count, POS, and METRC should match every day, not the week before an inspection. In Colorado it is the law; everywhere else it is simply the most reliable way to catch a broken sync while it is still one line, not thirty.
  • Log adjustments at the source. Every waste event, sample, and dispensing correction gets recorded when it happens, with the reason and a note, so the paper trail already exists if you are asked.
  • Write SOPs. Define who may adjust, when, and how, and require a second set of eyes on high-value corrections.

On the engineering side, this is where an authorized, well-built integration earns its keep. METRC's v2 API exposes the primitives a sync must use correctly (Metrc API docs): a Last Modified filter for incremental sync, record matching to reconcile deterministically, proper handling of server responses, and respect for rate and object limits with pagination. A resilient integration builds on those with idempotency so a retried sale is never double-posted, retry with backoff, an error queue for failed syncs, an offline queue that flushes when METRC comes back, and an immutable log of every adjustment.

That is the kind of automation we build on LTFI, the same secure-by-construction discipline Brian S. Gagne documents for operators who want systems that still run at 3am, and the same integration craft behind our work on kief.dev. When the dependency graph itself is the attack surface (agents installing packages, CI pulling lockfiles), we point teams at free tooling like Vekt (22 lockfile formats, 12 ecosystems) and our open-source AUR security scanner for Arch package risk analysis. Different domain, same rule: unknown stays untrusted until the record proves clean.

Why an authorized, well-built integration matters

METRC runs a gated approval program. To work with the API, an integrator receives training, signs Metrc's API user agreement, and demonstrates its ability to operate within the state's licensing requirements (Metrc). Authentication uses both a vendor API key and a user API key, scoped per facility license, and approval is granted per state, not nationally. Because the license holder is always responsible for the data, an authorized, well-engineered sync is your first and best line of defense against ghost inventory.

Kief Studio is authorized by Metrc to build on its API. We build these systems the way we build everything: secure, documented, and boring in the best way, so your numbers just match. The same team runs continuous site protection with Aegis, growth campaigns for local contractors, and structured cloud reviews via Cloud Health Sec when your risk lives in AWS, Azure, or Google Cloud instead of a dispensary vault. One stack of operators. Different systems of record. Same discipline.

Frequently asked questions

What is ghost inventory in a cannabis dispensary?

Ghost inventory is product that exists in one system but not the other: POS stock that METRC does not show, or physical product that does not match state tag records. Regulators call it a discrepancy: any unexplained difference between physical inventory and track-and-trace records.

Why don't my POS and METRC numbers match?

Most often a sale or transfer failed to sync, or there was a data-entry error, unreported waste or moisture loss, an untagged package, a unit-of-measure mismatch, or a METRC outage or API throttle. METRC's own reason codes map directly to these causes.

How often should I reconcile POS to METRC?

Daily is the defensible standard, and in some states it is required. Colorado mandates close-of-business reconciliation every day (1 CCR 212-3, Rule 3-805). California requires qualifying activities recorded within 24 hours (4 CCR 15049).

Can I be penalized for an honest discrepancy with no theft?

Yes. Regulators generally treat an unresolved discrepancy as a compliance failure regardless of intent. Consequences can include administrative hold or further action (Ohio DCC). Catching and correcting gaps early matters.

How do I fix a discrepancy in METRC?

Use a Package Adjustment with the correct state-approved reason code and a Notes entry explaining what happened. Use Discontinue only for an error package with no transactions yet, since it is permanent. Do not use an adjustment to move, re-package, or transfer product.

What is METRC validation, and what does Kief Studio claim?

A Metrc validated integrator has signed Metrc's API user agreement, completed training and a sandbox assessment, and been added to a state's validated integrator list (Metrc). Kief Studio is Metrc-authorized and builds well-engineered syncs so discrepancies do not become your daily job. We only claim the credential we can substantiate.

The bottom line

Ghost inventory is rarely a theft story. It is a sync-and-process story, and it is solvable. Reconcile daily, log every adjustment with the right reason code, use the correct METRC mechanism to fix gaps, and run an authorized, well-built integration engineered to stay in sync. Do that and the three numbers (physical, POS, and state) simply agree, which is exactly where you want to be when an inspector walks in.

Kief Studio is a Metrc-authorized integrator that builds secure, reliable seed-to-sale integrations and the automation around them on LTFI. For the operator view of how we think about people, systems, and growth, see Amelia S. Gagne, Brian S. Gagne, and HxHippy. For prompt craft that makes the AI layer of those systems reliable, see Qurtoo. If your POS and METRC keep disagreeing, talk to our team. First conversation is free. No commitment.