Florida depends on integration quality more than most cannabis markets, because the state traceability layer is largely API-driven rather than a regulator-facing operator screen. An internal seed-to-sale system is considered fully integrated with the Department's system only when it establishes real-time connectivity through an API. There is no state-side interface where an operator can browse what was reported the way they can in some other markets.

What "no state UI" changes

When you can't log into a state screen to confirm what was reported, your only visibility comes through the integration's own tools: receipt audits, package journals, sync-level review screens, and manifest detail. In Florida those tools are the audit surface, so a reconciliation program has to treat the vendor's audit features as primary evidence. There is no second window onto the state record.

Two implementation details that matter

The External Package ID field

Some Florida integrations let an operator keep existing local Package IDs on physical labels while storing the BioTrack 16-digit identifier in an External Package ID field. That preserves on-package labels during a migration and gives a workbook both the local and the state identifier to join on. Any reconciliation that crosses between shop-floor labels and state records depends on that mapping existing and being correct.

MMUR read-only after integration

At least one platform makes the MMUR read-only once the BioTrack STS integration is live, posting dispensations through BioTrack instead of through separate manual MMUR actions. Platforms handle this differently, but the pattern is one to copy on purpose. Once retail teams get used to fixing things later in a second system, the records start to disagree, and every place a correction can be hand-entered is one more way for that to happen.

Behaviors to document for your deployment

  • Repost timing. A reposted receipt appears under the repost date, not the original, which creates an audit-date mismatch. Check this before you re-post anything.
  • Sync-level corrections. Integration-audit corrections can cause damage if you apply them without understanding the root cause first.
  • Sale-post timing. Find out whether sales post in real time or on a delay. Timing discrepancies tend to show up in that window.

A vendor due-diligence checklist

Public Florida operator documentation is stronger for some platforms than others. Where it's thin, demand documented proof in the vendor's Florida material or approved implementation docs for each item below. Anything undocumented can become an audit blind spot:

  • Package-level identifier mapping (local ID and the 16-digit state ID)
  • Sale-post timing and real-time behavior
  • Void and refund behavior, including inventory effect
  • Manifest handling for internal transfers and delivery
  • Order and route mapping into the MMUR
  • MMUR integration method (and whether it becomes read-only)
  • Error-log location and retry logic

Where this leaves you

In an API-only state, the integration is the compliance layer, which means the vendor's audit tools are the only evidence you have. Document how your own deployment behaves before you need the answer for an inspector.