Skip to content

ARTICLE

DIGEST

Access control that matches how a cannabis business operates

August 2, 2026

·

VSG Intelligence

·

5 min read

A reliable program connects each person, credential, zone, system, and review decision to a defined business need.

Access control is easy to reduce to card readers, locks, and badges. Cannabis operators need to know who is entering, what that person is allowed to reach, why the access is needed, and whether the permission still makes sense.

The most dependable programs connect physical access, digital accounts, job responsibilities, visitor handling, and management review. A card reader can enforce a rule, but management still decides who gets access, for how long, and who reviews exceptions.

Oregon rules require a cannabis license applicant to have an approved security plan before the pre-licensing inspection. Proposed changes to that plan require Commission approval before implementation. The rules define a limited access area as a building, room, or contiguous area where a marijuana item is present, apart from a retailer's consumer sales area. Camera coverage is required at entrances and exits, limited access areas, consumer sales areas, and other specified locations.

Those rules do not decide which roles belong in each area, how temporary access will work, who reviews exceptions, or how quickly permissions are removed when circumstances change. Oregon also requires employee and permitted-visitor identification, daily logs for specified work, and escorts for permitted visitors in limited access areas.

Start with the work

Build the access map around the work people perform and the assets they handle. Cultivation, processing, inventory storage, customer sales, surveillance equipment, information systems, and administrative records do not need the same permissions. Nor does every employee need the same path through a facility.

Assign an owner to each zone or system. Document the roles that need routine access, the circumstances that permit temporary access, and the person who can approve an exception. Keep life-safety and emergency-egress requirements in the design. Convenience should never create an uncontrolled route into a restricted area.

Manage credentials from issuance to revocation

Assign every badge and user credential to one person. Shared codes weaken accountability because an event log cannot show who used them. If another business system requires a service account, name an owner and restrict its use. Oregon's Cannabis Tracking System requires individual, nonshared user credentials and removal of access when authorization ends. New access should follow verified identity and an approved role. Job changes should trigger a permission review. Departures, lost devices, and expired contractor assignments should trigger prompt revocation.

Digital access deserves the same discipline. The Cannabis Tracking System, surveillance administration, alarm management, and business applications may expose different information or functions. Multi-factor authentication is useful for sensitive systems when the system supports it. NIST's zero trust guidance also supports granular, least-privilege decisions instead of broad trust based on location alone.

Pay attention to exceptions

Most successful entries need no follow-up. Review denied attempts, after-hours requests, doors held open, repeated overrides, inactive credentials, unusual administrative changes, and access that no longer matches a person's job. A single event may have an innocent explanation. A pattern may point to a training, process, maintenance, or supervision problem.

Review should be proportionate and privacy conscious. Collect what the business needs for security, compliance, and investigation. Limit who can see the records. Define retention and escalation rules. Before adopting biometrics, review enrollment, accuracy, data retention, privacy, and a workable non-biometric fallback.

A card reader can enforce a rule, but management still decides who gets access, for how long, and who reviews exceptions.

Operational standard

A cannabis operator should be able to answer these questions:

  • Is there a current map of controlled zones, assets, systems, and accountable owners?

  • Does each badge or user credential belong to one verified person, with separately owned and restricted service accounts where a system genuinely requires them?

  • Are permissions tied to a present job need and limited to the necessary actions?

  • Are visitors, vendors, and temporary workers handled through a documented process?

  • Do role changes and departures trigger access review and revocation?

  • Are denied attempts, overrides, and other exceptions reviewed on a defined schedule?

  • Can the business test its access process without compromising emergency exit or response needs?

Nexus insight

Nexus should help a reviewer compare approved access events, alarms, operating context, and incident records in one review queue instead of checking separate logs.

That picture still needs human judgment. The reviewer should be able to see the source, timing, uncertainty, and reason for a recommendation. The system should not suspend a worker, accuse a person, or change a sensitive permission on its own.

Work with VSG

VSG can help cannabis operators map access zones, review credentials, test visitor and revocation workflows, and document who owns each decision.

Sources