Skip to content

KB-005

FM-01

Fact-verified July 21, 2026 · Owner review

Fact-verified July 21, 2026 · Owner review

5 min read

Garrit Hunt

Oregon Cannabis Security

A rule-aware operating framework for turning OLCC security requirements into daily readiness.

A rule-aware operating framework for turning OLCC security requirements into daily readiness.

Oregon cannabis operators need to meet current OLCC security rules and manage the people, evidence, decisions, and review practices that keep those controls ready.

Oregon cannabis operators need to meet current OLCC security rules and manage the people, evidence, decisions, and review practices that keep those controls ready.

VSG Knowledge Brief KB-005 cover with an Oregon-focused security readiness grid.
VSG Knowledge Brief KB-005 cover with an Oregon-focused security readiness grid.

FULL-READING VSG INFOGRAPHIC

VSG-KB005-COVER-01

Opening thesis

Oregon cannabis security has two layers that should not be confused. The first is the legal baseline established by current Oregon Liquor and Cannabis Commission rules. The second is the operating discipline an organization uses to keep required controls effective, evidence available, and decisions accountable. This brief identifies selected rule requirements, then labels VSG recommendations separately. It is operational guidance for owner review, not legal advice; licensees should confirm current obligations with the OLCC and qualified counsel.

What the rules establish

Oregon’s recreational-marijuana rules require licensees to maintain security plans and surveillance controls appropriate to the licensed premises. The current rules address camera coverage, recording, retention, access, premises changes, incident notice, and related records. Requirements vary by license type and facility condition, so operators should work from the current rule text rather than a remembered checklist.

OAR 845-025-1440 identifies the required camera-coverage areas and placement outcomes, including applicable ingress and egress points. OAR 845-025-1450 separately governs recording and storage. It requires at least 90 calendar days of surveillance recordings and at least 30 days of off-site backup for recordings of the surveillance room or surveillance area. An equipment failure or system outage lasting 30 minutes or more must be reported to the Commission within 48 hours.

OAR 845-025-1230 requires a daily log of employees and permitted visitors who perform work on the licensed premises, subject to the rule’s stated exceptions. It also addresses identification, escort, and record details and requires the daily log to be retained for at least 90 days. Under OAR 845-025-1160, theft of marijuana items or money from the licensed premises must be reported in the prescribed manner as soon as reasonably practical and no later than 24 hours.

These are legal requirements, not VSG-created standards.

The January 2026 motion-detection option

The amendment to OAR 845-025-1450 effective January 1, 2026 allows a licensee to satisfy the rule’s continuous-recording requirement either with cameras that continuously record and store all recordings or with a qualifying motion-detection camera system. The option is conditional.

For the motion-detection path, the system must use video analytics for monitoring, store system-recorded video, and allow searching and auditing of logs, including changes to sensitivity settings and camera activity. The licensee must record and store every interval in which motion is detected, including all time a person is present in a required coverage area. Sensitivity and triggering thresholds must prevent an interruption while a person remains in view, and all areas specified by OAR 845-025-1440 must be inside the zones of detection. The applicable retention and backup requirements still apply.

This does not create a universal rule that every camera may simply store short motion clips. The licensee must be able to demonstrate that the selected system and its configuration satisfy every applicable condition. OLCC Compliance Education Bulletin CE2025-07 should be reviewed with the rule during implementation.

Change control is part of security control

Material physical and security-system changes should not be treated as ordinary maintenance. OAR 845-025-1175 requires prior written Commission approval for specified material changes to a licensed premises, including covered security-system and surveillance changes. OAR 845-025-1400 likewise governs security plans and prior approval for changes addressed by that rule.

VSG recommends a formal change record before relocating cameras, altering detection zones, changing retention architecture, modifying limited-access boundaries, or revising a security plan. That record should identify the rule reviewed, the requested approval, the person authorizing the work, the implementation date, and the evidence that the final configuration matches what was approved. This documentation practice is a VSG recommendation; the underlying approval obligations come from the cited rules.

Move from installed to ready

Compliance describes required conditions. Readiness asks whether the organization can rely on them now. VSG recommends assigning a named owner for surveillance health, access records, incident notification, and approved changes. Operators should test representative video retrieval, confirm that timestamps and coverage remain usable, review who can enter limited-access areas, and exercise the notification path before an incident.

VSG also recommends reviewing exceptions together. A camera outage, a repeated visitor-log gap, and an unapproved layout change may appear in different records while pointing to one management problem. A recurring security review should connect those conditions, assign action, and verify closure. These practices are not presented as additional Oregon law. They are VSG’s operational-readiness doctrine for sustaining the legal baseline.

FIELD OBSERVATION

A compliant design can become unreliable through ordinary operational change. Equipment is moved, storage settings are adjusted, responsibilities shift, and temporary workarounds remain after the original issue ends. The weakness may stay hidden until an inspector, incident, or evidence request tests the system. A useful readiness review compares the approved plan, current configuration, actual staff practice, and retrievable evidence rather than assuming they still match.

NEXUS INSIGHT

For regulatory readiness, a client-authorized Nexus deployment is intended to organize rule references, review dates, approved changes, incidents, assigned actions, and evidence status into a human-led operating picture. Nexus should support—not replace—the licensee representatives, counsel, vendors, and executives responsible for compliance and operational decisions. It does not grant regulatory approval or make independent changes. Human owners remain responsible for interpreting requirements, authorizing work, reporting events, and confirming closure.