User Access and Permissions Management Flashcards
6 cards from real METRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 User Access and Permissions Management flashcards as text
In METRC, who has the authority to create new employee user accounts for a licensed facility?
Answer: The facility administrator assigned to that license in METRC
Facility administrators are responsible for managing user accounts within their licensed facility in METRC. This includes creating new accounts, assigning roles, and deactivating accounts for departed employees.
An employee leaves a cannabis company. What must the facility do in METRC?
Answer: Immediately deactivate the former employee's METRC account to prevent unauthorized access
Prompt deactivation of departing employees' METRC accounts is a critical security and compliance requirement. Failure to do so leaves the facility vulnerable to unauthorized transactions and creates liability for actions taken using the former employee's credentials.
Which METRC user role typically has view-only access and cannot create, edit, or delete records?
Answer: A 'Viewer' or read-only user role assigned by the facility administrator
METRC supports role-based access levels, including view-only access for users who need to see records for reporting or oversight purposes but should not be able to modify any inventory, transfer, or plant data.
Why is it a compliance risk for multiple employees to share a single METRC login?
Answer: It prevents the system from creating an accurate audit trail linking specific transactions to the individual who performed them
METRC maintains a transaction log that attributes every action to a specific user account. When employees share credentials, regulators cannot determine who performed a given action, undermining accountability and making audit responses very difficult.
A METRC facility administrator wants to allow a new budtender to process retail sales but NOT create or modify packages. What should they do?
Answer: Assign the employee a role with sales permissions only, limiting their access to the retail/sales module
METRC's role-based access system allows administrators to grant granular permissions. Assigning a role scoped to sales functions prevents accidental or unauthorized changes to inventory packages while allowing the employee to do their job.
What is the consequence of a facility failing to maintain accurate and current user access records in METRC?
Answer: The facility may face regulatory violations during an audit, as inactive or unauthorized accounts indicate a breakdown in internal controls
State regulators treat user access management as a compliance matter, not just an IT issue. Active accounts for former employees or uncredentialed individuals can indicate control failures and result in warnings, fines, or license sanctions.