batchy://ops metrc v2 --:--:-- PT
METRC-v2 operations & compliance

METRC ops,
without the dread.

Batchy is the single-file platform that runs your cannabis distribution & manufacturing day — package tracking, fail-closed METRC writes, manifests, invoices, and a buyer portal — all audited, all in one place.

Single-file PHPSQLite0 dependenciesBluehost-ready
v2 · live Batchy — the friendly cannabis ops mascot
⛔ Writes fail-closed
⚗ Lab-gate enforced
❑ Outbox + audit
By the numbers

The whole METRC surface, covered.

0
METRC endpoints
0
Endpoint groups
0
Write endpoints
0/107
Tenant-isolation tests
0
PHP file
0
Vendor dependencies
Everything in the box

One file. The whole operation.

From the first METRC call to the last invoice, every part of the distro & manufacturing workflow lives in Batchy — nothing bolted on, nothing to integrate.

COMPLIANCE

METRC v2 integration

25 endpoint groups, 270 endpoints, environment-aware sandbox ⇄ production with facility-scoped credentials.

GATING

Writes fail closed

No live METRC write happens without a signer / date / document-hash authorization. High-risk, irreversible categories require a second-person approval.

AUDIT

Outbox & audit trail

Every write logs its authorization category, request/response hashes, a redacted response body, approval metadata, and operator notes.

INVENTORY

Inventory & packages

Package and inventory tracking that imports the official METRC “Condensed Inventory” XLSX and reconciles METRC qty vs. physical on-hand.

LAB GATE

Lab-testing sale gate

A package is only sellable once its test status is passed. Untested packages are blocked from invoices, pickers, the buyer menu, and the cart.

LOGISTICS

Transfers & receiving

A Transfers hub mirroring METRC licensed transfers, plus a receiving board: count / weigh-to-verify against the manifest with discrepancy flags.

PRODUCTION

Repackaging & batches

Turn bulk into retail children with finish-source and full lineage — the manufacturing side of the warehouse, tracked end to end.

ROUTING

Manifests + free routing

Build transport manifests with free OSRM routing on Manifest Assist — origin-to-stop directions without a paid maps key.

FINANCE
$

Invoices & A/R

Invoices plus a dedicated finance role with Accounts-Receivable reconciliation and a morning Order Queue.

CATALOG

Strains & guided items

Strains are first-class, with a merge-duplicates tool. The canonical name (Brand | Strain | Type | Weight) previews live and snaps back in one click.

B2B

Buyer / dispensary portal

A self-service B2B portal with its own session and login throttling — fully isolated from the staff app.

WEEDMAPS

Weedmaps catalog sync

A brand-aware importer that preserves your live Weedmaps external_id as the source of truth, minting a standardized SKU only as a fallback.

MENUS

MenuMaker

Public, tokenized, no-index menu pages — a shareable storefront menu without exposing the rest of your operation.

LOYALTY

Budtender appreciation

A loyalty program with hardened image / receipt uploads — validated and re-encoded on the way in.

MULTI-TENANT

Brands, org-isolated

Platform → organization → brand. Every read is brand/org-scoped and every by-id write authorizes its tenant. The IDOR class is closed, proven 107/107.

ADMIN

Admin tooling

Staff management, sensitive-action re-authentication, gzip SQLite backups with restore tests, and a Launch Status page.

The warehouse flow

Receive → test → repack → sell → reconcile.

Batchy was shaped on a real warehouse floor. The whole receive-to-cash loop is implemented end to end — each phase letter maps to a shipped capability.

PHASE D

Receive

Log an expected delivery, then count / weigh-to-verify against the manifest with discrepancy flags before it touches inventory.

PHASE C

Test

Submit for testing — Batchy computes the lab sample weight and an expected-pass date. Only passed packages become sellable.

PHASE E

Repackage

Split bulk into retail children with finish-source and lineage, so every child traces back to its parent package.

PHASE A·B

Name

Strains and items as first-class entities with guided creation, plus canonical-name drift repair that snaps names back to spec.

PHASE —

Sell

List to the buyer portal, the Weedmaps catalog, and tokenized MenuMaker pages — then cut invoices against on-hand stock.

PHASE F

Reconcile

A finance role closes the loop with Accounts-Receivable reconciliation and a morning Order Queue.

Built to deploy anywhere PHP runs

No Composer. No vendor lock-in.

Drop one file on shared hosting and load the page — the database creates itself. That's the entire install.

Runtime
PHP 8.0+ — a single index.php
Database
SQLite via pdo_sqlite, auto-creates on first request
Dependencies
No Composer, no vendor/ — Bluehost-friendly
Extensions
pdo_sqlite · curl · gd · fileinfo · sodium · mbstring · json
Hardening
Apache .htaccess at the edge
Routing
Free OSRM directions for manifests
bash — deploy
# 1 · drop index.php + .htaccess on the host
$ cp index.php /home/acct/public_html/portal/

# 2 · run it (db auto-creates on first hit)
$ php -S localhost:8000
→ batchy-private/data/batchy.db created
→ schema initialized · 0 deps

# 3 · that's the whole install.
$ open http://localhost:8000
Compliance by construction

Fail-closed, audited, tenant-isolated.

Batchy treats compliance as the default state, not a checkbox. Where it matters, it refuses to act rather than guess.

  • Secrets, the SQLite DB, logs and private uploads live outside the web root and outside version control.
  • .htaccess denies dotfiles, database/log/backup extensions, directory listing, and code execution inside uploads/.
  • METRC user keys are encrypted at rest; production writes are gated and fully audited.
  • Sensitive staff / admin / METRC actions require recent password re-confirmation; staff and portal logins are throttled.
  • Tenant isolation is proven by an automated harness — 107/107 — so one brand can never read or mutate another’s rows.
  • SQLite busy_timeout kills concurrent-write 500s; staff UI output is DOM-XSS escaped.
Fail
Closed
No auth · no write
Let's talk

Get a Batchy demo.

Tell us about your facility and what you're running today. We'll show you the receive-to-cash loop on real METRC data — sandbox first, no commitment.

✉ contact@batchy.co ⌂ Happy Travels LLC DBA Batchy · San Diego, CA ⏱ We reply within one business day
Request a demo// secure · csrf
0 / 4000

No account, no spam. Your note lands straight in our inbox.