
Cannabis dispensary security is a defense-in-depth program engineered to satisfy state licensing regulations and defeat a criminal threat profile at the same time — continuous recorded video held for a state-defined retention window, credentialed limited-access zones, a compliant safe or vault, monitored intrusion and duress alarms, seed-to-sale inventory reconciliation, and, where the state requires it, licensed security officers. The specific thresholds vary by state and municipality; the doctrine beneath them does not.
No mainstream retail format carries the risk stack of a licensed cannabis dispensary. It stores a federally controlled substance, it frequently transacts in cash because the banking system keeps it at arm’s length, and it operates inside a licensing regime that lets a regulator inspect the premises and pull the license on a security finding alone. Layered on top is a violent-crime and organized-theft profile that few independent retailers ever confront. This guide is the national, evergreen framework for that problem — written for dispensary owners, multi-state operator (MSO) security directors, and the general counsel and compliance leaders who own the license risk. It sets out what legal-cannabis states have in common, where their rules diverge, why the cash exposure is structural rather than incidental, and what separates a program that survives an inspection from one that genuinely protects people, product, and the license across a portfolio of sites.
Why does cannabis force security and compliance into a single discipline?
Cannabis remains a Schedule I controlled substance under federal law, and that single fact radiates into every security decision an operator makes. It is why the banking sector treats the industry with caution, why states regulate the category far more tightly than ordinary retail, and why a security lapse is at once a criminal-exposure problem and a licensing problem. Two consequences dominate. First, because the proceeds of a federally illegal activity carry money-laundering exposure, most national banks and card networks limit or decline cannabis accounts, leaving many operators holding and moving cash that criminals know is present. Second, the license that authorizes the business is conditioned on meeting a detailed security code, so an unmonitored camera or an unsecured safe is not merely a vulnerability — it is grounds for a citation, a suspension, or revocation.
The practical effect is that security and compliance cannot be run as separate programs. Every control does double duty — it must defeat an adversary and satisfy a regulator — and the two audiences reward different things. A criminal is deterred by hardening he can see and defeated by hardening he cannot; a regulator is satisfied only by documentation that a control exists, functions, and can be produced on demand. Elite operators design for both from the outset and treat the published state minimums as the floor of the program, never its ceiling. That distinction — floor versus ceiling — is the most reliable single predictor of whether a dispensary is actually secure or merely inspectable.
What security controls do legal-cannabis states share, and where do they diverge?
Every legal-cannabis state publishes a security code as a condition of licensure. The specifics differ, but the categories are strikingly consistent. An operator standing up a new program — or auditing an existing one — should expect obligations across the areas below, and should always confirm the exact language of the governing state rules and any local ordinance, because thresholds vary and are revised often.
- Recorded video surveillance: continuous camera coverage of regulated activity — points of sale, back-of-house product and cash handling, entrances, exits, and the exterior — at a resolution high enough to identify individuals, with no blind spots where product or money changes hands.
- Footage retention: recordings kept for a state-set minimum before they may be overwritten. Retention windows differ markedly — some measured in weeks, others in months — so the number is one to confirm jurisdiction by jurisdiction rather than assume.
- Restricted / limited-access areas: rooms holding product or cash are closed to the public and open only to authorized, badged personnel, with any visitor signed in and escorted.
- Secure safe or vault storage: product and currency locked in a safe or vault meeting a specified standard — and often in a restricted room — particularly outside operating hours.
- Monitored alarms with duress capability: a professionally monitored intrusion system across the perimeter and interior, with panic/duress signaling at registers and back-of-house, and notification when the system or a camera fails.
- Credentialed access with logging: entry to secured areas individually authenticated and recorded, producing an auditable trail of who went where and when.
- Seed-to-sale track-and-trace: mandatory integration with the state’s inventory-tracking system so every unit is accounted for from intake to sale; the platform is state-chosen (Metrc is one widely used example, not a universal one).
- Security personnel where required: some states and cities mandate licensed guards during operating hours, and a subset require armed officers, each subject to that jurisdiction’s security-licensing and firearms rules.
What varies is not the categories but the thresholds — the exact retention period, the required resolution and frame rate, whether guards are mandatory and whether they may be armed, how a vault must be rated, and which activities must be recorded. That variation is precisely why a national operator cannot copy one state’s build into the next. What does not vary is the doctrine beneath the rules: the same deter, detect, delay, respond model that underpins any serious physical-security design, articulated for practitioners in the standards and guidance of bodies such as ASIS International. Read that way, a state’s security code is simply defense-in-depth written into administrative law.
How should you approach video surveillance and retention across states?
Video is the most exhaustively specified control in every cannabis regime and, not coincidentally, the one most often found deficient. States prescribe not just the presence of cameras but their behavior: a resolution and frame rate adequate to identify a face and an action, unbroken coverage of every regulated area, continuous rather than motion-triggered capture, an accurate synchronized timestamp, and a retention period long enough to be useful after the fact. Retention is the specification operators most often underestimate, because losses surface late — at a reconciliation, or when an investigator, insurer, or regulator asks for footage of an event weeks past. The defensible posture is to hold recordings for the longer of the legal minimum and your own inventory-reconciliation cycle, and — across a multi-state portfolio — to standardize that window at the strictest state’s level rather than juggle a different setting per site.
The deficiencies that generate citations and collapse investigations are rarely exotic. A camera drifts out of alignment or is quietly obstructed; a recorder stops writing without anyone noticing; footage rolls over before the retention window closes; the system clock wanders off real time and strips the evidentiary value from every frame; or the recorder sits somewhere any staff member can reach it and delete what it captured. Enterprise programs treat surveillance as evidentiary infrastructure rather than a compliance ornament — recorders locked down and access-controlled so an implicated insider cannot erase the record, continuously health-monitored so a fault raises an alarm instead of leaving a silent gap, and exported under a documented chain of custody when footage has to support a prosecution, a claim, or a regulatory response. That is the point at which physical security and investigations have to be engineered as one discipline.
How do you secure cash under Schedule I and the banking gap?
Cash is the structural vulnerability of the industry, and it is a policy problem as much as a security one. Because cannabis is federally prohibited, the institutions that might otherwise hold a dispensary’s deposits face Bank Secrecy Act obligations that make the relationship costly and cautious: the Financial Crimes Enforcement Network (FinCEN) expects banks serving marijuana-related businesses to conduct heightened, ongoing due diligence and file specific suspicious-activity reports, which many institutions decline to take on. Federal legislation intended to give state-legal operators reliable banking access — the SAFER Banking Act and its predecessors — has been debated for years without becoming law. Until that changes, an operator must plan around a plain assumption: meaningful volumes of cash will be held on site and moved off it, and the security program has to drive that exposure down rather than wish it away.
Controlling that exposure comes down to a few disciplines applied consistently across every shift and every location. Keep as little currency on the sales floor as the day’s trade allows, clearing registers into a drop safe the cashier has no ability to reopen. Hold bulk cash in a rated safe under time-lock or dual-control inside a restricted room, so opening it always requires more than one person or a delay an offender cannot wait out. Never let a cash movement become predictable — randomize the timing, the route, and where possible the personnel, and hand transport to a professional secured-carrier arrangement rather than an owner making a bank run in a private car, because currency in motion is the single most exposed state it ever occupies, which is why dispensary cash-in-transit belongs under a controlled transportation and cargo security protocol. Balance the drawer and the vault against point-of-sale and track-and-trace figures every day, because a cash count that quietly diverges from recorded sales is usually the first visible symptom of internal theft. And keep the money out of sightlines entirely — visible cash is simply an invitation.

How do you deny robbery and burglary at a dispensary?
Dispensaries draw robbery and burglary at rates well above comparable retail because they concentrate three things an offender wants — currency, high-value resalable product, and a widespread (often accurate) belief that neither is fully banked. Deterring the daylight armed robbery starts at the threshold: a controlled entry or ID-check vestibule that confirms age and eligibility before anyone reaches the sales floor keeps product and registers behind a second controlled barrier, while visible cameras, strong lighting, and unobstructed sightlines tell a would-be offender he will be recorded and recognized. None of that is decorative — each element either discourages the attempt or shortens the time an offender is willing to spend inside.
When deterrence fails, the program has to detect and respond without turning a robbery into a homicide. Duress signaling at each register and in the back office lets an employee summon help silently, and floor staff should be trained and drilled to cooperate rather than resist — product and cash are insured and replaceable, and no inventory is worth a life. The after-hours burglary is a different engineering problem, solved at the building shell and the safe: reinforced doors, frames, and glazing; hardened roof and demising walls, since forced entry frequently comes through the roof or a neighboring tenancy; interior motion and glass-break sensors tied to the monitored alarm; and a safe rated to withstand attack for longer than any realistic response time. The objective is stated in one line and earned only through detail — make the premises not worth attacking, and if it is attacked, make the attack fail before it pays.
How do you shut down diversion and internal theft?
Diversion — product or money walking out with employees rather than robbers — is the quieter loss, and across a portfolio it is usually the larger one. It is also the failure regulators fear most, because cannabis leaking from the licensed market into the illicit one is the precise outcome the entire licensing scheme was built to prevent. The front-line control is the state’s seed-to-sale track-and-trace system, which gives every unit a tracked identity from intake to sale. But a ledger only exposes diversion if someone reconciles it and runs down the discrepancies. Strong operators count physical inventory against the system on a fixed, disciplined cadence, treat every unexplained variance as an investigative lead rather than a write-off, and pull the access log and camera footage for the window in question to turn a fuzzy shortage into a documented event with a name attached.
Software cannot see the human gaps, so procedure has to close them. Separate responsibilities so no individual controls both the product and the records that account for it. Require a second authorized person to verify high-value sales, returns, waste destruction, and transfer manifests. Vet personnel to the limit the law permits, and gate restricted areas by role so a floor associate has no path to the vault. Because internal loss almost always hides in the seams between inventory data, cash records, and physical-access history, the capability that actually catches it is the ability to correlate those three data sets — the domain of financial and forensic investigations, and the line between an operator who can prove an inside job and one who can only suspect one.
What are the guard rules, and how do multi-state operators standardize them?
Whether a dispensary must post security officers, and whether those officers may be armed, is one of the most jurisdiction-dependent questions in the field. Some states require licensed guards during all operating hours; some specifically require armed personnel; many leave the decision to the operator’s own risk assessment; and municipalities frequently add conditions of their own. Wherever officers are deployed, they must carry whatever security license the jurisdiction demands, and armed officers must additionally satisfy that state’s carry and training requirements — a compliance obligation every bit as enforceable as a camera rule. Fielding unlicensed or improperly licensed guards is itself a violation capable of endangering the very cannabis license the officer was hired to protect.
Presence alone accomplishes little; direction is what makes an officer effective. Guards should work to written post orders that spell out how the entry vestibule is run, how a duress alarm is answered, how opening and closing are conducted, and when to escalate to law enforcement — not a vague brief to watch the door. They should be woven into the cash, access, and inventory procedures rather than parked beside them. For the multi-state operator this is fundamentally a standardization challenge: the officer program, the retention setting, the reconciliation cadence, and the incident protocol have to be commanded to one standard across every site in the portfolio, so a store in one state is protected — and provably compliant — to the same level as a store in another despite different underlying rules. Consistency across the portfolio, not heroics at a single location, is what an enterprise security function delivers.
Minimum compliance versus an enterprise-grade program: what is the difference?
Many operators equate “we passed inspection” with “we are secure.” The two are not the same. The table below contrasts a bare minimum-compliance posture with an enterprise-grade program built to a national standard, so an operator can tell which they actually have.
| Dimension | Minimum-compliance posture | Enterprise-grade program |
|---|---|---|
| Regulatory scope | Meets one state’s checklist | Control matrix mapped to every state and locality in the portfolio |
| Surveillance | Cameras installed to spec | Access-locked, health-monitored recorder with chain-of-custody export |
| Retention | Set to each state’s bare minimum | Standardized to the strictest jurisdiction across all sites |
| Cash handling | A safe in the back | Drop and dual-control safes, secured transport, daily reconciliation |
| Robbery readiness | Alarm and door locks | Controlled entry, silent duress, drilled staff response |
| Diversion control | Track-and-trace data entry | Cyclical reconciliation, segregation of duties, forensic follow-through |
| Security officers | A presence at the door | Licensed (and where required armed) officers under written post orders |
| Portfolio governance | Each site improvises | One commanded standard, audited uniformly |
| Incidents | Closed and forgotten | Analyzed as a diagnostic that hardens the failed layer |
How do you build a multi-state dispensary security program? A seven-step framework
A credible program is built deliberately, from the regulation and the risk outward, and then held to one standard across the portfolio. The sequence below reflects the discipline elite operators follow.
- Build the multi-jurisdiction control matrix. For every license and site, capture the governing state regulations and any local ordinance, map each requirement — video, retention, alarms, storage, access, tracking, personnel — to a specific, testable control, and flag where states diverge so the portfolio standard defaults to the strictest.
- Run a site-by-site risk assessment. Evaluate each location on its own merits — local crime pattern, structural weak points, cash throughput, product value, and prior losses — so capital follows real exposure rather than a uniform template.
- Set the enterprise baseline. Define one program standard — retention window, camera coverage, alarm and duress design, safe rating, reconciliation cadence, officer post orders — pegged to the most demanding jurisdiction, so every new site opens above compliance instead of racing to catch up.
- Harden the shell and the entry. Reinforce doors, glazing, roof, and shared walls; establish a controlled ID-check entry that holds the public out of product and cash areas; and engineer lighting and sightlines to eliminate cover.
- Deploy surveillance and alarms as evidence, not decoration. Install compliant, gap-free cameras on a secured, health-monitored recorder retained to the enterprise baseline; add monitored intrusion, glass-break, and duress alarms; and predefine chain-of-custody export.
- Engineer the cash and inventory systems together. Place drop and time-lock/dual-control safes in restricted rooms, minimize floor cash, schedule varied secured transport, integrate seed-to-sale tracking, segregate duties, and reconcile cash and inventory against the records daily.
- Staff, direct, and re-audit continuously. Field properly licensed (and where required armed) officers to written post orders, drill all staff on robbery and duress response, and re-audit each site on a fixed cadence — treating every incident and every regulatory change as a trigger to update the matrix and harden the layer that gave way.
How does Honeybadger secure cannabis operators nationwide?
Honeybadger Solutions approaches cannabis security as one integrated, compliance-driven program rather than an assortment of hardware. Our commercial and corporate security practice builds the physical program — the multi-jurisdiction control matrix, site risk assessment, envelope and entry hardening, surveillance and alarm design, cash-and-vault engineering, and access control — while our transportation and cargo security capability protects currency and product in transit, the point of greatest exposure. Because our investigations and financial-forensic work is performed in-house, the systems we design generate records — locked-down video, access logs, reconciled inventory — that hold up as evidence when diversion, internal theft, or a robbery has to be proven, and our security consulting keeps the program current as each state’s rules move.
Headquartered in Arizona with offices in Casa Grande, Phoenix, and Oro Valley, we protect single-site dispensaries and multi-state operators across all of Arizona, nationwide, and internationally. Within Arizona, physical security and guarding are delivered by our own licensed, supervised in-house officers. Beyond Arizona, protective and guarding operations are directed through our commanded, vetted-partner network — with established theaters in California, Texas, and Florida and other regions served on a mandate basis — all run to a single standard from Arizona home command, so a multi-location operator is protected and audited the same way in every market. Our digital forensics, cybersecurity, financial-investigations, and background-intelligence teams support those programs remotely as a matter of routine. Operators weighing a new location or reassessing an existing program can request a confidential assessment through our Phoenix command.
Frequently asked questions
How long must a cannabis dispensary keep security video?
It depends on the state. Legal-cannabis states set their own minimum retention periods, and they vary widely — some require only a few weeks, others several months. The disciplined standard is to retain footage for the longer of the legal minimum and your own inventory-reconciliation cycle, since losses often surface weeks later, and — for multi-state operators — to standardize on the strictest state’s window across every site. Footage must sit on a secured, access-controlled recorder and be producible to regulators on demand.
Do cannabis security requirements differ from state to state?
Yes. The categories are strikingly consistent — recorded video with fixed retention, limited-access areas, secure safe or vault storage, monitored intrusion and duress alarms, credentialed access with logging, seed-to-sale tracking, and often licensed security officers — but the thresholds are not. Retention length, required camera resolution, vault ratings, and whether guards must be present or armed all differ by state and sometimes by municipality, so each site’s exact obligations must be confirmed against the local rule text.
Why is cannabis a cash business, and will federal banking reform fix it?
Because cannabis is a Schedule I substance federally, most banks and card networks limit or refuse the industry to avoid Bank Secrecy Act exposure, and FinCEN requires those that participate to perform heightened due diligence. Proposed federal fixes such as the SAFER Banking Act have been debated for years but have not become law. Until one does, operators should assume they will hold and move significant cash and build the security program around that reality rather than an anticipated reform.
How does a multi-state operator keep security consistent across markets?
Through a single commanded standard rather than site-by-site improvisation. The operator builds one control matrix covering every state and local rule in the portfolio, sets an enterprise baseline pegged to the strictest jurisdiction — retention window, camera coverage, safe rating, reconciliation cadence, and officer post orders — and audits every location against it. That way each store opens above compliance and is protected and inspected to the same level, regardless of the differing rules beneath it.
About Honeybadger Solutions
Honeybadger Solutions is an Arizona-licensed security and investigations firm delivering intelligence-led physical security, security consulting, investigations, protection, and cyber services to cannabis operators and organizations nationwide and internationally. Within Arizona, physical security and guarding are provided by our own licensed, supervised in-house officers; beyond Arizona, guarding is directed through a commanded, vetted-partner network with established theaters in California, Texas, and Florida and other regions served on a mandate basis, all run from Arizona home command. Digital forensics, cybersecurity, financial investigations, and background intelligence are handled in-house and delivered globally.
Offices: Casa Grande (HQ), Phoenix, and Oro Valley, Arizona.
Phone: 602-725-2818
Confidential consultation: discuss a compliant, multi-state cannabis dispensary security program with our team.