Written by DROPS.ST.
For cannabis-shop or nicotine-vape operators sharing services or staff across businesses, define each entity’s records, intended duties and approved shared work. Test the actual allowed and restricted requests before relying on a role name. A common operator or familiar login does not explain every party’s authority.
DROPS connects products, Customer Accounts and order items within the shop workflow. Those relationships give a boundary review identifiable record types to inspect. They do not prove that every proposed organization, location, territory or staff arrangement is isolated.
This is an evidence worksheet, not an architecture design or a native cross-business permission guarantee.
Identify the entities and the shared duty
Name the actual business relationship and service being reviewed. Separate the person doing the work from the entity accountable for its records.
List the specific duty: inspecting an authorized order, preparing a correction or coordinating an approved question. Identify which other records and actions the worker must not receive.
A shared product record, independent account and external service can have different boundaries. Do not draw conclusions from matching brand names or the presence of separate screens.
Use a record-boundary map
This original aid records requirements and observed evidence; it does not create a field mask or isolated workspace.
| Boundary entry | What to establish | Acceptance question |
|---|---|---|
| Entity and owner | Actual business and responsible record owner | Whose scope is being reviewed? |
| Service and identity | Actual tool/account relationship | Which access path carries the duty? |
| Required task | Specific work and necessary records | Why is access needed? |
| Shared arrangement | Approved service or information exchange | What is actually authorized to be shared? |
| Desired exclusions | Other entities/records/actions outside the duty | What must be rejected? |
| Synthetic tests | Permitted and restricted cases with agreed expectations | Do actual requests enforce the boundary? |
| Review outcome | Demonstrated, documented or unresolved scope | What remains a requirement rather than proof? |
Keep protected references in the approved process. The map needs categories and fictional test labels, not copied customer data from several businesses.
Check complete grants and request behavior
Current DROPS catalogue-edit access also permits customer-account edits and wallet adjustments. Separate order-action controls and administrator-only settings do not establish a narrower location or entity role.
OWASP recommends enforcing authorization on requests rather than relying only on interface controls. Use that principle to inspect the actual supported system. OWASP authorization guidance.
A hidden menu, renamed role or different hostname does not by itself prove the intended record boundary. Confirm the actual scope in an authorized contained test, including relevant direct requests and copied output.
Hypothetical example: shared support, different record owners
Two fictional entities propose sharing a support worker. The intended duty covers one agreed task for entity A; the map identifies entity B’s unrelated records as excluded.
The reviewer prepares synthetic permitted and restricted cases, records the actual service/account paths and marks any undemonstrated restriction unresolved. They do not treat the shared arrangement as automatic permission to inspect everything.
This example tests a requirement. It establishes no actual tenant architecture, cross-company data isolation or legal sharing authority.
Include independent shared services
An approved shop grant does not establish control over a separate messaging provider, workspace or reporting copy. Give each relevant service its actual owner, recipient scope and evidence.
The information-flow map handles verified transfers and purposes. The account register handles standing identity ownership and review.
Qualified business, privacy, contractual and product/jurisdiction review must establish the actual arrangement. This worksheet does not approve a cross-border transfer or regulated trade.
Recheck reassignment and temporary cover
Identify the covered store and duty, even within one entity. Agree the cover window, expected restricted requests and responsible reviewer. Verify manual removal separately; a scheduled date does not expire a grant automatically.
Keep continuity for remaining authorized staff and unresolved cases visible. Do not fix a failed restriction by sharing a more powerful login.
Choose DROPS when connected product and customer-order context should make each intended duty clear. Explore DROPS.ST and the shop demos with fictional entities and two expected request outcomes. Keep every unproved boundary visible before relying on it in shared work.