Authorized trading partners and the gates
Core module 3PL add-on For: Administrator, Compliance manager, Sales and purchasing Checked on 18.0.0.2.0, 18.0.1.0.0
Before DSCSA products change hands, Rx Tracking checks that the other party is an authorized trading partner according to the licenses you have recorded for it. The places where it checks are called gates: an order or a transfer that fails one is refused, with a message that names the partner and the reason.
What makes a partner authorized
A partner is an Authorized Trading Partner (the checkbox on the DSCSA tab of its contact) when both are true, today and for your current company:
- It has a DSCSA Role: Manufacturer, Repackager, Wholesale distributor, Third-party logistics provider (3PL) or Dispenser.
- Every license its role needs is recorded on it, verified by an Rx Tracking Manager, and in force: its Issue Date has come, its Expiry Date hasn't passed, and it isn't archived.
| DSCSA Role | License that counts |
|---|---|
| Dispenser (a pharmacy, a hospital pharmacy, a practitioner) | State license |
| Wholesale distributor | State license, plus an FDA 503(e) annual report when the setting Wholesalers/3PLs need a 503(e) report is selected |
| Third-party logistics provider (3PL) | State license, plus an FDA 503(e) annual report under the same setting |
| Manufacturer, Repackager | FDA establishment registration |
A DEA registration never counts. The status is the same for a company and all its contacts and addresses, so a sale to a pharmacy's receiving dock is checked against the pharmacy's licenses. When a partner isn't authorized, a yellow banner on its DSCSA tab says why, for example "… has no valid state license: license DEMO-CA-PHY-61177 expired on …". See Check whether a partner is an authorized trading partner, and why not and Record and verify a trading partner's license.
Licenses expire. A daily job gives each license that expires within 30 days a License expiring activity for its Responsible (Act on license-expiry reminders); the day it expires, the partner stops being authorized and its next order or transfer is refused.
Where the gates run
| When | What is checked | Procedure |
|---|---|---|
| Confirming a sales order (Confirm), a customer accepting it in the portal (Accept & Sign) or paying it online | the customer and the delivery address | OUT-01, OUT-02 |
| Confirming or approving a purchase order (Confirm Order, Approve Order, the list action Confirm RFQ) | the vendor | IN-01 |
| Validating a receipt, a delivery or a return | the transfer's partner and the partner of its sale or purchase order | IN-05, OUT-03 |
| Validating a customer return | also that the returned serials are ones you sold to that customer | RET-01 |
The check at validation repeats the check at confirmation on purpose: a license can expire between the order and the shipment.
Every gate works the same way:
- On the server, for every route. A form button, a list action on several records, an import, an API call, the customer portal and an online payment all meet the same check and the same message.
- For everyone. No role, setting or user skips it; the administrator is refused like anyone else. A salesperson without any Rx Tracking right is refused too, and can't fix the cause: an Rx Tracking user records or verifies the license.
- All or nothing. A refused action changes nothing.
- DSCSA products only. Only lines of products whose DSCSA Product box is selected are checked. An order or transfer without them goes through exactly as in standard Odoo, and the message of a mixed order names only the DSCSA products.
The full table of checks and routes, and the stock paths that are refused or left alone (dropship, manufacturing, inter-company transit), is in What is checked where.
With the 3PL add-on: owner, counterparty and facility checks
For an owner's stock, the operation is the owner's transaction, and your company acts as its third-party logistics provider. Validating a receipt, delivery or return of an owner's DSCSA units (and confirming an owner order, or validating a title transfer) checks three parties:
- The owner must be an authorized trading partner under the same rule. This always blocks.
- The owner's counterparty (its supplier, its customer, a return designee) must be authorized too. By default this blocks; with the company policy Owner counterparties set to warn, the transfer goes through with a warning.
- Your own facility needs your verified license for the activity: a 3PL license for owner stock (or the record that the state doesn't license 3PLs), a wholesale license where you buy an owner's units or hold a consignor's stock. This always blocks. The check reads the license's Activity and Facility, not its Jurisdiction: a license of another state recorded under the facility counts too (known issue PF-F06-01).
The customer's (ship-to) state is not checked: non-resident third-party logistics licenses of the states you ship into are neither recorded nor checked. Your procedure decides which states' licenses you need. See "What the check doesn't compare" in Record and verify our facility licenses.
Each result, refusals and passes alike, is written to the Gate Log (3PL ‣ Reports), which you can export for an inspector. See Get an owner transfer through the owner, counterparty and facility checks and Choose the company's 3PL policies.
Why it exists
Background: the gates come from DSCSA's rule that a distributor buys from and sells to authorized trading partners only. The modules follow the reading that the evidence for each role is an FDA registration for manufacturers and repackagers and a state license for wholesalers and dispensers, with a current 503(e) report for wholesalers, and that a DEA registration is not that evidence (FD&C Act § 582(c)(3), § 581(2); see Compliance background). The modules keep a license register with verification evidence and gate sale, purchase, shipping and receiving so that imports, the API and portal orders can't bypass them, and their design rule keeps every other product out of scope. For owner stock, the 3PL add-on adds owner, counterparty and facility checks and logs them (FD&C Act § 582(c)(3), § 581(2); § 584(a)–(b); see Compliance background). This is how the modules read the law; it has not been reviewed by counsel. See the disclaimer.
Your procedure decides how you verify a license at its source (the state board's website, FDA's databases), how often you re-check it, and who may verify; the software requires an Rx Tracking Manager to mark a license verified and checks the recorded licenses on every order and transfer.