Fulfillment software is easy to demo and hard to evaluate. This guide lists the capabilities that matter once you are shipping under FDA, DEA and state-board scrutiny, gives you a scoring table, and the seven tests that separate software that records from software that enforces.
The features that look good in a sales call — dashboards, dark mode, an AI chat box — are rarely the ones that matter at 2,000 orders a day with a cold-chain product and a state inspector on the calendar. What matters is whether the system makes the wrong thing impossible. Use this guide to cut through it, and run the tests in section three on every vendor, including us.
The ten capabilities that matter
1. Digital order intake with idempotency
Can partners submit orders programmatically, or is everything manual entry from a portal and a fax? Look for a real order API that is idempotent on the partner's own order id — a retried request must return the existing order, never create a second one — and that pushes status back to the partner over signed webhooks with retries.
2. A licence gate that fails closed
Before an order is accepted, the ship-to state should be checked against your licence table. The important detail is what happens when there is no licence row or the licence has expired: the order must be held, not let through. Controlled substances should require a licence that explicitly allows them.
3. Prescription ↔ order linkage
For patient-specific work, the prescription and the order should be linked rows, and the order should not be able to enter production until the prescription is in a filled state. DUR findings belong on the prescription record.
4. Batch genealogy with quantities and a BUD floor
If you compound, a batch must record which raw-material lots it consumed and in what quantity, enter production as In Process, and be released only after QC. The beyond-use date must never exceed the shortest component expiry. See compounding software.
5. A quality system in the same database
Deviations, CAPA, change control, environmental monitoring, QC testing and document control should live next to the batches they concern, not in a separate product that has to be reconciled at inspection time. 503B software covers this in depth.
6. Lifecycles enforced in the database
Order and lot statuses should be an allowed-transition graph enforced by a trigger, with a history row per change naming the acting user. Application-level rules can be bypassed by anyone with database access; a trigger cannot.
7. Part 11 signatures that verify at the moment of signing
An electronic signature should require the signer's identity and a fresh credential check when it is applied. If re-authentication fails, no signature. Read 21 CFR Part 11 for pharmacies.
8. Unit-level serialization and recall by unit
Lot-level tracking turns a recall into a phone tree. Unit-level GS1 serials with an event at fill, pack, verify and ship turn it into a query that returns the exact units, orders, patients and parcels, with per-unit disposition. Serialization & DSCSA explains the mechanics.
9. Pack-verify, carrier scans and cold-chain evidence
An order should not be markable as Shipped until pack-verify passed. Carrier scans should be de-duplicated and cascade to the order and its units; a parcel on QA hold should never be marked delivered; temperature readings should attach to the parcel. See the cold-chain guide.
10. A partner portal and finance from the same rows
Each brand you fulfil for should get a portal scoped to its own rows — orders, shipments, subscriptions, performance, billing, support. And the income statement, receivables and margin per product should be views over the operational tables, not an export someone reconciles. See the platform overview.
Scoring table
Print this, add a column per vendor, and score only what you have seen live. The Pharmacy Flow column is grounded in the product; the category column describes typical behaviour, not any named vendor.
Pharmacy Flow column as of September 2026. Fill the last column from a live demo, not a brochure.
Capability
Pharmacy Flow
Typical dispensing / WMS tool (category)
Your vendor
Order API idempotent on partner order id
✓
Uncommon
Licence gate holds order when no valid licence
✓
Often manual
Prescription must be filled before production
✓
Typical in dispensing systems
Batch consumes raw lots with quantities; BUD floor
✓
Lot-level at best
QMS in the same database
✓
Usually separate
Status graph enforced by trigger; history per change
✓
Application-level
Signature requires password re-authentication
✓
Varies
Unit GS1 serial + EPCIS-style events; recall per unit
✓
Lot-level
Shipped requires pack-verify; scans cascade; QA hold respected
✓
Varies
Brand-scoped partner portal; finance views over operational rows
✓
Rare / billing-centric
Control Tower dispatching tasks to people and machines
✓
WMS-only or absent
Free trial of every module; no per-module pricing
✓
Varies
Pack-verify is a station and a database rule, not a checkbox.
Seven tests to run on any vendor's live system
1
Submit the same order twice
Same partner order id, two calls. Expect the second to return the existing order.
2
Ship to a state with no licence, then an expired one
Expect both orders to be held before acceptance.
3
Skip a step through the database API
Move Received → Shipped directly. Expect a trigger to reject it and a history row to exist for every legitimate change.
4
Fill from a lot on hold
Expect the fill to be blocked by the database, not merely hidden by the screen.
5
Sign with a stale session
Expect a password re-check at the moment of signing.
6
Recall from a raw-material lot
Expect the exact units, orders, patients and parcels, with per-unit disposition, as a query.
7
Ask where the margin number came from
Expect a view over the operational tables, with the component-lot costs the batch actually consumed.
We built Pharmacy Flow so that every one of these passes because the rule is in Postgres. We will run all seven on a call, on our system, with you watching. Request a demo →
Match the software to your model
503A compounding
Weight tests 2, 3, 5 and 6. Prescription discipline and the licence gate matter most; batch genealogy matters as soon as you make anticipatory stock. 503A software →
503B outsourcing
Weight tests 4, 5, 6 and 8. Batch records with quantities, a QMS in the same database and per-unit serialization are the inspection story. 503B software →
Telehealth / GLP-1 fulfillment
Weight tests 1, 2, 9 and the portal. Idempotent intake, the licence gate, cold-chain evidence and a brand-scoped portal decide whether you can add a second brand without adding a coordinator. GLP-1 fulfillment →
Multi-site networks should add: facilities with their own licences, inventory and P&L; routing rules; inter-site transfers; and a Control Tower that dispatches work to people and machines through one task API. See WMS & Control Tower and fulfillment automation.
Migration, onboarding and pricing questions
What master data do you need from us?
Expect: formulations and variants, materials, products, suppliers, facilities, state licences, brands. Ask whether there is a wizard and whether the vendor maps from your current exports.
Can we run in parallel?
A week of orders on both systems, comparing the history rows and the serial ledger against your paper trail, is the safest cut-over. Ask whether the trial tenant becomes production.
Is the trial the real product?
Some vendors offer a sandbox with a different feature set. Ask whether the trial is your own tenant with every module on. Pharmacy Flow's is: 14 days, no card, every module.
How is pricing built?
Ask which inputs move the price and whether modules or users are sold separately. Pharmacy Flow quotes on facility count and monthly volume only; there is no per-module or per-user charge and no published tier chart. See pricing.
What is free?
For Pharmacy Flow: being in the directory, claiming your listing, posting requests for quotes, and the 14-day trial. See the directory.
Common mistakes
✓Scoring from a brochure. Only tick what you saw the system do, live, on the vendor's own data.
✓Treating compliance as a separate purchase. If quality lives in another product, every inspection starts with reconciliation.
✓Accepting lot-level traceability because "we've never had a recall". The cost of unit-level is near zero once it is built in; the cost of not having it is a week.
✓Ignoring the database. If a rule is only in the application, anyone with API access can bypass it.
✓Choosing on price before scoping. A cheap system that cannot add a second brand or facility is the expensive one.
Enforcement in the database. Most tools record orders and inventory; few make an invalid status change, a double dispense or a fill from an unreleased lot impossible at the row level. That is what determines whether the system holds at volume.
Does fulfillment software need to handle compliance too?+
For compounding and telehealth pharmacies, yes. Every physical task may involve a controlled substance, a state licence or a cold-chain product, so the licence gate, signatures and traceability cannot live in a separate system.
Is unit-level serialization worth it for a small pharmacy?+
If it is built in, the cost is a barcode on the label and it turns recall into a query. If it has to be bolted on later, it is a project. Choose software where it is on by default.
How should we evaluate the AI features?+
Ask what rows the AI reads and whether it can take a compliance action. AI should summarise, forecast and draft; people should sign, release and dispense. Pharmacy Flow's AI Insights reads the same tables the floor writes and never changes a status.
What should a demo look like?+
A real order run intake → eligibility → clinical review → batch → QC → serialized pack-verify → ship on the vendor's live system, then the seven tests. If a vendor cannot show that, keep looking.
How is Pharmacy Flow priced?+
Directory listings and claims are free; a 14-day trial of every module is free; the platform is quoted on facility count and monthly volume. No per-module or per-user charge and no published tier chart.
A working platform, not a slide deck. Book a walkthrough and we'll run a real order from intake to carrier lane — or explore the public directory first, no account needed.