Recurring, cold-chain, telehealth-driven and high-volume, all at once. A playbook organised by the day, from the morning numbers to the carrier pickup.
A compounded GLP-1 programme looks like a dispensing business and behaves like a fulfilment business. Orders arrive by API from platforms you do not control, most of them recur monthly, every one ships refrigerated, and demand moves in surges tied to someone else's marketing calendar. Pharmacies that run it well stop thinking in prescriptions and start thinking in flows: intake, refill, make, pack, ship, replenish. This playbook is organised that way, with the mechanisms in Pharmacy Flow named where they apply, and the parts that still need a human named too.
The morning numbers
Start every day with six figures, and make them the same six every day: orders received yesterday against the seven-day average; orders on hold and in which states; subscriptions overdue for their next fill; cold-chain parcels under a QA hold; materials short against the thirty-day forecast; and on-time delivery from carrier scans. In Pharmacy Flow the dashboard and the Insights page carry all six from tenant-wide SQL views, and the anomaly scan ranks the problems by severity with links to the records. If your system cannot produce these six without a spreadsheet, that is the first thing to fix, because everything below depends on seeing the problem the morning it starts, not the week after.
The six morning numbers on one screen, computed from the same tables the floor writes to.
Intake: let the gate do the arguing
The single largest source of rework in a GLP-1 programme is an order that should never have been accepted: a ship-to state where you hold no nonresident licence, a licence that lapsed last month, or a controlled add-on into a state that forbids compounded controlled substances. Manual intake catches these late, after a pharmacist has looked at them. An API with a fail-closed gate catches them at the moment of submission, creates the order On Hold with the reason written on it, and tells the partner by webhook. Pharmacy Flow's order endpoint does exactly that, and treats a retried call with the same client order id as the same order, so a partner's retry logic never creates duplicates. Insist on this from any system: the gate must fail closed, the reason must be on the order, and retries must be idempotent. The request and response shapes are documented on the telehealth API page.
The daily refill run
Most GLP-1 orders recur. A subscription in Pharmacy Flow is a recurring order with a cadence, a refill number and a next-fill date; the Subscriptions module lists them with overdue flags and lets you pause, reactivate or cancel. What it does not do today is create the next fill by itself: the refill is a staff action, and an automated scheduler is on the roadmap. So schedule the human. A daily refill run, first thing, working the overdue list and the fills due in the next two days, keeps recurrence from becoming a backlog. When a prescription backs the order, the refill action re-checks the DEA schedule rules (no Schedule II refills; five within six months for III–V) and the state licence, and holds the order if either fails.
If you take one thing from this section: decide who owns the refill run and when it happens, and put the overdue count on the morning list. A programme with 3,000 active subscriptions and no owner for the run accumulates missed fills at a rate nobody notices until the churn number moves.
Making to demand, not to fear
GLP-1 formulations have one bill of materials and many variants, and the temptation during a surge is to make a lot of everything. Make to demand instead. The forecast reads each variant's actual fills over the trailing thirty days, so it tells you which strengths are moving. The batch planner shows, for a variant and a quantity, which lots will be drawn (earliest expiry first), how much from each, and the cost per fill, before anything is committed. Then the batch is created in one transaction: the finished lot in quarantine, the batch In Process, the consumption recorded per lot, the BUD floored by the soonest component expiry, and the QC tests pending. Release is a separate, permission-gated action. See the compounding software page for the mechanics.
Plan the batch, see the draw and the cost, then commit it as one transaction.
Cold chain: packout, readings, holds
Cold chain fails in three places: the wrong packout for the lane, a reading nobody took, and an excursion nobody acted on. Address each mechanically. Packout should be chosen by the system from the product family, not by the packer's memory; in Pharmacy Flow the pack station assigns an insulated packout with gel packs and an expedited healthcare service to GLP-1 families and flags the parcel cold-chain. Readings should be recorded against the parcel and checked against a fixed window; an out-of-range reading marks an excursion, opens a QA hold and moves the parcel to Exception. And the hold must actually block: no staff action and no carrier delivery scan can move a held parcel to Delivered until a user with the QA release permission records a disposition. The cold-chain shipping guide goes deeper on packout design and lane testing.
What good looks like on the shipping screen
Every cold-chain parcel shows its packout, its service, its last reading and whether a hold is open. Carrier scans are stored once each, keyed on the carrier's event id, so a retried webhook cannot fake a second delivery. The delivery cascade to the order, and the partner's order.delivered webhook, wait for the hold to clear.
Strengths, serials and the verify scan
A wrong-strength dispense is the GLP-1 error with the worst consequences, and it is almost always a lookup error: a lot matched by product name, a label printed from the wrong record. Remove the lookup. Every strength is a variant with its own SKU; a finished lot is tagged with the variant it was made as; and the fill station will only commission a unit for an order from a lot of that exact variant, earliest BUD first. Each unit gets a serial and an SGTIN at fill. The verify station then scans the order and the serial and checks four things server-side: the unit belongs to this order, it has been packed, it is not recalled, and it is not past its BUD. A fail holds the order with the reason. The ship station, and independently the database, refuse to ship an order without that verification stamp. Make the verify scan mandatory in your process and it will catch the errors your training will not.
The verify scan: four checks, server-side, every parcel.
See the playbook running
We will submit a GLP-1 order by API, run the refill, plan the batch, pack it cold, record a reading, fail a verify on purpose and ship it, on a tenant you keep afterwards.
Running out of active ingredient mid-surge is the failure that ends programmes, because the partner does not wait. Buy on a forecast, not on the last stock-out. The Demand & Planning module turns trailing-30-day fills per variant into material requirements through each bill of materials, compares them to available stock and shows shortfall and weeks of cover per material, then drafts purchase orders grouped by preferred supplier in one action. Weekly buckets are projected with Holt-Winters once there are two weeks of history. Run it every week, not when someone is nervous, and treat the below-reorder and short-against-forecast anomalies as tasks with owners. Detail on the inventory page.
✓Weekly: run the forecast at a 60-day horizon and draft the POs
✓Daily: clear the below-reorder and forecast-shortfall anomalies
✓On receipt: supplier lot, expiry, temperature check and CoA reference go on the lot before it enters quarantine
✓Monthly: quarantine anything past expiry with the one-click sweep, and review lots expiring within 30 days
The floor: waves, not heroics
At a few hundred parcels a day a good lead can run the floor from memory. At a few thousand, memory is the bottleneck. Plan open orders into waves, emit pick, pack and sort tasks per order with cold-chain flags, dispatch them to whoever is capable, and track them to done on a board everyone can see. Pharmacy Flow's execution layer does this today with human resources and offers machines the same tasks through a keyed API; what is shipped and what is on the roadmap (constraint-aware dispatch, replenishment tasks, sortation) is listed plainly on the fulfilment automation page. The Control Tower is the board. The automation guide explains why orchestration comes before robots.
The board: what is flowing, what is stuck, who has it.
Partners: give them the webhook
Telehealth partners judge a pharmacy on two things: how fast the first shipment moves and whether their support team can answer a patient without calling you. Both are solved by pushing status to them. Pharmacy Flow sends signed webhooks for received, held, shipped (with carrier, tracking, ETA and SSCC), delivered and recall, from an outbox that retries failed deliveries with backoff, and the partner portal shows the brand's orders, shipments, subscriptions, billing and webhook delivery health. Put the partner on the portal on day one and on the API when volume justifies it. The partner programme page describes the relationship.
What the partner sees: their orders, their shipments, their webhook health, nothing else.
The failure modes, ranked
The list we use in onboarding. Every mechanism in the right column exists in the product today; the refill run is a human process.
Failure
Why it happens
Mechanism that prevents it
Shipping into an unlicensed state
Manual intake; licence table stale
Fail-closed gate at intake; licence expiry anomaly
What are the daily metrics for a GLP-1 programme?+
Orders received against the seven-day average, orders on hold by state, subscriptions overdue, cold-chain parcels under QA hold, materials short against forecast, and on-time delivery from carrier scans. The dashboard and Insights page carry all six.
How should refills be handled?+
As a scheduled daily run with a named owner, working the overdue list and the next two days' fills. Pharmacy Flow tracks cadence, refill number and next-fill date and flags overdue subscriptions; the refill itself is a staff action today.
What happens when a cold-chain parcel goes out of range?+
The reading is stored, the parcel is marked excursion and Exception, and a QA hold opens. Delivery is blocked, by staff or carrier scan, until a QA-release user records a disposition.
How do we prevent a wrong-strength dispense?+
Every strength is a variant; a unit is only commissioned from a lot tagged with the order's exact variant; and the verify scan checks that the serial belongs to the order before the ship station will release it.
How far ahead should we buy API?+
Run the forecast weekly at a 60-day horizon. It converts trailing-30-day fills into material requirements and drafts purchase orders by supplier; the suggested quantity covers the shortfall plus about two weeks of safety.
Do we need robots to run the floor at volume?+
No. Waves, tasks and a visible board with human resources are what change the ceiling. Machines take the same tasks through an API when volume justifies them.
What should partners get from us?+
Signed webhooks for received, held, shipped, delivered and recall, and a portal with their orders, shipments, subscriptions, billing and webhook health. That removes most of the calls to your team.
A working platform, not a slide deck. Book a walkthrough and we'll run a real order from intake to carrier lane — or explore the public directory first, no account needed.