Skip to content
§
§ · build vs buy

Communications Surveillance and Archiving Software: Buy the Capture, Build the Supervision Layer Above It

Channel count decides this, not headcount. One jurisdiction on email plus one chat platform, captured by one vendor, with no voice obligation, means buy Smarsh or Global Relay end to end and spend the difference on a reviewer.

Internal tools product interface illustration for Communications Surveillance Archiving Software Build vs Buy Guide.
The short answer

Channel count decides this, not headcount. One jurisdiction on email plus one chat platform, captured by one vendor, with no voice obligation, means buy Smarsh or Global Relay end to end and spend the difference on a reviewer. Past about five channels across more than one capture vendor, or with retention rules from two regimes colliding, the supervision question becomes specific to your firm and no vendor lexicon can answer it. Even then the right move is almost never a replacement. Keep the capture subscriptions and build only the supervision, identity and production layer above them.

When is off the shelf genuinely the right call here?

Smarsh, Global Relay, Theta Lake, Shield and Behavox all capture well. Connectors to WhatsApp, Bloomberg chat, Microsoft Teams, Zoom and a voice turret are maintained products carrying years of accumulated edge cases, and rebuilding one is an expensive way to reinvent something mature. Very few firms should be writing connectors.

Buy end to end, and stop reading here, if this describes your firm:

  • One jurisdiction, so one retention regime and one set of access rules to hold in your head.
  • Email plus one chat platform, captured by a single vendor.
  • A headcount where a qualified principal can genuinely review a meaningful sample each month rather than performing a ritual.
  • No voice obligation, or a turret recorder whose retention you never have to reason about.
  • No trade surveillance programme you need to link a message to.

That describes a large number of investment advisers and smaller broker dealers, and we say so on the first call. A packaged platform will cover capture, retention and review at that shape, and a build is an expensive route to the same place.

There is a second case where buying is right at any size. If your immediate problem is that capture itself is incomplete, fix capture with a vendor, run it for a year, then decide whether supervision is the constraint. Building a supervision layer over a partial record produces confident review of an incomplete archive, which is worse than an honest gap.

When does a custom build actually pay off?

Capture is the easy half. What an examiner actually tests is supervision: whether a qualified person reviewed the right things, on a defined basis, with documented reasoning, and whether you can prove it. That is where packaged tools hand you a lexicon, a queue and a checkbox, and where firms discover their review programme has quietly become a formality nobody believes in.

The tell is behavioural rather than technical. A keyword list flags every message containing the word guarantee, most of which are somebody guaranteeing to call back after lunch. Reviewers learn the pattern within a week and start closing in bulk. The queue is worked, the sign off is recorded, and you are funding a control that produces nothing.

Build the supervision layer when two or more of these are true:

  • More than about five channels across more than one capture vendor, each exporting in its own shape.
  • Reviewers who close flagged items in bulk, which everyone privately knows.
  • No way to produce a complete communication history for a named individual, across every channel, in under a day.
  • Retention conflicts between jurisdictions resolved by somebody's judgement rather than by a rule.
  • An existing trade surveillance programme with no way to link a message to a trading case without manual work.

Identity is usually the deciding factor. The same person is an email address, a Bloomberg identifier, a Teams object, a mobile number, a chat account and a turret extension, and several of those change over a career or when someone returns as a contractor. If that map is a spreadsheet maintained by whoever remembers, production requests keep missing things and you do not find out until somebody else does.

How do they compare on the things that matter in this industry?

Review population as policy. Packaged review starts from a search result. What survives examination is a population defined explicitly: everything from this desk during the quiet period, all external messages from staff on the restricted list, a stated random percentage from every registered person, plus risk triggered items. Each with a rationale, a reviewer role, a frequency and a version history. Ask a vendor how you evidence why you reviewed what you reviewed, and listen for whether the answer is a policy record or a saved query.

Identity over time. A configuration ceiling shows up here first. Vendor user directories model a current user, because that is what they need for capture. Supervision needs effective dated identifiers bound to a person record sourced from human resources (HR) and registration data, so a desk review covers the person who joined last Thursday and the contractor who came back under a different account.

Retention as a matrix. Products implement a retention policy. What they handle less gracefully is several overlapping policies where the longest applicable period wins, legal holds override the schedule, and the reasoning has to be reconstructable years later. If you operate in more than one regime, ask specifically how a disposition is evidenced, not how a policy is configured.

Data portability. Your archive outlives your vendor relationship by design. Ask how a complete export leaves the platform, including metadata and the supervisory record, and get the answer into the contract before renewal rather than during a migration.

Per seat economics. Capture pricing generally scales with registered persons and channels, which is fair. It also means the cost of the review layer rises with headcount even though your review policy did not change. That is worth modelling at double your current size before you sign a multi year term.

What does total cost of ownership look like at your scale?

On the build side, from Digital Heroes delivery experience, a focused first release runs $95,000 to $210,000 and ships in 14 to 20 weeks. That covers ingestion of your existing capture feeds into a unified message store, identity resolution across channels, policy defined review populations with lexicon and classifier scoring, reviewer workflow with documented sign off, and defensible search and export. A full platform adding voice transcription and review, cross channel risk scoring, legal hold and matter management, jurisdictional retention rules, capture assurance monitoring and linkage to trade surveillance cases runs $260,000 to $700,000 phased across 9 to 16 months.

Priced component by component so you can fund only what you need: capture assurance monitoring $15,000 to $30,000, classifier scoring alongside your lexicon $30,000 to $50,000, each additional jurisdiction $20,000 to $50,000, and voice as its own phase at $70,000 to $180,000. Voice is the largest single line in the category and the one most often deferred into a phase two that never gets funded.

Annually after go live, storage dominates. For a firm of around 900 registered people expect $2,000 to $8,000 a month, growing every month because retention obligations forbid trimming. Add $500 to $3,000 a month for classifier inference depending on how much of the population you score rather than sample, transcription priced per audio hour if voice is in scope, and 15 to 20 percent of build cost annually for support and change. Your capture subscriptions continue on top, and that belongs in the comparison honestly.

On the buy side the number to price is not the licence. It is the production request. Take your last significant one and count the elapsed weeks, the vendor coordination, the external legal hours and the internal compliance time. Then ask how long it would take today to answer, with confidence, whether a named person communicated with a named external party in a given month across every channel. If the honest answer is more than a day, that is your exposure.

What does the hybrid look like, and when is it the honest answer?

For almost every firm this is the answer, and we give it whether or not it wins us work. Keep Smarsh, Global Relay or whoever captures for you. Build the layer above them.

In practice that is three pieces:

  • An identity and ingestion layer. Every capture feed normalised into one message store, with each channel identifier bound to a person record with effective dates, sourced from human resources and registration records so joiners and leavers propagate automatically.
  • A supervision layer. Review populations expressed as versioned policy, lexicon and classifier scoring running together rather than one replacing the other, and reviewer sign off with stored reasoning. The model prioritises. The qualified principal decides and signs.
  • Capture assurance and production, $15,000 to $30,000. Every channel reporting expected against received volumes on a schedule, gaps raising an alert with a named owner, and a production package carrying a completeness statement naming the window, the channels in scope and any known gaps with explanations.

That last piece is the cheapest module in the plan and it addresses the largest uncosted risk you carry. A documented and explained gap is survivable. A gap found by the party reviewing your production is a much worse conversation.

The strategic argument is simple. Capture is a commodity and should be bought. Supervision is your policy, your risk appetite and a named principal's personal accountability, and none of those transfer to a vendor whatever the contract says.

Which should you choose, by operator size and stage?

Find your row and act on it.

  • Investment adviser or small broker dealer, one jurisdiction, email plus one chat. Buy end to end. Write your review policy down, sample honestly, and spend the difference on a reviewer.
  • Two or three channels, one capture vendor, no voice. Still buy. Put the effort into cleaning your identity map, which costs nothing and is what a production request will test.
  • Five or more channels across two capture vendors, one jurisdiction. This is the decision point. Keep capture and build the ingestion, identity and review layer above it, roughly $95,000 to $150,000 depending on vendor count and message volume.
  • Multi jurisdiction firm with retention conflicts and a live trade surveillance programme. Build the full supervision layer, phased. Ingestion, identity, populations and production first. Capture assurance, legal hold and the retention matrix second. Voice last.
  • Any firm whose reviewers close in bulk. Fix that before buying anything else. A labelled sample of a few thousand of your own historical messages, scored by your reviewers against the behaviours your policy names, costs nothing and tells you whether a classifier would beat your lexicon.

Two conditions apply to every build row. Start with one jurisdiction and one review policy version, because retention matrices multiply and debugging two things at once is how these programmes stall. And settle ownership before kickoff: the repository, the classifier training data and the cloud accounts should be yours in writing. A review programme you cannot open, explain and modify is one you cannot fully defend when it is examined.

If you would rather scope this before committing budget, Digital Heroes starts every engagement with a signed specification covering the data model, permissions and acceptance criteria, which is what keeps a fixed price fixed. You can take that specification to any other firm on your shortlist.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Analyst estimates place CRM implementation failure rates broadly between roughly 30% and 70% (Johnny Grow cites Forrester at 47%), with low user adoption repeatedly cited as a leading cause of failed CRM projects (this being Johnny Grow's own analysis, not a Forrester attribution). Source: Johnny Grow (industry analysis citing Gartner/Forrester) (2025) →
  2. Median SaaS spend reached $9,455 per employee, and organizations leave an average of 36% of their SaaS licenses unused. Source: Zylo (2026) →
  3. The global point-of-sale terminal market is projected to reach approximately $181.47 billion by 2030, growing at an 8.1% CAGR from 2025 to 2030, driven by digital payment adoption and demand across retail, restaurant, and hospitality sectors. Source: Grand View Research (2025) →
  4. In an RCT, text-message reminders (11.7% missed) were non-inferior to telephone reminders (10.2% missed; difference not significant, within the 2% non-inferiority margin) but far cheaper - total cost EUR 230 for SMS versus EUR 8,910 for telephone over 6 months - making SMS more cost-effective. Source: BMC Health Services Research / PubMed Central (Junod Perron et al.) (2013) →
FAQ

Frequently asked questions

Should we replace Smarsh or Global Relay entirely?

Usually not, and this is the decision firms most often get wrong. Capture connectors to WhatsApp, Bloomberg chat, Teams, Zoom and voice turrets are mature, maintained products, and rewriting them leaves you maintaining connectors forever for no reduction in regulatory risk.

What those platforms leave thin is supervision: a generic lexicon, a queue and a sign off checkbox. Build the layer holding your review policy, identity map, retention matrix and production evidence, and keep paying for capture. That split is what keeps a first release under $210,000.

What does it cost to switch archiving vendors?

The licence side is negotiable. The expensive part is that your archive has to survive the move intact, with metadata, chain of custody and the supervisory record attached, because you may be asked to produce from it years later.

Before signing anything, ask how a complete export leaves the platform and what shape it arrives in, and get the answer written into the contract rather than discovered during migration. Firms that own the identity map and the review policy independently of the capture vendor find switching far less painful, which is a further argument for the layered approach.

What if our vendor raises prices as we add channels and people?

Model your fee at double your current registered headcount and channel count before you sign a multi year term, because capture pricing generally scales with both and your review policy did not change when your headcount did.

The structural answer is to own the layer that carries the accountability. Once supervision, identity and production evidence are yours, capture becomes mechanics you can price, compare and move, rather than a bundled service with nothing to measure it against.

How long before a custom supervision layer is actually reviewing messages?

Fourteen to twenty weeks for a first release covering ingestion, identity resolution, policy defined review populations, reviewer sign off and defensible export.

The pacing item is almost never engineering. It is the identity map, because binding every channel identifier to a person record with effective dates means reconciling human resources data, registration records and each capture vendor's own user directory. Firms that have already cleaned that up reach go live noticeably faster, and firms that have not discover their historical gaps during this phase, which is the right time to find them.

Why is voice priced as its own phase rather than another connector?

Because everything about it degrades at once on a real trading floor. Transcription accuracy suffers from background noise, speaker separation on turret lines is genuinely hard, tickers and code words defeat general models, and multiple languages compound all of it.

Budget $70,000 to $180,000 for voice, plus per audio hour transcription costs modelled against your actual recorded minutes. Sequence it after identity resolution and review populations are reliable, otherwise you are listening to the wrong calls very expensively.

Is a classifier worth building, or is the vendor lexicon enough?

It adds roughly $30,000 to $50,000 and it is one of the clearer genuine uses of language models in compliance. Keyword matching cannot distinguish somebody guaranteeing to call back after lunch from a promise about performance, which is why reviewers learn to close in bulk.

Prove it before you fund it. Have your reviewers label a few thousand of your own historical messages against the behaviours your policy names. That sample becomes the evaluation set, so you can measure whether the model beats your lexicon rather than accepting anybody's claim, including ours.

How much does each additional jurisdiction add?

Plan $20,000 to $50,000 per regime. Retention and access rules have to coexist as a matrix rather than replace one another, with the longest applicable retention winning and legal holds overriding the schedule entirely.

The part that costs money is evidence rather than configuration. When a message is finally deleted you must be able to show which rule permitted it and confirm no hold applied. Start with one jurisdiction and add the second once the review workflow is proven, or you are debugging both at the same time.

Can we link communications review to our trade surveillance system?

Yes, and the combination produces materially stronger cases than either alone, because a trading pattern accompanied by a message discussing it is a different piece of evidence.

The practical design is not one merged system. It is a shared person identity across trading accounts and communication channels, with cases able to reference evidence from both. Build each side properly first, then link, or the joined output is noisy in both directions and reviewers stop trusting it.

What does an internal tool cost for a small business with 20 to 50 employees?

Plan on $5,000 to $15,000 for a focused tool that replaces one painful spreadsheet workflow, such as job scheduling, quoting, or PTO tracking. In Digital Heroes projects at this size, the sweet spot is one core workflow, two or three user roles, and a single integration, usually QuickBooks or Google Workspace. Quotes far below $5,000 usually mean a template with your logo on it rather than software built around your process.

What are the biggest mistakes first-time software buyers make?

Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.

We run everything on spreadsheets and Airtable. How do we know it's time for custom software?

The reliable signals are re-typing the same data into multiple tools, one employee acting as human middleware between systems, and errors appearing in handoffs between teams. Hard limits force the issue too: Airtable's Team plan caps at 50,000 records per base, and Business costs $45 per seat per month, so a 20-person team pays about $10,800 a year for a tool it has already outgrown. When workarounds consume more hours than the tools save, the spreadsheet era is over.

What does it cost to keep an internal tool running after launch, and do we need to hire a developer?

Budget 15 to 20 percent of the build cost per year, so a $25,000 tool runs roughly $300 to $400 a month covering hosting, security patches, dependency updates, and small tweaks, figures drawn from Digital Heroes maintenance contracts. You do not need an in-house developer; a monthly retainer with the agency that built it covers the typical internal tool comfortably. Hosting itself is cheap for internal audiences, often $20 to $100 a month, because you serve dozens of users rather than the open internet.

How many SaaS seats do we need before building custom becomes cheaper?

The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.

Can we start on Airtable or Retool now and move to custom software later?

Yes, and it is often the smartest sequence: run the workflow on Airtable or Retool for 6 to 12 months to learn what you actually need, then go custom once the process stabilizes. The no-code version becomes free requirements documentation, and its data exports cleanly into a custom database. The one risk is waiting too long, because teams stack automations and workarounds until migration becomes a project of its own, so set a concrete trigger in advance, such as hitting Airtable's 50,000-record Team plan cap.

What should I prepare before contacting a software development agency?

A one-page brief beats a 40-page requirements document: the business problem in plain words, who will use the system, the 5 to 10 workflows it must handle, the tools it must connect to, and your budget range and deadline driver. You do not need wireframes, a specification, or technical vocabulary; producing those is the agency's job during discovery. Stating a budget range up front is the single best move, because it gets you honest scoping instead of a quote engineered to win the meeting.

How do I calculate the ROI of a custom internal tool?

Count hours first: multiply the weekly hours staff spend on the manual process by their loaded hourly cost, then add the cost of errors such as mispriced quotes or missed renewals. A tool saving a 10-person team 5 hours each per week recovers about 2,500 hours a year, which repays a $20,000 to $30,000 build well inside a year at typical wages. Most internal tools Digital Heroes delivers reach payback in 6 to 18 months, with quoting and billing tools at the fast end because they plug revenue leaks, not just time.

At what point does Retool cost more than building a custom tool?

The crossover usually lands between 25 and 50 daily users. At Retool's published Business rates of $50 per standard user and $15 per end user monthly, a 40-person deployment with a typical seat mix runs roughly $9,000 to $15,000 per year, every year, while a comparable custom tool built once for $20,000 to $30,000 carries no per-seat fees and costs about 15 to 20 percent of the build price annually to maintain. On a three-year horizon, custom comes out ahead for most growing teams in Digital Heroes engagements.

Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply