Retail Shrink and Loss Prevention Software: Build vs Buy
Buy under roughly 40 stores. Agilence or Appriss Retail plus a disciplined store audit calendar will surface more exceptions than your team can work, and a build there is capital spent to avoid a subscription.
On this page
Buy under roughly 40 stores. Agilence or Appriss Retail plus a disciplined store audit calendar will surface more exceptions than your team can work, and a build there is capital spent to avoid a subscription. Build past about 150 stores, once investigators assemble case packages by hand and cases are being lost to recorder overwrite before anyone opens them.
What Appriss Retail and Agilence actually do well
Take the buy answer seriously before reading the rest. Under about 40 stores, a productised exception reporting tool plus a consistent store audit calendar finds more money than a project will, and the honest constraint at that size is people to work the flags rather than software to produce them.
Appriss Retail is strong on returns specifically because it sees a consortium view of return behaviour across retailers that you cannot reproduce from your own data at any price. That is a genuine advantage and it does not go away when you build. Agilence covers till and service desk exception reporting competently, ships with a rule library assembled from a broad sample of retailers, and gets a mid size chain to useful findings in weeks. Sensormatic at the door and computer vision at self checkout each do their own job well inside their own boundary.
They also carry things a build never gives you free. Somebody else updates the rule library when a new fraud pattern spreads. Somebody else keeps the point of sale (POS) journal parser working through a till software upgrade. Somebody else is on the phone when the overnight load fails.
Buy while your loss is opportunistic and your estate is homogeneous. Read on if your loss has become organised and your estate has become three acquisitions.
Where they stop: the case file lives on somebody's desktop
A shrink number is an accounting result. A case is what recovers money and stops the crew, and no exception reporting tool owns the case.
It is nine at night and a regional asset protection manager is working the daily report for 340 stores. One store shows a cashier with 41 no sale drawer opens on a single shift. Another shows a service desk associate who has processed eleven no receipt refunds to gift cards in eight days, every one landing just under the supervisor approval threshold. A third flag is an order picked, marked collected and refunded 40 minutes later at a different store. Three rows in a report. Not one of them is a case yet.
Turning them into something a prosecutor accepts means pulling video from two recorder brands whose clocks disagree by ninety seconds, exporting journal detail at line level, matching a loyalty identifier to a phone number that also appears on a marketplace listing, writing a narrative, and assembling a package that survives a defence attorney reading it. In the asset protection teams we have built for, an investigator spends six to twelve hours on a single organised retail crime package, and most of that is copying, renaming and cross referencing files. That is why most flagged incidents quietly expire.
The second thing that stops is the rule library itself. Productised rules are built from somebody else's shrink. Your fraud is shaped by your policies. If you allow no receipt returns to a gift card up to $100, your abuse forms at $99. If your price match permits an override without a manager code, that is where the leakage goes. Vendor rules can be tuned, but only inside their model of a transaction, and when your pattern depends on an override reason code their schema does not carry, the rule cannot be written at all. So the team exports to a spreadsheet every Monday, and a shadow reporting function is born.
The arithmetic: cost per store per month versus a build
Exception reporting is usually priced per store per month, sometimes with a data volume component. Take your rate, multiply by store count, multiply by 36 months, and add the second and third tools, because most chains run at least three products across returns, till exceptions and video.
Then price the part the subscription does not touch. Take last quarter's flagged incidents, count how many became a working case, and count how many closed with a recovery, a civil demand or a referral. The distance between those numbers is the leak, and it is measured in investigator hours rather than in licence fees.
Now count the cases lost to recorder overwrite. Every chain has them and almost nobody counts them. A clip that existed on the day of the incident and did not exist by the time an investigator got to it is a case that was funded and then thrown away.
The crossover in our delivery experience arrives near 150 stores, and it moves earlier when you carry more than one point of sale journal format or more than two video platforms. Below 40 stores, buy and hire. Between those numbers it depends on how heterogeneous your estate is after acquisitions, which is a question about integration rather than about size.
What a custom loss prevention build actually costs
Bands, from delivery experience rather than a price list. A first release covering exception rules run against your own point of sale, returns and fulfilment data plus a real case file with an evidence chain and immutable audit logging runs $90,000 to $180,000 and ships in 14 to 20 weeks. A full platform adding video correlation with clock drift handling, electronic article surveillance and self checkout vision events, entity resolution across stores, civil recovery and restitution tracking, store audit workflows and shrink attribution reporting runs $250,000 to $600,000 phased across 9 to 15 months.
Data migration adds 10 to 25 percent, and here it is mostly history and open cases. Closed cases can be loaded for retention. Open ones move with their evidence, their hashes and their custody log intact or they lose the property that makes them usable.
Year two runs 15 to 20 percent of build cost annually. Till software upgrades change journal formats, video platforms change export interfaces, and new fraud patterns need new rules written by people who understand your policies.
What pushes it up: the count of distinct video platforms, because each integration is real weeks and some older recorders have no usable interface at all. Point of sale heterogeneity after acquisitions, since two journal formats means two parsers and two rule sets. Transaction volume, which at several hundred stores forces a columnar store rather than a general purpose database. And legal review of retention and access, which is not optional when the records are discoverable.
What keeps it down: returns and refunds only, at your worst 30 stores, with video correlation deferred to phase two.
The four situations where building wins
- Regulatory fit. This system holds evidence, which changes the engineering. Under Federal Rule of Evidence 902(14), electronic records can be self authenticating where a qualified person certifies them by comparing a hash value produced by a reliable process, so hashing on ingest is not a nice detail, it is what keeps you out of an authentication argument. Retention has to be defensible in both directions, since preservation duties attach once litigation is anticipated while privacy rules push the other way. If your estate uses facial recognition anywhere, the Illinois Biometric Information Privacy Act sets written consent and retention schedule duties with a private right of action attached, and Texas and Washington have their own regimes. And recovery work now runs alongside the INFORM Consumers Act, which since 27 June 2023 has required online marketplaces to verify high volume third party sellers, giving your team a route to a name that did not exist before.
- Scale economics. Per store per month across three overlapping products, where every acquisition adds stores and another journal format at the same time.
- A workflow that is your competitive advantage. Entity resolution across suspects, vehicles, phone numbers, addresses and loyalty accounts is what turns scattered incidents into one organised retail crime case, and it depends entirely on the identifiers your own systems capture.
- Integration sprawl across three or more systems. Returns scoring, till exceptions, video, door alarms, self checkout vision, order management and the case folder on a shared drive. Every one is competent alone and none of them owns the object your team actually works.
Two of those true is a build. One of them is a better rule tuning session with your current vendor.
How to decide in a week, with ten flags
Take ten flags from last month's exception report, spread across returns, till and fulfilment.
Monday: assemble one of them into a complete case package exactly as you would hand it to a prosecutor. Time it honestly, including the video pull. That single number is the business case and most executives have never seen it.
Tuesday: for the other nine, check whether the relevant footage still exists. Count how many are already gone. Then look up when each incident was flagged and when an investigator first opened it.
Wednesday: write down your three most abused policies and try to express each as a rule in your current tool. The ones you cannot write are the ones costing you money, and the reason is almost always a field the vendor schema does not carry.
Thursday: take last month's inventory adjustments in your five worst stores and try to split them into theft, receiving variance, damage, markdown error and unrecorded write off. If you cannot, every intervention you fund is a guess applied evenly.
Friday: price it. Cases lost to overwrite, plus incidents flagged and never worked, plus three years of subscription across every tool. Under roughly $250,000 a year, tune the rules and hire an investigator. Above it, build the case file and evidence chain first and leave video correlation to phase two.
If it points to build, the next step is a paid discovery rather than a proposal. Two to three weeks, fixed fee, ending in a signed product requirements document covering the case model, the evidence chain and retention rules agreed with your counsel, the rule set, the integration list by vendor and version, and acceptance criteria. You keep that document whoever builds from it.
We are wrong for you if you run under 40 stores, if your loss is mostly receiving variance and damages rather than theft, or if you are choosing on hourly rate, and we would rather say so than bid it. Where Digital Heroes fits: more than fifty specialists, over 2,000 projects, our own products including ShopScore, HeroCheckout and Section Vault, and India LLP, US LLC and UK LTD entities so intellectual property assigns under your own law. This system holds evidence you may have to produce in court, so the repository and the cloud accounts are yours from the first commit, and our record is checkable on Clutch, Trustpilot, Fiverr Vetted Pro and our D-U-N-S listing.
Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- SaaS spend averaged $4,830 per employee (up 21.9% year over year), with large enterprises (10,000+ employees) spending roughly $284M annually and running about 660 apps, while organizations wasted an average of $21M annually on unused licenses. Source: Zylo (2025) →
- The right combination of digital transformation actions can unlock as much as US$1.25 trillion in additional market capitalization across Fortune 500 companies, while the wrong combinations put more than US$1.5 trillion at risk; companies with all three core factors (strategy, aligned technology, and change capability) saw a 5% market-value lift relative to peers. Source: Deloitte (2023) →
- Across more than 5,400 IT projects studied by McKinsey and the University of Oxford BT Centre, large IT projects ran on average 45% over budget and 7% over schedule while delivering 56% less value than predicted. Source: McKinsey & Company / University of Oxford (BT Centre for Major Programme Management) (2012) →
- Criteo's Global Commerce Review found retail apps convert at 18% versus 4% on mobile web (roughly 4.5x), and travel apps convert at 20% versus 6% on mobile web (about 3.3x). Source: Criteo (2017) →
Frequently asked questions
How long does it take to build a case management system for asset protection?
Fourteen to twenty weeks for a first release covering exception rules, case files and the evidence chain. Video correlation adds meaningfully and should usually be a second phase, since each platform integration is real weeks and older recorders sometimes offer no usable interface. The fastest projects start with returns and refund abuse at the worst thirty stores, which proves the case model before anyone spends on integrations.
Who owns the evidence and access logs if a vendor hosts the system?
You should own the repository, the cloud accounts and the unrestricted right to hire another firm, settled before kickoff. This matters more here than in most categories because you may need to produce those records and their access history in court, and an account you cannot reach without somebody else's cooperation is not evidence you control. At Digital Heroes the client owns the code from the first commit.
What happens if a defence attorney challenges our video export?
You are asked to show the clip was not altered between the recorder and the courtroom. The answer that holds is a hash recorded at ingest, an append only store, an immutable log of who accessed the file and when, and a documented retrieval process. Systems that export clips to a shared drive cannot answer that, which is why cases assembled from folders tend to settle rather than proceed.
Can we keep Appriss Retail and build only the case file?
Yes, and it is usually the right first phase. Keep the consortium return scoring you cannot reproduce, and build the object nobody owns: a case with a suspect, linked incidents across stores, hashed evidence, a custody log, a restitution figure and a status pipeline through interview, civil demand, referral and prosecution. That layer is where investigator hours go and where recovery actually happens.
Should a chain of 25 stores build loss prevention software?
No, and we would say so before quoting. At that size a product plus a consistent audit calendar surfaces more exceptions than your team can work, and the money belongs in people to work them. The case begins when investigators assemble packages by hand, when cases are lost to recorder overwrite, or when your loss is organised across stores and needs suspect linking a per store report cannot provide.
What is the difference between exception reporting and case management?
Exception reporting produces rows: a cashier, a pattern, a threshold crossed. Case management produces an object you can act on: a suspect, incidents linked across stores and dates, evidence with custody, a narrative, a recovery amount and a status. Most chains own the first and improvise the second in folders and spreadsheets, which is why flagged incidents outnumber worked cases by a wide margin.
How much does adding another video platform cost after launch?
It varies more than anything else in this category, because the ceiling is what the platform exposes. A modern system with a documented export interface is bounded work. A proprietary recorder from an acquired estate may offer nothing usable, in which case the honest answer is to replace the recorder rather than to pay a developer to fight it. Ask for the vendor and version before anyone quotes.
Can we tell how much of our shrink is actually theft?
Only by separating causes at the moment they happen rather than at count. Capture receiving variance at the door against the advance ship notice, make damages and markdowns coded events with a photo and an employee attached, and tie theft incidents to a case reference. Then shrink decomposes by cause, store, category and shift, which is what changes a budget conversation from more guards everywhere to a targeted intervention.
What happens to open cases during a migration?
They move with their evidence hashes and custody logs intact, or they stop being usable. Load closed cases for retention, migrate open ones individually with verification, and keep the old system readable until every case open at cutover has closed. A case that loses its access history in a migration has lost the property that made it admissible, which is an expensive way to learn the lesson.
Where does machine learning genuinely help here?
Two places earn their keep. Entity resolution across suspects, vehicles, phone numbers, addresses and loyalty accounts turns scattered incidents into one organised case, and it is a matching problem models handle better than rules. Drafting a narrative from structured incident data saves real hours per case. Anomaly detection replacing your rule set usually underperforms, because good rules encode policy knowledge a model cannot infer from transactions.
Why do BI dashboard quotes range from $25k to $200k for what sounds like the same project?
Four variables move the price: how many data sources you connect and how messy they are, real-time versus daily refresh, permission complexity, and whether outside customers will log in. A three-source internal dashboard with daily refresh sits near the bottom of that range, while a customer-facing product with row-level security and live data sits near the top. Wildly different quotes are usually pricing different assumptions about those four things, so pin them down in writing before comparing.
Is Tableau worth $75 per user per month, or should we build our own dashboard?
If you have analysts who explore data visually all day, Tableau Creator at $75 per user per month earns its price, and Viewer seats at $15 keep the total reasonable for a small team. The math flips once you have hundreds of viewers or need dashboards inside a customer-facing product, because per-seat pricing scales with your audience while a custom build does not. Run the 3-year seat cost before deciding; that horizon usually makes the answer obvious.
How long does it take to build a custom web or mobile app from scratch?
Plan on 8 to 16 weeks for a focused first version and 4 to 9 months for a larger platform, which is the typical spread across Digital Heroes builds. The first 2 to 3 weeks go to discovery and design before any production code ships. The two things that stretch timelines most are integrations with legacy systems and slow feedback from your side, not developer speed.
How do I vet a software development agency before signing a contract?
Ask to speak with two past clients whose projects resemble yours in size and industry, and ask exactly who will write your code, since some agencies sell senior faces and deliver junior or subcontracted hands. Demand a written specification with acceptance criteria before any fixed price, and check that their portfolio links to products that are actually live. An instant quote given without questions about your workflows is the clearest warning sign there is.
How small can the first version of my software be and still be worth building?
One workflow, end to end, for one type of user: the single process that currently burns the most hours or loses the most money. In Digital Heroes delivery experience, first versions scoped to 6 to 10 weeks of build time ship, get used, and generate the feedback that makes version two obviously right, while 9-month first versions routinely launch with features nobody touches. Everything you cut from v1 gets cheaper to build later, because real usage reorders the roadmap for you.
How do I vet an agency or developer for a BI dashboard project?
Ask them to walk you through the data model of a past project, not a portfolio of pretty charts, because dashboard failures are almost always data modeling failures. Good answers mention specifics like star schemas, dbt, incremental refresh, and how they handled a source schema change after launch. Then ask for a fixed-scope discovery phase with a written data audit as the deliverable, so you judge their real work for a small spend before committing to the build.
Who can build a custom business intelligence dashboards system?
Digital Heroes builds custom business intelligence dashboards systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other business intelligence dashboards companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .