Industry guide · Custom Software

Board Portal and Governance Software: When Directors Are Reading Three Different Versions of the Same Paper

Board Portal software visual showing presentation, planning calendar, and vote.
The short answer

$80,000 to $160,000 and 12 to 18 weeks is what a first release of a custom board portal costs in our delivery experience, covering pack assembly with contributor deadlines, controlled distribution with revocation, and annotation for directors. A full governance platform adding minutes and approval workflow, written resolutions with e-signature, conflicts and attendance registers, subsidiary board access and action tracking runs $200,000 to $500,000 phased over 7 to 12 months. This is the one category where we tell most buyers not to build. Diligent Boards or OnBoard will beat a custom project unless you have a structural reason, and the reasons are residency, group complexity or integration.

Why board packs go wrong in the last 48 hours

The board meets Thursday. Papers were due to the company secretary on Friday. By Monday afternoon four of eleven have arrived. The finance pack lands Tuesday morning, the strategy paper Tuesday evening with a note that the numbers on page six are provisional. The secretary assembles a PDF, paginates it, and emails it to eleven directors. Wednesday at 11pm the CFO sends a corrected page six.

Now there are two packs in eleven inboxes, and one director downloaded the first to an iPad, annotated it on the train, and will arrive Thursday having prepared against a superseded number. A second director forwarded the pack to their assistant to print. A third is a non executive who sits on a competitor's board in an adjacent sector and has just received a paper about a transaction they should have been walled out of, because the distribution list is a group in the secretary's email client and nobody edits it under pressure.

Then the meeting happens. Minutes get drafted from the secretary's notes over the following fortnight, circulated by email for comment, revised, and approved at the next meeting, by which point the action from item seven has been forgotten by everyone except the person who did not do it. Attendance is recorded in the minutes. Declarations of interest are in a standing register that lives in a Word document updated annually.

Every part of that is common at organisations that take governance seriously. The cost is not usually a dramatic breach. It is decisions taken on inconsistent information, an action log that exists in three places, and a paper trail that will not stand up if a regulator or a litigant asks how a decision was reached.

Problem 1: the pack is a build process and email cannot manage it

Assembling a board pack is a production job with contributors, deadlines, formats, page limits and an order. Doing it by email means the secretary is a manual build server: chasing, converting, paginating, bookmarking, and reissuing when anything changes.

What a custom build does: papers are items with an owner, a due date and a status. Contributors upload against the agenda item, and the pack compiles itself, paginated and bookmarked, at any point. If a paper changes after distribution, the pack version increments and every director's device gets the new version with the change flagged, rather than a second attachment arriving beside the first. Directors keep their annotations across versions where the page still exists, which is the feature that decides whether they use the portal or go back to printing.

Diligent Boards and Nasdaq Boardvantage both do this well. If pack assembly is your only pain, buy one of them. The reason to keep reading is what sits around the pack.

Problem 2: distribution is a security control, and email is not one

Board papers are the most sensitive documents most organisations produce: transactions before announcement, executive remuneration, litigation strategy, regulatory correspondence, security incidents. They are read by non employees on personal devices, sometimes on aircraft, sometimes by people who serve on several boards.

Email cannot revoke. When a director resigns, their inbox keeps every pack they ever received. A shared drive is barely better, because access removal does not touch what was downloaded.

What a custom build does: documents are served, not sent. Access is per director per pack, revocable, and revocation reaches the device. Offline access, which directors genuinely need, is granted as an encrypted local cache tied to the app and the user, wiped when access is withdrawn. Every open is logged, so if a paper leaks you have a distribution record rather than a shrug. Personalised watermarking on each rendering is a modest deterrent and worth having. We will also be honest about a limit: you cannot reliably stop someone photographing a screen, and any vendor claiming otherwise is overselling. What you can do is make casual copying inconvenient and deliberate copying attributable.

Problem 3: minutes, resolutions and the register are three documents that should be one record

The meeting produces several artefacts that most organisations manage separately. Minutes drafted after the fact. Resolutions passed in the meeting or later by written consent. Attendance, including who joined for which items, which matters when a director recuses. Declarations of interest made at the meeting, which should update a standing register. Actions with owners and dates.

Managed separately, these disagree. The minutes say a director declared an interest and withdrew for item five, and the standing register was never updated. A written resolution passed by circulation in August is filed in a folder and never makes it into the minute book.

What a custom build does: the meeting is the record. Minutes are drafted against agenda items with the pack still attached, so the paper the decision was based on is one click from the decision. Resolutions are objects with a status, a voting record and where required an e-signature, whether passed in the room or by written consent. A declared interest at the meeting updates the standing register and can trigger the recusal that removes that director's access to the relevant paper. Actions become tracked items that appear on the next agenda automatically with their status, which is the mechanism that stops the action log rotting.

Problem 4: subsidiary boards and committees break the simple model

A single board with four committees is a straightforward access model. A group with a plc board, an audit committee, a remuneration committee, a risk committee, two regulated subsidiary boards with independent non executives, a joint venture board with partner appointees and a charitable foundation is not. Membership overlaps. A director on the group board must not automatically see the regulated subsidiary's papers. The joint venture partner's appointees see their board and nothing else.

Products aimed at a single board handle this with separate workspaces, which means separate logins, separate packs and a secretary administering several instances. OnBoard and BoardEffect are good tools that are shaped for that simpler world.

What a custom build does: one identity per person, membership per body with dates, and access derived from membership at the time the pack was issued. A director who leaves the audit committee in March loses access to April's papers automatically and keeps the record of what they saw before. Where a group already maintains an entity register, the board and committee structures should be sourced from it rather than typed twice, which is one of the strongest genuine arguments for building rather than buying.

Problem 5: retention and residency are policy questions the software has to answer

Minutes and resolutions are corporate records with statutory retention expectations. Board packs, working drafts and annotations usually are not, and keeping them forever is a liability rather than a virtue, because everything retained is discoverable. Most organisations have never applied a deliberate retention rule to board material, so nine years of packs sit in a portal.

Regulated boards often also cannot accept a shared cloud tenancy, or need data held in a specific country. That constraint alone puts some organisations outside what the major vendors offer.

What a custom build does: retention as a rule per artefact type, with minutes and resolutions retained per policy and drafts and packs expiring on a schedule with a documented exception process for anything under legal hold. Hosting goes wherever your regulator or your risk committee requires, including your own tenancy. If residency is your reason for building, say so early, because it changes the architecture and the cost more than any feature does.

What this costs and how long it takes

Across the 2,000-plus projects Digital Heroes has delivered, the shape here is this. A first release covering agenda and paper collection with contributor deadlines, versioned pack compilation, controlled distribution with revocation, and director annotation on web and tablet runs $80,000 to $160,000 and ships in 12 to 18 weeks. A full governance platform adding minutes drafting and approval, resolutions with e-signature, attendance and conflicts registers, action tracking, subsidiary and committee structures and retention rules runs $200,000 to $500,000 phased over 7 to 12 months.

What drives cost up specifically for board systems: native tablet applications with offline access, which is a genuine second and third build rather than a responsive web page, and directors will demand it. Self hosting or a specific residency, which adds deployment and operations work. The number of boards and committees, since the access model is where complexity lives. E-signature integration for written resolutions. And the security review itself, because a board portal will be examined by your own risk function and possibly your regulator, and penetration testing plus remediation is a real line item you should budget rather than discover.

What keeps cost down: launching on the main board and one committee, with a web application first and the tablet app in the second phase once the pack model is settled.

Build versus buy, and when buying is the right call

We will say this more plainly here than in most categories: buy, unless you have a structural reason not to. Diligent Boards is the market standard and it is expensive because it is genuinely capable and because board material is unforgiving. OnBoard is a strong mid market option with better usability than its price suggests. BoardEffect fits nonprofit and healthcare governance well. If your problem is that pack assembly is painful and directors read old versions, a product solves that next quarter and a build solves it next year.

Build when one of these is true, and they are structural rather than about features. Your regulator or your risk appetite requires data in a specific jurisdiction or in your own tenancy, and no vendor offers it on acceptable terms. Your group has enough boards, committees, subsidiaries and joint ventures that per workspace licensing and administration has become its own job. You already run an entity management system and the duplication between it and a board portal is causing errors. Or your governance process has requirements the products genuinely cannot express, which is rarer than people think and should be tested against a real product demonstration before you commit a budget.

How to choose a developer for board and governance software

Ask what happens to a downloaded pack when a director resigns. If the answer does not include remote revocation of the offline cache, they are building a document sharing site and calling it a board portal.

Ask them to model a director who sits on the group board and the audit committee but must be walled out of one subsidiary. If they reach for a per document permission list maintained by hand, the company secretary will be maintaining that list forever and will make a mistake during a transaction.

Ask how annotations survive a pack reissue. Directors will not adopt a portal that discards their notes when page six changes, and this is the detail that decides whether the system is used or bypassed.

Ask about the security assurance you will get: penetration testing by an independent firm, the remediation process, and what evidence they will provide to your risk committee. Then ask who owns the code and where it is hosted, in writing, before kickoff. You should own the repository and the infrastructure accounts. At Digital Heroes the client owns the code from the first commit, and for a board portal we would insist on an independent security test before a single real pack is loaded.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. The federal government spends about 80% of its IT budget on operations and maintenance of existing systems rather than on development or modernization, with many critical systems being decades old. Source: U.S. Government Accountability Office (GAO) (2025) →
  2. Standish's 2015 CHAOS research found roughly a third of software projects (about 36% by the Modern definition) fully succeed on time, on budget, and on scope, with top success drivers including executive support, user involvement, and clear requirements/business objectives. Source: Standish Group (CHAOS Report) (2015) →
  3. A study (led by Prof. Pak-Lok Poon, published in Frontiers of Computer Science, 2024) reviewing decades of spreadsheet-quality research found that about 94% of spreadsheets used in business decision-making contain errors, illustrating the hidden risk of manual spreadsheet workarounds that custom software is built to replace. Source: Central Queensland University / phys.org (Prof. Pak-Lok Poon et al.) (2024) →
  4. The NRF discontinued its long-running annual shrink report, stating that a broad study of retail shrink 'is no longer sufficient for capturing the key challenges and needs of the industry' - important context that qualifies how POS/shrink benchmarks should be cited going forward. Source: Retail Dive (2024) →
Saanvi J. · Senior Shopify Engineer · B2B · Delhi

Saanvi works on B2B Shopify builds at Digital Heroes, where the requirements shift from consumer checkout to company accounts, customer specific pricing, purchase orders and approval steps. Her posts help wholesale businesses see how much of that a commerce platform handles and how much needs building.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

Should we build a board portal or buy Diligent?
In most cases buy. Diligent Boards is the market standard and board material is unforgiving, so a product that already exists will beat a custom project on both risk and time. The genuine reasons to build are structural: a residency or self hosting requirement no vendor will meet, a group with enough boards and subsidiaries that per workspace administration has become a job, or an existing entity management system whose duplication with a portal is causing errors.
How much does a custom board portal cost?
A first release covering paper collection with deadlines, versioned pack compilation, controlled distribution with revocation and director annotation typically runs $80,000 to $160,000 over 12 to 18 weeks, based on Digital Heroes delivery experience. Adding minutes, resolutions with e-signature, conflicts and attendance registers, action tracking and subsidiary structures takes it to $200,000 to $500,000 over 7 to 12 months. Native tablet apps with offline access and independent security testing are the two lines buyers forget.
How do you stop directors reading different versions of a pack?
Serve the pack rather than send it, and make versioning explicit. When a paper changes after distribution the pack version increments, every device receives the update with the change flagged, and the superseded version is withdrawn rather than sitting in eleven inboxes beside the new one. The detail that determines adoption is annotation carry over, because directors will go back to printing if a reissue wipes their notes.
What happens to board papers when a director resigns?
With email, nothing. Their inbox keeps every pack they ever received. A portal serves documents per director per pack with revocable access, and offline copies are held as an encrypted cache tied to the app and user so revocation reaches the device. That single difference is the strongest security argument for a portal over any shared drive or mailbox arrangement.
Can a portal prevent screenshots or photographs of board papers?
No, and be wary of any vendor implying otherwise. Someone can photograph a screen with a phone and no software prevents that. What is achievable is making casual copying inconvenient through download controls, and making deliberate copying attributable through per director watermarking and an access log that records every open. Treat those as deterrence and evidence rather than prevention.
How do we handle group boards, committees and subsidiary boards in one system?
Use one identity per person with dated membership of each body, and derive access from membership at the time the pack was issued. A director leaving a committee in March then loses access to April papers automatically while keeping the record of what they saw before. If you already maintain an entity register, source the board and committee structures from it rather than typing them twice, since that duplication is a common cause of access errors.
How should minutes, resolutions and interest declarations be linked?
Treat the meeting as one record rather than several documents. Minutes are drafted against agenda items with the pack still attached, resolutions are objects with a voting record and where needed an e-signature, and an interest declared in the meeting updates the standing register and can trigger the recusal that removes that director's access to the relevant paper. Actions carry forward onto the next agenda automatically with their status.
How long should we keep board packs?
Apply a deliberate rule per artefact type rather than keeping everything. Minutes and resolutions are corporate records with statutory retention expectations, while drafts, packs and annotations usually are not, and retaining them indefinitely creates discoverable material with no governance benefit. A workable policy expires packs and drafts on a schedule with a documented exception process for anything under legal hold.
What security assurance should we require from a developer?
Independent penetration testing before a single real pack is loaded, a documented remediation process for findings, and evidence you can hand to your own risk committee. Ask specifically how offline caches are encrypted and revoked, and how access logs are protected from administrator tampering. Then get code ownership and hosting location in writing before kickoff, since at this sensitivity you should own the repository and the infrastructure accounts outright.
What happens if I stop paying for maintenance after launch?
Nothing breaks on day one, which is what makes it dangerous. Within 6 to 18 months, unpatched dependencies accumulate known vulnerabilities, an integrated API like Stripe ships a breaking change, and the first fix requires a developer to relearn a stale codebase at full price. Budget 15 to 20% of the build cost per year for upkeep; it is the difference between a $500 patch and a $15,000 emergency.
Does the tech stack matter, and which one should I ask for?
It matters less than agencies imply, provided it is boring. A mainstream stack, something like React or Next.js on the front end, Node.js or Python behind it, and PostgreSQL for data, means thousands of developers can maintain your system if you ever change vendors. Apply one test: ask how hard it would be to hire a replacement developer for the proposed stack, and walk away from anything built on an agency's in-house framework.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
What should I have ready before I contact a development agency?
Three things, none of them technical: a one-page description of the problem in your own words, a list of the tools and spreadsheets the new system must replace or connect to, and a must-have versus nice-to-have split of features. Add a budget range, even a wide one, because it changes the conversation from fantasy to engineering. You do not need a formal specification; producing that is what a discovery phase is for.
What is the biggest mistake first-time software buyers make?
Choosing the lowest quote without asking why it is the lowest. A bid 40% under the field usually gets there by skipping tests, documentation, and code review, which are invisible in a demo and brutal to pay for later; every stalled project Digital Heroes has been asked to rescue tells some version of that story. The second mistake is signing without a written scope, which reliably turns the winning cheap quote into 1.5x to 2x the price by launch.
We run everything on Airtable and spreadsheets. When is it time to go custom?
The switch usually makes sense when you hit one of two walls: Airtable's record caps (125,000 records per base on the Business plan) or logic the tool cannot express, like multi-step approvals with conditional pricing. There is also a simple cost signal: 25 people on Business at roughly $45 per seat per month is about $13,500 a year, forever, for a tool you are already fighting. Custom is worth it when the workflow is core to how you make money; for peripheral processes, staying on Airtable is the right call.
How do I work out whether custom software will pay for itself?
Do the arithmetic on hours before anything else: if the system saves three staff eight hours a week at a $35 loaded hourly cost, that is about $43,700 a year against, say, a $70,000 build plus 15 to 20% annual maintenance, a payback around two years. Add revenue effects only if you can name them specifically, like faster quotes or fewer abandoned orders, not as vague growth. In our delivery experience the businesses that see payback inside 24 months are the ones automating a process they already measure.
How long does it take to build a custom web or mobile app from scratch?
Plan on 8 to 16 weeks for a focused first version and 4 to 9 months for a larger platform, which is the typical spread across Digital Heroes builds. The first 2 to 3 weeks go to discovery and design before any production code ships. The two things that stretch timelines most are integrations with legacy systems and slow feedback from your side, not developer speed.
How do we get years of data out of our old system and into the new one?
Treat migration as a planned sub-project: a field-mapping document, at least one dry run on a copy of your data, then a cutover with the old system kept read-only for 30 days as a safety net. On Digital Heroes projects it consumes 10 to 15% of the budget when the old system has an export, and more when data must be pulled out screen by screen. Ask any vendor to walk you through their last migration before you sign.
Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?