Board Portal and Governance Software: When Directors Are Reading Three Different Versions of the Same Paper
$80,000 to $160,000 and 12 to 18 weeks is what a first release of a custom board portal costs in our delivery experience, covering pack assembly with contributor deadlines, controlled distribution with revocation, and annotation for directors. A full governance platform adding minutes and approval workflow, written resolutions with e-signature, conflicts and attendance registers, subsidiary board access and action tracking runs $200,000 to $500,000 phased over 7 to 12 months. This is the one category where we tell most buyers not to build. Diligent Boards or OnBoard will beat a custom project unless you have a structural reason, and the reasons are residency, group complexity or integration.
Why board packs go wrong in the last 48 hours
The board meets Thursday. Papers were due to the company secretary on Friday. By Monday afternoon four of eleven have arrived. The finance pack lands Tuesday morning, the strategy paper Tuesday evening with a note that the numbers on page six are provisional. The secretary assembles a PDF, paginates it, and emails it to eleven directors. Wednesday at 11pm the CFO sends a corrected page six.
Now there are two packs in eleven inboxes, and one director downloaded the first to an iPad, annotated it on the train, and will arrive Thursday having prepared against a superseded number. A second director forwarded the pack to their assistant to print. A third is a non executive who sits on a competitor's board in an adjacent sector and has just received a paper about a transaction they should have been walled out of, because the distribution list is a group in the secretary's email client and nobody edits it under pressure.
Then the meeting happens. Minutes get drafted from the secretary's notes over the following fortnight, circulated by email for comment, revised, and approved at the next meeting, by which point the action from item seven has been forgotten by everyone except the person who did not do it. Attendance is recorded in the minutes. Declarations of interest are in a standing register that lives in a Word document updated annually.
Every part of that is common at organisations that take governance seriously. The cost is not usually a dramatic breach. It is decisions taken on inconsistent information, an action log that exists in three places, and a paper trail that will not stand up if a regulator or a litigant asks how a decision was reached.
Problem 1: the pack is a build process and email cannot manage it
Assembling a board pack is a production job with contributors, deadlines, formats, page limits and an order. Doing it by email means the secretary is a manual build server: chasing, converting, paginating, bookmarking, and reissuing when anything changes.
What a custom build does: papers are items with an owner, a due date and a status. Contributors upload against the agenda item, and the pack compiles itself, paginated and bookmarked, at any point. If a paper changes after distribution, the pack version increments and every director's device gets the new version with the change flagged, rather than a second attachment arriving beside the first. Directors keep their annotations across versions where the page still exists, which is the feature that decides whether they use the portal or go back to printing.
Diligent Boards and Nasdaq Boardvantage both do this well. If pack assembly is your only pain, buy one of them. The reason to keep reading is what sits around the pack.
Problem 2: distribution is a security control, and email is not one
Board papers are the most sensitive documents most organisations produce: transactions before announcement, executive remuneration, litigation strategy, regulatory correspondence, security incidents. They are read by non employees on personal devices, sometimes on aircraft, sometimes by people who serve on several boards.
Email cannot revoke. When a director resigns, their inbox keeps every pack they ever received. A shared drive is barely better, because access removal does not touch what was downloaded.
What a custom build does: documents are served, not sent. Access is per director per pack, revocable, and revocation reaches the device. Offline access, which directors genuinely need, is granted as an encrypted local cache tied to the app and the user, wiped when access is withdrawn. Every open is logged, so if a paper leaks you have a distribution record rather than a shrug. Personalised watermarking on each rendering is a modest deterrent and worth having. We will also be honest about a limit: you cannot reliably stop someone photographing a screen, and any vendor claiming otherwise is overselling. What you can do is make casual copying inconvenient and deliberate copying attributable.
Problem 3: minutes, resolutions and the register are three documents that should be one record
The meeting produces several artefacts that most organisations manage separately. Minutes drafted after the fact. Resolutions passed in the meeting or later by written consent. Attendance, including who joined for which items, which matters when a director recuses. Declarations of interest made at the meeting, which should update a standing register. Actions with owners and dates.
Managed separately, these disagree. The minutes say a director declared an interest and withdrew for item five, and the standing register was never updated. A written resolution passed by circulation in August is filed in a folder and never makes it into the minute book.
What a custom build does: the meeting is the record. Minutes are drafted against agenda items with the pack still attached, so the paper the decision was based on is one click from the decision. Resolutions are objects with a status, a voting record and where required an e-signature, whether passed in the room or by written consent. A declared interest at the meeting updates the standing register and can trigger the recusal that removes that director's access to the relevant paper. Actions become tracked items that appear on the next agenda automatically with their status, which is the mechanism that stops the action log rotting.
Problem 4: subsidiary boards and committees break the simple model
A single board with four committees is a straightforward access model. A group with a plc board, an audit committee, a remuneration committee, a risk committee, two regulated subsidiary boards with independent non executives, a joint venture board with partner appointees and a charitable foundation is not. Membership overlaps. A director on the group board must not automatically see the regulated subsidiary's papers. The joint venture partner's appointees see their board and nothing else.
Products aimed at a single board handle this with separate workspaces, which means separate logins, separate packs and a secretary administering several instances. OnBoard and BoardEffect are good tools that are shaped for that simpler world.
What a custom build does: one identity per person, membership per body with dates, and access derived from membership at the time the pack was issued. A director who leaves the audit committee in March loses access to April's papers automatically and keeps the record of what they saw before. Where a group already maintains an entity register, the board and committee structures should be sourced from it rather than typed twice, which is one of the strongest genuine arguments for building rather than buying.
Problem 5: retention and residency are policy questions the software has to answer
Minutes and resolutions are corporate records with statutory retention expectations. Board packs, working drafts and annotations usually are not, and keeping them forever is a liability rather than a virtue, because everything retained is discoverable. Most organisations have never applied a deliberate retention rule to board material, so nine years of packs sit in a portal.
Regulated boards often also cannot accept a shared cloud tenancy, or need data held in a specific country. That constraint alone puts some organisations outside what the major vendors offer.
What a custom build does: retention as a rule per artefact type, with minutes and resolutions retained per policy and drafts and packs expiring on a schedule with a documented exception process for anything under legal hold. Hosting goes wherever your regulator or your risk committee requires, including your own tenancy. If residency is your reason for building, say so early, because it changes the architecture and the cost more than any feature does.
What this costs and how long it takes
Across the 2,000-plus projects Digital Heroes has delivered, the shape here is this. A first release covering agenda and paper collection with contributor deadlines, versioned pack compilation, controlled distribution with revocation, and director annotation on web and tablet runs $80,000 to $160,000 and ships in 12 to 18 weeks. A full governance platform adding minutes drafting and approval, resolutions with e-signature, attendance and conflicts registers, action tracking, subsidiary and committee structures and retention rules runs $200,000 to $500,000 phased over 7 to 12 months.
What drives cost up specifically for board systems: native tablet applications with offline access, which is a genuine second and third build rather than a responsive web page, and directors will demand it. Self hosting or a specific residency, which adds deployment and operations work. The number of boards and committees, since the access model is where complexity lives. E-signature integration for written resolutions. And the security review itself, because a board portal will be examined by your own risk function and possibly your regulator, and penetration testing plus remediation is a real line item you should budget rather than discover.
What keeps cost down: launching on the main board and one committee, with a web application first and the tablet app in the second phase once the pack model is settled.
Build versus buy, and when buying is the right call
We will say this more plainly here than in most categories: buy, unless you have a structural reason not to. Diligent Boards is the market standard and it is expensive because it is genuinely capable and because board material is unforgiving. OnBoard is a strong mid market option with better usability than its price suggests. BoardEffect fits nonprofit and healthcare governance well. If your problem is that pack assembly is painful and directors read old versions, a product solves that next quarter and a build solves it next year.
Build when one of these is true, and they are structural rather than about features. Your regulator or your risk appetite requires data in a specific jurisdiction or in your own tenancy, and no vendor offers it on acceptable terms. Your group has enough boards, committees, subsidiaries and joint ventures that per workspace licensing and administration has become its own job. You already run an entity management system and the duplication between it and a board portal is causing errors. Or your governance process has requirements the products genuinely cannot express, which is rarer than people think and should be tested against a real product demonstration before you commit a budget.
How to choose a developer for board and governance software
Ask what happens to a downloaded pack when a director resigns. If the answer does not include remote revocation of the offline cache, they are building a document sharing site and calling it a board portal.
Ask them to model a director who sits on the group board and the audit committee but must be walled out of one subsidiary. If they reach for a per document permission list maintained by hand, the company secretary will be maintaining that list forever and will make a mistake during a transaction.
Ask how annotations survive a pack reissue. Directors will not adopt a portal that discards their notes when page six changes, and this is the detail that decides whether the system is used or bypassed.
Ask about the security assurance you will get: penetration testing by an independent firm, the remediation process, and what evidence they will provide to your risk committee. Then ask who owns the code and where it is hosted, in writing, before kickoff. You should own the repository and the infrastructure accounts. At Digital Heroes the client owns the code from the first commit, and for a board portal we would insist on an independent security test before a single real pack is loaded.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- The federal government spends about 80% of its IT budget on operations and maintenance of existing systems rather than on development or modernization, with many critical systems being decades old. Source: U.S. Government Accountability Office (GAO) (2025) →
- Standish's 2015 CHAOS research found roughly a third of software projects (about 36% by the Modern definition) fully succeed on time, on budget, and on scope, with top success drivers including executive support, user involvement, and clear requirements/business objectives. Source: Standish Group (CHAOS Report) (2015) →
- A study (led by Prof. Pak-Lok Poon, published in Frontiers of Computer Science, 2024) reviewing decades of spreadsheet-quality research found that about 94% of spreadsheets used in business decision-making contain errors, illustrating the hidden risk of manual spreadsheet workarounds that custom software is built to replace. Source: Central Queensland University / phys.org (Prof. Pak-Lok Poon et al.) (2024) →
- The NRF discontinued its long-running annual shrink report, stating that a broad study of retail shrink 'is no longer sufficient for capturing the key challenges and needs of the industry' - important context that qualifies how POS/shrink benchmarks should be cited going forward. Source: Retail Dive (2024) →
Saanvi works on B2B Shopify builds at Digital Heroes, where the requirements shift from consumer checkout to company accounts, customer specific pricing, purchase orders and approval steps. Her posts help wholesale businesses see how much of that a commerce platform handles and how much needs building.
View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.
Frequently asked questions
Should we build a board portal or buy Diligent?
How much does a custom board portal cost?
How do you stop directors reading different versions of a pack?
What happens to board papers when a director resigns?
Can a portal prevent screenshots or photographs of board papers?
How do we handle group boards, committees and subsidiary boards in one system?
How should minutes, resolutions and interest declarations be linked?
How long should we keep board packs?
What security assurance should we require from a developer?
What happens if I stop paying for maintenance after launch?
Does the tech stack matter, and which one should I ask for?
Can we migrate years of data out of our current system into new custom software?
What should I have ready before I contact a development agency?
What is the biggest mistake first-time software buyers make?
We run everything on Airtable and spreadsheets. When is it time to go custom?
How do I work out whether custom software will pay for itself?
How long does it take to build a custom web or mobile app from scratch?
How do we get years of data out of our old system and into the new one?
Who can build a custom software system?
Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.