Industry guide · Internal Tools

Physical Security Information Management: When the Badge Alarm and Its Video Live in Two Different Systems

Physical Security Information Management software visual showing cctv, id card, and layout dashboard.
The short answer

If you run a global or regional security operations centre over an estate with three or more access control and video vendors, and an operator has to phone a local team to see what happened at an alarm, build. A focused first release covering event normalisation from two access control systems and two video platforms, a correlated alarm queue, and one response procedure typically runs $120,000 to $260,000 and ships in 16 to 24 weeks in our delivery experience. A full platform adding identity resolution across systems, mapping, mass notification, guard tour and audit reporting runs $300,000 to $800,000 phased over 10 to 18 months. If your whole estate runs one vendor, standardise on that vendor's platform instead.

Why a global security console can be blind at 3am

An operator in a security operations centre sees a forced door alarm at a site in another region. He needs three things immediately: who badged in that area in the last ten minutes, the video covering that door, and the procedure for this alarm at this site. What he actually has is a console showing the alarm text and a phone number for the local facilities manager. The site was acquired four years ago, it runs an access control platform nobody at head office has credentials for, and its video sits on a recorder behind a site firewall that the network team locked down after a security review. He calls the local team.

That is the normal condition in large estates. The corporate standard exists on paper, and the estate is a museum of every vendor and firmware generation acquired over two decades. Head office standardised in 2019, which means the fifteen sites bought since then are standardised and the other seventy are not. Meanwhile the operating model assumes one operating picture, because that is what the security function was funded to deliver.

The consequence is not usually a dramatic breach. It is response time and evidence quality. An incident gets handled in twenty five minutes instead of four because the console could not answer basic questions, and afterwards the investigation packet has to be assembled by hand from three systems by people who have to be woken up. In the security integration work we have delivered, the metric that moves first is time to first useful evidence, and it moves a long way.

Problem 1: every acquired site speaks a different dialect

Access control and video are mature markets with genuine standards, and the standards only take you part of the way. ONVIF gives you a common approach to many video devices, but profile support varies by device and generation, and the recorder's own interface still holds the recorded footage and its bookmarking. On the access side, older readers on Wiegand and newer ones on OSDP behave differently, and the head end platforms expose events through SDKs, database connections, or in some cases nothing you are allowed to use without a licence.

Then there is the estate reality. Servers on site rather than centrally. Firmware several versions behind because upgrading means a maintenance window in an operating facility. Sites where the integrator who installed the system is out of business and nobody has the admin password.

What a custom build does: a connector per system and generation that normalises events into one internal model, with the connector deployed close to the site rather than assuming central access, and with an explicit contract about what it may do. Read only is the right default. A central console that can unlock doors across an estate is a much larger risk conversation than one that observes and escalates, and starting read only usually gets you through security review months earlier.

Problem 2: correlation is the actual product, and identity is the hard part

A PSIM is worth having only if it can answer questions that span systems. Show me everyone in this zone right now. Show me this person's movements across all sites in the last hour. Show me the video for this badge event without knowing which recorder owns the camera.

Every one of those questions breaks on identity. One employee exists as five different records with five different card numbers in five access systems, plus a record in the identity provider, plus a contractor entry with a different spelling of their name. Nobody has ever reconciled those, because inside each site the local record was sufficient.

What a custom build does: an identity resolution layer that maps person records across systems to a single subject, sourced where possible from your directory or joiners and leavers process rather than from the access systems themselves. Then a card, a badge event, a camera, a door, and a floor plan position all attach to a common model, and correlation becomes a query rather than a phone call. This is also the layer that lets you answer the audit question nobody enjoys: which credentials does this departed contractor still hold, across all systems.

Camera to door mapping deserves its own attention. In most estates it lives in a drawing. Making it explicit data is what turns a badge event into an evidence packet automatically.

Problem 3: what Genetec, Qognify Situator and Vidsys actually do

Genetec Security Center is a strong unified platform and if you can standardise your estate on it, that is often the right answer and cheaper than integrating around it. The honest limitation is what it is optimised for: it is at its best as the system of record for access and video, so the more of your estate you migrate to it, the better it gets. If your reality is seventy sites on other vendors that you are not going to replace, you are asking a platform to be an integration layer for its competitors, and depth varies by which competitor.

Qognify Situator and Vidsys are genuine PSIM products with real strength in situation management and response procedures, which is exactly the part most homegrown attempts underestimate. The practical considerations are deployment weight and change cost: integration modules are built and licensed per device type and firmware generation, professional services cycles are long, and adding a newly acquired site with an unusual system is a vendor engagement rather than an internal task. Vendor consolidation in this market has also been active, so ask directly about roadmap and support commitments for the specific modules your estate depends on before you commit.

The honest decision rule: if your estate can be standardised, standardise. If it genuinely cannot, then you are choosing between a PSIM product where each new site is a vendor project and a build where each new site is your own connector. That choice comes down to how often your estate changes and whether you have or can hire the engineering capability.

Problem 4: response procedures are policy, and generic workflow does not encode policy

The value of a situation management layer is that an operator at 3am is guided rather than improvising. What guidance means is specific: for this alarm type, at this site, during these hours, do these steps in this order, notify these people, log these decisions, and escalate if step three is not complete in six minutes.

That content is your security policy, and it differs by site, by jurisdiction, by tenancy agreement, and by whether the site is manned. It is also revised after every incident review. If changing a procedure requires a vendor ticket, the procedures will go stale and operators will revert to a laminated card.

What a custom build does: procedures as versioned, editable data owned by your security operations team, with each step recorded as it is completed, including who did it and when. Two benefits follow. Operators get consistent handling, and the post incident review has a real timeline instead of recollections. That timeline is also what defends the organisation when the handling of an incident is questioned.

Problem 5: connecting everything centrally is itself a risk you must design for

The moment you build a console that reaches every security system in the estate, you have created a target and a data protection obligation. Movement data about identified people is personal data in most jurisdictions, video adds more, and any use of biometrics brings its own rules that vary significantly by country and by state, so this is a question for your privacy counsel rather than your integrator.

What a good build does: segmented connectors with least privilege credentials, read only by default and any control capability separately approved and separately audited, retention rules per data type and per jurisdiction enforced by the system rather than by policy documents, and an audit log of operator access to footage and movement history. Your own security engineering team will ask for this. It is far better to design it in than to be sent back after a review, which typically costs a quarter.

What this costs and how long it takes

Across the 2,000-plus projects Digital Heroes has delivered, this is the honest shape. A focused first release covering connectors for two access control systems and two video platforms, event normalisation, a correlated alarm queue with camera to door mapping, and one response procedure runs $120,000 to $260,000 and ships in 16 to 24 weeks. A full platform adding identity resolution across systems, mapping and situational display, mass notification, additional connectors, guard tour and patrol, visitor integration, and audit and reporting runs $300,000 to $800,000 phased over 10 to 18 months.

What drives price up specifically here: the number of distinct system types and firmware generations, since each connector is a discrete piece of work and the awkward ones are legacy platforms with poor or undocumented interfaces. Whether vendors will licence you interface access at all, which is a commercial negotiation that can outlast the engineering. Network and security review cycles in a large organisation, which are real months. Any control capability beyond read only. Video specifically, because live streaming and recorded retrieval across mixed recorders is materially harder than event ingestion. And geographic spread, which brings data residency and retention differences.

What keeps price down: starting with the two systems that cover most of your alarm volume, read only, and one region, then proving the response time improvement before extending the estate.

Build versus buy, and when buying is right

Buy, and standardise, if your estate is small enough or homogeneous enough that migrating to a single unified platform is realistic within a couple of budget cycles. One vendor doing access and video well beats an integration layer over a mess, every time, if you can actually get there.

Buy a PSIM product if your estate is mixed but stable, you have a modest number of system types, and your security team would rather manage a vendor than an engineering backlog. That is a legitimate and common answer.

Build when the estate changes faster than a vendor engagement cycle, which is the case for any organisation acquiring sites regularly. Build when your operating picture has to include systems no PSIM covers, such as internal case management, HR (Human Resources) joiners and leavers, travel security, or building systems. Build when you have been quoted per site integration fees that make the total look absurd across a large estate. And build when the procedures encode policy that changes after every incident review, because that content has to be yours to edit.

How to choose a developer for PSIM and security integration

Ask how they would resolve one person appearing as five records across five access systems. If they do not immediately reach for the directory or the joiners and leavers process as the authority, the correlation will never be trustworthy and every query you care about depends on it.

Ask what they have actually integrated, by vendor and by generation. Reading events from a current version platform with a documented interface is routine. Getting reliable events from a decade old head end at a site with no vendor support is the work, and it is where the schedule risk sits.

Ask how they will pass your security engineering review. The right answer starts with least privilege, segmentation, read only defaults, credential handling, and an audit log of operator access to footage. If security review comes up as an afterthought, expect the project to lose a quarter to it.

Ask who owns the code and settle it in writing before kickoff. You should own the repository, the cloud and on premise infrastructure, and the right to hire anyone else. At Digital Heroes the client owns the code from the first commit, and in a security context you should be able to have any part of the system independently reviewed without asking a supplier's permission.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. A study (led by Prof. Pak-Lok Poon, published in Frontiers of Computer Science, 2024) reviewing decades of spreadsheet-quality research found that about 94% of spreadsheets used in business decision-making contain errors, illustrating the hidden risk of manual spreadsheet workarounds that custom software is built to replace. Source: Central Queensland University / phys.org (Prof. Pak-Lok Poon et al.) (2024) →
  2. The median annual wage for U.S. software developers was $133,080 in May 2024, and employment is projected to grow 15% from 2024 to 2034 - a core input to any in-house build-vs-buy TCO model. Source: U.S. Bureau of Labor Statistics (2024) →
  3. Only 22% of firms are 'future ready' having significantly transformed digitally; these companies show average revenue growth 17.3 percentage points and net margins 14.0 percentage points above their industry average. Source: MIT Center for Information Systems Research (MIT Sloan) (2022) →
  4. Gallup reports global employee engagement fell to 20% in 2025 (its lowest since 2020, down from a 2022-2023 peak of 23%), and estimates low engagement costs the world economy an estimated $10 trillion in lost productivity, or 9% of global GDP. (Note: this figure appears in Gallup's evergreen State of the Global Workplace page, currently reflecting the 2026 edition reporting on 2025 data.). Source: Gallup (2025) →
Tahlia L. · Senior Mobile Designer · Sydney

Tahlia designs mobile apps at Digital Heroes, working close to the iOS and Android engineers who build them. Day to day that is screens, states, motion and the specs that tie them together. Her posts are for anyone weighing up what a good app actually takes to design.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom PSIM software cost for a global security operations centre?
A focused first release covering connectors for two access control systems and two video platforms, event normalisation, a correlated alarm queue with camera to door mapping, and one response procedure typically runs $120,000 to $260,000 and ships in 16 to 24 weeks, based on Digital Heroes delivery experience. A full platform adding identity resolution, mapping, mass notification, additional connectors, and audit reporting runs $300,000 to $800,000 phased over 10 to 18 months. Cost scales with the number of distinct system types and firmware generations rather than the number of sites.
Is Genetec Security Center a PSIM, and is it enough?
Genetec Security Center is a strong unified platform for access control and video, and if you can migrate your estate onto it, that is often better and cheaper than integrating around it. It is optimised as the system of record rather than as an integration layer for competing vendors, so the value increases with the share of your estate that runs on it. The mismatch appears when most of your sites run other vendors you have no plan to replace.
What should we ask Qognify Situator or Vidsys before buying?
Ask which specific integration modules exist for your actual systems including firmware generations, what a newly acquired site with an unfamiliar platform costs to add, and how long that engagement takes. Ask who can edit response procedures, your team or the vendor, because procedures change after every incident review and vendor tickets guarantee they go stale. Vendor consolidation in this market has been active, so ask directly about roadmap and support commitments for the modules you will depend on.
Why can't our operators pull video for an access control alarm?
Because in most estates the mapping between a door and the cameras that cover it exists in a drawing or in someone's memory rather than as data, and the recorded footage sits on a site recorder that the central console has no authenticated route to. Fixing it needs two things: explicit camera to door mapping as maintained data, and a connector deployed close to the site that can retrieve footage on request. Neither is exotic, and skipping either leaves the operator on the phone.
How do you handle one employee having different card numbers in every system?
With an identity resolution layer that maps person records across systems to a single subject, sourced from your directory or joiners and leavers process rather than from the access platforms, which each believe their own record is authoritative. Without it, questions like where is this person now or which credentials does this departed contractor still hold cannot be answered reliably. It is usually the highest value component after basic event ingestion.
How long does a PSIM integration project take?
A first release usually ships in 16 to 24 weeks in our experience, covering two access systems and two video platforms in one region. The schedule risk is rarely software. It is obtaining vendor interface access on commercial terms, getting network paths approved by security engineering, and finding credentials for sites whose original integrator is long gone. Treat those three as work streams with owners from week one rather than as assumptions.
Should a central security console be able to unlock doors?
Start read only and treat control as a separate, separately approved capability. A console that can act across an entire estate is a much larger risk conversation and it will slow your security review considerably, while an observation and escalation system delivers most of the operational value immediately. When control is added later, it should carry its own authorisation model and its own audit trail rather than inheriting operator permissions.
What privacy obligations come with centralising access and video data?
Movement data about identified people is personal data in most jurisdictions, video adds to that, and biometric data carries additional rules that differ significantly by country and by state. That makes retention periods, access controls, and audit logging of who viewed which footage design requirements rather than policy documents. Get your privacy counsel involved before the architecture is fixed, because retention and residency rules directly shape where data is stored.
Who owns the code if an agency builds our security integration platform?
You should own the repository, the cloud and on premise infrastructure, and the unrestricted right to hire another firm, settled in the contract before kickoff. At Digital Heroes the client owns the code from the first commit. In a security context this is more than commercial hygiene, because you should be able to have any component independently reviewed or penetration tested without needing a supplier's permission.
How long does it take to build an internal tool from scratch?
A working first version typically ships in 4 to 8 weeks, and larger multi-module tools run 10 to 16 weeks. Across Digital Heroes internal tool projects the schedule splits into roughly one week of process mapping, 3 to 6 weeks of build, and 1 to 2 weeks of testing with your actual staff. The most common delay is not development but waiting on the client for sample data and workflow decisions, so name one internal owner before kickoff.
How much should a small business budget for its first custom app or website?
For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.
What are the biggest mistakes first-time software buyers make?
Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.
What does it cost to keep an internal tool running after launch, and do we need to hire a developer?
Budget 15 to 20 percent of the build cost per year, so a $25,000 tool runs roughly $300 to $400 a month covering hosting, security patches, dependency updates, and small tweaks, figures drawn from Digital Heroes maintenance contracts. You do not need an in-house developer; a monthly retainer with the agency that built it covers the typical internal tool comfortably. Hosting itself is cheap for internal audiences, often $20 to $100 a month, because you serve dozens of users rather than the open internet.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
Who owns the code when an agency builds my software?
You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.
At what point does Retool cost more than building a custom tool?
The crossover usually lands between 25 and 50 daily users. At Retool's published Business rates of $50 per standard user and $15 per end user monthly, a 40-person deployment with a typical seat mix runs roughly $9,000 to $15,000 per year, every year, while a comparable custom tool built once for $20,000 to $30,000 carries no per-seat fees and costs about 15 to 20 percent of the build price annually to maintain. On a three-year horizon, custom comes out ahead for most growing teams in Digital Heroes engagements.
How many developers does it take to build an internal tool?
Two to four people covers nearly every internal tool: one or two developers, a part-time designer, and a project manager who doubles as your single point of contact. Internal tools rarely need consumer-product polish, so a full-time dedicated designer is usually wasted budget. On Digital Heroes projects, a two-person core team handles the typical 4 to 8 week build, with a specialist pulled in briefly for a tricky integration or a security review.
Should we build the whole internal tool at once or start with an MVP?
Start with a version that fully replaces one workflow, ship it in 4 to 6 weeks, and let real usage set the roadmap. Internal tools have a captive audience, so you learn within days which features matter, and across Digital Heroes projects roughly a third of initially requested features never get built once staff work with version one. Phasing also spreads the spend: a $40,000 vision becomes a $15,000 phase one that starts paying for itself while phase two is scoped.
What tech stack should an internal tool be built with?
Boring and popular: a React or Next.js frontend, a Node.js or Python backend, and PostgreSQL covers the vast majority of internal tools and keeps future hiring easy. The stack matters far less than whether a different developer can pick the code up in two years, so require documentation as a deliverable and avoid anything exotic. Treat it as a red flag if an agency pushes a proprietary platform only they maintain, because that quietly converts your tool into a subscription to that agency.
How do I calculate whether custom software will pay for itself?
Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.
Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?