Industry guide · Business Intelligence Dashboards

Retail Loss Prevention Software: Why Exception Reports Never Turn Into a Case That Holds Up

Retail Shrink Loss Prevention software visual showing cctv, file search, and trending down.
The short answer

Expect $90,000 to $180,000 for a first release in 14 to 20 weeks covering exception rules run against your own POS (Point of Sale) and returns data plus a real case file with an evidence chain, and $250,000 to $600,000 phased over 9 to 15 months for a full platform adding video and RFID correlation, multi-store organised retail crime linking, restitution tracking and audit workflows. That is Digital Heroes delivery experience, not a list price. Build when you are past roughly 150 stores, your investigators assemble case packages by hand, and your exception rules were written by a vendor who has never seen your return policy. Do not build if you run under about 40 stores or your loss is mostly process error at receiving, because Agilence or Appriss Retail plus a disciplined store audit calendar will find more money faster than a project will.

Why exception reporting stops exactly where the case begins

It is 9pm on a Tuesday and a regional asset protection manager is working through the daily exception report for 340 stores. Store 118 shows a cashier with 41 no sale drawer opens on one shift. Store 402 shows a service desk associate who has processed 11 no receipt refunds to gift cards in eight days, every one of them landing just under the $75 supervisor approval threshold. A third flag is a buy online pick up in store order that was picked, marked collected, and refunded 40 minutes later at a different store. Three rows in a report. Not one of them is a case yet.

Turning those rows into something a prosecutor will accept means pulling video from two recorder brands whose clocks are 90 seconds apart, exporting POS journal detail at line level, matching a loyalty ID to a phone number that also appears on a marketplace listing, writing a narrative, and assembling the whole thing into a package that survives a defence attorney reading it. In the asset protection teams we have built for, an investigator burns six to twelve hours assembling a single organised retail crime package, and most of that is copying, renaming and cross referencing files. That is why the majority of flagged incidents quietly expire.

The typical stack is Appriss Retail scoring returns, Agilence or a POS vendor module producing till exceptions, Sensormatic or a similar system at the door, Everseen or another computer vision layer at self checkout if you have invested there, a separate video management system per acquisition, and a case file that is a folder on a shared drive named by store number and date. Every one of those products is competent inside its own boundary. None of them owns the object your team actually works: the case, with a suspect, a set of linked incidents across stores, an evidence list with hashes and custody, a restitution figure, and a status that a prosecutor or a civil recovery firm can act on.

Problem 1: the rule library is somebody else's shrink

Productised exception reporting ships with a rule library built from a broad sample of retailers. That is genuinely useful on day one and it is why Agilence and Appriss Retail earn their money at mid size chains. The limit is that your fraud is shaped by your policies, and your policies are not the sample. If you allow no receipt returns to a gift card up to $100, your abuse pattern forms at $99. If your price match policy permits an override without a manager code, that is where the leakage goes.

Vendor rules can be tuned, but tuning happens inside their model of a transaction. When your loss pattern depends on a field their schema does not carry, for example the specific override reason code your chain uses or the employee who authorised a produce markdown, the rule cannot be written at all. Teams then work around it by exporting to Excel every Monday, which is where an entire second shadow reporting function is born. That is not a reporting problem, it is an unbuilt system.

Problem 2: the case file is the product, and it lives on a desktop

A shrink number is an accounting result. A case is the thing that recovers money and stops the crew. The case has requirements no reporting tool was designed for: chain of custody on every clip and document, a record of who viewed what and when, notes that are discoverable and therefore must be written knowing they are discoverable, links between incidents that establish a pattern across seven stores in three districts, and a status pipeline that runs through interview, civil demand, police referral, prosecution and restitution.

When that lives in a folder plus a spreadsheet plus an inbox, two things break. The first is legal: you cannot prove an exported clip was not edited, and a defence attorney will ask. The second is intelligence: nobody can see that the store 118 incident and the store 402 incident share a vehicle plate captured six weeks apart, because those facts sit in two documents nobody has opened together. A custom build makes the case a first class record with append only evidence entries, file hashing at ingest, immutable audit logging, and entity resolution across suspects, vehicles, phone numbers and loyalty accounts. That entity graph is the single feature that converts a pile of incidents into an organised retail crime case, and it is the one no exception reporting tool will build for you because it depends on the identifiers your systems actually capture.

Problem 3: video, EAS and self checkout vision never agree on time

Correlating a transaction to footage sounds trivial and is not. Your POS timestamps come from one clock, your recorders from another, your Sensormatic pedestal alarms from a third, and stores acquired in the last merger run a video platform the rest of the estate does not. An investigator asked for the clip covering a 19:42:11 transaction gets footage that is a minute and a half off, and then spends fifteen minutes scrubbing.

What the build must include is unglamorous and it is the difference between a tool people use and shelfware. Clock drift measurement and correction per device. A camera to register mapping so a transaction resolves to the right lane view without a human choosing. Clip retrieval by transaction rather than by time, so an investigator clicks a line on a receipt and gets the frames. Automatic pull and retention of clips attached to an open case before the recorder's 30 day overwrite destroys them, which is the single most common way a case is lost.

Problem 4: refund abuse moved omnichannel and the rules did not

The interesting fraud is no longer at a single till. It is a return of an item that was never shipped, a ship from store order cancelled after pick, a curbside handoff marked complete with no customer present, a gift receipt refunded at a store 200 miles from the purchase, and a marketplace listing of items that match your shrink profile SKU for SKU. Appriss Retail is strong on the returns side specifically because it sees a consortium view of return behaviour. What it does not see is your fulfilment system's pick, pack and handoff events, because those live in your order management platform.

A custom build joins order lifecycle events to POS and returns in one timeline per customer identity. That lets you write the rules that actually matter to an omnichannel chain: refund issued without a corresponding fulfilment completion, collection scanned by an associate who also processed the refund, repeat cancellations from one account across many stores, or return velocity by delivery address rather than by loyalty ID, since the fraudster changes the ID and keeps the address.

Problem 5: you cannot separate theft from process loss, so you fund the wrong fix

Every asset protection budget conversation eventually reaches the same question: how much of this shrink is theft. Most chains cannot answer it because receiving variances, unrecorded damages, markdown errors, expired product write offs and actual theft all land in the same inventory adjustment bucket at count time. So the response is uniform: more guards, more locking fixtures, more source tagging, applied evenly across stores whose loss has different causes.

What a build adds is attribution. Receiving variance is captured at the door against the ASN, not reconciled at count. Damage and markdown are their own coded events with a photo and an employee. Then the shrink number decomposes by cause, by store, by category and by shift, and the investment argument changes completely. In our delivery experience this analysis is what wins the budget argument, because a VP of Asset Protection can finally say which portion of the number is addressable by which intervention.

What this costs and how long it takes

A first release covering exception rules against your own POS, returns and fulfilment data plus a proper case file with evidence chain and audit logging runs $90,000 to $180,000 and ships in 14 to 20 weeks. That is a system your investigators work in daily, not a dashboard. A full platform adding video correlation with clock drift handling, EAS and self checkout vision events, entity resolution across stores, civil recovery and restitution tracking, store audit workflows and executive shrink attribution reporting runs $250,000 to $600,000 phased across 9 to 15 months.

What pushes the number up in this category specifically: the number of distinct video platforms in the estate, because each integration is real weeks and some older recorders have no usable API at all. POS heterogeneity after acquisitions, since two journal formats means two parsers and two sets of rules. Data volume, because a 500 store chain generates a transaction line volume that forces a columnar store rather than a general purpose database. And legal review of retention and access, which is not optional when the records are discoverable.

What keeps it down: starting with returns and refunds only, at your worst 30 stores, with video correlation deferred to phase two. Refund abuse is usually the fastest recoverable money and it proves the case model before you spend on integrations.

Build versus buy, and when buying is the right call

Buy if you are under roughly 40 stores. Agilence or Appriss Retail plus a store audit programme will surface more than you can act on, and a build would be spending capital to avoid a subscription. Buy if your shrink is concentrated in receiving and damages rather than theft, because your fix is a process and a scale at the back door, not software. Buy if your video estate is a single modern platform and your POS is one vendor across the chain, since the integration pain that justifies a custom build is largely absent.

Build when two or more of these are true. Your investigators assemble case packages by hand and cases are being lost to recorder overwrite. You run more than one POS journal format or more than two video platforms. Your loss is organised rather than opportunistic, meaning you need cross store linking and an entity graph rather than a per store report. Your return policy has enough exceptions that vendor rules cannot express it. Or you have been asked by a prosecutor for something you could not produce, which is the moment most chains we work with pick up the phone.

How to choose a developer for loss prevention software

Ask them to describe the evidence chain before they describe the dashboard. A developer who has done this will talk about hashing on ingest, append only storage, immutable access logs and retention policy per record type, and they will ask who your legal counsel is. A developer who opens with charts is building reporting, and you already have reporting.

Ask specifically how they handle clock drift between POS and video, and how a clip gets pulled and preserved before the recorder overwrites it. If they have not hit this, they have not shipped in retail asset protection and you will discover it in month four.

Ask what they have actually integrated by name. An Oracle Retail Xstore journal is a different problem from a NCR or Toshiba one. Milestone or Genetec video export is different from a proprietary DVR with no documented interface. Sensormatic pedestal events are different again. Ask for the vendor and the version, not a claim about integrations in general.

Ask who owns the code and get it in writing before kickoff. You should own the repository, the cloud accounts and the right to hire anyone else to continue the work. At Digital Heroes the code is yours from the first commit, and given that this system will hold evidence, a developer who wants to keep the repo or host it on their own accounts is a risk you should refuse.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Deloitte reports that modern ERP implementations aim to deliver reduced manual effort, greater transparency, a single source of truth, and increased productivity, but many organizations do not capture the full expected benefits (a significantly lower ROI) without disciplined strategy, change management, and data readiness. Source: Deloitte (2024) →
  2. An independent Forrester Total Economic Impact study of OutSystems found a 363% three-year ROI with payback in under 6 months, illustrating that faster, lower-labor build approaches can materially shift the payback math. Source: Forrester Consulting (commissioned by OutSystems) (2024) →
  3. U.S. retailers lost an average of 1.6% of sales to shrink in FY2022 (up from 1.4% the prior year), equating to $112.1 billion in inventory losses - the benchmark case for POS-integrated loss prevention and inventory accuracy. Source: National Retail Federation (NRF) (2023) →
  4. IBM frames first-time fix rate as a core field service KPI, noting the industry average sits around 80% (roughly one in five jobs needs a return visit). Correction: IBM cites best-in-class providers at 89-98%, not '85%+'. Source: IBM (2024) →
Shreyansh S. · Managing Director · Lucknow

Shreyansh runs the Lucknow operation, sitting between clients who need software built and the teams who build it. Most of his week goes on scoping work honestly, deciding what a project should and should not include, and keeping delivery promises realistic. He writes for readers weighing up whether to commission custom software at all.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom retail loss prevention software cost for a 300 store chain?
A first release with exception rules against your own POS and returns data plus a real case file and evidence chain runs $90,000 to $180,000 and ships in 14 to 20 weeks in Digital Heroes delivery experience. A full platform with video correlation, cross store organised retail crime linking and restitution tracking runs $250,000 to $600,000 phased over 9 to 15 months. The cost drivers specific to a chain that size are the number of video platforms in the estate and whether acquisitions left you with more than one POS journal format.
Is Appriss Retail or Agilence enough, or do we need to build?
They are strong products and for a chain under roughly 40 stores they are the right spend. Appriss Retail is particularly good on return behaviour because it sees a consortium view you cannot replicate. The gap appears when your rules need fields their schema does not carry, such as your specific override reason codes, or when you need fulfilment events from your order management system joined to POS in one timeline. If your team is exporting to Excel every week to answer basic questions, that gap is already costing you.
What makes an organised retail crime case package hold up in court?
Chain of custody is the whole answer. Every clip and document needs a hash recorded at ingest, an immutable log of who accessed it, and storage that nobody can quietly edit, because a defence attorney will ask whether the footage was altered. The second requirement is preservation timing: a clip attached to an open case must be pulled and retained before the recorder overwrites it, which is the most common way a case dies. Involve your legal counsel in the retention and access design, not after it ships.
How long does it take to build a loss prevention case management system?
Fourteen to twenty weeks for a working first release covering exception rules, case files and evidence chain. Video correlation adds meaningfully to that and should usually be a second phase, because each video platform integration is real weeks and older recorders sometimes have no usable interface at all. The fastest projects start with returns and refund abuse at the worst thirty stores, which proves the case model before anyone spends on integrations.
Can we connect video, EAS and self checkout vision to transactions automatically?
Yes, and the unglamorous part is what makes it work: measuring and correcting clock drift per device, mapping cameras to registers, and retrieving clips by transaction rather than by timestamp. Once that exists, an investigator clicks a receipt line and gets the frames instead of scrubbing for fifteen minutes. Systems from Sensormatic at the door and computer vision at self checkout become additional event streams on the same case timeline rather than separate dashboards nobody opens.
How do we tell how much of our shrink is actually theft?
You separate the causes at the moment they happen rather than at count time. Receiving variance gets captured at the door against the advance ship notice, damages and markdowns become coded events with a photo and an employee attached, and theft related incidents carry a case reference. Then shrink decomposes by cause, store, category and shift. Most chains cannot do this today because every one of those losses lands in the same inventory adjustment bucket, which is why the response is always more guards everywhere.
Where does AI genuinely help in loss prevention, and where is it hype?
Two places earn their keep. Entity resolution across suspects, vehicles, phone numbers, addresses and loyalty accounts is what turns scattered incidents into one organised retail crime case, and it is a matching problem that machine learning handles far better than rules. Narrative drafting from structured incident data saves an investigator real hours per case. Anomaly detection that replaces your rule set entirely usually underperforms, because your best rules encode policy knowledge a model cannot infer from transactions alone.
Who owns the code if an agency builds our asset protection platform?
You should own the repository, the cloud infrastructure accounts and the unrestricted right to hire another firm to continue the work, and it belongs in the contract before kickoff. This matters more than usual here because the system holds evidence and access logs that you may need to produce in court, and you cannot have that sitting in a vendor's account. At Digital Heroes the client owns the code from the first commit. Ask this question first, not last.
Do we need custom software if we only have 25 stores?
Almost certainly not, and we would say so before quoting. At that size Agilence or Appriss Retail plus a consistent store audit calendar will surface more exceptions than your team can work, and the money is better spent on people to work them. The build case starts when investigators are assembling packages by hand, when cases are being lost to recorder overwrite, or when your loss is organised across stores and you need suspect linking that a per store report cannot give you.
How long does it take to build a custom web or mobile app from scratch?
Plan on 8 to 16 weeks for a focused first version and 4 to 9 months for a larger platform, which is the typical spread across Digital Heroes builds. The first 2 to 3 weeks go to discovery and design before any production code ships. The two things that stretch timelines most are integrations with legacy systems and slow feedback from your side, not developer speed.
How long does it take to build a custom BI dashboard?
A working first version usually ships in 4 to 8 weeks, and a full production build with multiple integrations and permissions takes 3 to 6 months. In Digital Heroes delivery experience, schedules slip on data access, meaning credentials, API approvals, and cleanup of source data, far more often than on the dashboard screens themselves. Lining up access to every data source before kickoff routinely saves 2 to 3 weeks.
When is it time to move from Excel reports to an actual dashboard?
The reliable signal is when someone spends more than a few hours a week copying data between spreadsheets, or when two teams arrive at a meeting with different numbers for the same metric. At that point the spreadsheet is acting as an unversioned, single-person database, and a costly error is a matter of time. A first dashboard that automates those recurring reports typically pays for itself in recovered hours within the first year.
How do I calculate whether custom software will pay for itself?
Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.
Can custom software connect to the tools we already use, like QuickBooks, Stripe, and Google Workspace?
Yes, and connecting your existing tools is one of the main reasons to build custom: mainstream platforms like QuickBooks, Stripe, Shopify, and Google Workspace all publish documented APIs. Budget 1 to 3 weeks of work per integration depending on API quality and how much data flows in both directions. Ask any vendor whether they have integrated with your specific tools before, because quirks like QuickBooks' OAuth token handling and API rate limits get learned on someone's project, and it should not be yours.
What do I need to prepare before contacting an agency about a dashboard project?
Bring three things: a list of your data sources with who controls access to each, the 5 to 10 recurring decisions the dashboard should support, and examples of the reports or spreadsheets it will replace. That package lets an agency quote in days instead of weeks, and in our discovery work it cuts the audit phase roughly in half. You do not need wireframes or a technical spec; a good agency produces those with you.
Who owns the code, data models, and pipelines when an agency builds my dashboard?
You should own all of it, and the contract should say so explicitly: source code, data models, pipeline configurations, and infrastructure accounts in your name, with IP transferring on final payment. The trap to avoid is an agency hosting your dashboard on their proprietary platform, which quietly turns a custom build back into vendor lock-in. Digital Heroes delivers into the client's own cloud accounts and repositories by default, and any agency should agree to the same in writing.
How do I make sure each client sees only their own data in a shared dashboard?
That is row-level security, and it must be enforced in the database or API layer, never by hiding filters in the interface. Each query carries the logged-in client's identity, and the data layer refuses to return rows outside their account, so a crafted URL or modified request cannot leak another client's numbers. Make any vendor show you exactly where that filter lives, because interface-level filtering is the most common security mistake we find when auditing dashboards built elsewhere.
How do I vet a software development agency before signing a contract?
Ask to speak with two past clients whose projects resemble yours in size and industry, and ask exactly who will write your code, since some agencies sell senior faces and deliver junior or subcontracted hands. Demand a written specification with acceptance criteria before any fixed price, and check that their portfolio links to products that are actually live. An instant quote given without questions about your workflows is the clearest warning sign there is.
Should I embed Power BI or Tableau in my SaaS product, or build custom charts?
Embed first if you need analytics inside your product within weeks, but treat it as a bridge rather than the destination. Embedded licensing meters your customer traffic, so your analytics cost grows with your user count, and the look and feel never fully matches your product. In Digital Heroes projects, SaaS teams usually switch to custom charts built in React with a library like ECharts or Recharts once analytics becomes a selling point instead of a checkbox.
Who can build a custom business intelligence dashboards system?

Digital Heroes builds custom business intelligence dashboards systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other business intelligence dashboards companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?