Skip to content
Retailium Help Center home

About the Retailium platform

What the platform does

The Retailium ORC Intelligence Platform helps retail loss prevention teams investigate and manage organized retail crime. Organized retail crime (ORC) is coordinated theft or fraud committed by criminal networks that target stores for profit: distinguished from one-off shoplifting by its organization, its recurrence, and its scale.

The platform's core value is connecting data across incidents, people, and locations to reveal crime networks that would otherwise stay hidden in separate store-level records. It brings together several kinds of work:

  • Recording security incidents at individual stores.
  • Grouping related incidents so a pattern across stores, dates, and suspects can surface.
  • Managing formal investigations (called cases) from start to close.
  • Creating and distributing BOLO ("be on the lookout") alerts about active suspects.
  • Running AI-assisted analysis to find gaps and connections in an investigation.
  • Visualizing where incidents concentrate through dashboards and a heat map.
  • Documenting non-crime accidents at stores for liability and insurance record-keeping.
  • Running scored in-store compliance checks (Store Assessment).

The main building blocks

A few record types appear throughout the platform. It helps to know how they relate before you start.

Incidents (the platform's word for a recorded crime event) are the foundation. An incident is one reported crime (a shoplifting, robbery, fraud, or similar), at one store, with its suspects, stolen products, witnesses, and vehicles. Incidents feed everything else: pattern detection, investigations, and BOLO alerts. In the app, this area is labeled Incidents.

Cases (also called investigations) are formal investigative records that track a criminal subject, crew, or operation over time. A case pulls together members (suspects and associates), activities, evidence, financials, and a network picture. Incidents can be linked to a case to bring their stolen-product data with them.

BOLOs are alert bulletins. A BOLO carries a suspect photo, an incident summary, and a description of the suspect's method, and it is circulated to store staff and partners. Every BOLO is created from either an incident or a case.

Entities are the people, vehicles, addresses, organizations, and sellers attached to a case. They form the nodes of the case's network graph.

Accident reports are a separate record type for non-crime events at a store, such as a slip-and-fall. An accident report is never an incident: the two are never counted, clustered, or linked together.

How the pieces connect

A typical flow runs from the ground up. A store records an incident. The platform automatically compares that incident against others and proposes connections where suspects, methods, timing, or vehicles line up. When a pattern emerges, an investigator promotes it into a case and works it in the case workspace. Along the way, they can generate a BOLO to warn stores about an active suspect, and use the analytics dashboards to see where crime is concentrating.

A word on what you will see

The platform serves many roles, from store-floor associates who file intake forms to administrators who manage the whole organization. What you can see and do depends on your role, on which investigative categories you belong to, and on which product areas your organization is entitled to. Before going further, read Roles and access so you know why some features described in this manual may not appear for you.