Skip to content
Retailium Help Center home

Review and update an incident

Summary: You will open an incident to review its full record and perform the common follow-up actions.

Open and read an incident

Select an incident from the Incidents list to open its detail view. The view opens with six summary tiles: incident date, store, total loss, number of suspects, number of items stolen, and whether police were contacted.

Below the tiles are the incident's details, narrative, observation method, CCTV availability, and police information, along with which case the incident is linked to. Cards follow for suspects, products, witnesses, vehicles, and attachments. A suspect card shows the photo and description, including the generated visual description when one exists.

Attachments download through short-lived links created at the moment you select them: no permanent public link to a file ever exists.

Reading times and timezones

An incident's date and time belong to the store, not to you. Every screen shows the store's local time with its zone abbreviation, followed by your own time in parentheses: for example 8/17/2026, 8:00 PM PDT (8/17/2026, 11:00 PM EDT). On dense screens such as lists and map popups, only the store's time shows inline; the full form is in the tooltip.

Times taken from an imported document (such as a suspect's entry and exit times) are kept exactly as the document worded them ("around 4:15," "afternoon") and are never converted or sorted. The Incidents list always filters and sorts on the recorded event time, not the written-down one.

Track recovered merchandise

You can record how much of the stolen product was recovered.

  1. On the detail view, switch the Total Loss tile into its editable state.
  2. Enter a recovered quantity per product. These roll up into a recovery total for the whole incident.

Recovered quantity can never exceed the quantity stolen: the control will not go past it, and the limit is enforced when you save.

Note: Which roles can edit recovery figures is still being settled. If you expect the Edit Recovery control and do not see it, this is why.

You can link an incident to a case, and unlink it again later.

  • Linking attaches the incident to the case and copies every stolen product on the incident into the case's stolen-items list. Linking the same incident twice never duplicates those items.
  • The case picker offers only open cases you could already open yourself (and all of them. It is scoped by the same category rules that govern case access, so a case in a category you do not hold is neither offered nor named. It also omits cases this incident is already linked to. There is no cap, so you can reach the fifty-first open case. There is no search box on the picker yet, so an organization with many open cases gives you a long list to scroll), a known gap, not a limit.
  • Unlinking detaches the incident and removes the case items that came from it, in that case only. The confirmation names how many items will go and where they end up: "This also removes N stolen product item(s) previously imported into this case's Case Items. Removed items are soft-deleted: kept in the record and restorable by an administrator."
  • One incident can be linked to more than one case. Unlinking from one leaves the others untouched.

Generate a BOLO

Select Generate BOLO to create an alert from this incident. The dialog opens pre-filled from the incident's own fields. See Create a BOLO from an incident for the full flow.

Export the incident

Any role that can view an incident can download it as a branded PDF containing the incident details, stolen products, suspects, vehicles, witnesses, and the suspect and vehicle photos. (Store associates are the exception: they cannot export.)

  • Empty sections are left out of the document.
  • Photos are embedded, so the PDF is complete and permanent on its own: it contains no links that expire.
  • A photo that cannot be retrieved is left out and the rest of the export still succeeds.
  • Export covers one incident at a time; there is no bulk export.

Edit or delete

Editing opens the same form as creation, pre-filled. Saving an edit re-checks the incident against other incidents, so a correction can change which connections are proposed.

Deleting is a soft delete, no incident is ever truly erased, but it takes effect everywhere at once:

  • The incident disappears from the Incidents list, from search, from every case tab that showed it, and from the network picture.
  • Its proposed and confirmed connections, its place in any cluster, and its entry in the matching index are removed. There is no undelete: even if the record were restored, those relationships would have to be rebuilt.
  • Stolen items copied into a case from this incident are removed from every case that received them.
  • Any BOLO built from the incident keeps its content, but the audience it reaches is recalculated without the deleted incident.