Home / Use Cases / Retail

Use Case · Retail · India

AI CCTV for Retail Stores

AI CCTV for retail turns store cameras into a loss prevention and operations system. Models detect theft cues, staff anomalies and queue spikes, package the evidence, and route it to whoever is on shift. Footfall and heatmap data come from the same cameras, running on site.

Dr Vivek Gujar, Chief Strategy Officer · 27 August 2026 · 13 min read

Retail loss is rarely one dramatic event

Store managers picture shrinkage as a person walking out with an armful of stock. That happens, and it is the easiest kind to catch. The losses that actually accumulate are smaller and duller: an item slipped into a bag in a low-traffic aisle, a return processed against nothing, a void at the till at the end of a shift, stock leaving through the goods-in door during a delivery.

None of these produce a moment anyone notices. They produce a discrepancy at stocktake, weeks later, with no way to trace it back. By then the footage has usually rolled over, and even where it has not, nobody has the hours to scrub through it.

That is the actual gap. It is not that stores lack cameras. Most Indian retail sites have had cameras for years. It is that the footage is only useful if you already know what you are looking for and when it happened, which is precisely the information the losses deny you.

What the Retail Loss Agent does

An agent is not a single detector. It bundles the models a situation needs with the rules for when a detection matters, the workflow for who gets told, and the reporting that makes the pattern visible. The full architecture is set out in the AI apps and agents catalogue.

Detects

Theft cues

Concealment gestures, unusual dwell at high-value fixtures, and items leaving a zone without passing a till.

Detects

Staff movement anomalies

Unusual patterns around the till, the stockroom and the back door, particularly outside trading hours.

Detects

Queue spikes

Queues building past a threshold, which costs revenue at the till rather than stock off the shelf.

Delivers

Evidence and reporting

Clips packaged automatically around each event, and a weekly shrink report showing where and when losses cluster.

An important distinction

A theft cue is a prompt for a human to look, not a determination that theft occurred. The system flags a pattern worth thirty seconds of a manager's attention. It does not accuse anyone, and treating cues as conclusions creates both operational and legal risk. Any process built on this should have a human verification step before anything is said to a customer or an employee.

AI CCTV for retail: what to watch, zone by zone

Retail is unusual among use cases because the zones are well understood and stable across formats. A pharmacy, an apparel store and a supermarket differ in stock, not in structure.

Retail zones and what each camera is for
ZoneWhat it is watching forWhat the camera must resolve
EntranceFootfall counts, identification-grade capture of everyone enteringFaces at identification quality, which drives mounting height
AislesDwell, concealment gestures, heatmap for merchandisingTorso and hand movement, full aisle length
High-value fixturesExtended dwell, item removal without progression to tillHands and product at close range
Point of saleVoids, returns, scan avoidance, cash handlingTill surface, product and operator hands together
Goods-in and back doorMovement during deliveries, after-hours activityFull doorway, both directions, low light capable
StockroomAccess outside expected hours, stock movementEntry point and main racking runs

The useful discipline is that every camera is traced to a named risk, so no camera exists without a job. Stores that accumulate cameras over years usually end up with coverage that is dense where it was easy to run cable and absent where the losses are.

Beyond loss: the same cameras, more answers

Loss prevention justifies the deployment in most stores, but the cameras are already capturing everything needed for operational questions that usually go unanswered.

Traffic

Footfall and conversion

People entering, counted accurately, against transactions. Conversion rate stops being a guess.

Layout

Heatmaps

Where customers actually go and linger, which fixtures get ignored, and whether a merchandising change worked.

Service

Queue management

Queue length crossing a threshold, alerted in time to open a second till rather than reported afterwards.

Mix

Visitor analysis

Aggregate patterns by time of day and day of week, useful for staffing rather than for identifying anyone.

The commercial argument for retail is stronger than for most sectors precisely because of this. A deployment justified on shrink reduction also produces the footfall and layout data that merchandising has been buying separately, or guessing at.

Camera placement decides whether any of this works

Most retail CCTV disappointment traces to a decision made before installation. A pixel-per-metre (PPM) figure tells you what a camera resolves at a given distance. Detecting that a person is present needs relatively little. Recognising a known individual needs more. Identifying a stranger from footage, to a standard useful in an incident review or an insurance claim, needs roughly 80 PPM at the subject.

The single most common error in retail is mounting the entrance camera too high. It produces a clean view of the tops of heads, which counts people adequately and identifies nobody. The camera looks well positioned and the footage is worthless for the one thing you will eventually need it for.

The fix is a three-step survey: establish the identification point at each entrance, set mounting height and angle to hit the required PPM at that point, and check the result against real store lighting rather than a plan drawing. Glare from a glass frontage at particular times of day defeats more entrance cameras in India than any other single factor.

A worked example

A single-floor apparel store of roughly 500 square metres has stock going missing from the storage area behind the shop floor. The existing installation is eight cameras, all on the shop floor, added over four years.

The feature-list approach adds theft detection to all eight cameras. It generates alerts across the whole floor, most of them from ordinary browsing behaviour, and within a month the manager stops opening them.

The outcome approach observes that the loss is in storage, not on the floor. That points to two cameras covering the storage entrance and the goods-in door, running after-hours intrusion and staff movement anomaly detection, with alerts to the store manager's phone. On the floor, one camera at the entrance is repositioned to hit identification PPM, and heatmap plus footfall run across the existing aisle cameras for merchandising.

Fewer cameras carry the analytics, alerts are few enough to be acted on, and the manager gets a weekly report showing whether storage-area activity correlates with the discrepancies. The first approach costs more and gets switched off by month three.

Your customers are data principals

Retail differs from a factory in one legally important way. Your employees have an employment relationship with you. Your customers do not. Everyone walking through the door is a person whose personal data you are processing, and they have not signed anything.

DPDP Rule 4 commences on 13 November 2026. Organisations processing personal data through video systems will need to describe what they collect, why, for how long, and on what lawful basis. For retail specifically that means clear notice at the entrance, a retention period you can actually justify and enforce, and a defensible answer to what the footage is used for.

Where retailers get into difficulty

Face recognition of customers is a different order of decision. Counting people crossing a line and identifying named individuals against a watchlist are not variations of the same thing. The second warrants a documented impact assessment, a specific lawful basis, and a retention and deletion policy for the enrolled set. Many retailers who think they want it, on examination, want reliable identification-grade footage for incident review instead, which carries far lighter obligations.

Signage is not a formality. Notice at the point of entry is the mechanism by which people know processing is happening. A faded sticker on a door is not adequate notice for analytics that were installed years after the sticker.

Retention has to be real. A stated period that the system does not enforce is worse than a longer honest one, because it is a commitment you are visibly failing.

Running inference on site narrows the exposure considerably, because the hardest questions concern personal data replicated to infrastructure you do not control. Privacy masking, face masking and licence plate masking redact at the point of capture. None of that substitutes for notice, lawful basis and retention policy, which remain yours.

What a retail deployment actually includes

  1. Design

    Camera placement traced to named risks per zone, blind spots measured, and identification points established at each entrance. Produced from a plain-language description of the store.

  2. Hardware

    Cameras where the design needs them, the EdgeBox running models on site, storage sized on real bitrates for your retention period, PoE switch, UPS, cabling and mounts.

  3. Models

    The Retail Loss Agent, plus footfall, heatmap and queue management where the operational case justifies them. Configured per camera rather than blanket-enabled.

  4. Install and go live

    Survey and marking, cabling, configuration and aiming, and an acceptance test that checks the entrance camera actually resolves at the identification point.

  5. Run it

    Alerts to the phone of whoever is on shift, evidence packs for anything escalated, and a weekly shrink report. Annual maintenance and one number to call.

Most stores keep their existing cameras. The EdgeBox ingests RTSP and ONVIF streams from any manufacturer, and analog estates connect through an encoder, so a store with cameras added piecemeal across several years does not need to be rationalised first. The full sequence is set out in how IndoAI works.

The honest limits

What to expect, and what not to

Cues are not verdicts. The system flags behaviour worth a look. It does not establish that theft occurred, and no action should be taken against a customer or an employee on an alert alone.

Accuracy is store-specific. Lighting, aisle width, fixture height, camera angle and how often the event actually occurs all move the numbers. A single headline percentage quoted without those conditions describes a benchmark, not a prediction about your store.

Bad placement cannot be fixed in software. An entrance camera mounted too high produces footage no model can rescue. Some stores need cameras moved before analytics are worth adding, and the design should say so.

Alert volume has a ceiling. Beyond what a store manager can genuinely act on during a trading day, each additional detector reduces effectiveness. Fewer, better-targeted alerts beat comprehensive coverage nobody reviews.

It does not fix process gaps. If voids at the till are unmonitored as a policy matter, better footage of them changes nothing on its own. The analytics surface the pattern, but somebody has to own the response.

Frequently asked questions

Do I need to replace my existing store cameras?

Usually not. The EdgeBox ingests RTSP and ONVIF streams from cameras already installed regardless of manufacturer, and analog systems connect through an encoder. The common exception is the entrance camera, which often needs repositioning or replacing because it was mounted too high to resolve faces at identification quality.

How many cameras does a typical store need?

It depends on floor area, layout and where losses are actually occurring rather than on a rule of thumb. Camera count frequently falls after a proper design, because coverage traced to named risks replaces coverage accumulated over years of ad hoc additions. The design stage establishes the number and states what each camera is for.

Can it tell me who is stealing?

It flags behaviour patterns worth a human looking at, and packages the clip so that looking takes seconds rather than hours. It does not determine that theft occurred, and no action should follow from an alert alone. Reliable identification depends on camera placement resolving faces adequately at the entrance.

Will I get useful footfall data from the same cameras?

Yes. People counting, heatmaps, queue management and aggregate visitor patterns run on the same estate that handles loss prevention. This is a large part of the commercial case in retail, because a deployment justified on shrink also produces the merchandising and staffing data most stores currently estimate.

Do I need customer consent for AI CCTV in my store?

You need clear notice at the point of entry, a lawful basis for the processing, a retention period you can enforce, and a defensible account of what the footage is used for. Facial recognition against a watchlist is a materially heavier decision than counting or event detection and generally warrants a documented impact assessment.

Does the footage leave my store?

Not by default. Inference runs on the EdgeBox on your premises, and raw video stays there. What travels, if anything, are events and evidence packs you have chosen to route to a phone or dashboard. Privacy, face and licence plate masking can redact personal data at the point of capture.

How quickly do alerts reach staff?

In real time, to the phone of whoever is on shift, because inference happens on site rather than in a remote service. The design stage determines which event types alert immediately, which are collected for review, and who receives each, since routing everything to everyone reliably results in nothing being read.

What happens to alerts when the store is closed?

After-hours rules typically differ from trading-hours rules. Movement in the stockroom at two in the morning is a different event from the same movement at two in the afternoon, and the orchestration rules reflect that. This is one of the clearest cases where an agent outperforms an individual detector.

Can it work across multiple stores?

Yes. Each site runs its own appliance with inference local to that store, and an optional cloud dashboard provides centralised monitoring across the estate. Reporting can be viewed per store or aggregated, which is how regional managers usually want it.

What if my store has poor lighting?

Lighting affects what any camera can resolve, and no model recovers detail the sensor never captured. Glare from a glass frontage at certain times of day defeats more entrance cameras in India than any other single factor. The design stage assesses real store lighting rather than working from a plan drawing.

How long before it pays for itself?

That depends on your current shrink rate, which most stores know only approximately, and on whether anyone acts on the alerts. The weekly report is the mechanism for finding out, because it makes the pattern of loss visible over a few cycles. Any vendor quoting a payback period without knowing your numbers is guessing.

What is the first thing I should do?

Establish where the loss is actually occurring before selecting any analytics. Stock going missing from storage points at a completely different camera and model configuration from stock leaving the shop floor. Describing the store and the concern to the AI Advisor produces a design that works backwards from the outcome rather than forwards from a feature list.

Start here

Describe your store. Get the design back in one session.

Tell the AI Advisor your floor area, layout and what is going missing. You will get camera placement traced to each risk, blind spots measured, the model mix per camera, and an itemised bill of materials.

Open the AI Advisor

Related reading: how IndoAI works, end to end, the AI app and agent catalogue, the IndoAI EdgeBox, and the AI vision glossary.

VG
Author Dr Vivek Gujar

Chief Strategy Officer at IndoAI. He holds a PhD alongside an MBA and a B.Tech, and has spent more than two decades in business development and IT security across technology and non-technology sectors. He reviews IndoAI's published technical claims.