Black Shard

Custom software or off-the-shelf: the criteria that decide it.

Most standard needs should be bought; custom software wins when the process is your differentiator, when generic tools force double-handling, when data and audit obligations reach into the architecture, or when the tool is becoming the business.

Build or buy is usually the first significant technology decision a business faces. The criteria here are the ones we apply to our own builds.

Most of the time the answer is buy. Off-the-shelf products are faster to adopt, cheaper for standard needs, and maintained by someone else. Custom software wins in specific, nameable situations: when the process is your differentiator, when generic tools force double-handling, when data control and audit obligations reach into the architecture itself, or when the tool is becoming the business.

Black Shard builds and operates production software, and built the client systems GRM LAW and Stone Leaf Capital run on, both of which had those reasons.

Side by side.

Custom software compared with Off-the-shelf SaaS
CriteriaCustom softwareOff-the-shelf SaaS
Time to startSlower by nature. Even a tightly scoped build needs a brief, a design pass, and a first working slice. Fixed-scope work is briefed and dated before it starts, but nothing ships on day one.Immediate by comparison. Sign up, configure, import your data. For a standard need this speed is decisive, and no build can compete with it.
Fit to processExact. The system is shaped to how you work. GRM LAW's portal holds the firm's own intake, conflicts checks, and matter register.Approximate. You adopt the vendor's model of the work. For a standard process that model is usually good enough. For a differentiated one, you bend the process to fit the tool and lose the edge.
Cost shape over timeFront-loaded. The build is scoped and priced before work starts; after launch, the costs are hosting and maintenance you control. No per-seat pricing.Low then compounding. Cheap to adopt, then per-seat and per-module fees that grow with headcount for as long as you use it. For a standard need, years of subscription still usually cost less than a build.
Integration depthAs deep as the work demands. A custom system can sit over the tools you keep and close the gaps between them. GRM LAW's portal sits over Smokeball and adds the conflicts checks, AML/CTF readiness, and audit trail the firm needed.Bounded by the vendor's API. Mainstream pairings work well. Anything off the beaten path becomes CSV exports and re-keying, which is double-handling with a subscription attached.
Data control and residencyDesigned in. We build on Azure in Australian regions, with tenancy, retention, and access modelled on your obligations. Stone Leaf Capital's data model is built around the firm's AFSL perimeter.The vendor's call. Many handle Australian residency well; some do not. Confirm where the data sits, who can reach it, and what crosses borders before you sign.
Security accountabilityConcentrated. The team that built the system secures it: threat modelling from the first design session, least-privilege access, audit trails you can inspect. One party answers for the outcome.Inherited. You take on the vendor's posture, staffing, and breach history. Their assurance reaches you as documents: independent assessments, audit reports, a sub-processor list.
EvolutionContinuous. Software under an ongoing engagement changes when the workflow does; we ship to the GRM LAW portal weekly, and Stone Leaf Capital's portal evolves the same way. The roadmap is yours.The vendor's roadmap. Your feature request queues behind every other customer's. Acquisitions, pivots, and product sunsets happen on their schedule, and you migrate on it too.

When custom software wins

  • The process is the differentiator. If the way you run intake, deal flow, or compliance is why clients choose you, a generic tool averages you back to the market. GRM LAW runs on a portal built to its own workflow because that workflow is the firm's.
  • Off-the-shelf forces double-handling. When staff re-key the same matter or client into two systems, the subscription is the smaller cost. A custom layer over the tools you keep removes the re-keying instead of adding a third silo.
  • Data, residency, or audit obligations outrun configuration. Stone Leaf Capital's portal captures actor, action, and before and after state on every change, structured around an AFSL perimeter. Obligations at that level sit in the architecture.
  • The tool is becoming the business. Aurii is clinical voice software Black Shard built end to end, from the native iOS and Android apps to the multi-tenant data layer, and it runs for Australian private-hospital specialists.
  • No vendor covers the work. Restart Recruitment runs structured scorecard screening per role so the brief gets judged the same way every time, built for a search model that takes on fewer searches at a time. If your method has no product category, the category will not appear on schedule.

When off-the-shelf is simply right

  • The need is standard. Accounting, payroll, email, documents, calendars, video calls: these are solved problems with mature products behind them.
  • Compliance logic lives in the product. Payroll and tax rules change constantly, and the established products encode the changes as they land. A bespoke rebuild of that logic is a standing liability.
  • The process is still forming. If you have not run the workflow manually for long enough to know its shape, a subscription you can cancel is the cheapest way to learn. Build after the process proves itself.
  • The value is the network. Electronic signatures, payments, conferencing: the worth sits in the counterparties and the compliance regime already on the platform.
  • A mainstream tool fits with light configuration. If a standard CRM covers your pipeline once configured, take the win. A custom build has to clear a high bar over a configured product.

Why the default is buy

A build is an asset with a lifetime. Someone has to patch it, monitor it, back it up, and answer for it when it breaks. Every feature is code someone maintains and a surface someone can attack.

So the decision rule we apply in our own builds is narrow. Buy for every standard need. Build only where the software touches the thing that makes the business different, and compare that build against a well-configured off-the-shelf alternative.

How do you know the process is the differentiator?

Most businesses overestimate how special their process is. The test is commercial: if a competitor adopted your workflow tomorrow, would clients notice? Standard sales pipelines, standard bookkeeping, and standard support queues fail that test, and they should be bought. The conflicts-and-compliance workflow a law firm runs its matters through every day passes it. GRM LAW engaged us to build that workflow into a portal, over Smokeball rather than instead of it, because the firm's process was worth keeping exactly as the firm runs it.

Regulatory perimeters produce the same answer by a different route. Stone Leaf Capital operates under an AFSL, and its obligations reach into the data model itself: what is retained, who acted, what changed, before and after state on every change. Generic tools let you configure fields. They do not let you make the audit trail machine-enforced, and when the obligation is structural, the software has to be.

The third trigger is quieter: double-handling. When a team keys the same client into the practice system and the spreadsheet beside it, or exports CSVs every Friday to assemble the report no tool produces, the off-the-shelf stack has stopped saving money. The subscription line appears on the invoice. The labour it fails to remove does not appear anywhere, but it is a real cost. Counting both is usually what settles the question.

How a Black Shard build runs

If the answer is build, the engagement is legible: the workflows covered, the integrations, the environments, and the tenancy model are all scoped before work starts. Threat modelling happens in the first design session. We build on Azure in Australian regions, under least-privilege access, with the audit trail built in. Our approach page describes the method; our trust page shows the posture behind it.

Delivery is either a defined build with a brief and a delivery date, or an ongoing engineering engagement where the product continues to evolve after launch. GRM LAW and Stone Leaf Capital both operate day-to-day on portals we still ship to under ongoing engagements; the build evolves with the workflow. Delivered Australia-wide from our Brisbane head office.

Questions, answered

Is custom software more secure than off-the-shelf SaaS?
Not automatically. A major SaaS vendor employs more security engineers than most Australian businesses ever will. What custom software changes is accountability and inspectability: the builder answers for the design, and you can read the audit trail. We build secure-by-design, with threat modelling before a line is written and least-privilege architecture throughout. Our own posture is on our trust page.
What does custom software cost?
No range is published; scope decides it. The drivers are the workflows covered, the integrations, the number of environments, and the tenancy model; a defined build is agreed with a brief and delivery date before work starts. The comparison is build price against years of per-seat fees plus the cost of the double-handling the subscription leaves in place.
Can custom software work alongside the SaaS we already use?
Often that is the right architecture. GRM LAW kept Smokeball; the portal we built over it carries the workflow the practice system does not, through to an append-only audit ledger machine-enforced on every state change. Buy the commodity layer, build the layer over it, and integrate the two.
When should we replace an off-the-shelf tool with a custom build?
When the workarounds become the job. The signals are consistent: staff maintaining spreadsheets beside the tool, weekly CSV exports to build the report it cannot produce, the same record keyed into two systems, or an audit obligation the tool cannot evidence. If none of those are present, keep the subscription.
Should a new business ever build custom software?
Mostly no. Buy nearly everything and spend the build budget on the single system that makes the business different. The rest of a young company's stack should be bought, configured, and left alone.

Send the decision and the workflow behind it.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au