A biometric loss-prevention system went live with almost no announcement
Grocery Outlet has been running SAFR Guard facial recognition at store entrances, and the deployment surfaced through local reporting rather than a corporate disclosure. Journalists confirmed the technology at four San Francisco stores in the Mission, Portola, Bayview, and Richmond, plus locations in Pleasant Hill and Concord, while the Emeryville-based chain has not detailed how far the rollout extends. SAFR Guard is built by SAFR LLC, a subsidiary of RealNetworks, and marketed specifically for retail loss prevention. The quiet posture is itself the story for any executive who owns this decision.
For a retail CISO or CIO, the lesson lands before the technical merits. A face-scanning system that customers discover through a newspaper is a governance failure regardless of how accurate the matching engine is. The gap between deploying a capability and disclosing it is exactly where regulatory and reputational risk concentrates. When biometric collection reaches the store floor without a clear public position, the organization has already ceded control of the narrative, and it will spend far more recovering trust than it saved on shrink.
How the SAFR pipeline actually processes a shopper's face
The mechanics matter for anyone evaluating vendor claims. SAFR cameras capture a face on entry and generate an encrypted biometric template inside the camera itself, then compare that template against an in-camera watchlist of suspected shoplifters. A potential match is routed to human verification before the retailer receives any alert, which keeps a person in the decision loop rather than automating enforcement. Templates belonging to non-matched shoppers are deleted within one second, according to SAFR's design, so the vast majority of scans leave no lasting biometric record.
The retention detail that deserves scrutiny is the exception. SAFR's privacy policy allows encrypted images to be retained up to 30 days, which means the one-second deletion claim covers templates, not necessarily every captured image. A technology leader signing off on this needs to map exactly what is stored, where, for how long, and who can access it. On-camera processing reduces the attack surface compared with cloud-based matching, but the watchlist itself becomes a sensitive asset that requires its own access controls, audit trail, and error-handling process.
The Rite Aid order is the benchmark every retailer should study
The precedent looming over this category is the Federal Trade Commission's action against Rite Aid, which barred the chain from using facial recognition for five years after its system produced thousands of false matches. That order established that a retailer can be held accountable for the downstream harm when the matching is wrong, well beyond the act of collecting biometrics. False positives in a loss-prevention context are not abstract errors; they translate into shoppers wrongly flagged, confronted, or barred, disproportionately affecting the communities where these systems are deployed.
For a decision-maker, Rite Aid reframes the build-versus-buy and deploy-versus-wait question. The core risk is not whether a vendor's accuracy numbers look good in a demo. It is whether the organization has the operational discipline to manage a watchlist responsibly, review every match, correct errors quickly, and document the whole process well enough to withstand a regulator. If that operational capacity does not exist, the technology should not go live, regardless of the shrink figures a business unit is chasing.
Disclosure signage is a control, and small notices undercut it
SAFR requires participating businesses to post disclosure signage, which is meant to give shoppers notice that facial recognition is in use. Reporters covering the Grocery Outlet deployment found some of these notices small and easy to miss. That detail turns a compliance checkbox into a live liability, because a disclosure that technically exists but is not reasonably visible offers little protection when a regulator or plaintiff argues that customers were never meaningfully informed.
Retail leaders should treat signage as a real control with measurable standards, not an afterthought delegated to store operations. Placement, size, legibility, and language coverage all determine whether the notice functions as consent infrastructure or as decoration. The privacy critique is pointed. Mario Trujillo, a staff attorney at the Electronic Frontier Foundation, put it directly: "This is a dragnet that scans everyone. Even if you've done nothing wrong, your face is being scanned." A weak sign does nothing to answer that objection.
The vendor's framing does not resolve the trust question
SAFR is careful to draw a boundary around what its system is. President Charisse Jacques states that the platform "is not a law enforcement system and has no connection with law enforcement," positioning it as a private loss-prevention tool rather than surveillance infrastructure. That distinction is legally meaningful and worth noting, but it does not settle the trust question for a shopper who is scanned on entry, and it does not relieve the retailer of responsibility for how the watchlist is built and used.
The macro backdrop explains the demand. US shoplifting fell 9% in 2025 yet remains roughly 36% above 2019 levels, so the pressure to deploy automated loss prevention is real and unlikely to fade. That pressure is precisely why a CIO needs a clear internal position before a vendor's ROI pitch drives the decision. The right question runs deeper than whether the technology works. It is whether the organization is prepared to own every consequence of scanning every customer who walks through the door.
What a technology leader should actually do with this
Treat biometric loss prevention as a board-level governance decision, not a store-operations purchase. Before any pilot, define the retention schedule in writing, separate template retention from image retention, establish who can add or remove names from a watchlist, and mandate human review with a documented error-correction path. Build the disclosure program to a visibility standard you would defend publicly, and decide in advance how you will respond when a match is wrong, because that moment is when the system is truly tested.
The strategic read is that this category is arriving faster than the governance around it. Grocery Outlet's rollout shows a retailer can put facial recognition in front of every shopper with minimal public process, and the Rite Aid order shows how that ends when controls fail. The competitive advantage will go to operators who can deploy sensitive technology with disclosure, retention, and accountability strong enough that a regulator, a journalist, and a customer all reach the same conclusion: the organization knew exactly what it was doing and could prove it.



