"Delivered" is a carrier event, not proof that the intended recipient received a parcel. A customer may report a missing package because it was scanned early, left at the wrong address, collected by another household member, held at a pickup point, or stolen after delivery. Support teams need a method that preserves these possibilities long enough to make a fair and consistent decision.
This protocol evaluates completed claims. It does not estimate neighborhood crime, decide whether a customer is truthful, or prescribe one replacement policy. It tests whether the organization captured the report, assembled available evidence, applied the correct decision authority, coordinated external actions, and communicated an outcome supported by the record.
Define the event without presuming theft
The study unit is one order shipment reported missing after an expected delivery event. Link multiple contacts and claim attempts about the same parcel. Keep separate parcels from a split order as separate units because their carriers, scans, and outcomes can differ.
Use initial neutral categories: no delivery scan, delivered scan at expected location, delivered scan at inconsistent location, pickup event, return-to-sender event, damaged or empty package, and unknown. Add "reported stolen" when that is the customer's account, but reserve "confirmed theft" for cases with independent evidence defined in the study protocol.
Record the requested remedy separately: locate, reship, refund, carrier investigation, signature evidence, account protection, or reporting guidance. This prevents an analyst from treating every contact as a refund request.
Assemble evidence from the entire fulfillment chain
Join the order record, address version used for the label, warehouse tender event, carrier tracking events, delivery scan, available photo or signature, geolocation confidence if lawfully retained, support conversations, refund or replacement actions, chargeback events, and carrier claim. Preserve native timestamps and the timezone associated with each system.
Do not assign automatic priority to a delivery scan. A scan is relevant evidence, but its meaning depends on event type, location, and carrier process. Customer-provided doorbell footage or a police report is also evidence, not a universal prerequisite. Code the existence, source, time, and limitations of each item.
NIST SP 800-92 describes processes for generating, transmitting, storing, accessing, and analyzing log data (NIST SP 800-92). That guidance supports maintaining a traceable event history. It does not define retail liability or establish that any single log is correct.
Distinguish merchant, carrier, and law-enforcement paths
Map each action to the organization that can perform it. The merchant can decide a replacement or refund under its policy. The carrier can research scans or accept a service claim. Law enforcement can receive a crime report. Customers should not be sent between those paths without a clear explanation of purpose.
The United States Postal Inspection Service states that it investigates mail and package theft and directs people to the appropriate reporting paths (What We Do, Report). Its site also distinguishes suspected mail theft from USPS delivery delays or service issues. A support script should preserve that distinction. It should not promise that a report will produce a merchant refund or characterize every missing commercial parcel as a federal case.
For each referral, record whether the customer received an accurate link or contact method, what information support said would be needed, and whether the merchant continued its own review. A reporting referral should not become a way to close a case that still requires a merchant decision.
Reconstruct the address and delivery context
Compare the address submitted at checkout, any approved post-order change, the label address, and the carrier's reported delivery location at an appropriately minimized level. Code apartment, access, locker, concierge, and signature instructions where they materially affect the workflow. Avoid copying full addresses into general support notes or analytical datasets.
Identify who controlled each mismatch. A customer typo, merchant label error, unauthorized account change, carrier misdelivery, and unclear delivery evidence require different actions. Do not collapse them into "customer says not received."
Review whether the agent asked bounded questions before requesting sensitive evidence. A description of the delivery location may be sufficient to identify a mismatch. Requiring surveillance footage or a police report in every case can exclude customers who lack those resources and may not match the merchant's policy.
Audit the decision rule and authority
Document the policy version in effect at claim time, value thresholds, repeat-claim review triggers, restricted-item rules, evidence requirements, and who can approve exceptions. Test whether similar evidence led to similar decisions. If fraud tooling influenced the outcome, preserve the reason category and human review path without exposing a security playbook in public reporting.
Separate three decisions: whether to credit the customer, whether to reship merchandise, and whether to pursue recovery from a carrier or insurer. They can legitimately differ. A replacement can be issued before a carrier claim closes, while a refund may be inappropriate if a replacement was accepted.
Record manual overrides, including who made them and why. An override can be a correct exercise of authority. It should not disappear from the analysis as if the default policy produced the outcome.
Reconcile payment and merchandise outcomes
Track refund authorization, settlement, replacement creation, replacement delivery, store credit, and chargeback status separately. A support promise is not a settled refund. A reshipment record is not proof that the replacement arrived. Duplicate remedies should be distinguished from intentional partial remedies.
FTC consumer guidance discusses steps people can take when billed for goods they did not receive and describes certain payment-dispute options (What To Do if You Are Billed for Things You Never Got). Use it to explain why accurate payment records and timely escalation matter. Do not imply that every reported package theft has the same legal or card-dispute result.
Create a contradiction table: delivered scan at a different location, refund promised but not settled, replacement issued to the same disputed address without confirmation, carrier claim closed while the customer case remains open, or both refund and chargeback posted. Preserve the contradiction until evidence resolves it.
Evaluate communication safety and accuracy
Code whether the agent acknowledged uncertainty, stated the current evidence, explained the merchant decision, distinguished external reporting from the merchant claim, and gave a case reference. Flag accusations, unsupported certainty, or instructions that could put a customer at risk, such as confronting a suspected thief.
Measure time to acknowledgment, evidence-complete review, merchant decision, payment or reship action, and accurate final notice. A quick close with no executable action is not a successful resolution. Analyze weekends and handoffs separately so time in an unattended queue remains visible.
Test reliability and report limitations
Have two reviewers code a stratified sample containing no-scan cases, expected-location scans, inconsistent-location scans, repeat claims, high-value reviews, approved remedies, denials, and unresolved cases. Calculate agreement for event category, evidence sufficiency, policy application, outcome, and communication accuracy.
Report missing evidence explicitly. Carrier data can expire, images can be unavailable, and a customer may not respond. Run conclusions once with unavailable cases treated as incomplete and again with them reported separately. The method can identify process gaps and inconsistent decisions. It cannot prove who possessed a parcel after a scan or determine criminal liability.
For ecommerce operators, the staffing implication is concrete: a defensible process needs agents who can collect a bounded evidence set, a named reviewer with remedy authority, and a tracked carrier handoff. Those capabilities connect directly to ecommerce support, order and account support, and CS operations and reporting.