Security Guard Incident Report: A Manager’s Guide

Security Guard Incident Report: A Manager’s Guide

When a security incident occurs at a commercial property, the first account is often the one that shapes every later decision. A useful report gives managers a reliable record of what was observed, where and when it happened, what actions followed, and who was notified.

Call (833) 272-7247 to discuss accountable security reporting for your property.

A security guard incident report should document the exact time and location, objective observations, people or witnesses when appropriate, actions taken, notifications, related photos or video, evidence handling, and required follow-up. GPS-enabled Daily Activity Reporting can add verified timestamps, location data, checkpoint activity, and supporting media, while emergency services or law enforcement remain the priority when circumstances require them.

Good documentation is more than a completed form. It gives property and facility teams a clear basis for handoffs, review, corrective action, and accountability without confusing observed facts with assumptions. Start by defining the report’s operational purpose, then build the required details around that purpose.

What Is a Security Guard Incident Report Used For?

A security guard incident report is a written or digital operational record of a criminal event, accident, hazard, or unusual occurrence observed during a guard’s shift. It explains what happened, where and when it occurred, what the guard observed, what actions followed, and who was notified. The goal is not to speculate about intent. It is to create a clear record that managers can review, share with authorized stakeholders, and use to guide follow-up.

For a property manager, the report creates continuity between the guard on duty, dispatch, site leadership, and the next shift. A useful record can support internal review, a later investigation by the appropriate authority, or a compliance audit. It also helps separate immediate observations from decisions that still need confirmation. For example, a guard can document a damaged door, the time it was found, and the people contacted without declaring who caused the damage.

What the report is designed to capture

The format may vary by site, but the report should give readers enough context to understand the event without relying on verbal recollection.

  • The date, time, and precise location of the occurrence.
  • A neutral description of what the guard saw or was told.
  • People involved or witnesses, when identification is appropriate and authorized.
  • Actions taken, notifications made, and any follow-up requested.
  • References to photographs, video, access records, or other supporting material.

Reports should be completed promptly while details are fresh. If information is incomplete at first, an initial entry can identify what is known and be updated as additional facts become available. Managers should protect reports through appropriate access controls, especially when they contain personal information, injury details, or security-sensitive observations.

Incident report versus Daily Activity Report

A Daily Activity Report, or DAR, is the broader shift record. It tracks routine patrols, checkpoint visits, access-control activity, observations, and other scheduled duties. An incident report focuses on a specific event that requires documentation or follow-up. The two records can work together. A DAR may show when a guard was at a location, while the incident report provides the detailed narrative of what was discovered there.

That distinction matters when managers evaluate a site’s exposure. A security risk assessment can identify which events, locations, notifications, and evidence fields should be standardized before an incident occurs.

What Should a Security Guard Incident Report Document?

A useful report gives a manager a clear record of what occurred, where it occurred, who was involved, and what happened next. It should be specific enough to support a shift handoff, internal review, insurance documentation, or a follow-up conversation without turning assumptions into facts. A form can guide the process, but the narrative still needs to explain the event in plain language.

Use the following checklist for each security guard incident report. Record only information that is relevant, authorized, and necessary for the operational record. Protect personal information in accordance with your site’s procedures. Route emergencies or suspected crimes to the appropriate emergency service or law enforcement agency instead of waiting for paperwork to be completed.

  1. Date and time: Enter the date and the most precise time available for the initial observation, the reported occurrence, and major follow-up actions. If the exact time is unknown, label it as an estimate and explain the basis, such as a witness statement, access record, alarm notification, or guard observation. For a continuing event, use a short timeline rather than one vague time entry.
  2. Exact location: Identify the property, building, floor, entrance, room, parking area, loading zone, or other specific point where the incident occurred. Include nearby landmarks or access points when they help another manager or responding professional find the area. Avoid broad descriptions such as “the site” when a more precise location is available.
  3. Incident category and scope: Select the closest category, such as trespassing, theft, vandalism, fire or smoke, assault, an alarm, a hazard, or an accident. More than one category may apply. Note whether the event was observed directly, reported by someone else, discovered during a patrol, or identified through a system alert. Classification helps supervisors route the report for review, but it should not replace the written account.
  4. People and witnesses: Record the names or identifiers of the guard, reporting party, involved people, and witnesses when it is appropriate and authorized. Include each person’s role and the information they personally provided. Use direct quotes for important statements when possible. Keep phone numbers, home addresses, identification numbers, medical details, and other sensitive information in an authorized system.
  5. Objective narrative: Describe what happened in chronological order, including the conditions observed, actions seen, words heard, and sequence of events. Separate direct observations from information received from a witness or system. Write “the door was open and the lock appeared damaged,” rather than assigning intent or responsibility without support. Include relevant actions taken, while omitting tactical details that do not belong in a general client record.
  6. Damage, injuries, and impact: Document property damage, apparent injuries, hazards, affected areas, or interrupted operations when applicable. Describe visible conditions without diagnosing an injury or estimating a loss unless an authorized source has provided that information. Note whether medical assistance, emergency services, or law enforcement was contacted, and identify the time and person responsible for that notification when known.
  7. Reporter details and supporting records: Identify the reporting guard, shift, post, and submission time so a supervisor can clarify the entry later. Attach or reference authorized photos, video, access records, witness statements, or other evidence according to site policy. Proofread the report before submission, confirm that required fields are complete, and flag any information that remains unverified. An initial report can be updated when additional facts become available, provided the update is clearly marked and preserves the original record.

Managers should review the completed entry for clarity, privacy, and consistency with other available records. The goal is not to make the incident sound more serious or less serious than it was. The goal is to leave the next decision-maker with a reliable account, clear ownership of follow-up, and enough context to determine whether site procedures need attention.

How Do Guards Keep Incident Reports Factual and Clear?

A strong report separates what the guard directly saw, heard, or did from what someone believes may have happened. That distinction gives property managers a useful operational record without turning an observation into an accusation. A report should explain the event clearly, not argue a conclusion.

Use a chronological account

Begin with the earliest relevant observation and move forward in order. Include the date, exact time or time range, location, and conditions that help the reader understand the sequence. For example, write that the guard observed a person enter through a propped-open side door at 10:42 p.m. The guard notified the supervisor at 10:45 p.m. The door was secured at 10:49 p.m. A timeline is more useful than a general statement such as “the area was checked.”

Use specific locations when it is safe and appropriate. Examples include a building entrance, loading area, or parking level. If the time is estimated, say so. If the report is updated later, identify the update rather than silently changing the original account.

Describe observations, not assumptions

Choose neutral language. “The window was cracked and glass fragments were visible on the floor” records observable conditions. “The person attempted to vandalize the building” may be an interpretation unless the guard directly witnessed the relevant action. When intent is unknown, state what was observed and identify the uncertainty.

Record witness information when available, along with each person’s role or relationship to the incident. Direct quotes can be useful, but mark them as quotes and preserve the speaker’s meaning. Do not improve, summarize, or present a secondhand statement as something the guard personally observed.

Privacy also matters. Include information necessary for site follow-up, notification, and authorized review, but avoid unnecessary personal details. Use approved record-access procedures for names, contact information, medical information, video, photographs, and other sensitive material. An incident report should support accountability without broadly exposing information about tenants, employees, visitors, or witnesses.

Call (833) 272-7247 to discuss clear, accountable security reporting.

Security guard documenting observations during a property patrol

Before submitting, read the narrative once as a manager who was not present. Can that reader identify what happened, when and where it occurred, what was directly observed, and which details remain unconfirmed? That final review helps keep the security guard incident report factual and useful for the next decision.

How Are Actions, Notifications, and Evidence Handled?

A useful report does more than describe an event. It shows what happened next, who was informed, what evidence exists, and which details still require follow-up. The sequence below keeps the record operational without exposing sensitive response tactics.

  1. Address immediate safety first. Identify active hazards, injured people, fire or smoke, violence, or other conditions that require urgent attention. Follow the site’s emergency procedures and request emergency services or law enforcement when appropriate. A security guard incident report documents the response, but it does not replace emergency response, police action, legal advice, or a formal investigation. Record the time the condition was recognized and the immediate protective action taken, such as moving people away from a hazard or restricting access when it can be done safely.
  2. Preserve the scene when safe and authorized. Avoid disturbing objects, surfaces, access points, or other conditions that may matter later. If the area must be changed to protect people or prevent additional damage, state what was changed and why. Do not include tactical details that could compromise a response plan. Note whether the area was secured, who assumed control, and any access limits placed on the location.
  3. Notify the right parties and record the notification. Document calls or messages to the dispatcher, property or facility contact, supervisor, emergency services, or law enforcement, as applicable. Include the time, recipient, communication method, and information shared. If a police report was requested or filed, record the agency and report reference when available. Initial information may be incomplete, so label unconfirmed details clearly and update the record as facts are validated. ASAP’s 24/7 security guard services model includes human dispatch coordination, but site-specific notification procedures and authorized contacts should control.
  4. Capture photos, video, and witness information appropriately. Take photographs or video only when permitted, safe, and consistent with site policy. Describe what each file shows, when it was created, and where it is stored. List witnesses and their contact or identification details only in the authorized system. Summarize relevant statements accurately, using quotation marks only for words actually spoken. Keep personal, medical, access-control, and other sensitive information limited to those who need it.
  5. Document evidence and chain of custody. Reference physical items, media files, access logs, camera footage, or witness statements without guessing about their meaning. Record who collected, received, stored, or transferred an item, along with dates, times, and the authorized storage location. Do not handle or move potential evidence unnecessarily. Close with the next owner and pending action, such as preserving footage, contacting a stakeholder, or obtaining a supplemental statement.

This structure gives managers a clear trail from immediate safety through follow-up while separating observed facts from assumptions. It also makes later review more efficient without turning the report into a conclusion about responsibility.

How Does GPS-Tracked Reporting Support Accountability?

A well-written security guard incident report explains what happened. GPS-enabled Daily Activity Reporting can add operational context that helps a property manager evaluate when and where an activity occurred, what was documented, and which follow-up steps were taken. ASAP Security Guards uses GPS-enabled DAR for real-time accountability, combining mobile entries with location verification, timestamps, photos or video metadata, checkpoint checks, and incident documentation.

Basic narrative reporting compared with GPS and DAR-supported verification
Reporting elementBasic narrative reportGPS and DAR-supported reporting
Time and locationRelies on the writer’s stated time and location.Can add precise timestamps and GPS geolocation tied to the entry.
Patrol activityDescribes a patrol or check in narrative form.Can record assigned-location check-ins and checkpoint verification.
Supporting evidenceReferences photos, video, or other evidence if available.Can attach photos or video with related metadata and transmit the entry digitally.
Manager visibilityMay require delivery and review after the shift.Digital entries may be available to authorized clients before shift end.

Making time and location easier to verify

Mobile reporting lets guards log activities from assigned locations, follow standardized prompts, and upload documentation as work occurs. A timestamp does not prove every detail of an event by itself. It creates a more useful reference point for comparing an entry with dispatch records, access activity, camera footage, or statements from people on site. GPS information can also help managers review whether a checkpoint or patrol stop was recorded at the expected location.

This is especially useful when a property has multiple buildings, parking areas, entrances, or remote sections. Instead of relying only on a general statement such as “the property was checked,” a manager can review the specific activity recorded for the assigned area. Vehicle patrol documentation may also include GPS-tracked routes, photo-verified checkpoint visits, and timestamps, giving the review a clearer operational trail.

Connecting documentation with dispatch and follow-up

GPS and DAR do not replace professional judgment, direct communication, or emergency response. If a situation requires emergency services or law enforcement, those services take priority. Technology supports the documentation surrounding the response. Dispatchers can assess the situation, coordinate the appropriate unit, notify the client when applicable, and connect the response record with DAR entries, photos, and follow-up information.

For property managers, that connection can make a security guard incident report easier to review after the immediate issue is addressed. It may show when an activity was logged, where the guard was assigned, what media was submitted, and whether the matter was passed to dispatch or management. Authorized access should still be controlled, especially when reports contain personal information, sensitive site details, or images involving tenants, employees, or visitors.

For more context on the operational side of these tools, review ASAP’s security reporting and accountability resources. The goal is not to turn every event into a technology exercise. It is to give managers a clearer record for handoffs, internal review, client communication, and practical follow-up while keeping human judgment at the center.

What Should a Property Manager Do After Receiving the Report?

Receiving a security guard incident report is the start of the management review, not the end of the process. Treat the document as an operational record that helps you confirm what occurred, assign follow-up, and improve site procedures. Keep the review focused on documented observations and authorized next steps. Do not treat the report as a substitute for emergency services, law enforcement, legal advice, or a formal investigation.

1. Check completeness and accuracy first

Begin by checking whether the report provides enough information for another responsible person to understand the event. Confirm the date, time, exact location, incident category, reporting guard, people or witnesses identified where appropriate, and a clear chronological narrative. Compare the narrative with available access-control records, dispatch notes, camera footage, or other authorized records when those sources are available.

  • Separate what the guard directly observed from assumptions about intent or cause.
  • Look for missing timestamps, unclear locations, unexplained gaps, or contradictions.
  • Confirm that damage, injuries, hazards, notifications, and actions taken are addressed when applicable.
  • Ask for clarification through the approved reporting channel rather than editing the guard’s account without documentation.

Proofreading and validation matter because a report may later support a handoff, internal review, insurance inquiry, or site-procedure decision. Federal guidance also recognizes that complete, validated information may not be available at an initial notification. If facts are still developing, retain the initial version, label the status clearly, and add a dated update as information is confirmed.

2. Assign ownership and notify the right people

Decide who owns each follow-up item. Depending on the event, that may include the property manager, facilities lead, security supervisor, tenant contact, human resources representative, risk manager, or another authorized stakeholder. Use the site’s notification matrix, lease requirements, emergency plan, and client instructions to determine who should be informed and how quickly.

Record who was notified, when the notification occurred, and any direction received. If emergency services or law enforcement are appropriate, follow the established escalation process immediately. Avoid distributing sensitive personal details or tactical response information beyond the people who need it to perform their roles.

3. Secure evidence and confirm access

Identify the supporting material referenced in the report, such as photographs, video, witness statements, access logs, work orders, or dispatch communications. Confirm that each item is stored in the approved system, associated with the correct incident, and accessible to authorized reviewers. Note when evidence was received and whether any requested item remains outstanding.

A digital reporting process can make this review more practical by connecting incident documentation with timestamps, locations, photos, and follow-up communications. Even then, access should follow the property’s retention and privacy procedures. For broader context on selecting controls and prioritizing vulnerabilities, see this security risk assessment guide.

4. Correct the immediate issue and track updates

Translate the report into specific actions. Examples include repairing a damaged gate, correcting a lighting problem, adjusting access permissions, contacting an affected tenant, scheduling a recheck, or assigning additional documentation. Give each action an owner and due date. Keep the incident record open until the responsible person confirms completion or explains why the action changed.

If new facts emerge, update the record rather than silently replacing the original account. A clear version history helps later reviewers distinguish the initial notification from validated follow-up information.

5. Review site procedures after closure

Once immediate actions are complete, ask whether the event exposed a gap in patrol instructions, visitor control, lighting, camera coverage, tenant communication, or after-hours escalation. A single report may require no procedural change, while a recurring pattern may justify a documented review of the site’s security plan. Managers overseeing multiple buildings can also compare trends across locations without sharing unnecessary personal information. For operational planning, review this guide to commercial property security guards.

Call (833) 272-7247 to discuss accountable incident reporting for your property.

Frequently Asked Questions

When should a security guard incident report be completed?

Complete the initial report as soon as practical after the scene is safe and immediate notifications are made. Record the known facts while details are fresh, then identify any information still being confirmed. An authorized supervisor can update the report when additional witness statements, photographs, or follow-up details become available.

What if the guard did not see how the incident started?

Document exactly what the guard observed, including the time, location, conditions, people present, damage, and actions taken. Clearly label statements from witnesses as statements, and avoid presenting assumptions about intent or cause as fact. A careful report can be useful even when it does not establish the complete sequence of events.

Does an incident report replace calling emergency services or law enforcement?

No. A report is an operational record, not a substitute for emergency response, law enforcement, legal advice, or a formal investigation. Follow the site’s escalation procedures and contact emergency services or law enforcement when the circumstances require it. Record who was notified, when the notification occurred, and any applicable report or case reference.

How can GPS-tracked reporting help verify an incident response?

A GPS-enabled Daily Activity Report can associate entries with timestamps and locations, while also supporting photos, video metadata, checkpoint verification, and incident documentation. This gives managers more context for reviewing where and when an activity was logged. Access should still follow the property’s privacy, evidence-handling, and authorized-record procedures.

Schedule a Conversation About Accountable Coverage

A clear incident reporting process helps property and facility managers review what happened, coordinate follow-up, maintain visibility across the site, and support consistent communication with stakeholders. If you want to discuss accountable security guard coverage and incident reporting for your property, call (833) 272-7247 to speak with ASAP Security Guards.

Author

  • Mega AI

    Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut tincidunt, velit sed molestie tempus, elit eros placerat dui, sed varius nibh neque ut ipsum.