Security Guard Reports Explained: Daily Activity Reports, Incident Reports, and Patrol Verification

A guard report should be more than proof that someone showed up. Learn how daily reports, incident reports, patrol records, urgent notifications, and management reviews work together to create accountability.

The short answer

Start here

A professional security reporting system should answer five questions: What was the officer assigned to do? What activity occurred? What exception or incident was observed? Who was notified and what action followed? What should the client or security supervisor do next? Daily activity reports document routine work; incident reports document significant events; patrol-verification records support—but do not replace—the written account. Timely notification and management review turn those records into accountability.

Key takeaways

  • Define required reports and urgent-notification events before the first shift.
  • Use a daily activity report for the shift’s routine chronology and a separate incident report for significant events.
  • Record objective observations, attributed statements, actions, notifications, and follow-up—not assumptions or legal conclusions.
  • Treat GPS, checkpoints, photos, and timestamps as supporting data, not automatic proof of service quality.
  • Protect personal, medical, employee, tenant, student, and investigative information through role-based access and retention rules.
  • Preserve corrections and original records; never silently overwrite a material fact.

The reporting stack: one form cannot do every job

A common mistake is expecting one end-of-shift narrative to serve as a patrol log, incident investigation, emergency alert, safety record, and performance dashboard. Those purposes have different urgency, audiences, and privacy requirements.

Record or communication Primary purpose Typical trigger Timing
Shift or daily activity report (DAR) Chronological record of routine duties, observations, checks, contacts, and turnover Every covered shift Entries during shift; finalized at turnover or end of shift
Incident report Detailed record of a significant event Crime, threat, injury, major hazard, police/EMS response, serious policy event, or other defined threshold As soon as practical after urgent actions and notification
Patrol or checkpoint record Supporting data for location, time, route, or task completion Scheduled or randomized patrol activity Captured during activity
Exception or equipment report Documents a missed checkpoint, alarm, open door, camera failure, key issue, or other deviation Defined exception Promptly, with immediate notice if risk is urgent
Shift-turnover note Communicates unresolved conditions and responsibilities to the next officer Open item at relief Before the outgoing officer leaves
Supervisor inspection or review Documents quality control and corrective action Scheduled or exception-based review According to the supervision plan
Immediate notification Gets decision-makers or responders involved now Violence, fire, medical event, forced entry, weapon, police/EMS, uncovered post, or client-defined critical event Immediately through the approved channel

A report does not replace an emergency call. Post orders should state who calls 911, which client and security contacts receive immediate notice, what channel to use, and what information to communicate.

What belongs in a daily activity report

A DAR should let a reviewer reconstruct the shift without reading a minute-by-minute diary of trivial activity. Required fields should reflect the post.

Header and assignment

  • Property or client name and precise post
  • Date, shift start and end, and time zone if relevant
  • Officer name or approved identifier
  • Supervisor or dispatch contact
  • Post-order version or assignment reference when useful
  • Equipment, keys, radio, vehicle, or access credentials received and returned

Chronological activity

Each meaningful entry should record time, location, task or observation, action, and result. Depending on the assignment, this may include:

  • Shift briefing and unresolved turnover items
  • Entrance, gate, door, fence, lighting, alarm, or equipment checks
  • Patrol zones or checkpoints
  • Authorized visitors, vendors, deliveries, or after-hours employees
  • Hazards, maintenance conditions, suspicious activity, and policy exceptions
  • Calls for service and assistance provided
  • Client, supervisor, police, fire, or EMS notifications
  • Incident-report number when a separate report was created
  • Items requiring management follow-up

Avoid filler such as “all secure” repeated every hour without saying what was checked. Conversely, a DAR should not expose sensitive personal details merely to appear comprehensive.

What belongs in an incident report

An incident report should answer who, what, when, where, how the officer learned of it, what the officer directly observed, what actions were taken, who was notified, and what remained unresolved. It should not declare guilt, diagnose a person, or determine liability.

Use this practical structure:

  1. Identification: Exact date, time, property, specific location, report number, officer, and relevant assignment.
  2. Initial information: How the officer became aware—personal observation, radio call, alarm, employee report, or another identified source.
  3. Conditions on arrival: People present, observable conduct, hazards, damage, open doors, alarms, lighting, weather when relevant, and other time-sensitive facts.
  4. Chronology: Actions and observations in order, with separate timestamps for significant developments.
  5. Statements: Identify the speaker and make clear that the information is attributed, not personally verified. Use exact short wording only when materially important and permitted.
  6. Actions and notifications: Safety actions, access control, 911, client contacts, supervisor direction, medical response, and police or fire agency information.
  7. Evidence and records: Approved photographs, video reference, found property, access logs, or scene protection—handled only under policy.
  8. Disposition and follow-up: Who took control, case or call number if supplied, temporary measures, open tasks, and required management review.

A simple quality test: FACTS

This is an editorial memory aid, not an industry or legal standard:

  • F — Factual: Separate direct observation from attributed statements and conclusions.
  • A — Accurate: Check names, approved identifiers, addresses, times, directions, and report numbers.
  • C — Chronological: Present events in an order a new reader can follow.
  • T — Timely: Notify urgent matters immediately and complete the record while details are fresh.
  • S — Secure: Use approved devices and systems, protect sensitive information, and preserve the audit trail.

Objective writing: show the behavior

Specific observable details are more useful than labels.

Weak wording Stronger, objective wording
“The man was suspicious.” “At 10:42 p.m., the person tried the north-office door handle three times after the building closed, then looked through the adjacent window.”
“The customer became crazy and violent.” “The customer raised their voice, struck the counter once with an open hand, and said, ‘I am not leaving.’”
“The employee was drunk.” “The employee’s speech was slurred, and the employee leaned against the wall while walking. I notified the shift manager at 8:16 p.m.”
“I handled the problem.” “I asked both visitors to step apart, contacted the client manager, and called 911 at 6:07 p.m. after one visitor displayed a knife.”
“Everything was fine.” “I checked the west gate, electrical-room door, loading-dock doors 1–4, and south fence line; no open access point or visible damage was observed.”

Do not add details that were not observed. If a person reports something, write “Jordan Lee stated…” rather than presenting the statement as established fact. Avoid slang, sarcasm, moral judgment, unnecessary descriptions of protected characteristics, and copy-and-paste language that does not match the event.

A clearly fictional example

The following sample illustrates structure only. It is not an Arrow form and should not be used as legal or evidentiary advice.

What makes the entry useful is not length. It states the assignment context, observation, location, time, safety decision, attributed information, notifications, resolution, and follow-up without guessing how the door opened.

GPS, checkpoints, and guard-tour data

Location technology can establish that an approved device reported from a place at a time. Depending on the system, it may capture a single point, geofence arrival, QR or NFC scan, patrol route, dwell time, photograph, or task response. Those are not equivalent.

Before contracting, define:

  • What the system actually records
  • Which device and user generate the record
  • Required zones, checkpoints, time windows, and randomized elements
  • What happens when GPS, cellular service, battery, camera, or the application fails
  • How missed or unusually fast patrols are flagged and reviewed
  • Whether a correction preserves the original record
  • Who can access officer location and when
  • Retention, export, deletion, and security controls
  • Whether the client sees raw data, summaries, exceptions, or none of the above

A checkpoint scan does not prove that the officer inspected the entire area, recognized a hazard, or followed the correct response. Pair verification data with meaningful observations, incident reports, supervisor review, and client feedback.

Arrow’s current property-management page says its daily activity reporting application captures an officer’s precise location as nightly reports are completed. That wording does not by itself establish continuous tracking, a full patrol route, every checkpoint, live client access, or a universal feature on every contract. Ask the proposal to document exactly which location, patrol-verification, client-access, and reporting features are included.

Photographs, video, and evidence

Photographs can document damage, an open gate, a lighting failure, a vehicle condition, or a hazard. They can also expose patients, students, residents, employees, license plates, access credentials, computer screens, or investigative information.

Create written rules for:

  • Situations in which an officer may or must take a photograph
  • Prohibited subjects and areas
  • Approved devices, accounts, applications, and storage
  • Original-file preservation, metadata, captions, and corrections
  • Who may view, download, share, redact, or delete a file
  • Retention holds, subpoenas, investigations, and client departure
  • What to do if an image is captured or shared improperly

Never use a personal phone, personal email, consumer messaging application, or personal cloud storage unless an emergency policy and counsel expressly authorize a specific exception. Do not touch, move, collect, or package potential evidence unless post orders, training, law, and the investigating agency allow it. Safety, emergency care, scene protection, and prompt police notification take priority. The National Institute of Justice emphasizes methodical scene documentation and chain of custody for trained investigators; a private guard should preserve observations and follow policy, not imitate a forensic investigator.

Corrections and record integrity

People make mistakes. A trustworthy system allows correction without concealing what changed.

The process should:

  • Preserve the original submission or an audit history
  • Identify the person making the correction
  • Record date, time, reason, and approval where required
  • Distinguish a factual correction from a later supplemental fact
  • Notify the client when a material report already delivered has changed
  • Prohibit deletion or backdating outside an approved records process

Supervisors should return vague or incomplete reports for correction while details are available. They should not rewrite an officer’s first-person observations to produce a preferred narrative.

Privacy, access, and retention

More data is not automatically better. Report only information necessary for the protective purpose and contractual obligation. Set role-based access for the security provider, client contacts, HR, legal, compliance, healthcare privacy, school leadership, insurance, and law enforcement as applicable.

There is no responsible universal retention period for every guard report. Requirements may arise from the contract, statutes of limitation, litigation holds, insurance, employment law, OSHA recordkeeping, healthcare or student privacy, public records, and industry rules. Obtain counsel’s approval and pause routine deletion when a legal hold or investigation applies.

A security incident report also does not replace an employer’s OSHA obligations. Covered employers may need an OSHA 301 Incident Report or equivalent for a recordable work-related injury or illness and must follow the timing, retention, privacy, and access provisions of 29 CFR Part 1904. The client—not the guard’s report template—determines and fulfills those obligations with qualified advice.

Turn reports into client accountability

Reports create value when someone reviews them, assigns action, and checks the result.

Every shift or next business day

  • Confirm critical events were already communicated
  • Check incomplete reports, missing patrols, or unresolved turnover
  • Route hazards and maintenance items to an owner
  • Preserve information needed for an investigation

Weekly or monthly service review

  • Group calls and exceptions by location, time, and type
  • Identify repeated open doors, lighting failures, trespass points, alarms, or policy conflicts
  • Compare assigned versus completed patrols and post coverage
  • Review report timeliness and quality
  • Track client complaints and compliments
  • Assign changes to staffing, patrol routes, post orders, training, maintenance, lighting, cameras, or access controls

Useful performance measures

Measure What it may show What it does not prove alone
Post and shift coverage Reliability of staffing Quality of officer decisions
Patrol completion and exceptions Adherence to assigned route/timing Complete inspection or crime prevention
Notification time Speed of communication Appropriateness of all actions
Report completion and correction Documentation discipline Accuracy without review
Repeat hazards closed Whether findings drive action Overall risk reduction by itself
Incident trend Changes in detected events Causation; more reporting may mean better visibility
Supervisor inspections Management presence and review Continuous performance at every post

Security does not guarantee that crime, injury, or loss will not occur. A sound reporting system demonstrates what was assigned, observed, communicated, reviewed, and improved.

Client report-quality checklist

  • The contract and post orders define DARs, incident reports, and urgent notifications.
  • Reports identify the exact post, officer, date, shift, time, and location.
  • Entries distinguish direct observations from statements by others.
  • Significant events have a clear chronology, notifications, disposition, and follow-up.
  • The client has approved photograph, video, GPS, privacy, retention, and correction rules.
  • Missed checkpoints, device failures, and uncovered posts generate documented exceptions.
  • Supervisors review quality and preserve an audit trail.
  • Client managers receive reports through secure, defined channels.
  • Recurring risks become assigned corrective actions with deadlines.
  • Legal, HR, safety, healthcare, or school records are routed to the correct separate process.

Frequently asked questions

What is the difference between a daily activity report and an incident report?

A DAR is the chronological record of routine shift activity. An incident report provides focused detail about a significant event. The DAR can reference the incident-report number, but sensitive incident details should not be copied unnecessarily into every routine report.

Should an incident report include photos and GPS data?

Only when relevant and authorized. GPS may support the time and location; an approved photograph may document a condition. Neither is necessary or appropriate in every event. Healthcare, schools, residences, employee matters, and active investigations may require stricter privacy and evidence controls.

Can GPS prove a patrol happened?

It can support that an approved device was at a recorded location and time, depending on the system. It does not automatically prove who carried the device, what was inspected, what was observed, or how well the task was performed.

When should the client be called instead of waiting for the report?

The contract and post orders should list immediate-notification events. Common examples include violence, weapons, fire, serious medical events, forced entry, major property damage, police or EMS response, missing critical keys, a major access failure, or an uncovered post. Emergencies go to 911 first as the plan requires.

How long should security reports be kept?

There is no universal period. The client and provider should set a counsel-approved schedule that accounts for contract needs, insurance, privacy, employment and safety records, potential claims, investigations, and legal holds.

Can report volume show whether security is effective?

Not by itself. More reports may reflect better detection or a worsening condition; fewer reports may reflect improvement or underreporting. Evaluate coverage, report quality, response, patterns, corrective actions, stakeholder feedback, and outcome data together.