protocolsdispatchoperationspatrols

Alarm Response SOP for Contract Guards: The Whole Run, Start to Close

Edison U. •

Alarm response is the service a guard company is most likely to sell badly and perform badly at once, because almost nobody writes down what the run consists of. The contract says “response to alarm activations”, the rate is agreed per run, and then the first activation lands on a Sunday at 04:20 and the officer improvises.

Here is one full run, from the notification to a file closed well enough to survive a client dispute three months later.

First, a vocabulary correction that matters

The alarm signal does not come from your office. It comes from a central station — a facility that receives alarm, fire and video signals from third-party systems and handles them under a defined procedure. That is a regulated, listed thing; in the United States the reference is UL 827, Central-Station Alarm Services, and the listing is audited.

Your dispatch desk is not that. It is your own operations desk: the people who know which posts are filled right now, take reports from the field, arrange relief and send a supervisor or a patrol vehicle. Its raw material is your officers at your sites, not other people’s alarm signals.

This is the single most common vocabulary mistake in the industry, and using the two terms interchangeably in a proposal tells a sophisticated buyer exactly how much you know. Both entries are in the industry glossary, with what each one gets confused with. Keep them apart in your SOP too: the central station dispatches you, and your dispatch desk assigns the run.

Step 1 — The notification lands

The call from the central station should give you five things, and if it does not, your dispatcher asks for them before hanging up:

  • The site and the specific zone that tripped
  • The signal type — burglary, fire, panic, supervisory, trouble
  • The time of the activation, not the time of the call
  • Whether the subscriber has been reached, and what they said
  • Whether police or fire are already rolling

Write these into the case the moment you have them. The gap between activation and arrival is the number a client eventually asks about, and reconstructing it from memory is not a defensible answer.

Step 2 — Who goes

Three answers, in descending order of preference.

A dedicated mobile patrol unit. The right answer if you run one: already in the vehicle, not abandoning a post, and this is its whole job.

A roving supervisor. Acceptable, and common in smaller operations. Log it, because a supervisor on an alarm run is a supervisor not doing supervision, and three of those a week is a staffing problem disguised as a service.

Pulling an officer off a static post. This should require dispatcher authorization every single time, and it should be uncomfortable. It trades one client’s service for another’s, and the client whose post went dark did not agree to it. If your post orders permit it at all, they should name the exact circumstances.

Whoever is running your dispatch desk owns the ETA. Give the central station a real number and update it if it slips. “On the way” is not an ETA.

Step 3 — The approach

The officer is responding to an unknown, not clearing a building. The distinction governs everything he does next.

Park short and dark. Not at the front door. Far enough back that the vehicle is not the first thing anyone inside sees, and positioned so it is not boxed in.

Announce arrival on the radio before leaving the vehicle, with the location and a plain-language description of what he can see. This is one of the few moments where plain language beats radio codes — dispatch needs to understand it the first time, and so will anyone who reads the transcript later.

Do the exterior first, and completely. A full circuit before touching a door: ground-floor windows, service doors, the visible roof line, the dumpster enclosure, the loading bay, vehicles that do not belong. Note doors unsecured but undamaged — those are as informative as broken ones.

Step 4 — The entry decision

This is the point in the SOP that most companies leave blank, and it is the one that gets officers hurt.

Default to no entry. An unarmed contract officer, alone, at night, entering a building where a burglary alarm has activated is doing law enforcement’s job without law enforcement’s training, equipment or backup. The written default: secure the exterior, hold a position with a view of the point of concern, and wait.

Entry is authorized only when specific conditions hold, written per account: the exterior is intact with no signs of forced entry, the officer has a key or code and is trained on the panel, the post orders authorize interior checks, and dispatch has acknowledged the entry before it begins. Interior checks after a confirmed forced entry are a police function. Full stop.

Signs of forced entry, a person on site, or anything the officer cannot explain: back out and call. There is no version of this business where an hourly officer should be clearing a building because a client would prefer not to have a false-alarm fee.

Step 5 — Calling police, and what you say

Call when there is evidence of forced entry or a crime in progress, when a person is on the property who should not be, when there is any injury, or when the client’s post orders say so regardless of what you find.

What you tell the 911 dispatcher, in this order:

  1. Location — full street address, plus the building or gate to come to. Not the account name; “Northgate Logistics” means nothing to a patrol car.
  2. What you have — “forced entry to a rear service door at a commercial warehouse, alarm at 04:20, no one visible.”
  3. Whether anyone is inside — including your own officer. Say so explicitly.
  4. Who your officer is and where he is — uniform, vehicle, exact position. This is the part people forget, and the part that stops a uniformed private officer with a flashlight being mistaken for the burglar.
  5. A callback number a human answers. Your dispatch line, not the officer’s cell.

Then tell your officer that police are coming, where they will approach from, and to stay visible and keep his hands empty.

Step 6 — What gets documented, and when

Document as the run happens, not at the end of the shift. A run written from memory at 06:30 loses exactly the details that matter.

The record should carry:

  • Activation time, notification time, dispatch time, on-scene time, cleared time. Five timestamps, and they are the spine of the whole document.
  • Zone and signal type as given by the central station.
  • The exterior circuit — what was checked and what condition it was in, including the things that were fine. “All ground-floor windows intact” is evidence; silence is not.
  • Whether entry was made, on whose authorization, and what was found.
  • Police involvement: whether they were called, when, whether they attended, and any report number they gave you.
  • Who reset the alarm and whether the site was left secure.
  • Photographs.

On photographs: capture them at the scene, in the app, attached to the case as you go. A picture of the damaged door taken at the door carries a timestamp and a location. The same picture texted from a personal phone next morning carries neither, and if the run becomes a claim, how the evidence was handled is examined as closely as what it shows.

One note before you promise anything: on a site with no cell signal, an incident filed in the CGuardPro app is held in an offline queue and keeps its real capture time, so a 04:41 exterior check is recorded as 04:41 even if it only reaches the server when the vehicle gets back to the road. Patrol checkpoint scans do not preserve their original time, so if timing is contractually important, put it in the incident, not the scan — a rule that applies to patrol runs generally.

Step 7 — Closing it so it is still useful in three months

Most alarm runs are false. That is not a reason to close them thinly. Write for the dispute that arrives in February about a run in November: your officer never showed, or he showed but he did not check the back, or we were billed for four runs and I only know about two.

A closeable file answers all three without anyone’s memory. Five timestamps, the exterior circuit in the officer’s words, the photographs, the police report number if there is one, and a stated cause where one is known — a door that does not latch in cold weather, a motion sensor aimed at an HVAC vent, a cleaning crew arriving early.

That last field turns alarm response from a cost into an argument for renewal. Four runs in six weeks on the same zone is not four incidents; it is one maintenance problem you are being paid to absorb. Put it in the monthly reporting with the cause attached and the conversation changes from a line item to a fix.

Two more things belong in the close:

Route the serious ones by severity, not by type. A run that turned up a forced entry is not the same record as one that turned up a loose door, even though both start identically. Give the run a severity at close and let that decide who reads it tonight versus Monday — incident reporting should treat a confirmed break-in the way it treats any other serious event.

Keep the officer’s own panic path separate. Alarm response is a service you sell; the panic button on your officer’s phone is a protection you owe him. They travel different routes, to different people, at different speeds, and merging them so that an officer’s SOS lands in the same queue as a client’s false burglary alarm is a mistake with a predictable ending. When an officer on an alarm run presses SOS, that is a Level 1 event in your operation, and nothing about the alarm run matters until he answers.

Run the whole operation in one place

Shifts, attendance, patrols, incident logs and clients on one platform — with the guard app on site and the client portal on the other side.

  • Attendance with selfie and GPS
  • QR patrols and a digital logbook
  • Client portal included

Keep reading