reportsincident reportingpost orders

How to Write a Daily Activity Report (With Examples)

CGuardPro

Most daily activity reports are written for nobody. The officer fills them in because the post orders say to, the supervisor skims the last line, and the file sits until the day someone actually needs it — a client dispute, an insurance question, a subpoena — and then everyone discovers that eight months of DARs say “all secure” and nothing else. Learning how to write a daily activity report properly is not about writing more. It is about writing the specific things that will still mean something to a stranger a year from now.

Who actually reads a DAR

Write for four audiences, in this order:

The relieving officer. They need to know what is different about the site right now: which door is broken, which contractor is still inside, which vehicle has been in the lot for three days.

Your supervisor and account manager. They need patterns. Three DARs mentioning the same unsecured gate is a maintenance ticket for the client and a talking point at the next review.

The client. They are paying for presence and they read the DAR as proof of it. A vague report reads like an absent officer, even when the officer was excellent.

A lawyer, eventually. Somebody may read this in a deposition. That reader knows nothing about the site, was not there, and is looking for gaps and contradictions.

The fourth reader is the reason for almost every rule that follows. Write so that a stranger with no context can reconstruct the shift.

The five things every entry needs

Every line in a DAR should answer: when, where, what, who, and what came of it.

  • When — actual clock time, not “later” or “around midnight.”
  • Where — the specific location as named in the post orders. “Northeast stairwell, Level 3,” not “upstairs.”
  • What — an observable fact. Something you saw, heard, smelled or did.
  • Who — the people involved, identified as far as you legitimately could.
  • Outcome — what you did and how it ended.

If an entry is missing one of those, it is a note, not a record.

Weak versus strong: worked examples

The difference is never vocabulary. It is specificity and the discipline to separate what you observed from what you concluded.

Routine patrol

Weak: 0200 — Conducted patrol. All secure.

Strong: 0158–0221 — Exterior patrol of Building B perimeter, all four checkpoints scanned. All ground-floor doors and windows secured. Loading dock overhead door closed and locked. Lot lighting normal except pole light L-7 (northwest corner) out; same as noted on 08/19 and 08/21 DARs. No persons observed.

The strong version tells the relieving officer that L-7 is a three-day problem, which is how a maintenance request gets generated instead of a line item that repeats forever.

An unlocked door

Weak: Found a door open on the third floor. Secured it.

Strong: 0342 — Suite 310 main entry door found unlocked and closed, no lights on inside, no persons observed. Entered and cleared visible common area; no signs of disturbance or missing property observed. Secured door and verified latch engaged. Notified Dispatch at 0347. Per post orders, left voicemail for tenant contact Marisol Reyes at 0350. Reported to relieving officer at 0600.

Note what the strong version does not say: it does not say the tenant forgot to lock it, and it does not say nothing was taken. The officer does not know either of those things. “No signs of disturbance observed” is defensible. “Nothing was stolen” is a claim you cannot support and that a plaintiff’s attorney will enjoy.

A person on the property

Weak: Homeless guy hanging around the back. Told him to leave.

Strong: 2317 — Observed an adult male, approx. 40s, gray hooded sweatshirt, dark pants, seated against the wall near the rear dumpster enclosure. Approached and identified myself. Subject stated he was waiting for a ride. Advised him the property is private and that he needed to leave. Subject complied without incident and departed north on Marlow Street at 2323. No property damage observed. No police contact requested by client contact.

The weak version contains a conclusion about a person’s housing status the officer cannot know, no description, no times, and no outcome. If that man returns and something happens, the weak entry proves nothing. The strong one establishes a prior warning, a description and a timeline.

Equipment and alarms

Weak: Alarm went off, was a false alarm.

Strong: 0412 — Audible alarm at east fire exit, Building A. Responded and arrived at 0414. Door found ajar approx. six inches, propped with a folded cardboard box. No persons in the stairwell or corridor. Removed obstruction, closed and confirmed door secured; audible ceased at 0416. Notified Dispatch 0417. Photographed the propped door prior to removing obstruction. Cause of the door being propped is unknown.

“False alarm” is a conclusion. A propped fire exit is a fact, and it is a fact the client’s safety officer needs to see, because someone is propping it deliberately and repeatedly.

Language rules that hold up under scrutiny

Write in past tense, first person, active voice. “I observed,” not “it was observed.” Passive voice hides who did what, which is precisely the thing a reader is trying to establish.

Facts before conclusions — and label the conclusion. “Subject appeared unsteady on his feet and had slurred speech” is an observation. “Subject was drunk” is a diagnosis you are not qualified to make. Write the first.

No labels for people. No “suspicious,” “vagrant,” “gangbanger,” “crazy.” Describe behavior and appearance. Behavior is evidence; labels are opinions that will be read back to you.

No editorializing. “The tenants never lock anything” belongs in a conversation with your supervisor, not in a permanent record.

Times as clock times, always. “Approximately 0230” is fine when you are estimating; “later that night” is not.

Spell out names, plate numbers and unit numbers. Abbreviations that make sense to you today mean nothing in a year.

Never leave a gap. A DAR with entries at 2200 and 0400 and nothing in between reads as four hours of sleep, whether or not that is what happened. Log routine patrols even when nothing occurs — the pattern of activity is itself the record of presence.

Writing it in the field instead of at the end

The single biggest quality difference is when the entry gets written. A DAR reconstructed at 0545 from memory loses times, sequence and detail, and it is where invented precision creeps in. Entries written at the moment are shorter, more accurate and more defensible.

That is a practical argument for writing the DAR from the officer’s phone as the shift goes, with times, location and photos captured automatically at the moment of the entry rather than typed from memory hours later.

Officer mobile app incident and report screen used to log an entry from the field

It also connects the report to what the officer actually did. When patrol checkpoints are scanned with a QR-based tour system, the DAR does not need the officer to claim they walked the perimeter — the scan record shows the route and the times, and the written entries carry only what the officer saw.

What happens to the report after the shift

A DAR nobody reads teaches officers that DARs do not matter, and the writing quality follows within a month. The fix is unglamorous: supervisors read them, and officers see evidence that they were read.

On the operations side, reports that arrive in one queue can be reviewed, flagged and searched instead of accumulating in a binder at the guard shack.

Operations dashboard showing the incoming report and incident queue for review across sites

Give feedback on two or three reports per officer per month, and be specific: not “write better reports,” but “this entry needed the door’s condition before you touched it.” That is the whole training program, and it works better than any classroom session.

Search matters too. The value of a DAR archive is answering a question like “has anyone reported that gate unsecured before?” in thirty seconds during a client call. Structured daily activity reports that are searchable across sites and dates turn a compliance chore into the thing that wins the account renewal.

The one-sentence test

Before you close an entry, read it and ask: could someone who was not here reconstruct what happened, and would they reach the same conclusion I did? If yes, it is a report. If they would need to ask you a question, finish the entry.

If you want to see how field-written reports, tour scans and a reviewable queue fit together, explore CGuardPro or get in touch.

Run the whole operation in one place

Shifts, attendance, patrols, incident logs and clients on one platform — with the guard app on site and the client portal on the other side.

  • Attendance with selfie and GPS
  • QR patrols and a digital logbook
  • Client portal included

Keep reading