incident reportingprotocolsoperationssupervision

Security Incident Severity Levels: What Actually Earns a 3 a.m. Call

Edison U. •

At 3:14 a.m. an on-call supervisor’s phone rings. An officer at a distribution center found an interior office door unlocked, checked it, found nothing, and locked it. He did exactly what he should have done. He also did one thing he should not have: he called a sleeping supervisor to say so.

Six weeks later that same supervisor sleeps through a call about a broken ground-floor window, because by then his phone rings four times a night and he has learned to let it go to voicemail. That is what happens when every incident is urgent. The escalation path does not fail loudly — it erodes, one unnecessary call at a time, until the call that mattered is indistinguishable from the noise.

Security incident severity levels exist to solve exactly this. Not to create paperwork, and not to rank human suffering, but to answer one question at the post, in the dark, in under ten seconds: does this wake somebody up, or does it go in the report?

Why five-level scales fail in contract security

Most severity scales borrowed into this industry come from IT service management, and they arrive with five levels. Five is one too many for a field operation.

Here is the practical test. Hand a new officer a five-level scale on his second night and ask him to sort a car with a smashed window in an unattended lot. Is that a 3 or a 4? He does not know, and neither does the officer next to him. When two reasonable people classify the same event differently, the level stops carrying information and everyone downstream reverts to reading the narrative. At that point the scale is decoration.

The opposite failure is a two-level scale — “normal” and “emergency”. Everything alarming but not life-threatening (a repeat trespasser, a fire panel in trouble, a contractor on site at midnight with no work order) has nowhere to go, gets filed as normal, and is not seen until the pattern turns into a claim.

Four levels survives contact with a real shift: small enough to memorize, wide enough to hold the middle ground where most of the interesting work lives.

A four-level scale that works on a post

Level 1 — Critical: someone is hurt or about to be

Active violence, a weapon, a medical emergency, a structure fire, a missing child, an officer who has stopped responding on the radio. Anything where the correct next action involves 911 and the answer to “can this wait until morning” is obviously no.

Level 1 is deliberately narrow. If officers are filing several a week across a normal book of business, the definition has drifted — a category that fires constantly is one nobody sprints for.

Level 2 — Serious: the client’s interests took a hit, or nearly did

A completed break-in, theft above a threshold you set, property damage, a use-of-force event, a vehicle collision on site, a trespasser who refused to leave, an officer injury that did not need an ambulance. Nobody is in immediate danger, but a client is going to hear about it, and possibly a carrier or an attorney.

Level 2 is where most contract-security litigation risk actually lives, and it is the level companies most often under-call. A use-of-force event is Level 2 by definition, even when it lasted four seconds and everyone walked away — because the documentation window closes fast and the account of it you get at 6 a.m. is worse than the one you get at 2 a.m.

Level 3 — Notable: it matters, but it matters in the morning

The unlocked office door. A door held open with a wedge. A gate latch that has failed twice this week. A camera offline since Tuesday. A contractor on site outside approved hours. Graffiti. A vehicle parked in the same visitor space for four days.

Level 3 is the level the industry systematically ignores, and it is the most useful one you own. Nothing here needs a phone call, but every one of these is a precursor. The value only shows up when someone actually reads them — which means a Level 3 has to arrive somewhere a supervisor looks at the start of every day, not just into a report the client receives at month end.

Level 4 — Logged: it happened, it was handled, that is the record

Alarm activation that resolved as a false, a member of the public asking for directions, a delivery outside hours that was verified and let in, a fire-drill escort, a minor equipment fault the officer fixed. These belong in the shift log, not the incident queue.

Level 4 keeps the other three clean. Without it, officers trained to “document everything” file routine work as incidents, and incident volume becomes a measure of officer diligence rather than site risk.

Who assigns the level — and who is allowed to change it

The officer at the post assigns the initial level. That is not a compromise; it is the only workable design. He holds the facts, and any scheme requiring a supervisor to classify before the record exists just means the record gets created late.

Then two things must be true:

Officers can always over-call, never under-call, without consequence. State it in the post orders and say it out loud in training: if you are unsure between two levels, pick the higher one and nobody will second-guess you. The moment an officer gets criticized for a Level 2 that turned out to be a Level 3, you have taught your entire force to under-report, and you will not find out until something serious gets filed as routine.

Only a supervisor reclasses, and the reclass is visible. A supervisor downgrading a Level 2 to a Level 3 is a normal, healthy event. A supervisor downgrading it silently, so the original call disappears, is how a company ends up unable to explain in a deposition why nobody was notified. Keep the original level and the reclass together in the incident record, with the name of whoever made the change.

The notification matrix

The scale is worthless until it is attached to specific people and specific clocks. This is the part most companies never write down, and it is a single table:

LevelOfficer doesDispatch doesWho is contactedWithin
1 CriticalCall 911 first, then dispatchConfirm 911, notify on-call supervisor, start a caseOn-call supervisor, then the client’s emergency contact, then the account managerImmediately
2 SeriousFile before end of shift, attach photosAcknowledge, assign an owner, decide if the client is told tonightOn-call supervisor by phone; client per the contract’s notification clauseWithin the hour
3 NotableFile before end of shiftRoute to the account’s supervisor queueSite supervisor at the next business morningNext business day
4 LoggedRecord in the shift logNothingNobody—

Two details decide whether this survives:

“Immediately” and “within the hour” have to be real. If your on-call rotation is one person covering nine accounts, the matrix is fiction. Build the contact tree with a named backup at every position and a rule for when the primary does not answer.

The client’s notification threshold is a contract term, not an operational preference. Some clients want a call for any Level 2. Some want a call only for Level 1 and a morning summary for everything else. Some property managers explicitly do not want to be woken. Get it in writing during onboarding, put the answer in the post orders for that account, and note it beside the matrix — because the officer standing in the parking lot at 2 a.m. should not be guessing at a client’s preference.

Wiring it into the day

A severity scale that lives in a training binder gets used for about three weeks. To make it stick, it has to appear in three places officers already touch.

In the post orders, per account. The generic scale is company-wide, but the examples must be site-specific. “Level 3: any vehicle parked in the loading bay after 20:00” means something at a warehouse and nothing at a hospital. This is why post orders are the right home for the examples and the wrong home for the scale itself.

In the report form. A required field at the top of the incident, chosen before the narrative is written — not inferred afterwards by whoever reads it. Making it the first decision forces the officer to think about escalation while he still has the option to escalate.

In the pass-down. Every open Level 2 and Level 3 belongs in the shift pass-down, with what has been done and what has not. An incident that was “handled” on nights and never mentioned to days is functionally an incident that did not happen.

One boundary worth policing: severity is not incident type. A theft can be Level 1 or Level 3 depending on whether anyone is still on the property. If your team treats “theft” as a severity, two fields have collapsed into one — the distinction between an incident report and a DAR is the same argument one layer up.

The test of whether it is working

Run it for a quarter, then ask your on-call supervisor one question: how many calls last month should not have been calls?

Zero means the scale is too loose — officers are filing as Level 3 things that deserved a call, and a month of Level 3s will tell you which. “Most of them” means the definitions are not specific enough at the account level, and the fix is in the post orders. One or two means you have it.

Then the harder work starts: making sure somebody reads the Level 3s. That queue is where the pattern shows up, and it is the first thing to vanish when dispatch is busy — which is exactly why it needs a named owner and a standing time on somebody’s morning.

Run the whole operation in one place

Shifts, attendance, patrols, incident logs and clients on one platform — with the guard app on site and the client portal on the other side.

  • Attendance with selfie and GPS
  • QR patrols and a digital logbook
  • Client portal included

Keep reading