contractsclientsoperations

Service Level Agreements for Security Contracts

CGuardPro

There is a specific kind of contract security company that signs anything. The RFP comes back with a security service level agreement attached, the numbers look reasonable, somebody initials it, and eighteen months later there is a meeting where a client is reading a clause out loud and asking for a credit. Nobody in that meeting has the data to argue, because the metric that was promised was never something the company could actually count.

A security service level agreement is not a statement of intent. It is a set of numbers that someone will eventually try to enforce. The only useful discipline when writing one is to ask, for every line: can I produce the evidence, automatically, without a supervisor rebuilding it from memory at the end of the month?

The difference between a standard and a service level

Most guard contracts already contain standards: officers will be licensed, uniformed, trained on post orders, courteous to tenants. Those are conditions of performance. They are binary and mostly unmeasured — you either violated them or you did not, and the violation shows up as a complaint.

A service level is different. It is a continuous quantity with a target and a measurement window. “Officers will be on post” is a standard. “Scheduled post hours will be filled at or above an agreed threshold, measured monthly” is a service level. The second one has a denominator, and the denominator is what makes it enforceable — and what makes it dangerous if you cannot compute it.

Confusing the two is how companies end up with a security service level agreement full of adjectives. Nobody can litigate “professional appearance.” Everybody can litigate an unfilled shift.

Metrics that belong in a security service level agreement

The test for every candidate metric is threefold: it must be objectively countable, it must be inside your control, and the count must exist as a byproduct of normal operations rather than as extra clerical work.

Post coverage

The foundation of every guard contract. Scheduled post hours versus hours actually worked, with a defined treatment for late relief and for hours covered by an officer who was not the assigned officer. Both sides need to agree in advance on the grace window — is an officer clocking in eight minutes late a covered hour or a gap? Write it down, because you will argue about it otherwise.

Coverage is measurable if and only if your clock-in record is trustworthy. A paper sign-in sheet cannot support a coverage SLA; it can be filled in at the end of the week by anyone. Verified clock-ins with location and a photo turn coverage from an assertion into a record. This is the least glamorous part of a security operation and it is the part every SLA rests on.

Guard mobile app home screen showing the current shift, assigned post and clock-in action

Patrol and tour completion

Checkpoints scanned versus checkpoints scheduled, by tour and by shift. This is one of the cleanest SLA metrics in the industry because the evidence is timestamped at the point of performance and cannot be reconstructed afterward.

Two cautions. First, agree on what happens when a checkpoint is genuinely unreachable — a flooded stairwell, a locked tenant space, an active fire alarm. Build an exception path into the metric or you will be paying credits for events outside your control. Second, do not agree to a completion target of one hundred percent. It sounds strong in a proposal and it guarantees you are in breach the first month, which trains the client to treat the SLA as decorative.

Report delivery

Daily activity reports delivered within an agreed window of shift end. Incident reports delivered within a shorter window for defined severity levels. This is entirely within your control and it is one of the metrics clients care about most, because a late report is the thing their own boss notices.

Incident acknowledgment and escalation

Time from an incident being reported to the client’s designated contact being notified, by severity tier. Note the wording: acknowledgment and notification, not resolution. You control whether you call. You do not control whether the police arrive.

Supervisory visits

Field supervisor site visits per month, with an inspection record. Simple, countable, and it is often the metric that most improves actual service quality, because it forces the visit to happen.

Staffing continuity

The percentage of post hours covered by officers regularly assigned to the site, versus fill-ins. Clients rarely ask for this and value it enormously. It is also honest about the industry: you cannot promise zero turnover, but you can promise a continuity floor and a named primary officer.

Metrics that do not belong

Response time to an incident anywhere on a large property. Unless you have a way to timestamp both the call and the arrival, this is a number you are guessing at. Guessed numbers become credits.

Anything measured on the client’s systems that you cannot see. If the metric depends on their access control logs or their camera platform, you are agreeing to be judged by data you cannot audit.

Crime reduction. Some proposals actually promise a reduction in incidents on the property. Incident volume is driven by the neighborhood, the economy, the tenant mix and reporting diligence. Tie your fee to it and you have created an incentive to under-report, which is the single worst thing you can build into a security contract.

Turnover rate as a hard number. Labor market conditions are not within your control. Continuity of coverage at the site is; company-wide turnover is not.

Customer satisfaction scored by a survey nobody sends. If it is in the contract, it will be enforced by whoever remembers it exists, and that will be the client, at renewal.

Reporting without manual work

An SLA you report on by hand will be reported on for three months and then quietly stop. Somebody will be on vacation, then the supervisor who built the spreadsheet leaves, and the next time anyone assembles the numbers is when the client is unhappy — which is the worst possible moment to be discovering your own performance.

The way out is to make the SLA a view of the operating record rather than a separate reporting project. Coverage comes out of the scheduling and attendance record automatically. Tour completion comes out of the QR checkpoint scans automatically. Report timeliness comes out of the timestamps on daily activity reports. None of these require a person to compile anything; they require that the work was captured digitally when it happened.

Operations dashboard showing live coverage, patrol activity and incident volume across sites

Then give the client the same view. A client who can see coverage and tour completion in a portal at any time will almost never dispute the monthly number, because they have been watching it accumulate. A client who receives a single PDF at month end has every reason to be skeptical of it.

Writing the remedy clause carefully

Most SLA disputes are not about the metric. They are about what happens when you miss it. Three things are worth negotiating hard:

Cure periods. A first miss should trigger a corrective action plan, not an immediate credit. Security is a labor business and labor has bad weeks.

Credit caps. Uncapped credits on a low-margin guard contract can consume the entire profit of an account that is otherwise performing well.

Exclusions. Severe weather, client-caused access failures, a client’s own last-minute schedule changes, and force majeure. If the client’s property manager cancels a post at 4 p.m. and reinstates it at 6 p.m., that gap is not yours.

An SLA written this way protects both sides. It gives the client a real, auditable commitment instead of adjectives, and it gives you a defined boundary instead of an open-ended obligation to be perfect.

If you want to see what a continuously measured operating record looks like, explore CGuardPro or get in touch.

Run the whole operation in one place

Shifts, attendance, patrols, incident logs and clients on one platform — with the guard app on site and the client portal on the other side.

  • Attendance with selfie and GPS
  • QR patrols and a digital logbook
  • Client portal included

Keep reading