A guard tour system is the equipment and software a security company uses to record that an officer physically went to a specific place at a specific time, in a defined order, and to turn those records into something a client can read. That is the whole definition. Everything else — wands, QR codes, NFC tags, GPS, apps, dashboards — is an argument about how you capture that record and how much it is worth once you have it.
The reason the term shows up in so many conversations is that it sits exactly where a security contract is most fragile. The client is buying something they cannot see happening. The officer is doing work nobody watches. The tour system is the only thing standing between those two facts and a monthly argument.
How a guard tour system works, step by step
Strip away the vendor language and the mechanism is short:
- Checkpoints are fixed to the site. A physical token — a metal button, an NFC tag, a printed QR code — is mounted at a location that matters: a rear fire door, a chemical store, a stairwell landing, a gate post at the far end of the lot.
- A route is defined. Which points, in what order, within what window, how many times per shift. This is the part most companies under-think.
- The officer records each point. With a dedicated reader, or with the phone they already carry.
- The records reach a system. Immediately over the network, or later when the device is docked.
- Someone is supposed to look. A missed point should raise something while the shift is still running. If nobody looks until the monthly report, you do not have a tour system, you have an archive.
Step 5 is where most deployments quietly fail. Buying the hardware is easy. Building the habit of reacting to a missed point the same night is the part that changes anything.
The wand era, and why those buttons are still screwed to walls
For roughly three decades the standard tool was a handheld reader — a Deggy pipe, a Detex clock, an iButton wand. The officer touched it to a steel button embedded in a wall or post, and the wand stored a serial number and a timestamp in memory. At the end of the week someone docked the wand in a cradle, ran the desktop software, and printed a report.
It worked, on its own terms. It was rugged, cheap to run, needed no signal, and the buttons are effectively indestructible — which is precisely why you still find them on sites today, twenty years after the reader that read them was thrown away. Nobody removes them. A new contractor takes over the site, inherits a wall studded with little steel discs, and has no idea which system they belonged to.
What the wand era could not do is more important than what it could:
- Nothing was known until the download. A gap in Tuesday’s coverage surfaced on Friday, after the client had already asked.
- The record was a serial number and a time. No note, no photograph, no name of the officer unless someone wrote it in a logbook separately.
- The wand itself could go on the tour. A button-and-reader pair proves that reader met that button. It does not know who was holding it, and a wand fits comfortably in a coat pocket carried by somebody doing all four routes at once.
Phone-based systems inherited that last problem rather than solving it. They just made it cheaper to fail differently, and they added a name, a note, a photograph and a position to a record that used to be a number and a time.
The three checkpoint types, and what each actually buys you
QR codes. A printed code the phone camera reads. Effectively free to produce, replaceable by emailing a PDF to the site contact, and easy to add the same day a client asks for a new point. It fails in the dark without a light, in direct glare, and once weather has faded the print. It is also the easiest to photograph and scan off a screen.
NFC tags. A passive chip the phone reads on contact. Immune to light, grime and gloves; far more durable outdoors. It costs more per point, has to be ordered and shipped when one is destroyed, and it will not read at all if it is stuck directly to steel unless it is a tag built for metal mounting. The full comparison is in NFC vs QR checkpoints.
GPS-only checkpoints. No physical token at all: the system records the officer as having reached a point when the phone’s position falls inside a radius. Attractive because there is nothing to install and nothing to vandalise. The honest limitation is precision. Consumer GPS is accurate to a handful of metres outdoors on a clear night and considerably worse between buildings, under a canopy, in a parking structure or in a concrete stairwell — which is where the checkpoints that matter usually are. A radius wide enough to work reliably is often wide enough to be satisfied from the vehicle. GPS-only is reasonable on large open sites and vehicle patrol routes. It is weak everywhere the interesting parts of a building are.
Most companies past a handful of sites end up mixing all three, which is fine as long as one route can carry points of different kinds and the client’s report does not expose the difference.
What “proof of presence” actually proves
This is the sentence every vendor sells and almost nobody qualifies, so here it is plainly.
What a scan proves: a particular device, signed in as a particular user account, was close enough to a particular token to read it, and the system holds a record of when it learned about that.
What it does not prove:
- That the officer was the one holding the phone. Identity is an account, not a person. Requiring a photo at selected points is the cheapest correction available, because a photograph of the actual location at the actual hour is much harder to fake than a scan.
- That the token was where you left it. A tag can be pried off; a code can be photographed. Pairing each scan with a GPS position is what makes a scan recorded fifteen miles from the site obviously wrong. It does not make a scan from the parking lot obviously wrong.
- That anything was inspected. The scan says a point was reached. Only a note, a photo, or a checklist answer says anything about the condition of what was there.
- That the time on the record is the time it happened. This one deserves care. In our own system, a tour start and finish will queue if the officer is out of signal — but the scan is stamped when the server receives it, not when the officer stood at the point. An incident report is different: it keeps the time it actually happened. Clock-in does not queue offline at all. If a vendor tells you their tour timestamps survive a dead zone unchanged, ask them to show you, on a phone in airplane mode, in front of you.
None of this makes tour data worthless. It makes it evidence rather than proof, and evidence is what disputes are settled with. The distinction matters most when the record ends up somewhere formal, which is the subject of the guard tour audit trail.
Why the client asked for one
Operations managers tend to receive this request as a general interest in patrol quality. It almost never is.
A client who asks about a guard tour system is usually asking about one night. Something happened — a break-in through a door that was supposed to be checked hourly, a flooded plant room found at 7 a.m. that should have been seen at 3, a tenant complaint that the officer never left the lobby. The property manager has to explain it to somebody above them, and they have discovered that your evidence for that shift is a signature on a sheet.
Read the request literally and you will sell them checkpoints. Read it correctly and you will ask which night, and then design the route around the thing that went wrong: the specific door, the specific window of hours, the specific proof that would have settled it. That is also what makes the resulting report survive, because it answers a question the client already cares about. Reports built the other way — everything logged, nothing highlighted — go unread within two months. What clients actually read in a tour report covers the difference.
What to check before you buy one
Five questions, in the order they cost you money:
Who administers it, and how long does a change take? If adding a checkpoint requires a support ticket, your account managers will stop asking and the system will freeze in whatever shape it launched with.
What happens with no signal? Get the specifics for each record type — scans, incidents, clock-in — rather than the word “offline”. They are rarely the same.
What does the officer’s phone look like at the end of a 12-hour shift? A tour app that holds GPS continuously will flatten a battery, and an officer with a dead phone files nothing.
Where does the tour record sit relative to everything else? A tour system that does not connect to the roster cannot tell you the tour was missed because the post was uncovered. That linkage is the difference between a checkpoint tool and patrol management, and it is why tours, attendance and reporting are usually worth buying together.
What is the first-year total? Tags, printing, install visits, the site walk to place points, replacements, and the subscription. Compare that against what the tours are meant to protect: usually one contract.
If you want to see the mechanism rather than read about it, our guard tour system page shows how QR and NFC checkpoints, GPS position and officer identity are recorded together in the guard app, and you can get in touch if you would rather walk a route with us than watch a demo.