Security incident reporting software
that treats an incident as a case, not a diary entry
An incident is the exception, not the routine. Something discrete happened at a post — a trespass, an assault, a broken gate, a use-of-force — and from that moment it has a lifecycle: it gets documented, evidence gets attached, a supervisor reviews it, the client gets notified, and somebody closes it. CGuardPro gives that lifecycle a case number, an owner and a clock, so an event does not quietly become a paragraph nobody can find nine months later.
Real product screenshots
Why incident documentation fails in the field
Written at 3am, wanted at 9am
The officer writes it standing at a dock door in the dark, one-thumbed, at the end of a twelve. The account manager needs a clean, defensible version to send the client before the client hears it from their own staff. Six hours, and every hour of delay costs detail the officer will not remember.
The version that has to survive a subpoena
Twelve to eighteen months later a plaintiff's counsel or a carrier's adjuster asks for the report. What matters then is not the prose. It is who wrote it, when the system recorded it, where the phone was, what photos were attached at the time, and whether anything was edited afterwards and by whom.
Nobody owns it after the shift ends
The occurrence gets captured and then the case scatters: a supervisor text, an email to the client, a note about repairing the fence, a mention at the next site visit. There is no one place that says who reviewed it, what the escalation matrix required, and whether it was ever actually closed.
The lifecycle CGuardPro puts around an event
Occurrence: capture it at the post
The officer opens a case from the app at the post where it happened. Classification, narrative, involved parties, vehicles, injuries, whether law enforcement was called, whether force was used. The system stamps its own time and the device location — not a time typed in later from memory.
Evidence: attach it before it degrades
Photos, video, voice notes and witness statements attach to the case as it is written, each carrying its own capture time and author. Nothing is re-uploaded from a personal phone a week later, which is where chain of custody usually breaks in a guard operation.
Review: a supervisor signs off
The case routes to the on-call supervisor by severity. They can require a correction, add their own field observations, or push it up the escalation matrix. Every touch is recorded; the original narrative is preserved alongside the revision.
Notify and close: the client, then the file
The approved case reaches the client through the portal or as an export, in the format their contract asks for. The case stays open until the corrective action is recorded, then closes with a full history attached to the site, the client and the officer.
What a case-based record gives you that a narrative does not
- Every case carries a system timestamp, device location, named author and an unbroken edit history
- Severity drives routing: a use-of-force or a serious injury reaches the on-call supervisor immediately, not at shift change
- Evidence is attached at the moment of capture rather than collected from personal phones afterwards
- Client notification is part of the case, so you can show when the client was told and what they were sent
- Cases are searchable by site, client, officer, classification and date range, so a pattern at one post is visible before it becomes a claim
- Open cases are visible as work in progress, with an owner and an age, instead of living in someone's inbox
- Export a complete case file — narrative, revisions, evidence, review trail — for a carrier, an attorney or a client audit
Frequently asked questions
How is an incident report different from a daily activity report? +
A daily activity report is the routine log of a normal shift: tours completed, gates secured, deliveries received, nothing to report. An incident report is the exception — a discrete event that opens a case with its own lifecycle of documentation, evidence, supervisor review, client notification and closure. CGuardPro keeps both. If what you need is the routine shift log and the pass-down between officers, see our daily activity reports page; this page is about the exception.
Can an officer file an incident with no cell signal? +
Yes. The case is written and stored on the device, with its capture time and location preserved, and it uploads automatically when the phone reconnects. The record shows both when the event was captured and when it reached the server, which is the honest way to represent a delay rather than backdating it.
Can a report be edited after it is submitted? +
Corrections are a normal part of incident documentation and blocking them entirely produces worse reports, not better ones. CGuardPro keeps the submitted version and every subsequent revision, with the author and time of each change, so a reviewer can see exactly what the officer wrote first and what was amended after supervisor review.
Does it handle use-of-force documentation? +
Use of force is a classification with its own required fields and its own routing, so it cannot be filed as a general observation. It captures the sequence of events, what was used, injuries observed, medical response, whether law enforcement responded, and it escalates to the supervisor level your policy sets rather than waiting in a queue.
How does chain of custody work for photos and video? +
Media attaches directly to the case from inside the app, carrying its capture time, the device it came from and the officer it is attributed to. Because it never passes through a personal camera roll and an email thread, the file that ends up in the case file is the file that was taken at the scene.
How do we get a description in front of the officers who need it tonight? +
Through the channels the platform already runs to the post: an announcement to the officers assigned there, and push-to-talk voice in the same app when it cannot wait for someone to read. Attach the incident so the description travels with the case it came from rather than as a message with no history behind it. Agree the escalation path with your supervisors before you need it — the tooling matters less here than whether the night supervisor knows who to reach and how fast.
Do clients see incidents automatically? +
You decide, per client and per severity. Some contracts want everything visible in real time through the client portal; others want an account manager to review before anything is released. Either way the case records what the client was sent and when.
How do I get a case out of the system for a legal or insurance request? +
Cases stay attached to the site and the client record, so a request that arrives a year later resolves by searching the site and the date range rather than by asking who was working that night — which is the part that usually fails on paper. The incident record and its attached evidence come out of the system; ask during the evaluation exactly what an export contains and in what format, and have whoever handles your claims look at a real one before you rely on it. That is worth doing with any vendor, not only this one.
See a case open, escalate and close
Book a demo and we will run one event end to end: filed at the post, evidence attached, escalated to the on-call supervisor, released to the client, closed with the corrective action on the record.