Ask a facility head what their security problems are and the answer is rarely about intrusion. It is about a contractor who was on the floor for three hours before anyone asked who he was, a laptop that left the building on a Saturday, a visitor found on the wrong floor, or a monthly report that arrives and tells nobody anything.
These are not failures of guarding in the conventional sense. They are failures of definition, of boundary and of follow-through. This article sets out the problems that actually reach a facility head in a corporate environment, ordered by how often they do, with the cause and the control for each.
The eight problems, and what causes each
| # | How it is experienced | Underlying cause | Control |
|---|---|---|---|
| 1 | Contractors on the floor unannounced | Building admits them; tenant is not told | Written boundary with building security; permit copied to the tenant |
| 2 | Assets leaving without trace | Gate passes issued but never reconciled | Named reconciler, weekly review of outstanding returnables |
| 3 | Visitors on the wrong floor | Logged at the building, never handed over to the tenant | Host-notified arrival and escort to the floor |
| 4 | After-hours presence nobody can explain | Entry permitted on recognition and not recorded | Authorisation list held by the occupier, every entry logged |
| 5 | Access cards still active for leavers | Deactivation is an HR step that nobody owns | Exit process includes revocation; quarterly credential audit |
| 6 | Tailgating at the entrance | Recognition substituted for credential | Consistent presentation including for senior staff; positioned guard |
| 7 | Reports that change nothing | Reporting specified by the agency, not by the client | Client specifies the few things the report must state |
| 8 | A different guard every month | Agency attrition, usually driven by pay and post conditions | Continuity as a contract term; monthly deployment list |
Four of these — one, three, four and six — share a single root. They are all consequences of an undefined handover: between building and tenant, between gate and floor, between working hours and outside them, between credential and recognition. A corporate security arrangement is largely a set of handovers, and incidents collect wherever one has not been specified.
The boundary with building security
This deserves separate treatment because it is upstream of so much else. Most corporate offices occupy space within a building whose landlord provides its own security, and the division of responsibility between the two is frequently unstated.
Three questions settle it. Where does building security’s responsibility end — at the perimeter, the lobby, the lift, or the floor entrance? Who controls access to the tenant’s floor? And who holds the visitor record, in a form the occupier can retrieve?
The third question is the one that surprises people. An occupier who relies on the building’s visitor register has no independent record of who came to see them, and cannot produce one without asking the landlord. For most organisations that is an acceptable position only until the first time it is not.
The remedy is a short written statement, agreed with building management and held by both security teams, setting out who does what. It is not a negotiation about resources; it is a statement of fact that prevents both parties assuming the other is covering something.
Asset movement: the gap between a record and a control
Most corporate sites have a gate pass system. Rather fewer have an asset movement control, and the difference is reconciliation.
A pass is issued when something leaves. It is filed. The returnable ones are supposed to come back. If nobody reviews outstanding passes, nothing happens when an item does not return, and the system is producing paperwork rather than control. This is not a theoretical distinction — it is the difference between knowing an item is missing and finding out at the next audit.
Four provisions make it real: a pass for everything leaving regardless of who is carrying it; a clear returnable or non-returnable designation at issue with an expected date; a named person reviewing outstanding returnables weekly; and a written statement of who may authorise, for what value.
The third is the one that is almost always missing, and it costs very little to add.
After-hours access: the record that matters most is the one least kept
Out-of-hours presence is the category of activity most likely to require explanation after the fact, and the category least likely to be recorded, for a human reason: the guard recognises the person, so a challenge feels unnecessary and faintly rude.
The control is not to make the guard more suspicious. It is to take the decision away from them. The occupier maintains an authorisation list — who may enter outside business hours, and on what basis. Anyone on the list is admitted and logged. Anyone not on it is escalated to a named manager before entry, not after.
This reframes the interaction. The guard is not judging whether a colleague should be there; they are applying a list the organisation has produced. That is a position a guard can hold without friction.
Credentials: the quarterly audit most organisations have never run
Access credentials accumulate. People join, change roles, move sites and leave, and revocation depends on a step in the exit process that is nobody’s specific responsibility.
The audit is straightforward: export the list of active credentials, compare it against the current staff list, and investigate anything that does not match. Organisations running this for the first time generally find credentials belonging to people who have left, and occasionally find some belonging to people who were never employed there — contractors issued a card for a project that ended.
Run it quarterly, and make revocation an explicit item on the exit checklist rather than an assumed consequence of it.
Reporting: specify it from the client side
Security reporting is usually designed by the agency, which means it reports what the agency finds convenient to record. The result is a document that arrives monthly and changes nothing.
An occupier can fix this by specifying a small number of things the report must state. A workable set:
- Hours where any post was not occupied, and why.
- Supervisory visits, with dates and times, including those outside business hours.
- Outstanding returnable gate passes beyond their expected date.
- After-hours entries by exception — those not on the authorisation list.
- Incidents, with what was done and what remains open.
- Personnel changes on the site since the last report.
Six items, each of which can prompt a decision. That is a reporting standard worth paying for, and it is noticeably harder to produce if the service is not actually being delivered — which is rather the point.
Continuity: the cost that does not appear on the invoice
The last of the eight is the one most often treated as unavoidable. It is not, but addressing it requires looking at the cause rather than the symptom.
Site knowledge is a large part of what an occupier is buying: which contractor is expected, which door is propped open in summer, which employee works late, which supplier is genuine. A replacement guard has none of it, and rebuilds it over weeks. High turnover means the arrangement never reaches the standard that was contracted.
Three things help. Make continuity an explicit contract term with notice before planned changes. Ask for the monthly deployment list, which is the only way to observe turnover rather than be told about it. And examine whether the rate supports lawful wages for the people proposed — a deployment priced below what the statutory position requires will produce turnover, and the occupier will experience that as a security problem rather than a pricing one. Our guides to security guard costs in Maharashtra and choosing a security agency cover how to examine this.
Two problems that arrive later
Beyond the eight, two issues tend to surface once an arrangement has been running for a year or more, and both are worth anticipating.
The security team has absorbed tasks nobody agreed to. Over time a guard post accumulates duties: holding keys for a department, receiving personal deliveries, managing a meeting room, supervising a cleaning contractor. Each was added informally and none was costed. The effect is that the post is occupied with work that is not security, and the original duties are performed thinly. A periodic review of what the post is actually doing, against what the duty chart says it should be doing, usually recovers capacity without any additional spend.
Nobody on the client side owns security any more. The person who set the arrangement up has moved on, and responsibility has diffused between facilities, administration and human resources. The symptom is that the agency has no single point of instruction and the monthly report has no defined reader. This is worth correcting explicitly, because every control described above assumes a named person on the client side — the one who reconciles passes, maintains the authorisation list, runs the credential audit and reads the report.
Both of these are governance questions rather than security ones, and neither can be fixed by the supplier.
A sequence for fixing them
Taken together these look like a long list. In practice they resolve in a short sequence, because several share a cause.
- Agree the written boundary with building security. This addresses problems one, three and part of four.
- Establish the after-hours authorisation list, held by the occupier.
- Name someone to reconcile gate passes weekly.
- Run the credential audit, and add revocation to the exit checklist.
- Specify the six reporting items and review them monthly.
- Put continuity in the contract and request the deployment list.
None of these requires additional guards. Five of the six are decisions the occupier takes rather than services the occupier buys, which is why an arrangement can be expensive and still leave all eight problems in place.
Bryte provides corporate and commercial security with the boundary statement, duty chart, pass reconciliation process and reporting standard set out at mobilisation rather than offered later. Our corporate and commercial security service and business parks and corporate campuses practice describe the scope, and our guide for facility heads in Mumbai and Pune goes further into the operational detail. A site assessment produces a written review of an existing arrangement within 48 hours; occupiers in the city can begin at security agency in Mumbai.
Frequently asked questions
What are the most common security problems in a corporate office?
Contractors arriving on the floor unannounced; assets leaving without a traceable record; visitors reaching the wrong floor; after-hours presence nobody can account for; access cards still active for people who have left; tailgating at the entrance; monthly reports that prompt no decision; and frequent changes of deployed personnel. Most of these trace back to an undefined handover rather than to a guarding failure.
Who is responsible for security in a leased office — the landlord or the tenant?
Both, with a boundary that should be stated in writing. Building security typically covers the perimeter, main entrance and common areas; the tenant controls its own floor. Settle three questions with building management: where the building’s responsibility ends, who controls access to the tenant floor, and who holds the visitor record in a form the occupier can retrieve independently.
How should a company control laptops and equipment leaving the office?
A gate pass for anything leaving, regardless of who carries it, with returnable and non-returnable distinguished at issue and an expected return date on returnables. The step that makes it a control rather than paperwork is a named person reviewing outstanding returnable passes weekly and following up overdue items. Authorisation limits should be written down.
How do we manage employees entering outside office hours?
The occupier maintains an authorisation list of who may enter outside business hours. Anyone on it is admitted and logged; anyone not on it is escalated to a named manager before entry. This removes the judgement from the guard, who would otherwise rely on recognition — which is precisely why out-of-hours entries so often go unrecorded.
How often should access cards be audited?
Quarterly. Export the active credential list, compare it against the current staff list and investigate every mismatch. Organisations running this for the first time usually find active cards belonging to people who have left, and sometimes cards issued to contractors for projects that ended. Card revocation should also be an explicit item on the employee exit checklist.
What should a monthly security report contain?
Six things, specified by the client rather than the agency: any hours a post was unoccupied and why; supervisory visits with dates and times including out-of-hours ones; outstanding returnable gate passes past their expected date; after-hours entries by exception; incidents with action taken and what remains open; and personnel changes on site. Each should be capable of prompting a decision.
