Pune’s office market alone carries an estimated 86.7 million sq ft of stock, with roughly 3 million sq ft of gross absorption recorded in the first quarter of 2026 (Address Advisors, Q1 2026). A large share of that space sits inside multi-tenant campuses, where one landlord or park operator serves a number of occupiers who share gates, roads, parking and lift cores but do not share a security objective. IT-BPM firms account for about 32 percent of leasing in that market, ahead of engineering and manufacturing at 19 percent and BFSI at 16 percent, so a single campus commonly houses occupiers whose security requirements differ considerably.
This document sets out where authority divides in such a campus, which boundary points produce incidents that no party owns, and what a tenant can reasonably require in writing from the park operator and from its own security provider. It is written for facility heads and administration managers preparing a lease schedule, a service agreement or a vendor brief for an business park or corporate campus, and it applies equally to a technology park with data-hall tenants, for which the additional controls are described in the guide to data centre and IT park security in Pune and Navi Mumbai.
The structure of split authority
A multi-tenant park has at least three security layers, and each answers to a different party.
Layer 1: the park operator
The operator, or its facility management contractor, holds the estate perimeter, the main and secondary gates, internal roads, common parking, landscaped areas, utility yards and the shared infrastructure rooms. Its guards are deployed to protect the estate as a whole and are accountable to the operator, whose obligations to each tenant are limited to what the lease and the common-area maintenance terms say.
Layer 2: the tenant
Each tenant is responsible for its own floors or building, its reception, its access control inside the demised premises, its restricted zones, and the assets and people inside them. A tenant may deploy its own guards, receive them through its facility management provider, or rely entirely on the park for everything outside its suite.
Layer 3: shared and third-party operators
Food courts, transport operators, courier desks, housekeeping contractors and fit-out crews enter through the park’s gates and then move into tenant space. They belong to neither of the first two layers, and they most often pass between the two without a record on one side or the other.
Incidents fall through because each layer reasonably assumes that the adjacent layer handles the transition. The park gate checks a visitor against a tenant’s list and assumes the tenant will verify identity at reception. The tenant’s reception assumes that a person who reached the lobby was already screened at the gate. Neither is wrong in isolation, and the control is absent in aggregate.
Responsibility matrix for a multi-tenant campus
The matrix below is a working template. It assigns a primary owner and a secondary role to each security function, and it identifies the record that evidences the handoff. A tenant can annex an agreed version to the lease or to a facility service agreement; a park operator can use it to define its own scope before a dispute does.
| Function | Park operator | Tenant | Handoff record |
|---|---|---|---|
| Estate perimeter and patrol of common areas | Primary | Reports observations | Patrol log with timed checkpoints; incident register shared on request |
| Main gate vehicle entry and exit | Primary | Supplies authorised vehicle and vendor lists | Vehicle register with registration number, time in, time out, destination tenant |
| Visitor registration at the gate | Primary (common minimum) | Pre-registers expected visitors; may add stricter requirements | Visitor record with photo, identity type, host, tenant, time in and out |
| Visitor verification at the tenant reception | Not applicable | Primary | Tenant visitor pass reconciled with the gate record at end of day |
| Common lobby and lift core | Primary | Secondary for tenant floors | Post order stating which party staffs the lobby and during which hours |
| Tenant floor entrance and restricted zones | Not applicable | Primary | Tenant access control log; access list review record |
| Goods inward and outward through the loading dock | Primary for the dock | Primary for the material gate pass | Gate pass signed by the tenant, matched by the dock guard at exit |
| Parking and vehicle control | Primary | Allots and revokes tenant parking entitlements | Parking allotment list with revision date |
| Out-of-hours access to tenant premises | Secondary (gate admission) | Primary (authorisation) | Written authorisation from a named tenant representative before admission |
| CCTV on common infrastructure | Primary | Requests clips for incidents | Clip request log with retention period and approving person |
| CCTV inside tenant premises | Not applicable | Primary | Tenant retention and access policy |
| Emergency response and evacuation coordination | Primary for the estate | Primary for the floor, with trained wardens | Joint drill schedule and drill report |
| Incident reporting between parties | Reports within an agreed interval | Reports within an agreed interval | Shared incident register with time of detection, time of notification |
Two entries in the matrix deserve attention. Visitor registration is split deliberately: the park holds a common minimum so that every person entering the estate is recorded, and the tenant applies its own verification at its own door. Out-of-hours access is split the other way: the park controls admission to the estate, but only the tenant can authorise entry into its premises, so the gate must not admit a person to a tenant floor on a verbal assurance.
Boundary points where incidents fall through
Experience across campus deployments identifies a consistent set of points where one party’s control ends before the other’s begins.
The gate-to-reception transition
A visitor registered at the main gate is normally issued a pass and sent onward. Unless the tenant’s reception reconciles that pass against its own expected-visitor list, the pass becomes a document that grants movement through the campus. The standard to specify is a pass that names the destination tenant, is valid only for a stated period, and is collected at exit. The park’s gate record and the tenant’s reception record should agree on the number of people who entered and the number who left.
Contractors and fit-out crews
Fit-out contractors enter in numbers, carry tools and materials, and often work extended hours. A park that registers them at the gate and a tenant that relies on its facility team to supervise them leaves open the question of who confirms identity, who tracks the materials brought in, and who confirms that every worker has left. The reliable arrangement is a named contractor list issued by the tenant and acknowledged by the park before work begins, with daily headcount reconciliation at the gate.
The loading dock and material movement
Goods leaving a tenant floor pass through a dock that the park staffs but whose contents the tenant owns. A dock guard who cannot see the tenant’s authorisation has two options, both poor: refuse legitimate movement, or release anything carried with confidence. A material gate pass issued by a named tenant signatory, with item description and quantity, and matched by the dock guard against what is physically carried, resolves the position for both sides. Asset-register discipline on the tenant side is the necessary complement, since a guard can only check what the paperwork states.
Lobby and lift core after hours
After hours a lobby often holds one park guard serving several tenants. The control to specify is a call-back to a named tenant contact, or a written authorisation lodged earlier in the day, before a person is released to a floor.
Shared CCTV and the clip request
A tenant investigating a loss in a common area depends on footage held by the park operator. Without an agreed process, the request is informal, the response is slow, and recordings may have been overwritten before the request is made. The agreement should state the retention period for common-area footage, who may authorise a release, the turnaround time for a request, and how the request is logged.
What a tenant can legitimately ask for
A tenant has no authority to direct the park operator’s guards, and a park operator is entitled to run one set of procedures for every occupier. Within those limits, a tenant can reasonably request, and a lease or service agreement can reasonably contain, the following.
From the park operator
- A written statement of the common-area security scope: gates, hours, posts, patrol frequency and the number of guards on each post by shift.
- The retention period for gate, vehicle and CCTV records, and the process and turnaround time for a tenant to request a record relating to an incident that affects it.
- Notification of any security incident in a common area that affects the tenant’s staff, vehicles, visitors or property, within a stated interval.
- Evidence that guards deployed in the park are supplied by an agency licensed under the Private Security Agencies (Regulation) Act, 2005, and that guard employment complies with the Maharashtra Private Security Guards (Regulation of Employment and Welfare) Act, 1981 where it applies. The compliance and licences page lists the documents a facility head should expect to see.
- Participation in joint emergency drills and a shared contact list for escalation.
What a tenant cannot require
A tenant cannot require the park to change its gate procedure for that tenant alone, to release another tenant’s data, to staff a post at the tenant’s expense without a commercial agreement, or to exercise any authority beyond that of a private security guard. Guards on a campus have no powers of arrest or detention. Their function is to control access, observe, record and report, to ask an unidentified person to stop and state their business, and to summon the appropriate authority for anything that goes beyond that function. Every post order should say so plainly, so that no tenant or occupant relies on a capability the guard does not hold.
A tenant’s boundary checklist
The checklist below is intended to be completed jointly by the tenant’s facility head and the park’s operations manager during onboarding, and again at each lease renewal. Each item should resolve to a named person and a document.
- The security scope of the park operator is available in writing, including posts, hours and guards per shift.
- The tenant’s list of authorised visitors, vendors, contractors and vehicles is lodged with the park gate, with a named person responsible for updating it.
- The gate record and the tenant reception record both capture time in and time out, and are reconciled daily.
- The material gate pass format is agreed, with the names of authorised tenant signatories lodged at the dock.
- Out-of-hours admission to tenant premises requires written authorisation or a call-back to a named contact.
- The retention period and release procedure for common-area CCTV are agreed and recorded.
- An incident notification interval is agreed in both directions.
- The parking allotment list is reconciled against current headcount at least once a quarter.
- Joint emergency drills are scheduled, with a named warden for the tenant’s floors.
- The licence and statutory compliance documents of the park’s guarding agency and of the tenant’s agency have been sighted and filed.
- Post orders for both layers state that guards have no powers of arrest or detention and name the escalation contact for each category of incident.
- The agreement is reviewed at each change in the tenant’s headcount, hours, floor area or sensitivity of operations.
Incident handoff standard
An incident that crosses the boundary should be handled to a stated standard, because delay at the boundary is where evidence is lost. The following sequence is a reasonable specification.
- Detection: the guard who first observes the event records time, location and a factual description in the incident register, without characterising intent.
- Internal escalation: the guard informs the shift supervisor immediately, and the supervisor informs the facility head or the duty manager of the affected party within the interval agreed in the service agreement.
- Cross-boundary notification: the supervisor informs the counterpart on the other side of the boundary by telephone and confirms by written message, recording the time of each.
- Evidence preservation: the party holding relevant gate records, vehicle records or CCTV footage secures them against routine overwriting as soon as the incident is notified.
- Authority involvement: where an incident requires intervention beyond a guard’s role, the supervisor contacts the competent authority and the facility head is told that this has been done.
- Closure: both parties record the outcome in the shared register and agree any change to a procedure that the incident exposed.
Data, privacy and records
Gate registers, visitor photographs, vehicle numbers and CCTV footage are personal data under the Digital Personal Data Protection Act, 2023. The agreement between park and tenant should state who holds which category of record, for how long, who may access it and how a copy is requested and logged, and signage at gates and tenant entrances should describe the collection.
Specifying the tenant’s own security team
Where a tenant adds its own guarding layer, the brief should describe the interface to the park as precisely as the posts inside its premises: daily pass reconciliation, incident notification and attendance at coordination meetings as named duties, registers formatted to reconcile with the park’s, and a supervisor who knows both procedures. The security cost calculator allows configurations to be compared before a proposal is requested, and any comparison should use the Security Guards Board order in force for the contract period.
Reviewing the arrangement
The division of responsibility should be reviewed at each change in a tenant’s headcount, hours or floor area, and at least once a year. A useful test is to send a prepared visitor, vendor and vehicle through the gate to the tenant floor and compare the park’s record, the tenant’s record and the actual path taken.
Frequently asked questions
Who is responsible for security inside a multi-tenant IT park?
Responsibility is divided by area and by function. The park operator normally holds the perimeter, main gates, estate roads, parking and common areas, while each tenant is responsible for its own floors, suites and the assets inside them. Where the two meet, at the lobby, the lift core and the loading dock, the division should be written down in the lease schedule or a facility service agreement rather than left to custom.
Can a tenant require the park’s security team to follow its own visitor policy?
A tenant can request it, but the park operator is entitled to run one common gate procedure for all occupiers. The practical route is to agree what the park gate captures for every visitor, and to apply the tenant’s stricter checks at the tenant’s own reception or floor entrance, so that the two layers complement each other rather than conflict.
Does a tenant need its own security guards if the park provides security?
Often yes, for the tenant’s own entrance, reception, restricted zones and out-of-hours cover, because park security is deployed to serve the whole estate and is not accountable to one occupier. Whether it is needed depends on the sensitivity of the tenant’s operations, the hours it runs and what the lease and service agreement already commit the park operator to.
Who owns CCTV footage in a multi-tenant park?
Footage recorded by the park operator on common infrastructure is held by the park operator, and footage from cameras a tenant installs inside its own premises is held by the tenant. Both are personal data under the Digital Personal Data Protection Act, 2023, so retention periods, access rules and the process for a tenant to request a clip of an incident in a common area should be agreed in writing.
Can security guards stop or detain a person at a business park?
No. Private security guards do not have powers of arrest or detention. Their role is to control access, observe, record and report, to challenge unauthorised entry by asking a person to stop and state their business, and to summon the appropriate authority when an incident is beyond that role. Post instructions should say this explicitly so that no one on site expects more.
Next steps
A tenant preparing a lease schedule, or reviewing the guarding arrangement for an existing campus, can start from the matrix and checklist above. Bryte Guard Force offers a free site risk assessment that maps the park-to-tenant boundary for a specific campus, and a written proposal within 48 hours. To compare guarding configurations first, use the security cost calculator, or request a quote for a campus or a single tenant floor. Related guidance for tenant offices is available in the guide to corporate office security in Mumbai and Pune, and for technology facilities in the page on data centres and IT parks.
