Category: Guard Management

  • Employee Write Up Form: 6 Steps From Verbal to Final

    Employee Write Up Form: 6 Steps From Verbal to Final

    An employee write up form is the written record that documents each step of progressive discipline, from a first verbal conversation to a final warning before dismissal. Its value is not in the form itself but in the process behind it: a defensible write-up shows that the employee was told what went wrong, given a chance to respond and moved through fair, escalating stages by a named manager on a recorded date.

    employee write up form

    Most security supervisors reach for an employee write up form only when a situation has already gone wrong. A guard has been late four times, a client has complained twice, and now someone needs to be removed from site. The write-up gets filled in that afternoon, backdated in spirit if not on paper, and filed. Months later a dismissal is challenged and the same question always lands: where is the trail that shows this was fair?

    The form is the easy part. Downloading a template and typing “poor performance” takes two minutes. The hard part is that an employee write up form has to prove a process happened, and a single sheet produced at the end proves nothing except that someone wanted the employee gone.

    This guide walks through the six steps of a defensible write-up process, from the first verbal warning to the final notice, and what each stage has to record to hold up when someone reads it who was not there.

    Why a single write-up form is not enough

    Discipline that stands up to challenge is progressive. It gives an employee fair warning and a real chance to correct course before the consequences become serious. An employee write up form produced in isolation, with no earlier stages behind it, looks exactly like what it often is: a decision made first and documented afterwards.

    Progressive discipline protects two people at once. A complete employee write up form tells the employee precisely what to stop doing and by when, and it tells your future self why the decision that followed was reasonable. When only the final form exists, both of those break down.

    Three failures show up again and again:

    • The write-up appears from nowhere. There is no record of the verbal conversation that should have come first, so the written warning reads as the opening move rather than an escalation.
    • The steps are not dated or linked. A verbal note lives in one place, the written warning in another, the incident that triggered it in a third. Nobody can reconstruct the sequence in order.
    • The employee never acknowledged it. A form sits on file with no sign the employee saw it, read it or had the chance to add their side.

    Each of these is a recording failure, not a judgement failure. The supervisor usually made the right call. The employee write up form simply did not capture the process that made it fair.

    The 6-step employee write up process

    A fair write-up process moves through escalating stages. Not every issue travels the full distance; a serious safety breach can start further along. But the stages, and the record each one leaves, stay the same.

    Step 1 — Verbal warning

    The first conversation is informal but it should not be invisible. A supervisor raises the issue directly, states the standard that was missed and confirms what needs to change. Even though it is spoken, log a short dated note: who spoke to whom, about what and when. This note is what turns a later written warning into a genuine second step rather than a first strike.

    Step 2 — Written warning

    If the behaviour continues, the issue moves to a formal written warning. This is where a structured employee write up form earns its place. It records the staff member, the department and designation, the date and time, the specific conduct or performance standard that was missed, and the improvement expected. This is the fields-heavy stage, and the fields matter enough to cover on their own: see our guide to the employee warning notice for the nine details every written warning has to carry.

    Step 3 — Employee response

    A defensible process gives the employee a chance to respond before the record is closed. They may accept the account, dispute it or add context you did not have. Capturing that response, and the fact it was invited, is what separates a fair notice from a one-sided one. In AVES this is handled through the acknowledgement trail rather than a signature image, which we cover below.

    Step 4 — Final written warning

    When earlier stages have not corrected the behaviour, a final warning states plainly that the next step is dismissal. It references the earlier stages by date so the escalation is visible in one place, restates the standard and sets a clear review point. The value here is entirely in the linkage: a final warning that cannot point back to its predecessors is just another first warning wearing a serious title.

    Step 5 — Review and decision

    Before any dismissal, the sequence is reviewed as a whole. Were the stages fair, dated and acknowledged? Was the employee given a real opportunity to improve? A complete, ordered trail makes this review quick and the decision confident. A scattered one turns it into a reconstruction exercise nobody has time for.

    Step 6 — Outcome record

    Whatever the decision, the employee write up form is recorded and tied to the trail that led to it. If the employee corrected course, that closes the loop and protects them from an unfair reference to old issues. If the outcome is dismissal, the record shows a fair process was followed from the first verbal note onward.

    What each write-up record must capture

    Across those six steps, the details that make an employee write up form defensible stay consistent. A record at any stage should capture:

    • The employee’s full name, identification number, department and designation
    • The exact date and time the issue occurred and the write-up was issued
    • A specific, factual account of what happened, not a label like “bad attitude”
    • The standard, rule or post order that was not met
    • Any supporting evidence, such as a photo attached at the time
    • The improvement required and the review date
    • Who issued the write-up, with their name, date and time
    • Confirmation the employee was notified and given the chance to respond

    The AVES Staff Show Cause module records these directly. It captures the staff name, staff identification number, department and designation, the date and time, the show-cause account itself, a photo taken at the point of issue, the flag confirming the employee was notified, and the name, date and time of the person who issued it. One honest note on how sign-off works: AVES has no signature-image field. Acknowledgement is a structured accept, decline or submitted state with a name, date and time attached, which is more useful in a later review than a scanned squiggle because it timestamps who acted and when.

    Common mistakes that make a write-up worthless

    • Starting in writing. Skipping the verbal step and issuing a formal warning first makes the whole process look punitive. Log the early conversation, even briefly.
    • Recording conclusions instead of facts. “Insubordinate” is a judgement. “Refused a direct instruction to cover the north gate at 22:15” is a fact that survives scrutiny.
    • Leaving the form undated or unsigned by the issuer. A write-up with no author and no date proves only that a page exists, not when or by whom it was created.
    • Never linking the stages. When the verbal note, the written warning and the final warning cannot be seen in one ordered trail, each looks like a standalone first step.
    • Filing it and forgetting the review date. A write-up sets an expectation to improve by a point in time. If nobody checks on that date, the process stalls and the record loses its purpose.

    Frequently asked questions

    What is an employee write up form?

    It is the written record used to document a step in progressive discipline, from a verbal warning through to a final written warning. It sets out what the employee did, the standard they missed, what must change and who issued it, so the decision that follows can be shown to be fair.

    How many warnings before termination?

    There is no fixed number, and it depends on your policy and the seriousness of the conduct. A typical progression is verbal, written, then final written warning before dismissal, but a serious breach can begin at a later stage. What matters is that each stage was fair, recorded and acknowledged.

    Does an employee have to sign an employee write up form?

    A signature is one way to show the employee saw the write-up, but it is not the only one and refusal to sign does not void it. What counts is a record that the employee was notified and given a chance to respond. AVES captures this as a dated accept, decline or submitted acknowledgement rather than a signature image.

    What should you avoid writing on an employee write up form?

    Avoid labels and opinions such as “lazy” or “bad attitude”. Record specific, dated facts: what happened, when, which standard it breached and what was said. Facts survive a later review; judgements invite dispute.

    Can a verbal warning be part of the record?

    Yes, and it should be. A short dated note of the verbal conversation is what makes a later written warning a genuine escalation rather than a first strike.

    Turn a scattered paper trail into one ordered record

    An employee write up form is only as strong as the process behind it. If your verbal notes, written warnings and final notices live in different files, drawers and inboxes, the trail that proves fairness is the first thing to fall apart when it is challenged.

    AVES keeps every stage in one place, dated, attributed and acknowledged, so a disciplinary decision can be shown to be fair from the first conversation onward.

    Book a 30-minute demo and we will show you the actual Staff Show Cause screen and how the acknowledgement trail records who was notified and when: avessecurity.com/book-demo

    Prefer to explore it yourself first? Start a free AVES account and set up your first show-cause record in minutes.

    Follow AVES on Instagram for more security operations guidance.

  • Employee Warning Notice: Building a Defensible Record

    Employee Warning Notice: Building a Defensible Record

    An employee warning notice is a formal written record that tells a member of staff which rule or standard they fell short of, when it happened and what must change. It sits between a verbal conversation and a termination decision, and its value depends entirely on whether the facts, the date and the person who issued it were recorded at the time.

    Most security teams only discover the weakness in their employee warning notice process at the worst possible moment: a dismissal is challenged, a client asks why a guard was removed from site, or a tribunal asks for the paper trail. The notice exists, somewhere. Nobody can find it, the copy on file has no date, and the supervisor who issued it left the company in March.

    employee warning notice

    The notice itself is not the hard part. Writing “you were late three times” takes a minute. The hard part is that an employee warning notice has to survive being read months later by somebody who was not there, and that only happens when the right fields were captured at the moment it was issued.

    This guide sets out the nine fields a defensible employee warning notice must carry, why each one matters and the mistakes that quietly make a notice worthless.

    Why a vague employee warning notice protects nobody

    A warning serves two people. It tells the employee exactly what to stop doing, and it tells your future self why the decision that followed was fair.

    A vague notice fails both. “Attitude problem, spoken to” gives the guard nothing to correct, so the behaviour repeats. Then, when the behaviour repeats and you act on it, there is no record showing the employee was warned, told what to change, given a chance to respond and issued the notice by a named manager on a specific date.

    Three failures show up again and again:

    • The notice is verbal only. A conversation happened. There is no document, so as far as any later review is concerned, no warning was ever given.
    • The notice has no date or no author. A signed page in a drawer proves somebody wrote something. It does not prove when, or by whom, or that the employee ever saw it.
    • The notice is never linked to what happened next. The warning sits in one file, the incident in another, the eventual dismissal letter in a third. Nobody can reconstruct the sequence.

    Each of these is a recording failure, not a judgement failure. The manager usually made the right call. The employee warning notice simply did not capture enough to show it.

    The 9 fields every employee warning notice must include

    These are the fields to capture at the moment the notice is issued. Skip one and you create a gap somebody else will have to explain later.

    1. Staff name. Full legal name as it appears on the employment record, not a nickname or a radio callsign. If two guards share a surname on the same site, a first initial is not enough.
    2. Staff ID number. The name identifies a person to you. The ID number identifies them to the system, to payroll and to whoever reads the file in two years. It is what lets you pull every notice attached to one individual instead of searching by a name that may be spelled three ways.
    3. Department. A warning for a control-room operator and a warning for a mobile patrol officer sit in different operational contexts. Recording the department also lets you see whether an issue is one person or one team.
    4. Designation. The role held at the time of the warning, which is not always the role held today. Somebody promoted from guard to supervisor six months later must have their notice read against the standard that applied when it was issued.
    5. Date. The calendar date the notice was issued. This is the single most commonly missing field and the one that does the most damage, because without it no sequence can be established. A first warning that cannot be dated cannot be shown to precede a second.
    6. Time. More precision than most templates bother with, and worth it. When a warning and an incident happen on the same day, the time is what shows which came first. It also tells you whether the notice was issued while the facts were fresh or three weeks later.
    7. The show-cause statement. The substance: what the employee did or failed to do, which standard or instruction it breached, and what is required now. Write it as facts rather than characterisation. “Left post at gate 2 from 02:10 to 02:45 without informing the supervisor, contrary to the post orders issued on 3 June” is a statement somebody can respond to. “Unreliable” is not.
    8. Notice photo. An image of the physical notice, or of the document as it was presented and acknowledged. Where a paper notice is still used on site, this is what stops the only copy living in a folder in a guard hut.
    9. Issued by, with date and time. The named manager who raised the notice, stamped automatically. Accountability runs both ways here: it protects the employee from an anonymous warning appearing in their file, and it protects the manager by showing the notice was raised through a proper channel rather than invented after the fact.

    A tenth item is not a field but a flag: a record that the employee was notified. Knowing a notice was issued is not the same as knowing it reached the person it concerns.

    How AVES records an employee warning notice

    AVES handles this through the Staff Show Cause module, which is the formal disciplinary notice inside the platform rather than a free-text note.

    The form captures staff name, staff ID number, department and designation, the date and time, and the show-cause text itself. A photo of the notice can be attached. A notified flag records that the staff member was informed. Every notice carries an issued-by value together with the date and time it was raised, so the author and the moment are part of the record rather than something reconstructed later.

    It is worth being precise about one thing, because plenty of software in this space is not. AVES has no signature-image field anywhere in the product. Acknowledgement is handled as an audit trail of accept, decline and submitted states with the associated user, date and time, not as a captured handwritten signature. If a scanned signature is a hard requirement for your legal team, attach the signed page as the notice photo and treat the system record as the index to it.

    The practical gain is retrieval. Because every employee warning notice is stored against a staff ID rather than in a folder, the full disciplinary history for one person is one lookup, with dates intact and authors named. That is the thing paper cannot do, and it is the thing you need on the day somebody asks.

    For the wider picture of how notices, actions and outcomes connect, see our guide to disciplinary action tracking. Where the issue is capability rather than conduct, a performance development plan is usually the more appropriate route, and a signed policy acknowledgement form is what establishes the rule existed before the breach.

    Common mistakes when issuing an employee warning notice

    • Writing character judgements instead of conduct. “Lazy”, “difficult”, “bad attitude”. None of these can be evidenced or corrected. Describe the behaviour, the date and the standard it breached.
    • Backdating the notice. Recording a warning as issued on the day of the incident when it was actually written a fortnight later is the fastest way to lose credibility with everyone. Record the real issue date. A gap is explainable. A falsified date is not.
    • Issuing a first warning that is actually a final one. If an employee warning notice says nothing about what happens if the behaviour continues, escalation later looks arbitrary. State the next step.
    • Leaving no evidence the employee saw it. An employee warning notice nobody received is not a warning. Use the notified flag, and where a paper copy is handed over, capture it as the notice photo.
    • Keeping the notice separate from the incident it concerns. A warning about a missed patrol and the patrol record that shows it were both created in your systems. If they cannot be read together, half the value is lost.
    • Letting each supervisor use their own template. Five formats across five sites means five sets of missing fields. One structured employee warning notice form is what makes the records comparable.

    Employee warning notice FAQ

    What should an employee warning notice include?

    Staff name, staff ID number, department, designation, the date and time of issue, a factual show-cause statement describing the conduct and the standard breached, a photo of the notice where one exists, confirmation the employee was notified, and the name of the manager who issued it with the date and time.

    Does a warning notice have to be in writing?

    A verbal warning may be a legitimate first step, but only a written employee warning notice creates a record you can rely on later. If it matters enough to escalate, it matters enough to write down.

    How long should a warning notice stay on file?

    That depends on your jurisdiction and your own policy, and it is a question for your HR or legal adviser rather than a software vendor. What software should do is make sure the notice can still be found, with its original date and author intact, for as long as your policy requires.

    Can an employee respond to an employee warning notice?

    They should be able to. A show-cause notice is by definition an invitation to explain. Record the response alongside the notice so the file shows both sides.

    What is the difference between a warning notice and a performance development plan?

    A warning addresses conduct that breached a standard. A development plan addresses capability that needs to improve. Using one where the other belongs is a common and expensive mistake.

    Get the record right the first time

    Every employee warning notice you issue is a bet that you will still be able to explain the decision months from now. Structured fields, a real timestamp and a named author are what let you win that bet.

    Book a 30-minute demo and we will show you the actual Staff Show Cause screen, the fields it captures and how a full disciplinary history pulls up against a single staff ID.

    Prefer to look around first? Start a free AVES account and set up your own notice workflow.

    Follow AVES on Instagram for more security operations guidance.

  • Near Miss Report Form: Catch the Hazard Before It Lands

    Near Miss Report Form: Catch the Hazard Before It Lands

    A near miss report form is the record a security guard completes after a hazard almost causes harm but does not. An unlocked fire exit found on patrol, a spill left on a stairwell, a contractor working without a permit, a vehicle that nearly struck someone at a gate: none of these caused an injury this time, but each one could have. The near miss report form captures what happened, where and why, so the hazard is fixed before it turns into a real incident. This guide sets out the eight fields every near miss report form must include, the mistakes that weaken it and how to keep the record consistent across every shift and site.

    near miss report form

    Near misses are the cheapest lessons a site will ever get. They carry all the warning of a serious incident and none of the cost, but only if they are written down and acted on. A hazard that is spotted, reported and closed out is a claim that never happens. A hazard that is noticed and then forgotten is an incident waiting for its turn. The goal of a good near miss report form is simple: make reporting quick enough that guards actually do it, and structured enough that someone can act on what they report.

    Why a near miss report form matters

    Every serious incident is usually preceded by several near misses that went unrecorded. The value of catching them is that you fix the cause while it is still harmless, rather than after someone is hurt or something is damaged. A near miss report form is what turns a fleeting observation on a night shift into an action a supervisor can take the next morning.

    Without a proper form, a site is exposed on three fronts. There is safety exposure, because hazards that are never logged are never fixed, and they recur until one of them lands. There is client exposure, because sites increasingly want proof that their security team is spotting and closing risks proactively, not just reacting after the fact. And there is operational exposure, because patterns, the same loose railing, the same blocked exit, the same blind corner, stay invisible when reports are thin or scattered. A consistent form makes near misses countable, and what gets counted gets fixed.

    How a near miss report form works

    A good near miss report form is completed at the moment the hazard is spotted, not remembered at the end of a shift. The guard records the facts in a fixed set of fields, attaches a photo of the hazard and submits it for review, so the right person sees it and owns the fix.

    In AVES, a near miss is logged through the safety and defect reporting forms, which capture the complaint or defect against a reference and let the guard attach photos of the hazard as it was found. Where the near miss involves something more serious, such as a near-collision or an equipment failure, the incident forms add structured fields for date, time, location and type, six-sided photo capture so a hazard can be photographed from front, back, left, right, top and bottom, and attached video and audio. Both routes carry a reviewer sign-off, so once a hazard is fixed the resolution can be photographed and the record closed out by a named reviewer. Every submission carries a review trail, so it is clear who reported the near miss, who acted on it and when.

    The value of that structure is that a near miss does not depend on a guard remembering to mention it. It is captured where it is seen, with the evidence attached, and it lands in front of someone who can close it.

    The 8 fields every near miss report form must include

    These are the fields a useful near miss report form needs. Each one closes a question a reviewer will otherwise be left asking.

    1. Date, time and location. Exactly when and where the hazard was found. Precise location lets the same recurring risk at one spot be spotted across many reports.
    2. Who reported it. The guard who observed the near miss, recorded clearly so the report can be followed up and so reporting is credited rather than discouraged.
    3. What the hazard was. A plain description of the condition or event: a wet floor, a propped fire door, an unguarded edge, a vehicle that came too close. Facts, not labels.
    4. What could have happened. The potential consequence had it not been caught: a fall, a fire that could not be escaped, a collision. This is what separates a near miss from a trivial note and sets the urgency.
    5. Immediate action taken. What the guard did on the spot, such as coning off a spill, closing a door or warning a contractor. This shows the risk was contained while a permanent fix was arranged.
    6. Photos of the hazard. An image of the condition as it was found, so the reviewer sees the real risk rather than a description of it. Six-sided capture is available where the hazard needs it from more than one angle.
    7. Reference and category. A reference number and the type of hazard, so near misses can be grouped, counted and trended rather than sitting as one-off notes.
    8. Resolution and review. What was done to fix the cause, a photo of the resolved condition where relevant, and the named reviewer sign-off that closes the record.

    Common mistakes that weaken a near miss report form

    The most common failure is under-reporting. Guards skip near misses because the form is slow, because nothing seemed to happen, or because reporting feels like creating work for themselves. A near miss report form that takes seconds on a phone, with the photo captured on the spot, is the single biggest fix for this.

    The second is vague description. “Nearly had an accident” tells a reviewer nothing. “A pallet was left blocking the north fire exit; a person leaving in a hurry would not get through” tells them exactly what to fix and why it matters. A form should record what was seen and what could have followed, not a feeling that something was unsafe.

    The third is no photo. A near miss described in words is easy to dismiss and hard to act on. A photo of the blocked exit or the spill removes the argument and gives whoever owns the fix a clear picture of the real condition.

    The fourth is inconsistency between guards and sites. When everyone reports near misses differently, or some report and some do not, the numbers mean nothing and no pattern is visible. A fixed set of fields, used the same way every time, makes near misses comparable across a whole portfolio. The same discipline that makes a plain incident report form reliable applies to near misses, with the advantage that here nobody has been hurt yet.

    The fifth, and the most costly, is no closeout. A near miss that is reported and never resolved is worse than useless, because it records that the site knew about a hazard and did nothing. The reviewer sign-off and the resolved photo, the same closeout discipline behind defect and damage reporting, are what turn a report into a fix.

    Frequently asked questions

    What is a near miss report form?
    It is the record a security guard completes when a hazard almost causes harm but does not. It sets out what the hazard was, where and when it was found, what could have happened and what was done about it, supported by a photo, so the cause can be fixed before it leads to a real incident.

    When should a near miss report form be completed?
    As soon as the hazard is spotted, ideally on the spot while the guard is still there. Completing it immediately preserves the detail, captures the photo of the real condition and means the hazard is contained rather than left for the next person.

    What is the difference between a near miss and an incident?
    A near miss is an event that could have caused injury or damage but did not. An incident is one that did. The near miss report is the more valuable of the two because it lets you fix the cause at no cost, before anyone is hurt.

    Who reviews a near miss report form?
    A supervisor or manager reviews it through a documented review trail that records who reported it, who acted on it and when. That sign-off, together with a photo of the resolved condition, is what closes the record and proves the hazard was fixed.

    What evidence should a near miss report form include?
    A photo of the hazard as it was found is the most important. Where the near miss is more serious, six-sided photos, video and audio can be attached, along with a photo of the resolved condition once the fix is done.

    Turn near misses into fixes, not paperwork

    A near miss report form is only as strong as the structure behind it, and only as useful as the number of guards who actually bother to fill it in. Keep the eight fields the same every time, make the photo quick to capture, and route every report through a documented review with a resolved photo, and you turn the hazards your guards spot into the incidents that never happen.

    Book a 30-minute demo and we will show you the actual AVES safety and incident forms, including hazard photo capture and the reviewer sign-off, on screen: book a demo. Prefer to try it first? Start free.

    Follow AVES on Instagram for more security operations guidance.

  • Use of Force Report: How to Write One That Holds Up

    Use of Force Report: How to Write One That Holds Up

    A use of force report is the written record a security guard completes after using physical force during an incident. It captures what happened, why force was necessary and what followed, so the event can be reviewed fairly and defended later if it is challenged. When a guard restrains a trespasser, breaks up a fight or removes an aggressive person from a site, the report is the difference between a defensible account and a costly dispute. This guide sets out the eight fields every use of force report must include, the mistakes that weaken it and how to keep the record consistent across every shift and site.

    Force incidents are rare, but they carry more legal and reputational risk than almost anything else a guard does. A vague or late report is the first thing a claimant, a regulator or an insurer will attack. The goal is simple: a report so complete and so clearly evidenced that it stands on its own months after the incident, when memories have faded and the only thing left is the record.

    use of force report

    Why a use of force report matters

    Every use of force by a security officer can be questioned. Was the force reasonable, was it proportionate to the threat and did the guard have the authority to use it. A use of force report answers those questions while the detail is still fresh, and it does so in a fixed structure that a reviewer, a client or a court can follow.

    Without a proper report, a firm is exposed on three fronts. There is legal exposure, because an incomplete account is hard to defend if a complaint or a claim follows. There is client exposure, because sites want proof that their guards act within policy. And there is operational exposure, because patterns of force at a particular site or with a particular officer go unnoticed when reports are thin or missing. A consistent report turns a stressful, contested event into a documented one.

    How a use of force report works

    A good report is built at the point of the incident, not reconstructed from memory hours later. The guard records the facts in a fixed set of fields, attaches evidence and submits it for supervisor review. Because the structure is the same every time, nothing important is left to chance, and reviewers compare like with like.

    In AVES, a use of force event is logged through the incident forms, which capture structured details such as the date, time, location and type of incident alongside the guard’s account of what happened. The forms support six-sided photo capture, so an injury, a damaged door or a recovered weapon can be photographed from front, back, left, right, top and bottom rather than from a single angle that leaves gaps. Video and audio can be attached to the same record, and the findings and actions are recorded in their own fields. Every submission carries a review trail, so it is clear who logged the report, who reviewed it and when.

    The value of that structure is that the record is complete and time-stamped at source. There is no gap between the incident and the paperwork for details to slip, and there is no loose photo sitting on a personal phone with no link to the event.

    The 8 fields every use of force report must include

    These are the fields a defensible use of force report needs. Each one closes a question a reviewer will otherwise be left asking.

    1. Date, time and location. Exactly when and where the force was used. Precise timing lets the report be matched against patrol logs, CCTV and access records.
    2. Officer and people involved. The reporting guard, the subject or subjects and any other staff who took part or witnessed the event, recorded clearly enough to identify each person later.
    3. Type of incident. What the event was: a trespass, an assault, a theft in progress, an ejection. This frames why force came into play at all.
    4. What led to the force. The sequence of events before the guard acted, including any warnings given and any attempt to de-escalate. This is where proportionality is judged.
    5. The force used and for how long. A plain description of the physical action taken, its duration and when it stopped. Restraint held for thirty seconds is a different account from restraint held for ten minutes.
    6. Injuries and damage. Any injury to the subject, the guard or a third party, and any property damage, each supported by six-sided photos so the extent is visible from every angle.
    7. Evidence attached. Photos, video and audio tied to the record, plus references to CCTV or other sources. Evidence held inside the report, not scattered across devices, is what makes it hold up.
    8. Findings, actions and review. What was concluded, what was done next, whether police or medical services were called, and the supervisor sign-off through the review trail.

    Common mistakes that weaken a use of force report

    The most common failure is delay. A report written the next day loses the small details that make it credible, and a late report looks defensive. Capturing the account at the point of the incident avoids this.

    The second is opinion in place of fact. “The man was aggressive” is a conclusion. “The man raised his fist and stepped towards me twice after I asked him to leave” is an observation, and observations are what survive scrutiny. A report should record what the guard saw and did, not how the guard felt about it.

    The third is thin evidence. A single photo of an injury, taken from one angle, leaves room for dispute. Six-sided capture, video and audio close that gap, and keeping them inside the incident record rather than on a phone means nothing goes missing.

    The fourth is inconsistency between guards and sites. When everyone writes force reports differently, reviewers cannot compare them and clients cannot trust them. A fixed set of fields, used the same way every time, removes that variation. The same discipline that makes a plain incident report form reliable applies with more force here, because the stakes are higher.

    The fifth is treating the report as the whole record. A use of force event often needs a supporting witness statement form from anyone who saw it, so the guard’s account is corroborated rather than standing alone. Teams that log these consistently through incident reporting software keep every report and its evidence in one defensible place.

    Frequently asked questions

    What is a use of force report?

    It is the written record a security guard completes after using physical force in an incident. It sets out what happened, why force was necessary, what force was used and what followed, supported by photos, video and audio, so the event can be reviewed and defended.

    When should a use of force report be completed?

    As soon as possible after the incident, ideally at the point it happens and while the guard is still on site. Completing it immediately preserves detail and avoids the credibility problem that comes with a late or reconstructed account.

    What evidence should be attached to a use of force report?

    Six-sided photos of any injury or damage, video and audio of the scene where available, and references to CCTV or other sources. Keeping the evidence inside the incident record, tied to the report, is what makes it defensible.

    Who reviews a use of force report?

    A supervisor or manager reviews it through a documented review trail that records who logged the report, who reviewed it and when. That sign-off is part of what makes the report stand up to later challenge.

    How is a use of force report different from a general incident report?

    A use of force report is a specific type of incident report focused on an event where a guard used physical force. It carries the same structured fields as a general report but places extra weight on proportionality, the force used and the evidence, because the legal exposure is higher.

    Keep every use of force report defensible

    A use of force report is only as strong as the structure behind it. Capture the eight fields the same way every time, attach real evidence at the point of the incident and route each report through a documented review, and you turn your most contested events into your best-documented ones.

    Book a 30-minute demo and we will show you the actual AVES incident forms, including six-sided photo capture and the review trail, on screen: book a demo. Prefer to try it first? Start free.

    Follow AVES on Instagram for more security operations guidance.

  • Incident Report Example for Security Guard: A Complete Sample

    Incident Report Example for Security Guard: A Complete Sample

    Most guards are never taught how a strong report reads until a claim, a complaint or a court date puts theirs under the microscope. This worked example shows you exactly what a complete, defensible entry looks like, and breaks down the eight parts that make it hold up. Copy the sample, adapt the fields to your site and you will log cleaner proof from your very next shift.

    incident report example for security guard

    An incident report is the written record of something that went wrong on your watch: a theft, an injury, a trespass, a fire alarm, an altercation. Written well, it protects the guard, the client and the guarding company. Written badly, it becomes the weakest link in an investigation.

    Why the incident report example for security guard beats a blank form

    A good worked example does something a blank form cannot. A blank form tells you which boxes exist. It does not tell you how to fill them so the record survives scrutiny weeks later. That is why a worked example is worth more than any empty template: it shows the level of detail, the neutral tone and the sequencing that separate a usable record from a vague one.

    Three things go wrong most often. Guards write what they concluded (“the man was clearly drunk”) instead of what they observed. They leave time gaps, so nobody can reconstruct the sequence. And they describe damage or injury in words alone, with no supporting evidence. A good example fixes all three by design.

    A complete incident report example for a security guard

    The sample below is a realistic, filled-out report for a common scenario: an after-hours intruder at a warehouse gate. Adapt the names, times and site details to your own.

    Incident report — sample

    Report number: IR-2026-0417
    Date of incident: 14 September 2026
    Time of incident: 02:18
    Location: North goods gate, Unit 4, Riverside Distribution Park
    Reporting guard: J. Okafor, badge 3391, night shift 22:00-06:00
    Incident type: Unauthorised entry attempt

    What happened (factual account): At 02:18 during a routine patrol of the north perimeter, I heard the sound of the goods gate chain being moved. I walked to the gate and saw one male attempting to climb the pedestrian side rail. I called out and identified myself as security. The male stopped, stepped down on the outer side and ran north along the fence line towards the canal path. I did not pursue beyond the boundary.

    Description of person: Male, approximately 1.8 metres, medium build, dark hooded top, light trousers, carrying a small dark bag. Face not clearly seen.

    Actions taken: Secured and rechecked the gate chain and padlock at 02:21. Radioed the control room at 02:22 to log the event. Reviewed the north gate camera and confirmed footage exists for 02:16-02:20. Increased patrol frequency of the north perimeter for the remainder of the shift.

    Evidence attached: Six-sided photo set of the gate and rail, short video walk-through of the entry point, camera reference NGC-02 clip 02:16-02:20.

    Witnesses: None on site. Control room operator M. Devi confirmed radio log.

    Injuries or damage: No injuries. Minor scuff to the pedestrian rail paint, photographed.

    Police or client notified: Client duty manager notified at 02:35. Police non-emergency reference PR-88214 logged at 02:41.

    Follow-up required: Client to review whether the pedestrian rail needs a higher anti-climb section. Camera coverage of the canal path to be assessed.

    This sample is worth reading back closely. Notice what it does: it records observations rather than opinions, it timestamps every action, and it points to attached evidence rather than relying on memory. That is the standard every guard report should set, and it is the bar this sample is built to.

    The 8 parts every incident report includes

    Whatever your site format, a defensible report covers these eight parts, and a good example hits all of them. The sample above does.

    1. Report and reference details — a unique number, the guard’s name and badge, the shift.
    2. When — date and exact time of the incident, not the time you sat down to write it.
    3. Where — the specific location, precise enough to place on a site map.
    4. What happened — a plain, chronological, factual account in the guard’s own words.
    5. Who was involved — descriptions of people and any vehicles, kept observational.
    6. Actions taken — what the guard did, in order, with times.
    7. Evidence — photos, video, audio and any camera references that back the account.
    8. Notifications and follow-up — who was told, when, and what still needs doing.

    How AVES turns the example into a clean digital record

    Writing a strong report on paper is hard at 02:18 in the rain. The AVES incident forms are built so the eight parts above are captured in order, on a phone, at the scene.

    Every incident is logged against a report record with the date, time, location and type set as structured fields, so nothing is left to a guard’s handwriting. Evidence is not an afterthought: the form uses a six-sided photo capture, so the guard records the scene from front, back, left, right, top and bottom, and can add a short video and an audio note alongside. Findings and actions are recorded on the same record, and the report carries a review trail showing who checked it and when. Because the capture happens at the scene, the timestamps are real rather than reconstructed later.

    The result is a digital record, the same as the sample above: a complete, evidence-backed record that a client, an investigator or a court can rely on, without depending on a tired guard remembering to write everything down at the end of a shift.

    Common mistakes that weaken a report

    • Opinions instead of observations. “He was aggressive” is a judgement. “He raised his voice and stepped towards me twice” is an observation. Stick to what you saw and heard.
    • Missing or vague times. “Early hours” helps nobody. Log exact times for the incident and for each action.
    • No supporting evidence. A description of damage with no photo is far easier to dispute. Capture the scene before it changes.
    • Writing hours later. Memory fades and details blur. Record at or near the scene while it is fresh.
    • Editing the story to look better. Never soften or embellish. An accurate record protects you; an altered one destroys your credibility.

    How to adapt this example to your site

    No two sites report the same way, so treat this example as a base to shape, not a form to copy word for word. Start by matching the incident types you actually see. A retail site logs shoplifting and refused-entry cases far more than perimeter breaches, while a warehouse or distribution park sees more gate and loading-bay events. Rename the incident type list so guards pick from options that fit the site rather than forcing every event into a generic label.

    Next, fix the location detail to your layout. “North goods gate, Unit 4” only works if your gates are named and mapped. Agree a simple, shared naming scheme for gates, doors, floors and zones, and make sure every guard uses the same names. Vague locations are one of the fastest ways to weaken an otherwise solid report.

    Finally, decide your escalation and notification rules up front. The sample notified a client duty manager and logged a police reference. Your site may need a different order: control room first, then client, then emergency services. Writing those steps into the report structure means the guard records who was told and when, every time, without having to remember the sequence under pressure.

    Frequently asked questions

    What should an incident report for a security guard include?

    A complete incident report should include the report reference and guard details, the exact date, time and location, a factual account of what happened, descriptions of anyone involved, the actions taken with times, the supporting evidence, and any notifications and follow-up. The sample above shows each part filled in.

    How detailed should a security incident report be?

    Detailed enough that someone who was not there can reconstruct the sequence without asking you questions. Prioritise exact times, specific locations and observed facts over general impressions.

    Should a guard write what they think happened or only what they saw?

    Only what they directly saw, heard or did. Conclusions and opinions weaken a report because they can be challenged. Record the observations and let the facts speak.

    How soon after an incident should the report be written?

    As soon as it is safe to do so, ideally at or near the scene, which is why good training stresses speed. The longer the delay, the more detail is lost and the easier the account is to dispute.

    Can photos and video be part of the report?

    Yes, and they should be. Evidence captured at the scene, such as a six-sided photo set with a short video, makes a report far harder to dispute than words alone.

    Ready to see it on the real screen?

    Book a 30-minute AVES demo and we will show you the real six-sided evidence capture and review trail in the incident form: Book a demo. Prefer to explore first? Start free. See also our incident reporting software, the security incident report format and the witness statement form, or follow AVES on Instagram.

  • Contractor Sign In Sheet: 8 Fields Your Template Needs

    Contractor Sign In Sheet: 8 Fields Your Template Needs

    A contractor sign in sheet is the record, kept at the gate or reception, of every contractor who comes on site to work. It captures who they are, who they work for, why they are there and when they arrive and leave. Unlike a visitor who is escorted for a meeting, a contractor is often on site for hours, moving through areas staff do not watch, sometimes doing work that carries its own risk. The sign in sheet is where accountability for that starts.

    Most contractor sign in sheets fail for one reason: the template is missing the fields that matter, so the record has gaps exactly where you later need proof. This guide sets out the eight fields every contractor sign in sheet template should have, and why a digital sheet closes the gaps a paper one cannot.

    contractor sign in sheet

    Why a contractor sign in sheet matters

    A contractor is not a guest. They carry tools, they may work alone in a plant room, and the task itself, hot work or an electrical isolation for example, can be the very thing that causes an incident. The sign in sheet is the first control that ties a named person to a company, a task and a window of time on your site.

    It matters in three moments. In an evacuation it tells the fire marshal how many contractors are still inside and where they were working. In a safety review it links each person to the permit or approval that authorised their work. After an incident it answers the question every investigation opens with: who was here, and who let them in.

    The weakness of the paper sheet is that it relies on the contractor to fill it in fully and honestly, and on nobody being able to walk past the desk unchecked. A clipboard left on a counter is not a control at all. That is what the right fields, and a digital format, are there to fix.

    The 8 fields every contractor sign in sheet needs

    1. Contractor name – the full name of the individual, so the entry is attributable to a person and not just a company.
    2. Company – the firm the contractor represents, so you can trace the work back to a supplier.
    3. On-site contact or host – the member of staff who authorised the work and is responsible while the contractor is on site.
    4. Purpose of work – what the contractor is there to do, in enough detail to match it against any permit.
    5. Permit or approval reference – the number of the work permit or access approval that authorised entry, where the task requires one.
    6. Time in – the arrival time, recorded at the gate.
    7. Time out – the departure time, recorded when the contractor leaves. This is the field paper sheets lose most often, and the one an evacuation depends on.
    8. Pass or badge number – ties the contractor to the physical or digital pass they were issued for the day.

    Higher-risk sites add two more: a photo of the contractor and a scan of a photo ID, so the person at the gate can match the badge to the face. In AVES, each access pass is issued with an approval step, a QR code and an id or profile photo, so the entry is tied to a verified identity rather than a name written by hand. Where the work is hazardous, the hot work permit adds an invitation, an approval, a QR check-in and a terms and conditions acknowledgement on top of the sign in, so a contractor cannot start high-risk work without an authorised permit on record.

    Paper sign in sheet versus a digital one

    A paper template works until the moment it matters. The recurring failures are always the same: the time-out field left blank, handwriting no one can read, a permit reference nobody wrote down, a page that has gone missing. None of these is visible until you need the record and find it incomplete.

    A digital contractor sign in sheet captures the same eight fields as structured data. Required fields cannot be skipped, entries are legible because they are typed or selected, and the departure is recorded when the pass is scanned or returned rather than relying on the contractor to sign out. The record is searchable, so you can pull every visit by one firm, or everyone on site during a shift, in seconds. For the full workflow around passes, approvals and access, see the AVES visitor management system. To see how contractor access differs from payroll-style management, see contractor management for security teams.

    Common contractor sign in sheet mistakes

    No sign-out. The single most common gap. Without a time out you cannot prove when a contractor left or run an accurate evacuation count.

    No permit link. A contractor doing hazardous work with no permit reference on the sheet means there is no record that the work was ever authorised.

    An unattended clipboard. A sheet on the counter with no one checking it lets anyone write anything, or nothing.

    No named host. If no staff member authorised the work, no one is accountable for where the contractor goes or what they do.

    No identity check. A name with nothing behind it is trivial to fake, and a contractor pass is easy to reuse the next day.

    Keeping old sheets on display. A completed sheet shows every prior contractor’s details to the next person who signs in. That is a privacy failure. Records should be stored securely, not left face-up on the desk.

    Contractor sign in sheet checklist

    • Every entry has a contractor name, company and named host.
    • Purpose of work is recorded in enough detail to match a permit.
    • A permit or approval reference is captured where the task requires one.
    • Both time in and time out are recorded.
    • A pass or badge number ties the person to a pass issued for the day.
    • Higher-risk sites add a photo and ID check.
    • The sheet is controlled by a person, not left unattended.
    • Prior entries are not visible to the next contractor.
    • Records are stored securely and retained only as long as needed.

    Frequently asked questions

    What is a contractor sign in sheet?
    A contractor sign in sheet is a record kept at a site entrance of every contractor who comes on site to work, capturing their name, company, host, purpose of work and their time in and out. It supports evacuation roll calls, permit control and after-incident accountability.

    What fields should a contractor sign in sheet have?
    Contractor name, company, on-site host, purpose of work, permit or approval reference, time in, time out and pass number. Higher-risk sites also add a photo and an ID check.

    What is the difference between a contractor and a visitor sign in sheet?
    A visitor is usually escorted for a short meeting, so a name and host is often enough. A contractor works on site for longer, sometimes on hazardous tasks, so the sheet also needs a purpose of work and a link to the permit that authorised it.

    Do contractors need a work permit as well as a sign in sheet?
    For hazardous tasks such as hot work, yes. The sign in sheet records entry; the permit authorises the specific work. The permit reference should appear on the sign in record so the two tie together.

    How do you stop a contractor pass being reused?
    Control the sheet at the gate rather than leaving it out, and issue a pass tied to an approval and an identity check. A digital pass with a photo and a QR code ties each day’s entry to a verified person.

    Move your contractor sign in off the clipboard

    If your gate still runs on a paper sheet, the gaps are only a matter of time, and with contractors the gap is often a missing permit link or a blank time out. AVES issues every contractor an access pass with an approval step, a QR code and a profile photo, ties hazardous work to an authorised hot work permit, and records each visit as a private, searchable entry with the time out captured when the pass is scanned.

    Book a 30-minute demo and we will show you the actual access pass, approval and permit screens: Book an AVES demo

    Prefer to explore first? Start a free account: Create your AVES account

    Follow AVES on Instagram: instagram.com/avessecurity

  • Security Patrol Report: What to Record and Why It Matters

    Security Patrol Report: What to Record and Why It Matters

    A security patrol report is the record that proves a guard actually walked the site. It documents where they went, when they got there, and what they found along the way. Without it, a patrol is just a claim. With it, you have verifiable evidence that the checkpoints were covered, the round was completed, and any issue was seen and logged.

    The value of the report depends entirely on what it records. A report that says “all clear, 10pm” proves nothing; the guard could have written it from the gatehouse. A report that ties each checkpoint to a GPS location, a scan time and a photo is evidence. This guide sets out the seven things every security patrol report must record, and how a digital patrol makes each one verifiable.

    security patrol report

    Why the security patrol report matters

    A patrol report answers three questions that clients and courts both ask. Did the guard cover the whole site, or just the easy parts? When exactly were they at each point? And what did they do about anything they found?

    The report matters most when something goes wrong. If a break-in happens between two checkpoints, the report shows whether the round was on schedule or whether a section was skipped. If a client disputes that the site was patrolled at all, the report is the proof. This is why proof of patrol is a real requirement, not a formality: it is the difference between a defensible service and a guard’s unverified word.

    The 7 things every security patrol report must record

    1. Guard and shift – who patrolled and on which shift, so the round is attributable.
    2. Date and start and end times – when the patrol began and finished, from the waypoint start and end times, not a figure written afterwards.
    3. Checkpoints visited – each checkpoint on the route, confirmed by a QR scan so the guard had to be physically present to log it.
    4. Time at each checkpoint – the scan time at each point, which shows the round was walked in sequence and on schedule.
    5. GPS location – the location captured at each scan, tying the guard to the place, not just the time.
    6. Verification media – a selfie or photo where required, adding a further layer of proof.
    7. Observations and issues – anything found on the round: an unlocked door, a hazard, a suspicious person, with the action taken.

    AVES patrols capture exactly these: checkpoints visited with GPS location and scan time, a QR code at each point, an optional required selfie, waypoint start and end times, and the total distance covered. That last figure, total distance, is a quiet but powerful check: a full round covers a known distance, and a short one shows on the record.

    How a digital patrol report is verified

    A paper patrol log can be written anywhere, which is precisely its weakness. A digital patrol removes the ability to fake it. The guard must scan a QR code fixed at each checkpoint to log it, and the scan captures the GPS location and the exact time automatically. Where a selfie is required, the guard cannot log a point without it.

    The result is a report that is verifiable rather than merely claimed. A supervisor can see the route as it was actually walked, the time spent, the distance covered and any gaps. For the full patrol and checkpoint workflow, see the AVES guard tour system. For why unverified patrols are a genuine liability, see missed patrol verification.

    Common security patrol report mistakes

    Written from the gatehouse. A report completed without walking the round proves nothing. QR scans at fixed points remove this.

    No time per checkpoint. A single end-of-round timestamp hides whether the patrol was on schedule. Each checkpoint needs its own scan time.

    No location. A time with no place does not prove the guard was where they should have been.

    Skipped checkpoints not flagged. A report that silently omits a missed point is worse than one that records the gap.

    Vague observations. “All fine” is not an observation. Note what was checked and anything found.

    Security patrol report checklist

    • Guard and shift recorded.
    • Patrol start and end times captured automatically.
    • Every checkpoint confirmed by a scan at the point.
    • A time recorded at each checkpoint, not just at the end.
    • GPS location captured at each scan.
    • Selfie or photo verification where required.
    • Observations and actions logged.
    • Total distance or route completeness visible, so gaps show.

    Frequently asked questions

    What is a security patrol report?

    A security patrol report is a record proving a guard patrolled a site, documenting the checkpoints visited, the time and location of each, and any issues found. It is used as proof of patrol for clients, insurers and investigations.

    What should a security patrol report include?

    The guard and shift, start and end times, each checkpoint with its scan time and GPS location, verification media where required, and observations with actions taken.

    How do you prove a patrol actually happened?

    By tying each checkpoint to a QR scan that captures the GPS location and time automatically, so the guard must be physically present to log it. A single written “all clear” does not prove a patrol.

    What is the difference between a patrol report and a daily activity report?

    A patrol report covers a specific round and its checkpoints. A daily activity report summarises everything across a shift. The patrol report feeds the wider activity record.

    Can a digital patrol report be faked?

    It is far harder. Because a checkpoint is only logged when the guard scans a fixed QR code, and the scan captures location, time and often a selfie, a report cannot be completed without being at the points.

    Give your patrols proof, not just a signature

    If your patrol reports are still handwritten logs, you cannot prove the round was walked. AVES patrols log each checkpoint by QR scan with GPS, time, an optional selfie and the total distance covered, so every report is verifiable.

    Book a 30-minute demo and we will show you the actual patrol and checkpoint screens: Book a demo.

    Prefer to explore first? Start a free account.

    Follow AVES on Instagram.

  • Visitor Sign In Sheet: The 7 Columns Your Template Needs

    Visitor Sign In Sheet: The 7 Columns Your Template Needs

    A visitor sign in sheet is the printable template that sits at your front desk: the single page a visitor completes on arrival, capturing who they are, who they are here to see, and when they came and went. It is the input at the point of entry, the thing a receptionist hands across the counter. This guide is about that sheet as a document: the columns your template must have before you print it, not the running record it eventually feeds.

    Most sign in sheets fail for the same reason: the printed template is missing the columns that matter, so every entry has gaps exactly where you later need proof. Below are the seven columns every visitor sign in sheet template should carry, the front-desk mistakes that make one worthless, and where a paper sheet stops being enough. For the ongoing record those sheets build up into, see the AVES visitor log book guide.

    visitor sign in sheet

    Why a visitor sign in sheet matters

    The sheet does more than log names. In an evacuation it is the roll call that tells a fire marshal how many non-staff are in the building. In a security review it is how you tie a person to a time and a host. After an incident it is the record that answers the only question that matters: who was here.

    The weakness of the paper sheet is that it depends on the visitor filling it in honestly and completely, and on nobody being able to read what the person above them wrote. A sheet left unattended on a counter is not a control at all. That is the problem the right columns, and a digital format, are there to fix.

    The 7 columns every visitor sign in sheet needs

    1. Visitor name – full name, so the entry is attributable.
    2. Company or affiliation – who the visitor represents.
    3. Host – the member of staff responsible for the visitor while on site.
    4. Purpose of visit – meeting, delivery, contractor work, interview.
    5. Time in – the arrival time, recorded at entry.
    6. Time out – the departure time, recorded when the visitor leaves. This is the column paper sheets lose most often, and the one an evacuation depends on.
    7. Pass or badge number – ties the visitor to the physical or digital pass they were issued.

    Higher-security sites add two more: a photo of the visitor and a scan of a photo ID, so the person at the desk can match the badge to the face. AVES issues each visitor pass with an approval step, a QR code and an id or profile photo, so the entry is tied to a verified identity rather than a name written by hand.

    Paper sign in sheet versus a digital one

    A paper template works until the moment it matters. The recurring failures are always the same: the time-out column left blank, handwriting no one can read, a visitor who signed in as someone they are not, a page that has gone missing. None of these is visible until you need the record and find it incomplete.

    A digital sign in sheet captures the same seven columns as structured data. Required fields cannot be skipped, entries are legible because they are typed or selected, and the departure is recorded when the pass is scanned or returned rather than relying on the visitor to sign out. The record is searchable, so you can pull every visit by a contractor or everyone on site on a given afternoon in seconds. For the full workflow around passes, approvals and access, see the AVES visitor management system. To understand why unreturned passes are a risk worth tracking, see visitor pass tracking.

    Common visitor sign in sheet mistakes

    No sign-out. The single most common gap. Without a time out you cannot prove when someone left or run an accurate evacuation count.

    An unattended clipboard. A sheet on the counter with no one checking it lets anyone write anything, or nothing.

    No host column. If no staff member is named, no one is accountable for where the visitor goes.

    No identity check. A name with nothing behind it is trivial to fake.

    Keeping old sheets on display. A completed sheet shows every prior visitor’s details to the next person who signs in. That is a privacy failure. Records should be stored securely, not left face-up on the desk.

    Visitor sign in sheet checklist

    • Every entry has a name, company and named host.
    • Purpose of visit is recorded.
    • Both time in and time out are captured.
    • A pass or badge number ties the person to a pass.
    • Higher-risk sites add a photo and ID check.
    • The sheet is controlled by a person, not left unattended.
    • Prior entries are not visible to the next visitor.
    • Records are stored securely and retained only as long as needed.

    Frequently asked questions

    What is a visitor sign in sheet?

    A visitor sign in sheet is a record kept at a site entrance of every non-staff visitor, capturing their name, host, purpose and their time in and out. It supports evacuation roll calls, security accountability and compliance.

    What columns should a visitor sign in sheet have?

    Name, company, host, purpose of visit, time in, time out and pass number. Higher-security sites also add a photo and an ID check.

    What is the difference between a visitor sign in sheet and a visitor log book?

    They are different stages of the same process. A sign in sheet is the printable template a visitor fills in at the desk, one page at a time. A visitor log book is the ongoing record those sheets accumulate into, kept for roll-call and retention. This guide covers the sheet; the log book guide covers the record.

    Is a paper visitor sign in sheet GDPR-safe?

    A paper sheet that displays previous visitors’ details to the next person signing in is a privacy risk. A digital sheet keeps each entry private and lets you retain and dispose of records securely.

    How do you stop people signing in as someone else?

    Control the sheet at the desk rather than leaving it out, and add an identity check. A digital pass with a photo and an approval step ties each entry to a verified person.

    Move your sign in sheet off the clipboard

    If your entrance still runs on a paper sheet, the gaps are only a matter of time. AVES issues every visitor a pass with an approval step, a QR code and a profile photo, and records each visit as a private, searchable entry with the time out captured automatically.

    Book a 30-minute demo and we will show you the actual visitor pass and approval screens: Book a demo.

    Prefer to explore first? Start a free account.

    Follow AVES on Instagram.

  • Incident Report Form: The 8 Fields Your Template Must Include

    Incident Report Form: The 8 Fields Your Template Must Include

    An incident report form is the blank template a guard fills in when something goes wrong on site: an injury, a theft, a trespass, a near miss, property damage. Before a word is written, the form itself decides how good the record can be. A template that prompts for the right fields, in the right order, produces a report an insurer or a court will accept. A blank box that just says “describe the incident” produces three vague lines and no evidence.

    This guide is about the form as a document: the eight fields your template must contain before you hand it to a guard, the mistakes that make a filled-in form worthless, and when a printable paper form is enough versus when you need a digital one. If what you need is how to write up the report once you have the form, that belongs in our security incident report format guide; this piece stays on the form itself.

    incident report form

    Why the incident report form matters

    The report is written in minutes but read for months. It is the document a claims adjuster uses to decide a payout, the record a lawyer reads before a liability case, and the evidence a client reviews when they ask what their security provider actually did. If a detail was not captured at the scene, it usually cannot be recovered later.

    A structured form matters because it removes the guesswork under pressure. A guard dealing with an injured person should not have to remember what a complete report needs; the form should ask. That is what separates a system that produces usable evidence from one that produces a pile of inconsistent notes.

    The 8 fields every incident report form must include

    1. Date and time of the incident – the actual time it happened, not the time the report was written.
    2. Location – the specific place on site, precise enough that someone who was not there can picture it.
    3. Reporter details – the name and role of the guard completing the form, so the account is attributable.
    4. People involved – names and roles of everyone present: victims, witnesses, staff, third parties.
    5. Description of what happened – a factual, chronological account, without opinion or blame.
    6. Action taken – what the guard did: first aid given, police called, area secured, supervisor notified.
    7. Evidence – photos, video or audio from the scene. AVES incident forms capture six-sided photo evidence (front, back, left, right, top, bottom) plus video and audio.
    8. Findings and follow-up – the outcome, any corrective action, and whether a police report or investigation was raised.

    Together these eight answer the questions every reader asks: what, when, where, who, what was done, and can you prove it.

    How a digital incident report form works

    A paper form relies on the guard remembering to fill every box and on the handwriting being legible weeks later. A digital incident report form removes both risks. The fields are mandatory where they need to be, so a report cannot be submitted half-finished. Photos, video and audio attach directly to the record rather than living on someone’s phone. The timestamp and the reporter are captured automatically.

    Because the report is data rather than paper, it is searchable and it routes to the right person for review the moment it is submitted. For the full workflow around logging, escalating and analysing incidents, see the AVES incident reporting software. If you need the specific layout conventions, the security incident report format guide covers structure.

    Common incident report form mistakes

    Opinion instead of fact. “The visitor was aggressive” is a judgement. “The visitor raised his voice and struck the counter” is an observation. Reports record observations.

    Missing the time of the incident. Recording only when the report was written loses the single most important timestamp.

    No evidence. A description with no photo is an assertion. A single photo of a wide area proves little. Capture the scene from multiple angles.

    Blame and speculation. A report that guesses at cause or assigns fault undermines its own credibility. Record what was seen; leave conclusions to the investigation.

    Gaps left blank. An empty field is a question left unanswered, and it is often the answer the reader needs most.

    Written hours later. Memory fades fast. A report completed at the scene is far more reliable than one reconstructed at the end of a shift.

    Incident report form checklist

    • Date and time of the incident recorded, separate from the report time.
    • Specific location captured.
    • Reporter named, with role.
    • All people involved listed with roles.
    • Factual, chronological description with no opinion.
    • Action taken recorded.
    • Evidence attached: photos from multiple angles, plus video or audio where relevant.
    • Findings and follow-up noted, including any police report.

    Frequently asked questions

    What is an incident report form?

    An incident report form is a structured document that records the details of an incident on site: what happened, when and where, who was involved, the action taken and the evidence captured. It is used for insurance, liability and investigation.

    What should an incident report form include?

    At a minimum: date and time of the incident, location, reporter, people involved, a factual description, action taken, evidence, and findings or follow-up.

    What is the difference between an incident report form and a witness statement?

    The incident report is the guard’s structured account of the event. A witness statement is a separate first-person account from someone who saw it. Both support the same case. See the AVES witness statement form.

    Should incident reports be written on paper or digitally?

    Digital is more reliable. Paper forms are prone to blank fields, illegible handwriting and lost evidence. A digital form enforces the required fields, attaches photo, video and audio directly to the record and timestamps it automatically.

    How soon should an incident report be completed?

    As close to the incident as possible, ideally at the scene. Memory and evidence both degrade quickly, so a report written hours later is weaker.

    Give your guards a form that captures real evidence

    If your incident reports still come in as a few handwritten lines, the evidence you need after an incident is not there. AVES incident forms prompt for every required field and capture six-sided photo evidence plus video and audio, so every report is complete and defensible.

    Book a 30-minute demo and we will show you the actual incident form and evidence-capture screens: Book a demo.

    Prefer to explore first? Start a free account.

    Follow AVES on Instagram.

  • Shift Change Request Form: 7 Fields It Must Include

    Shift Change Request Form: 7 Fields It Must Include

    A shift change request form is how a guard asks to swap, drop or move a shift, and how a manager approves or rejects that change on the record. It sounds like a small piece of admin. In practice it is the difference between a roster you can trust and a roster where a post quietly goes uncovered because two people agreed a swap in a WhatsApp message no supervisor ever saw.

    Most shift change request form entries fail for the same reason a paper visitor sheet fails: the request is verbal or informal, so there is no record of who agreed to what, and no approval step to confirm the site is still covered. This guide sets out the seven fields every shift change request form should capture, and why a digital request beats a paper slip or a text message.

    shift change request form

    Why a shift change request form matters

    Security rosters are coverage promises. A client pays for a post to be manned from a set time to a set time, and the roster is how you keep that promise. The moment a guard cannot make a shift, that promise is at risk, and the shift change request form is the control that protects it.

    A good shift change request form does three things. It captures the request in writing so there is no dispute later about who asked for what. It forces the swap to name a replacement, so a change never leaves a gap. And it routes the request to a manager for approval, so no change goes live until someone accountable has confirmed the post is still covered.

    Without a form, changes happen in the gaps: a guard tells a colleague they will cover, the colleague forgets, and the first anyone hears of it is an empty post at 2am. The form exists to stop that conversation ever being informal.

    The 7 fields every shift change request form needs

    1. Requesting employee – the guard asking for the change, so the request is attributable.
    2. Original shift – the date, time and site or post the guard is currently rostered for.
    3. Type of change – a swap with a named colleague, a drop, or a move to a different date or time.
    4. Replacement or cover – who will work the shift instead. A swap request that names no replacement is not a plan, it is a gap.
    5. Reason – why the change is needed. This lets a manager judge the request and spot patterns, such as one guard repeatedly avoiding night shifts.
    6. Date submitted – when the request was made, so late requests can be distinguished from those raised with proper notice.
    7. Manager decision – approved or rejected, by whom, with the date and time. This is the field that turns a request into an authorised change.

    Keep the form to these fields and it stays quick to complete, which matters because a form guards will not fill in is no better than no form at all.

    Paper shift change slip versus a digital shift change request form

    A paper slip or a group chat works right up to the moment it matters. The recurring failures are always the same: a swap agreed verbally that one party forgets, a slip that never reaches the supervisor, a change approved by someone with no authority to approve it, or a request lost so completely that no one can say whether it was ever agreed.

    A digital shift change request form captures the same seven fields as structured data and routes it for approval automatically. In AVES, shift change requests are raised by staff and sent to a manager for approval, so a change is only live once it has been authorised, not the moment two guards shake hands on it. Because the request sits against the roster, an approved swap updates the schedule the whole team is working from rather than living in one person’s memory.

    The roster it updates is generated and managed in the same system. For how the underlying schedule is built, see the AVES security guard duty roster. For what the guard coming on shift should confirm at handover once a change has gone through, see the shift handover checklist. And because a swap only counts once the replacement actually turns up, geofenced attendance is what confirms the covering guard was on site.

    Common shift change request form mistakes

    No named replacement. A request to drop a shift without saying who covers it is not a swap, it is a hole in the roster waiting to be found.

    Verbal-only agreements. A swap agreed in a corridor or a chat leaves no record. When the post is missed, there is nothing to show what was agreed or by whom.

    No approval step. If a change goes live the moment two guards agree, no manager has confirmed the site is still covered or that the replacement is qualified for that post.

    Approval by the wrong person. A colleague saying “fine by me” is not authorisation. The decision field must record a manager, not a peer.

    Late requests treated the same as planned ones. Without a submission date you cannot tell a request raised a week ahead from one raised an hour before the shift. The reason and date fields let you manage notice periods fairly.

    Shift change request form checklist

    • The requesting guard and their original shift are named.
    • The type of change is clear: swap, drop or move.
    • A replacement is named for every swap or drop.
    • A reason is recorded.
    • The submission date is captured.
    • A manager, not a peer, approves or rejects the request.
    • The decision, the approver and the date and time are all recorded.
    • An approved change updates the roster the whole team works from.

    Frequently asked questions

    What is a shift change request form?

    A shift change request form is a record of a guard’s request to swap, drop or move a rostered shift, capturing the original shift, the replacement, the reason and a manager’s approval. It keeps roster changes authorised and on the record rather than informal.

    What should a shift change request form include?

    The requesting employee, their original shift, the type of change, the named replacement or cover, the reason, the date submitted and the manager’s decision with the date and time.

    What is the difference between a shift swap and a shift change request?

    A shift swap is one type of change, where two people exchange shifts. A shift change request is the broader form that also covers dropping a shift or moving it to a different time, each still needing a named replacement and manager approval.

    Why does a shift change need manager approval?

    Because only a manager can confirm the post is still covered and the replacement is qualified for it. Without an approval step, a change agreed between two guards can leave a site uncovered or manned by someone not cleared for that post.

    Can a shift change request be handled digitally?

    Yes. A digital shift change request form captures the same fields, routes the request to a manager automatically and updates the shared roster once approved, which removes the verbal agreements and lost slips that paper processes rely on.

    Take shift changes off the group chat

    If your shift swaps still happen in a group chat, the missed post is only a matter of time. AVES lets a guard raise a shift change request that names the replacement and routes to a manager for approval, so no change goes live until the coverage is confirmed and the roster is updated for everyone.

    Book a 30-minute demo and we will show you the actual shift change request and approval screens: Book a demo

    Prefer to explore first? Start a free account: Start a free account

    Follow AVES on Instagram: Instagram