Most guards are never taught how a strong report reads until a claim, a complaint or a court date puts theirs under the microscope. This worked example shows you exactly what a complete, defensible entry looks like, and breaks down the eight parts that make it hold up. Copy the sample, adapt the fields to your site and you will log cleaner proof from your very next shift.

An incident report is the written record of something that went wrong on your watch: a theft, an injury, a trespass, a fire alarm, an altercation. Written well, it protects the guard, the client and the guarding company. Written badly, it becomes the weakest link in an investigation.
Why the incident report example for security guard beats a blank form
A good worked example does something a blank form cannot. A blank form tells you which boxes exist. It does not tell you how to fill them so the record survives scrutiny weeks later. That is why a worked example is worth more than any empty template: it shows the level of detail, the neutral tone and the sequencing that separate a usable record from a vague one.
Three things go wrong most often. Guards write what they concluded (“the man was clearly drunk”) instead of what they observed. They leave time gaps, so nobody can reconstruct the sequence. And they describe damage or injury in words alone, with no supporting evidence. A good example fixes all three by design.
A complete incident report example for a security guard
The sample below is a realistic, filled-out report for a common scenario: an after-hours intruder at a warehouse gate. Adapt the names, times and site details to your own.
Incident report — sample
Report number: IR-2026-0417
Date of incident: 14 September 2026
Time of incident: 02:18
Location: North goods gate, Unit 4, Riverside Distribution Park
Reporting guard: J. Okafor, badge 3391, night shift 22:00-06:00
Incident type: Unauthorised entry attemptWhat happened (factual account): At 02:18 during a routine patrol of the north perimeter, I heard the sound of the goods gate chain being moved. I walked to the gate and saw one male attempting to climb the pedestrian side rail. I called out and identified myself as security. The male stopped, stepped down on the outer side and ran north along the fence line towards the canal path. I did not pursue beyond the boundary.
Description of person: Male, approximately 1.8 metres, medium build, dark hooded top, light trousers, carrying a small dark bag. Face not clearly seen.
Actions taken: Secured and rechecked the gate chain and padlock at 02:21. Radioed the control room at 02:22 to log the event. Reviewed the north gate camera and confirmed footage exists for 02:16-02:20. Increased patrol frequency of the north perimeter for the remainder of the shift.
Evidence attached: Six-sided photo set of the gate and rail, short video walk-through of the entry point, camera reference NGC-02 clip 02:16-02:20.
Witnesses: None on site. Control room operator M. Devi confirmed radio log.
Injuries or damage: No injuries. Minor scuff to the pedestrian rail paint, photographed.
Police or client notified: Client duty manager notified at 02:35. Police non-emergency reference PR-88214 logged at 02:41.
Follow-up required: Client to review whether the pedestrian rail needs a higher anti-climb section. Camera coverage of the canal path to be assessed.
This sample is worth reading back closely. Notice what it does: it records observations rather than opinions, it timestamps every action, and it points to attached evidence rather than relying on memory. That is the standard every guard report should set, and it is the bar this sample is built to.
The 8 parts every incident report includes
Whatever your site format, a defensible report covers these eight parts, and a good example hits all of them. The sample above does.
- Report and reference details — a unique number, the guard’s name and badge, the shift.
- When — date and exact time of the incident, not the time you sat down to write it.
- Where — the specific location, precise enough to place on a site map.
- What happened — a plain, chronological, factual account in the guard’s own words.
- Who was involved — descriptions of people and any vehicles, kept observational.
- Actions taken — what the guard did, in order, with times.
- Evidence — photos, video, audio and any camera references that back the account.
- Notifications and follow-up — who was told, when, and what still needs doing.
How AVES turns the example into a clean digital record
Writing a strong report on paper is hard at 02:18 in the rain. The AVES incident forms are built so the eight parts above are captured in order, on a phone, at the scene.
Every incident is logged against a report record with the date, time, location and type set as structured fields, so nothing is left to a guard’s handwriting. Evidence is not an afterthought: the form uses a six-sided photo capture, so the guard records the scene from front, back, left, right, top and bottom, and can add a short video and an audio note alongside. Findings and actions are recorded on the same record, and the report carries a review trail showing who checked it and when. Because the capture happens at the scene, the timestamps are real rather than reconstructed later.
The result is a digital record, the same as the sample above: a complete, evidence-backed record that a client, an investigator or a court can rely on, without depending on a tired guard remembering to write everything down at the end of a shift.
Common mistakes that weaken a report
- Opinions instead of observations. “He was aggressive” is a judgement. “He raised his voice and stepped towards me twice” is an observation. Stick to what you saw and heard.
- Missing or vague times. “Early hours” helps nobody. Log exact times for the incident and for each action.
- No supporting evidence. A description of damage with no photo is far easier to dispute. Capture the scene before it changes.
- Writing hours later. Memory fades and details blur. Record at or near the scene while it is fresh.
- Editing the story to look better. Never soften or embellish. An accurate record protects you; an altered one destroys your credibility.
How to adapt this example to your site
No two sites report the same way, so treat this example as a base to shape, not a form to copy word for word. Start by matching the incident types you actually see. A retail site logs shoplifting and refused-entry cases far more than perimeter breaches, while a warehouse or distribution park sees more gate and loading-bay events. Rename the incident type list so guards pick from options that fit the site rather than forcing every event into a generic label.
Next, fix the location detail to your layout. “North goods gate, Unit 4” only works if your gates are named and mapped. Agree a simple, shared naming scheme for gates, doors, floors and zones, and make sure every guard uses the same names. Vague locations are one of the fastest ways to weaken an otherwise solid report.
Finally, decide your escalation and notification rules up front. The sample notified a client duty manager and logged a police reference. Your site may need a different order: control room first, then client, then emergency services. Writing those steps into the report structure means the guard records who was told and when, every time, without having to remember the sequence under pressure.
Frequently asked questions
What should an incident report for a security guard include?
A complete incident report should include the report reference and guard details, the exact date, time and location, a factual account of what happened, descriptions of anyone involved, the actions taken with times, the supporting evidence, and any notifications and follow-up. The sample above shows each part filled in.
How detailed should a security incident report be?
Detailed enough that someone who was not there can reconstruct the sequence without asking you questions. Prioritise exact times, specific locations and observed facts over general impressions.
Should a guard write what they think happened or only what they saw?
Only what they directly saw, heard or did. Conclusions and opinions weaken a report because they can be challenged. Record the observations and let the facts speak.
How soon after an incident should the report be written?
As soon as it is safe to do so, ideally at or near the scene, which is why good training stresses speed. The longer the delay, the more detail is lost and the easier the account is to dispute.
Can photos and video be part of the report?
Yes, and they should be. Evidence captured at the scene, such as a six-sided photo set with a short video, makes a report far harder to dispute than words alone.
Ready to see it on the real screen?
Book a 30-minute AVES demo and we will show you the real six-sided evidence capture and review trail in the incident form: Book a demo. Prefer to explore first? Start free. See also our incident reporting software, the security incident report format and the witness statement form, or follow AVES on Instagram.
