When an Incident Report Must Be Filed
An incident report is filed whenever something happens on a post that is outside normal routine and that someone other than the guard may later need to know about. The test is not severity; it is whether a question could be asked afterwards. A visitor who argued at the gate and left is an incident. A fire alarm that turned out to be a test is an incident. A vehicle that scraped the barrier is an incident. If in doubt, file.
The daily occurrence book records routine events in sequence; the incident report is a separate, structured document for anything that needs investigation, escalation, insurance, police involvement or a client conversation. The shift report and handover article explains how the two relate. A guard should never be told to 'just put it in the register' for something that a client will later ask about.
Timing matters. The report is written during or immediately after the shift while the times and sequence are fresh, not the next day from memory. Where the guard cannot write it at once because the incident is ongoing, the supervisor takes a verbal account and the guard writes the full report within the same shift.
- File for anything outside routine that could later be questioned
- Theft or attempted theft, unauthorised entry, alarms, medical emergencies, damage, altercations, suspicious objects, equipment failure at the post
- File even when the outcome was harmless (false alarm, visitor left)
- Write during or immediately after the shift, never the next day
- One incident, one report; do not combine unrelated events
The 5W1H Structure
The simplest way to make sure a report is complete is to answer six questions in order: what happened, who was involved, where exactly, when (with exact times), why it happened if known, and how it was handled. A report that answers all six can be read by someone who was not there and still understood; a report that answers four leaves the reader guessing.
What: a plain description of the event, in the order it happened. Who: everyone involved by name where known, or by description where not, including the reporting guard, other guards, employees, visitors, police, and witnesses. Where: the site, the post, and the precise location within the site (Gate 2 barrier, third-floor fire exit, parking bay B-14). When: date and time of the first observation, each significant step, and the time the incident ended or was handed over.
Why is the question most often answered with speculation, and it should be answered only with facts the guard observed or was told, attributed to the source. How: the actions the guard took, in sequence, and the outcome of each. This last section is where the guard's professionalism is judged, so it should be specific: 'called supervisor at 22:14; supervisor arrived 22:31; police called at 22:35 by supervisor' rather than 'informed everyone'.
- What: plain description in chronological order
- Who: names or descriptions of all persons involved and witnesses
- Where: site, post, exact location
- When: exact times for first observation, each action, and close
- Why: only facts observed or attributed; How: each action and its outcome
Mandatory Fields
Whether the report is on paper or in an app, the fields below should exist and be filled. A client-specific format may add fields (asset tag numbers, CCTV camera IDs, insurance reference) but should never remove these. The supervisor sign-off is not optional: it is the point at which the agency takes ownership of the report and decides what escalation is needed.
- Report number and date of filing
- Site name, client name, post name
- Date and time of incident (start and end)
- Reporting guard name, employee ID, shift
- Incident type (from a fixed list) and severity as assessed by the supervisor
- Persons involved: names, roles, descriptions, vehicle numbers where relevant
- Description of incident in chronological order
- Actions taken by the guard, with times
- Witnesses with contact details
- Evidence attached: photographs, CCTV clip reference, documents, GPS location
- Escalation: who was informed (supervisor, client contact, police, ambulance) and when
- Injuries or damage, and any first aid given
- Supervisor review, comments and sign-off with time
- Client acknowledgement where required by the contract
Writing Rules: Facts, Sequence, Exact Times, No Blame
The report is a record that may be read by the client's management, an insurer, the police or a court. Every sentence should be something the guard saw, heard or did, or something another named person told the guard. 'The visitor appeared drunk' is an opinion; 'the visitor was unsteady on his feet and his speech was slurred' is an observation. 'The contractor was careless' is blame; 'the contractor's vehicle reversed into the barrier at approximately 15:42' is a fact.
Keep to chronological order and use the 24-hour clock with exact times. Where a time is approximate, say so. Use full names and IDs the first time a person is mentioned and a consistent short form after. Avoid abbreviations that the client may not know. Write in the first person ('I observed', 'I called') so that responsibility for each statement is clear.
Do not leave blank fields. If a field does not apply, write 'nil' or 'not applicable'. Do not alter a report after it has been signed; if a correction is needed, add a dated addendum. On paper, strike through and initial rather than overwrite. In an app, the audit trail records the change automatically.
- Observations, not opinions; actions, not judgements
- Chronological order with exact 24-hour times
- Full names and IDs on first mention
- First person for the guard's own actions
- No blank fields; corrections by dated addendum, never by overwriting
Sample Incident Report
The sample below uses fictional names and a fictional site. It is a complete report for an attempted unauthorised entry at a warehouse, written to the rules above.
Incident Report No. WH2-2026-014. Site: Sector 44 Warehouse (Client: [Client name]). Post: Main Gate. Date of incident: 24 September 2026. Time: 22:05 to 22:48. Reporting guard: Ramesh Kumar, ID SG-0217, night shift 20:00–08:00. Incident type: attempted unauthorised entry. Severity (supervisor): medium.
Description: At approximately 22:05 I observed a white two-wheeler without a number plate stop about 20 metres from the main gate. The rider, a male of about 25 to 30 years wearing a dark jacket, walked to the boundary wall on the east side and attempted to climb it using the electricity meter box as a step. I shouted a challenge from the gate. The person dropped back to the ground and moved towards the two-wheeler. I called the site supervisor, Mr Suresh Yadav (ID SG-0088), at 22:07. The person left on the two-wheeler towards the service road at about 22:09. I did not leave the gate post. Mr Yadav arrived at 22:24, inspected the east wall and meter box with me, and found no damage and no entry. Mr Yadav informed the client's night duty manager, Mr Anil Mehta, by phone at 22:31. Mr Yadav asked the client's CCTV operator to preserve footage from camera C-06 (east wall) for 21:55 to 22:15. No police complaint was lodged on the client's instruction. Incident closed at 22:48.
Actions taken: verbal challenge (22:05); supervisor informed (22:07); post maintained; joint inspection of east wall (22:24 to 22:30); client informed (22:31); CCTV preservation requested (22:33). Witnesses: none other than the reporting guard. Evidence: two photographs of the east wall and meter box taken at 22:26 (attached); CCTV camera C-06 reference. Injuries or damage: nil. Supervisor review: 'Report accurate. Recommend anti-climb guard on meter box; patrol frequency on east wall increased to hourly for the week.' Signed Suresh Yadav, 23:10. Client acknowledgement: Anil Mehta, 25 September 2026, 09:15.
Common Incident Types and What to Capture
Different incidents need different details, and a guard under pressure benefits from knowing in advance what to note. The list below is the minimum extra detail per type, beyond the mandatory fields. Print it on the back of the paper form or build it into the app's incident type selection so the right prompts appear.
- Theft or attempted theft: what was targeted, whether anything was taken, how access was gained or attempted, description of persons, direction of departure, CCTV camera references, whether police were informed and the complaint number
- Unauthorised entry: point of entry, how detected, whether the person was identified, what they were doing, whether they were escorted out or detained until police arrived, any damage to fencing or locks
- Fire alarm: which zone or panel, time of alarm, whether smoke or fire was seen, evacuation actions, fire brigade called and arrival time, who reset the panel, whether it was confirmed as false
- Medical emergency: person affected, symptoms observed, first aid given and by whom, ambulance or doctor called and arrival time, hospital taken to, family or employer informed
- Vehicle damage: vehicle number, driver name and contact, what was struck, photographs of damage from several angles, whether the driver accepted responsibility, client asset owner informed
- Altercation: persons involved, what was said or done as observed, whether anyone was injured, how it was de-escalated, whether police were called
Digital Incident Reporting From the App
Paper incident reports have three weaknesses: they are written after the fact, they cannot carry photographs or location, and they reach the client only when someone scans and emails them. App-based reporting fixes all three. The guard opens the incident type on the phone, the form shows the prompts for that type, the phone attaches photographs with their timestamp and GPS position, and the report reaches the supervisor and, where configured, the client contact within minutes.
The GPS stamp and photo timestamp are not decoration. They establish that the guard was at the post when the incident was recorded, which answers the first question every client asks. Attend Mitra's security guard tracking software includes incident reporting from the guard app with photographs, an SOS alert for emergencies that notifies the supervisor immediately, and duty reports per shift, all linked to the guard's attendance record so the report, the presence and the post assignment are one record. The SOS alert glossary entry explains how emergency alerts differ from incident reports.
Client contracts increasingly specify reporting SLAs: for example, verbal notification within 15 minutes and a written incident report within 4 hours for medium incidents, and immediate notification for high. Digital reporting makes these achievable and, more importantly, provable, because the submission time is recorded. Where the client requires a signed paper copy, export the app report as a PDF and countersign it.
- Incident type selection drives the prompts the guard sees
- Photographs carry timestamp and GPS position automatically
- Supervisor and client contact notified on submission
- Report linked to the guard's attendance and post assignment
- Submission time proves compliance with reporting SLAs

