TEMPLATE

Security Guard Incident Report Format: Fields, Writing Rules and a Full Sample

How security guards should write an incident report: when to file, the 5W1H structure, mandatory fields, rules for factual chronological writing, a complete sample report, what to capture for common incident types, and how app-based reporting with photos and GPS stamps changes the record.

Security guard filing an incident report from a mobile app with photo evidence

When an Incident Report Must Be Filed

An incident report is filed whenever something happens on a post that is outside normal routine and that someone other than the guard may later need to know about. The test is not severity; it is whether a question could be asked afterwards. A visitor who argued at the gate and left is an incident. A fire alarm that turned out to be a test is an incident. A vehicle that scraped the barrier is an incident. If in doubt, file.

The daily occurrence book records routine events in sequence; the incident report is a separate, structured document for anything that needs investigation, escalation, insurance, police involvement or a client conversation. The shift report and handover article explains how the two relate. A guard should never be told to 'just put it in the register' for something that a client will later ask about.

Timing matters. The report is written during or immediately after the shift while the times and sequence are fresh, not the next day from memory. Where the guard cannot write it at once because the incident is ongoing, the supervisor takes a verbal account and the guard writes the full report within the same shift.

  • File for anything outside routine that could later be questioned
  • Theft or attempted theft, unauthorised entry, alarms, medical emergencies, damage, altercations, suspicious objects, equipment failure at the post
  • File even when the outcome was harmless (false alarm, visitor left)
  • Write during or immediately after the shift, never the next day
  • One incident, one report; do not combine unrelated events

The 5W1H Structure

The simplest way to make sure a report is complete is to answer six questions in order: what happened, who was involved, where exactly, when (with exact times), why it happened if known, and how it was handled. A report that answers all six can be read by someone who was not there and still understood; a report that answers four leaves the reader guessing.

What: a plain description of the event, in the order it happened. Who: everyone involved by name where known, or by description where not, including the reporting guard, other guards, employees, visitors, police, and witnesses. Where: the site, the post, and the precise location within the site (Gate 2 barrier, third-floor fire exit, parking bay B-14). When: date and time of the first observation, each significant step, and the time the incident ended or was handed over.

Why is the question most often answered with speculation, and it should be answered only with facts the guard observed or was told, attributed to the source. How: the actions the guard took, in sequence, and the outcome of each. This last section is where the guard's professionalism is judged, so it should be specific: 'called supervisor at 22:14; supervisor arrived 22:31; police called at 22:35 by supervisor' rather than 'informed everyone'.

  • What: plain description in chronological order
  • Who: names or descriptions of all persons involved and witnesses
  • Where: site, post, exact location
  • When: exact times for first observation, each action, and close
  • Why: only facts observed or attributed; How: each action and its outcome

Mandatory Fields

Whether the report is on paper or in an app, the fields below should exist and be filled. A client-specific format may add fields (asset tag numbers, CCTV camera IDs, insurance reference) but should never remove these. The supervisor sign-off is not optional: it is the point at which the agency takes ownership of the report and decides what escalation is needed.

  • Report number and date of filing
  • Site name, client name, post name
  • Date and time of incident (start and end)
  • Reporting guard name, employee ID, shift
  • Incident type (from a fixed list) and severity as assessed by the supervisor
  • Persons involved: names, roles, descriptions, vehicle numbers where relevant
  • Description of incident in chronological order
  • Actions taken by the guard, with times
  • Witnesses with contact details
  • Evidence attached: photographs, CCTV clip reference, documents, GPS location
  • Escalation: who was informed (supervisor, client contact, police, ambulance) and when
  • Injuries or damage, and any first aid given
  • Supervisor review, comments and sign-off with time
  • Client acknowledgement where required by the contract

Writing Rules: Facts, Sequence, Exact Times, No Blame

The report is a record that may be read by the client's management, an insurer, the police or a court. Every sentence should be something the guard saw, heard or did, or something another named person told the guard. 'The visitor appeared drunk' is an opinion; 'the visitor was unsteady on his feet and his speech was slurred' is an observation. 'The contractor was careless' is blame; 'the contractor's vehicle reversed into the barrier at approximately 15:42' is a fact.

Keep to chronological order and use the 24-hour clock with exact times. Where a time is approximate, say so. Use full names and IDs the first time a person is mentioned and a consistent short form after. Avoid abbreviations that the client may not know. Write in the first person ('I observed', 'I called') so that responsibility for each statement is clear.

Do not leave blank fields. If a field does not apply, write 'nil' or 'not applicable'. Do not alter a report after it has been signed; if a correction is needed, add a dated addendum. On paper, strike through and initial rather than overwrite. In an app, the audit trail records the change automatically.

  • Observations, not opinions; actions, not judgements
  • Chronological order with exact 24-hour times
  • Full names and IDs on first mention
  • First person for the guard's own actions
  • No blank fields; corrections by dated addendum, never by overwriting

Sample Incident Report

The sample below uses fictional names and a fictional site. It is a complete report for an attempted unauthorised entry at a warehouse, written to the rules above.

Incident Report No. WH2-2026-014. Site: Sector 44 Warehouse (Client: [Client name]). Post: Main Gate. Date of incident: 24 September 2026. Time: 22:05 to 22:48. Reporting guard: Ramesh Kumar, ID SG-0217, night shift 20:00–08:00. Incident type: attempted unauthorised entry. Severity (supervisor): medium.

Description: At approximately 22:05 I observed a white two-wheeler without a number plate stop about 20 metres from the main gate. The rider, a male of about 25 to 30 years wearing a dark jacket, walked to the boundary wall on the east side and attempted to climb it using the electricity meter box as a step. I shouted a challenge from the gate. The person dropped back to the ground and moved towards the two-wheeler. I called the site supervisor, Mr Suresh Yadav (ID SG-0088), at 22:07. The person left on the two-wheeler towards the service road at about 22:09. I did not leave the gate post. Mr Yadav arrived at 22:24, inspected the east wall and meter box with me, and found no damage and no entry. Mr Yadav informed the client's night duty manager, Mr Anil Mehta, by phone at 22:31. Mr Yadav asked the client's CCTV operator to preserve footage from camera C-06 (east wall) for 21:55 to 22:15. No police complaint was lodged on the client's instruction. Incident closed at 22:48.

Actions taken: verbal challenge (22:05); supervisor informed (22:07); post maintained; joint inspection of east wall (22:24 to 22:30); client informed (22:31); CCTV preservation requested (22:33). Witnesses: none other than the reporting guard. Evidence: two photographs of the east wall and meter box taken at 22:26 (attached); CCTV camera C-06 reference. Injuries or damage: nil. Supervisor review: 'Report accurate. Recommend anti-climb guard on meter box; patrol frequency on east wall increased to hourly for the week.' Signed Suresh Yadav, 23:10. Client acknowledgement: Anil Mehta, 25 September 2026, 09:15.

Common Incident Types and What to Capture

Different incidents need different details, and a guard under pressure benefits from knowing in advance what to note. The list below is the minimum extra detail per type, beyond the mandatory fields. Print it on the back of the paper form or build it into the app's incident type selection so the right prompts appear.

  • Theft or attempted theft: what was targeted, whether anything was taken, how access was gained or attempted, description of persons, direction of departure, CCTV camera references, whether police were informed and the complaint number
  • Unauthorised entry: point of entry, how detected, whether the person was identified, what they were doing, whether they were escorted out or detained until police arrived, any damage to fencing or locks
  • Fire alarm: which zone or panel, time of alarm, whether smoke or fire was seen, evacuation actions, fire brigade called and arrival time, who reset the panel, whether it was confirmed as false
  • Medical emergency: person affected, symptoms observed, first aid given and by whom, ambulance or doctor called and arrival time, hospital taken to, family or employer informed
  • Vehicle damage: vehicle number, driver name and contact, what was struck, photographs of damage from several angles, whether the driver accepted responsibility, client asset owner informed
  • Altercation: persons involved, what was said or done as observed, whether anyone was injured, how it was de-escalated, whether police were called

Digital Incident Reporting From the App

Paper incident reports have three weaknesses: they are written after the fact, they cannot carry photographs or location, and they reach the client only when someone scans and emails them. App-based reporting fixes all three. The guard opens the incident type on the phone, the form shows the prompts for that type, the phone attaches photographs with their timestamp and GPS position, and the report reaches the supervisor and, where configured, the client contact within minutes.

The GPS stamp and photo timestamp are not decoration. They establish that the guard was at the post when the incident was recorded, which answers the first question every client asks. Attend Mitra's security guard tracking software includes incident reporting from the guard app with photographs, an SOS alert for emergencies that notifies the supervisor immediately, and duty reports per shift, all linked to the guard's attendance record so the report, the presence and the post assignment are one record. The SOS alert glossary entry explains how emergency alerts differ from incident reports.

Client contracts increasingly specify reporting SLAs: for example, verbal notification within 15 minutes and a written incident report within 4 hours for medium incidents, and immediate notification for high. Digital reporting makes these achievable and, more importantly, provable, because the submission time is recorded. Where the client requires a signed paper copy, export the app report as a PDF and countersign it.

  • Incident type selection drives the prompts the guard sees
  • Photographs carry timestamp and GPS position automatically
  • Supervisor and client contact notified on submission
  • Report linked to the guard's attendance and post assignment
  • Submission time proves compliance with reporting SLAs

Frequently Asked Questions

What should a security guard incident report include?
Report number, site, post, date and time of incident, reporting guard and shift, incident type, persons involved, a chronological factual description, actions taken with times, witnesses, evidence such as photographs and CCTV references, escalation details, injuries or damage, and supervisor sign-off. Client acknowledgement is added where the contract requires it.
How soon should an incident report be written?
During or immediately after the shift in which the incident occurred, while times and sequence are fresh. If the incident is ongoing, the supervisor takes a verbal account and the guard completes the written report before going off duty. Client contracts often set a written report deadline of a few hours for medium and high severity incidents.
How do you write a security incident report without opinion?
Record only what you saw, heard or did, and attribute anything told to you to the person who said it. Replace judgements with observations: not 'appeared drunk' but 'unsteady and slurred speech'. Use exact 24-hour times, chronological order, full names on first mention, and first person for your own actions.
What is the difference between an incident report and an occurrence book entry?
The occurrence book is a running log of everything that happens on a shift, routine or not, in one or two lines each. An incident report is a separate structured document for any event that needs investigation, escalation or client reporting, with full description, actions, evidence and sign-off. Every incident report should also have a one-line occurrence book entry.
Can a security incident report be filed from a mobile app?
Yes, and it is increasingly the standard. App-based reporting attaches photographs with timestamp and GPS position, notifies the supervisor and client on submission, links the report to the guard's attendance and post, and records the submission time for SLA purposes. A PDF export can be printed and countersigned where a paper copy is required.

Related guides

Ready to put this into practice?

Start your free trial or book a live demo with our team.