Security patrols
Security monthly report: what goes in it, and how to make the numbers mean something
A security monthly report is a recurring summary, usually written by the security company for its client, of a property's security over one calendar month: post coverage, patrols, incidents, alarms, trends and open actions.
It turns a month of daily activity reports, incident reports and patrol rounds into something a property manager or facility manager can read in ten minutes. Done well, it shows whether the posts were covered, what happened on the property, what is getting better or worse, and what needs fixing. Done badly, it is a page of totals nobody can check. This guide covers what to include, how to build the figures, which statutory records sit beside it, and how to review it with the client.
01
What a security monthly report is, and what it is not
A security monthly report is a summary of the security operation at a property over a calendar month. In a contract security arrangement, the security company's account manager or site supervisor writes it for the client: the property manager of an office tower, the facility manager of a corporate campus, the director of a hospital's security department, the board of an HOA. In an in-house department, the security manager writes it for the leadership team. Either way, its job is the same: to turn a month of shift-level records into a short account of coverage, activity, incidents, trends and open actions.
No federal or state law requires a private property to receive a monthly security report. It is a creature of the contract. The security services agreement usually says what reports the provider owes, how often, to whom and by what date, and the monthly report is typically where the security KPIs are reported against their targets. If the contract is silent, agree on the contents in writing before the first month ends, or each side will expect a different document.
Federal contracting shows why the report matters. The Federal Acquisition Regulation, section 46.401 (FAC 2026-01) says quality assurance surveillance plans should be prepared alongside the statement of work and should specify "all work requiring surveillance" and "the method of surveillance." A private client does not have to follow the FAR, but the idea carries over: the monthly report is one of the ways the client watches the work, so it should be built from records the client could check.
02
What goes in a security monthly report
The best monthly reports are short at the front and detailed at the back. The client should be able to read the first page and know whether the month went well; the appendix is there for anyone who wants to check. A typical report covers:
- Executive summary: three to six sentences on the month. What went well, what went wrong, what changed on the property and what the provider wants the client to decide.
- Coverage and staffing: scheduled hours against hours worked, posts left uncovered and for how long, overtime, officers new to the site, turnover and any post orders changed during the month.
- Patrols and checkpoints: rounds scheduled against rounds completed, checkpoints missed and why, and any change to the patrol route.
- Incidents: counts by category (for example theft, trespass, vandalism, disturbance, medical, fire alarm, suspicious activity, use of force), each with the date, location and a one-line outcome, and a reference to the full incident report.
- Alarms, monitoring and access control: intrusion and fire alarm activations and how many were false, any outage in the camera or alarm monitoring systems, doors found unsecured or propped, badges reported lost, visitor and contractor volumes where the lobby post tracks them.
- Building conditions found on patrol: lights out in parking levels and stairwells, doors not latching, damaged fencing, water leaks, blocked exits, and whether each was reported and fixed.
- Officer safety: injuries to officers, workplace violence incidents involving them, and follow-up actions, without names.
- Training and licensing: officers whose state registration, firearms permit or annual training falls due in the next 60 to 90 days, and any officer working the site without current training.
- Client requests and service changes: special coverage for events, lockouts, escorts, changes the client asked for, and updates on requests still open.
- Trends, recommendations and open actions: what the numbers suggest, what the provider recommends, who owns each action and when it is due.
Not every property needs every heading. A single-post lobby contract may fit on two pages; a large hospital or mixed-use development may need a page per building. What matters is that the same headings appear in the same order every month.
Leave out what the client cannot act on or should not see. Officers' home details, full names of people involved in incidents and medical information have no place in a report that will be forwarded around a property management office. Refer to the incident report by number instead.
03
Building the figures from DARs and incident reports
A monthly report is only as good as the shift records underneath it. The figures should come from the daily activity reports, incident reports, the pass-down log, alarm system exports and the schedule, not from memory in the last week of the month. Four habits make the difference.
- Fix the categories. Agree on a short list of incident categories with the client and use it on every incident report. If one officer writes "disturbance" and another writes "verbal altercation" for the same thing, the monthly count is meaningless.
- Fix the counting rules. Decide whether a trespasser removed three times in one night is one incident or three, whether a false alarm the officer cleared counts as an alarm or an incident, and whether a round started late but completed counts as completed. Write the rules into the report's appendix.
- Compare like with like. Show each figure against the previous month and, once there is a year of data, the same month last year. Parking-lot incidents in December and June are not comparable to each other, but December this year and December last year are.
- Close the loop on every open item. An open action from last month's report either appears again with its status or is marked closed with the date and how. Items that silently disappear are the ones clients remember.
Suspicious activity needs particular care, because a count of "suspicious persons" can hide bias as easily as it shows risk. The Department of Homeland Security's page on what suspicious activity is says that "factors such as race, ethnicity, sex, national origin, religion, or disability are not suspicious", and asks people to report behavior and situations, not appearance. Write that into the categories: a report of someone trying door handles on a parking level is suspicious activity; a description of who they looked like is not a category.
04
The statutory records that sit beside the monthly report
A monthly report summarizes. It does not replace the records a statute requires, and it should say which of them exist and who keeps them. Four come up often on security contracts.
California's violent incident log. Most California employers must keep a workplace violence prevention plan and a violent incident log under California Labor Code section 6401.9. At a multiemployer worksite, the employer or employers whose employees experienced the incident record it, so a contract security company records incidents its officers experience. The employer must omit personal identifying information such as names, addresses and telephone numbers. Violent incident logs, hazard records and incident investigation records must be kept for at least five years, training records for at least one year, and the plan must be reviewed at least annually, when a deficiency becomes apparent and after a workplace violence incident. A monthly report can count and summarize these incidents; it is not the log.
The OSHA 300 Log. An officer's recordable work injury goes on the employer's OSHA 300 Log and 301 Incident Report. Under 29 CFR 1904.29, each recordable case must be entered within seven calendar days of the employer receiving the information, and privacy concern cases, such as sexual assault injuries or mental illness, are recorded without the employee's name. The security company, as the employer, keeps the log; the monthly report to the client should give a count and the follow-up, not the log itself. In a state with an OSHA-approved state plan, check the state's own recordkeeping rule.
The Clery daily crime log. On a college campus, 34 CFR 668.46(f) requires the institution to keep a daily crime log recording "the nature, date, time, and general location of each crime" reported to campus police or security, with an entry made within two business days and the most recent 60 days open to public inspection. The institution owns that log. A contractor's monthly report should reconcile with it, not compete with it.
Training and licensing records. States that license security officers set their own training rules. In California, the Bureau of Security and Investigative Services' security guard fact sheet sets 32 hours of skills training, 16 of them within 30 days of employment and all of them within the first six months of registration, and eight hours of continuing training every year, and requires employers to keep training records for the duration of the officer's employment. The New York Department of State's security guard training requirements set an 8-hour pre-assignment course, 16 hours of on-the-job training within 90 days of employment and 8 hours of annual in-service training each calendar year. The monthly report is a good place to show which officers are coming due; the records themselves stay in the training file.
Workplace violence in general has no single federal standard. OSHA's workplace violence page states that "there are currently no specific OSHA standards for workplace violence." Outside California, the monthly report's workplace violence section is usually the only place the client sees these incidents together, which is one more reason to keep the categories consistent.

05
Reviewing the monthly report with the client
The report should arrive on an agreed date, usually within the first five to ten business days of the following month, and be discussed at a regular meeting between the client's facility or property manager and the security company's account manager. A monthly report sent and never discussed teaches both sides that it does not matter.
A useful order for the meeting is:
- Open actions from last month: closed, still open, or overdue, and why.
- Coverage: any uncovered post time, and whether it is a scheduling problem or a staffing one.
- Incidents and trends: anything new, anything rising, anything that needs a change to post orders or patrol routes.
- Building conditions: which reported defects are still open, and whose they are. Many sit with the client's building engineer or maintenance vendor rather than the security company.
- Recommendations: what the provider proposes, what it would cost, and what the client decides.
- Changes coming: events, construction, tenant moves, holidays and anything else that will change the next month.
Read the trends, not only the totals. Ten trespass incidents a month is neither good nor bad on its own; ten a month rising from three, all on the same parking level after 10 p.m., is a lighting survey and a change to the patrol route. Equally, a sudden fall in reported incidents after a new officer starts may mean the property is quieter, or it may mean less is being written down.
Turn every recommendation into an action with an owner and a date, and record the client's decision, including a decision not to act. When a recommendation such as more lighting or a card reader on a stairwell door is declined, the report is the record that it was made.
06
Where the record fails, and where SiteClara fits
Of everything in a security monthly report, patrol completion and building conditions are the figures most often built on the weakest evidence. They are usually taken from daily activity reports and supervisors' notes written at the console. "0300 patrol completed, all secure" reads the same whether the officer checked every door or not, a missed round is rarely written down as missed, and a stairwell light reported out on the 4th may still be out on the 30th because the note never reached the building engineer.
SiteClara records the routine part of the shift where it happens. A printed QR poster, with an optional NFC tag behind it, goes at each checkpoint the post orders name: a stairwell door, a loading dock, a roof hatch, a parking level. The officer scans the code or taps the tag on their own phone, with no app to install, sees the checks due at that point and marks each one done, or says what stopped them. The time and the named officer are recorded as it happens, with a photo when one is asked for. A problem found on the round is reported there and goes onto the team's list of jobs until someone closes it.
The supervisor sees what was due, done and missed, and records the reason a check was missed. Each day they review the totals and photos, add a note and approve a report that goes to nominated management or client contacts at 8 a.m. the next morning, showing what was reported, what was completed, what is still open and how the scheduled checks went, for example 11 of 12 completed. By the end of the month, the patrol completion and open-defect figures in the monthly report have a daily source recorded at the time, rather than one reconstructed the week the report is due.
07
Questions people ask
How do you write a security monthly report?
Start from what the contract says the report must contain, then build each figure from records the client could check: daily activity reports, incident reports, the patrol record and alarm system exports. Federal government contracting offers a model: the Federal Acquisition Regulation, section 46.401 says a quality assurance surveillance plan should specify "all work requiring surveillance" and "the method of surveillance," so write the report to show that work and how it was checked. Put a short executive summary first, keep the same headings in the same order every month, and carry each open action forward until it is closed.
Can you provide an example of a security report?
A widely published example in the United States is a college's annual security report under the Clery Act. Under 34 CFR 668.46, an institution must prepare an annual security report reflecting its current policies, with crime statistics for the three most recent calendar years, and a campus with a police or security department must also keep a written daily crime log. A contractor's monthly report is a private document with no set form, but the Clery report shows the same discipline: fixed crime categories, counted the same way every year.
08
Further reading, and a list to take away
For the statutory records that sit beside a monthly report, read California Labor Code section 6401.9 for the workplace violence prevention plan and violent incident log, 29 CFR 1904.29 for the OSHA 300 Log, and 34 CFR 668.46 for campus crime reporting. Your state's security licensing board sets the training the report should track.
Before you accept or send a security monthly report, check that:
- the contract says what the report contains, who receives it and by what date;
- the first page tells the client in a minute whether the month went well;
- coverage shows scheduled hours against hours worked, including uncovered post time;
- patrol completion shows missed rounds and the reason, not only completed ones;
- incidents use agreed categories and counting rules, with a reference to each full report;
- suspicious activity describes behavior, never appearance;
- each figure traces back to a named daily report, log or export;
- building defects found on patrol show who owns them and whether they were fixed;
- last month's open actions are carried forward or closed with a date;
- statutory logs are named and kept by their owner, not replaced by the report;
- the report is discussed at a meeting, and the decisions are recorded.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Federal Acquisition Regulation, section 46.401 acquisition.gov
- 34 CFR 668.46 govinfo.gov
- What suspicious activity is dhs.gov
- California Labor Code section 6401.9 leginfo.legislature.ca.gov
- 29 CFR 1904.29 osha.gov
- Security guard fact sheet bsis.ca.gov
- Security guard training requirements dos.ny.gov
- OSHA's workplace violence page osha.gov



