Post Orders That Hold Up After an Incident

What to write down. Confirm client and state rules.

guardfirmready Editorial Team
9 min read

Starting a security company?

The Security Company License Kit maps the 7-step path, names your state's licensing authority, and includes the qualifying manager log and contract templates. $249 one time, 30-day money-back guarantee.

See the License Kit
In This Article

Use current guidance from the Occupational Safety and Health Administration and the U.S. Small Business Administration as starting points. Post orders should also be checked against the client contract, site rules, insurance requirements, collective bargaining terms where applicable, and the laws and regulations in the state where the work occurs.

Post orders are written instructions for the people assigned to a location, shift, patrol route, desk, vehicle, or other post. They explain what the employee is expected to do, what must be reported, whom to contact, and how to preserve information after an incident.

Good post orders are not written to make an organization look prepared. They are written so another trained person can understand the assignment and follow it under pressure. After an incident, they may also be reviewed by a client, investigator, regulator, insurer, attorney, or judge. Clear, dated, practical instructions are easier to defend than informal habits or unwritten expectations.

What should post orders accomplish?

Post orders should define the assignment in operational terms. A reader should be able to determine the location covered, the hours of coverage, the duties required, the limits of the role, and the actions expected when conditions change.

Start with the purpose of the post. For example, the assignment may involve access control, visitor processing, property observation, safety monitoring, reception, alarm response, or documentation. Avoid vague wording such as “maintain security” unless the order explains what that means at the site.

Each order should identify:

  • The post name and exact location.
  • The client, property, department, or work area served.
  • The shift hours and relief procedure.
  • Routine duties and required intervals.
  • Emergency contacts and escalation steps.
  • Required logs, forms, systems, or devices.
  • Restrictions on access, force, searches, movement, or information sharing.
  • Procedures for equipment failure, staffing gaps, and unusual conditions.

Who is the intended reader?

Write for the employee who must perform the assignment, the supervisor who must review it, and the person who may need to evaluate it later. These readers have different needs.

The employee needs direct instructions. The supervisor needs measurable standards and escalation points. A later reviewer needs enough context to understand what the employee was told before the incident occurred.

Use ordinary language, defined terms, and short sections. Explain local names, abbreviations, radio codes, access points, and alarm identifiers. If a term could be misunderstood, define it in the post orders instead of assuming that everyone has the same background.

Do not write instructions that depend on one employee’s personal knowledge. If a procedure is important, put it in the document, a controlled attachment, or an identified site manual. Make sure employees know where the current version is kept.

What location details belong in the document?

Location details help establish what the employee could reasonably observe and control. Include the address, building or site name, post position, covered areas, entrances, exits, restricted areas, emergency equipment locations, assembly areas, and nearby hazards that affect the assignment.

Use a site map when words alone are not enough. Label doors, gates, cameras, intercoms, radios, panic devices, first-aid equipment, fire equipment, elevators, stairwells, loading areas, and locations where visitors or vehicles are processed. Identify whether the map is current and who is responsible for updating it.

Do not include sensitive information merely because it exists. Access codes, personal information, security weaknesses, and confidential client details should be handled through an approved process. If employees need such information, explain how they receive it and how changes are communicated.

What routine duties should be written down?

Routine duties should be specific enough to be observed and documented. State what must be done, when it must be done, and what record is required.

Instead of writing “check the property regularly,” identify the route, frequency, areas to inspect, conditions to look for, and required log entry. If the timing is flexible because of operational demands, describe the acceptable range and require the employee to document a missed or delayed check.

Routine instructions may address:

  • Opening and closing procedures.
  • Visitor, contractor, and delivery processing.
  • Badge, key, and equipment control.
  • Vehicle or pedestrian observations.
  • Inspection routes and checkpoints.
  • Lost-and-found property.
  • Housekeeping or hazard observations that must be reported.
  • Shift relief, breaks, and post abandonment restrictions.

Separate required duties from helpful practices. Employees should be able to tell which actions are mandatory and which actions are recommended when circumstances allow.

What should the orders say about an incident?

Define an incident broadly enough to capture events that may later become important. An incident may include an injury, illness, threat, violence, fire, alarm, unauthorized access, missing property, vehicle collision, damaged equipment, suspicious activity, environmental condition, or any event that interrupts normal operations.

Tell the employee what to do first. The sequence commonly includes protecting life, contacting emergency services when needed, notifying the designated supervisor or client contact, controlling access when safe, preserving the scene, and making a timely report. The exact sequence must match the role, site, training, and applicable rules.

Use conditional language where conditions matter. For example, “If immediate medical assistance is needed, call the appropriate emergency service and provide the site address” is more useful than “handle medical emergencies.” Do not instruct employees to provide medical, legal, technical, or emergency services beyond their training and authority.

What information should an incident report capture?

A post order should identify the required report fields. The employee should not have to guess what information matters after a stressful event.

Require the report to capture:

  • Date, time, and location.
  • How the event was discovered and by whom.
  • People involved, witnesses, and contact information when authorized and available.
  • Objective observations, including conditions, actions, and words heard.
  • Notifications made, including the time and recipient.
  • Actions taken and the reason for each action.
  • Injuries, medical assistance, property damage, or service interruption.
  • Evidence or property secured, moved, released, or left in place.
  • Camera, access-control, radio, telephone, or other records that may exist.
  • Follow-up still needed at the end of the shift.

Require a report even when the event appears minor if the client, employer, insurer, or applicable rule requires one. A short report made promptly is usually more useful than a detailed report reconstructed days later.

How should employees separate facts from conclusions?

Post orders should direct employees to record what they personally observed, heard, did, and were told. They should identify the source of information when it comes from another person or system.

“I observed a broken pane on the east door at 9:14 p.m.” is stronger than “Someone broke in.” The first statement records an observation. The second states a conclusion that may not be established.

Encourage employees to use exact words for important statements, placing them in quotation marks when remembered accurately. If the wording is uncertain, say that it is approximate. Do not encourage employees to fill gaps with assumptions, diagnose injuries, assign blame, or describe a person with unnecessary personal details.

Reports should be complete without being argumentative. Avoid sarcasm, speculation, insults, exaggerated descriptions, and copied language that does not match the employee’s own observations.

What documentation controls should be included?

Post orders should explain how reports and logs are created, corrected, submitted, stored, and accessed. Identify the approved form or electronic system. State the deadline or timing requirement using the client’s and employer’s approved standard.

Explain how to correct an error without deleting the original entry. For paper records, the process may involve a single line through the error, the corrected information, initials, and the date. For electronic systems, employees should use the approved correction or amendment function. Do not create a process that conflicts with the employer’s records policy or the system’s audit controls.

State who receives the report and who may receive copies. Address confidentiality, personal information, photographs, video, recordings, and requests from outside parties. Employees should know that they must not post incident information on social media or send it through personal accounts unless an approved policy expressly permits it.

What limits and prohibitions should be clear?

Post orders should define what employees must not do. This protects the public, the client, the employee, and the integrity of the response.

Depending on the assignment, restrictions may cover:

  • Entering areas that are unsafe or outside the employee’s authority.
  • Touching, moving, cleaning, or repairing potential evidence.
  • Using force, restraints, searches, or detention procedures.
  • Making promises, admissions, public statements, or media comments.
  • Sharing personal information or confidential client information.
  • Operating vehicles, equipment, or systems without authorization.
  • Leaving the post without relief or supervisor approval.

Do not rely on broad statements such as “use reasonable judgment” without explaining the employee’s authority, training, and escalation path. If a rule varies by state, client, license, contract, or role, mark the section for local confirmation instead of treating one version as universal.

How should the document address state and client rules?

Begin with a requirements review before issuing or revising the post orders. Confirm the client’s contract, site procedures, emergency plan, insurance conditions, employee handbook, training requirements, and recordkeeping expectations. Then confirm the rules that apply in the state and local jurisdiction where the work occurs.

State requirements may affect licensing, training, reporting, privacy, recording, workplace safety, firearms, transportation, medical response, or the use of force. Requirements can also vary by industry and by the employee’s assigned duties.

Keep a written review record showing who confirmed the requirements, the date of review, the sources checked, and unresolved questions. Use qualified legal or compliance assistance when the assignment involves significant risk or a specialized regulatory area. The post order should not claim that a procedure is legally required unless that statement has been verified.

How should changes and approvals be managed?

Every post order should have document control. Include a title, site, version number, effective date, owner, approval authority, and review date. Identify superseded versions and remove obsolete copies from active use.

Require review after an incident, near miss, change in client operations, construction, equipment change, staffing change, emergency-plan change, or legal or regulatory update. A review does not always require a rewrite, but the decision should be documented.

Train affected employees on material changes. Obtain a dated acknowledgment that the employee received and understood the current instructions. An acknowledgment is evidence of distribution and training, not proof that every instruction was lawful or adequate. Management remains responsible for maintaining accurate orders and appropriate training.

What should a supervisor verify at the start of a shift?

A shift-start checklist can expose gaps before an incident occurs. The supervisor or designated employee should confirm that the current post orders are available, the employee is assigned to the correct post, required equipment works, emergency contacts are current, and known site conditions have been communicated.

The checklist should also address relief, open incidents, restricted areas, maintenance concerns, weather or operational changes, and any temporary instruction. Temporary instructions should be recorded, approved, and given an end date or review point. Informal verbal changes are easy to forget and difficult to evaluate later.

What should happen after an incident review?

Conduct a fact-based review after the immediate response and required reporting are complete. Compare the incident with the post orders, training, equipment, staffing, communications, and site conditions. Ask whether the instructions were available, understandable, realistic, and consistent with the employee’s authority.

Do not revise post orders merely to assign blame. Identify whether the document failed to address a foreseeable condition, used unclear language, omitted a contact, required unavailable equipment, or conflicted with a client or state requirement.

Record corrective actions, responsible owners, target dates, and completion status. If the incident may involve a claim, investigation, or legal hold, preserve relevant records and follow the direction of the responsible organization and qualified advisors.

What is a practical post-order template?

A useful template can contain the following sections:

  1. Assignment: site, post, shift, purpose, and coverage area.
  2. Authority: permitted actions, limits, and required escalation.
  3. Routine duties: tasks, timing, routes, and logs.
  4. Contacts: emergency, supervisor, client, maintenance, and backup contacts.
  5. Incident response: immediate priorities, notifications, scene protection, and reporting.
  6. Documentation: required fields, submission method, corrections, and confidentiality.
  7. Equipment: issued items, inspection steps, failures, and replacement process.
  8. Restrictions: prohibited conduct and activities requiring approval.
  9. Handover: relief, open issues, outstanding reports, and key changes.
  10. Approval: version, effective date, review date, approvers, and employee acknowledgment.

Before implementation, walk through the document at the actual site with the people who will use it. Test contact numbers, routes, equipment, forms, and escalation steps. Confirm locally that the final instructions match the client’s expectations and all applicable state and local requirements. A post order that works in practice is more likely to produce reliable records when an incident puts every instruction to the test.

Get the whole path in one place

The Security Company License Kit: the 7-step launch path, your state's licensing authority named and linked, the qualifying manager experience log, the insurance briefing and broker letter, and the first-contract templates. $249 one time, 30-day money-back guarantee.

See the Security Company License Kit

Disclaimer: GuardFirmReady is an independent information publisher. We are not a law firm, licensing consultant, insurance broker, or government agency, and nothing here is legal advice. Security licensing requirements change and vary by state and city; always confirm current requirements with your state licensing authority before acting. We make no promises about license approval, timelines, income, or business results.

Read our full disclaimer

guardfirmready Editorial Team

Researched and edited by the GuardFirmReady Editorial Team. We are an independent publisher, not a law firm or government agency, and we cite the authority behind every requirement.

How we research and review our content

Related Guides

GuardFirmReady
See the License Kit