Post Orders Are a Document Problem That Becomes an Operations Problem
Most security failures trace back to a decision point where an officer did not know what to do, did not know who to call, or defaulted to the wrong action because no one had written down the right one.
Post orders are supposed to prevent that. In practice, they often make it worse.
The typical post order binder at a commercial building or corporate campus is a 60-page document last updated three years ago. It lists emergency contacts for people who no longer work there, references access control hardware that was replaced, and contains procedures so generic they could apply to any building in any city. Officers treat it as furniture. Supervisors rarely read it. When something goes wrong, everyone discovers simultaneously that the document was not fit for purpose.
If you manage security at a facility—whether you run an in-house program or oversee a contract provider—your post orders deserve a hard look.
What a Functional Post Order Actually Does
A post order has one job: give an officer at that specific post the information needed to make a correct decision without calling a supervisor.
That means it must be:
- Site-specific. Not a template with your building’s name dropped in. The document should describe your loading dock, your server room, your VIP parking procedure, your overnight cleaning crew schedule.
- Current. Emergency contacts verified within the last 90 days. Access control procedures matching the system actually in use. Tenant or department names reflecting who occupies the space today.
- Actionable. Every procedure should end with a clear outcome: who was notified, what was logged, what was done. “Use best judgment” is not a procedure.
- Proportional. A lobby post at a Class A office building needs different depth than a fixed post at an industrial gate. Match the document to the complexity of the assignment.
How to Audit What You Have
Start with a field read. Sit down with an officer who has worked the post for less than 90 days—someone who still relies on the document rather than institutional memory. Ask them to walk you through three scenarios using only the post orders: a medical emergency, an unauthorized access attempt, and a fire alarm activation.
Watch where they hesitate. Watch where they skip sections. Watch where they have to improvise.
That exercise will surface problems faster than any desk review.
Common failures to look for
Dead contacts. Call every number in the emergency contact list. If more than two are wrong, the whole list is suspect.
Procedure gaps. Many post orders cover fire and medical but say nothing about active aggressor response, utility failures, or severe weather. If your building has a generator, your post orders should explain what the officer’s role is when it kicks on.
Undefined authority. Officers need to know exactly what decisions they can make independently. Can they deny access to a contractor who shows up without an escort? Can they call 911 without supervisor approval? Ambiguity here creates hesitation at the worst possible moment.
Compliance requirements buried or missing. Healthcare facilities, government sites, and data centers often have regulatory or contractual obligations that affect how officers operate—visitor logging requirements, escort mandates, specific incident documentation standards. If those requirements are not in the post orders, they will not be followed consistently.
Rebuilding Post Orders That Work
You do not need to start from scratch. You need a structured revision process.
Step 1: Assign ownership. One person is responsible for each post order document. That is usually the account manager or site supervisor on the contract side, or the facility security manager on the in-house side. No owner means no accountability for accuracy.
Step 2: Set a review cycle. Quarterly is appropriate for high-activity posts. Semi-annual works for stable, low-complexity sites. Every review should include a sign-off from the client or facility representative confirming contacts and procedures are current.
Step 3: Write for the officer, not the auditor. Post orders often get written to satisfy a contract requirement or pass an inspection. The result is dense, passive, and hard to use under stress. Write in plain language. Use numbered steps for procedures. Put the most critical information—emergency contacts, escalation paths—at the front.
Step 4: Test before you publish. Run the field read described above with a new officer before finalizing any revision. If they cannot execute the procedures without help, the document is not done.
Step 5: Integrate with training. Post orders should be part of site-specific orientation for every new officer assigned to the post. Reading the document once during onboarding is not sufficient. Supervisors should reference post orders during shift briefings and after-action reviews.
The Operational Payoff
Well-written post orders reduce supervisor burden, improve incident documentation quality, and give you a defensible record of what your program requires. When something goes wrong—and eventually something will—the question of whether your officers had clear guidance is one you want to be able to answer.
More practically: officers who know exactly what is expected of them perform better and stay longer. Ambiguity is a retention problem as much as it is an operations problem.
Post orders are not glamorous. They are also not optional if you want a security program that holds up under pressure.
Tags: operations, commercial