Placing security guards at the entrance of a site does not, by itself, create security.
A uniform provides visibility. A guard may observe movements, welcome visitors, control access, or respond to incidents. However, unless that guard has received a clearly defined mission, supported by recognised rules and legitimate authority, his ability to protect the site remains extremely limited.
Security does not begin with manpower. It begins with authority.
A guard cannot invent the rules
A security guard cannot personally decide who may enter, which areas are restricted, what identification is required or which behaviour is acceptable.
These decisions belong to the authority responsible for the site: the director of a company, the head of a school, the general manager of a hotel, an ambassador or another formally designated authority.
That authority must first define the internal security rules.
Only then can those rules be transformed into operational instructions for the security team.
Without this framework, the guard is placed in an impossible position. He is expected to enforce restrictions that have never been formally established, communicated or accepted.
When challenged, he has no recognised rule to rely on.
He is left to improvise.
At SDS, improvisation is never considered a security policy.
The guard exercises delegated authority
A guard should never attempt to impose his own authority.
He exercises authority delegated to him by the organisation responsible for the site.
When he requests identification, refuses access, checks a vehicle, or asks someone to leave a restricted area, he must not be acting on personal preference. He must be applying a rule already established by the site authority.

He must be able to say, in substance:
“This is not my personal decision. This is the rule applicable to this site, and I have been instructed to enforce it.”
This distinction gives legitimacy to his actions.
It also protects the organisation by ensuring that security decisions do not depend on an individual guard’s personality, judgment, or courage.
A security system cannot rely on the hope that one guard will be more confident, more experienced or more willing than another to confront a difficult person.
The rule must exist before the guard can apply it.
Rules must be known before they can be enforced
Employees must clearly understand:
- which rules apply;
- Why do those rules exist;
- what their responsibilities are;
- who has the authority to enforce them;
- and what the consequences of non-compliance may be.
Where appropriate, employees should formally acknowledge that they have received and understood these rules.
Their signature is not merely an administrative formality.
It confirms that the rules exist, that they have been communicated and that they form part of the organisation’s recognised operating framework.
The same principle applies to visitors, suppliers, contractors and service providers.
Anyone entering a site must comply with the authority governing that site.
The guard becomes the operational representative of that authority.
But he can only fulfil this role when the rules are clearly defined, formally recognised and consistently supported.

Management must respect the rules it creates
Neither a guard nor a security company can enforce rules that management itself treats as optional.
A security provider can advise, report and recommend. It cannot impose upon the client rules that the client’s own authority refuses to adopt.
If employees are permitted to enter without badges, if senior managers routinely bypass access controls or if verbal exceptions continually override written procedures, the guard’s authority rapidly disappears.
The problem is no longer the guard’s performance.
The organisation has undermined its own security system.
It may even raise a fundamental question:
Why employ guards if the organisation does not want the rules they are expected to enforce?
In the absence of recognised rules, individuals begin to create their own arrangements for their own convenience.
Every exception weakens the next control.
Every manager who publicly contradicts a guard teaches employees, visitors and contractors that security procedures can be negotiated.
In the event of a deliberate intrusion, these informal exceptions may provide precisely the opportunity that an intruder requires.
Eventually, the guard stops enforcing the rule.
Not necessarily through negligence, but because the organisation has repeatedly demonstrated that it does not genuinely support it.
Responsibility requires authority.
Authority requires rules.
Rules require consistent management support.
The SOP transforms rules into a mission
Once the authority responsible for the site has defined and accepted the rules, those rules can be translated into precise operational instructions for the security team.
This is the purpose of the Standard Operating Procedure.
The SOP tells the guard:
- what must be protected;
- who is authorised;
- what must be controlled;
- what must be refused;
- what exceptions may apply;
- who may authorise those exceptions;
- and how incidents must be reported or escalated.
Without that translation, the rule remains theoretical.
The guard cannot be properly briefed, trained, or held accountable for situations that the organisation has never formally addressed.
The rule defines the authority.
The SOP defines the mission.
The SDS experience
SDS encountered this situation during a long-term security contract lasting almost ten years.
Throughout that period, security personnel were expected to control access, enforce restrictions and respond to incidents. Yet no formally approved security SOP had been adopted by the client’s designated authority.
SDS drafted procedures and discussed operational instructions with the relevant representatives.
We repeatedly requested that the applicable rules be formally reviewed, approved and assumed by those responsible for the site. SDS also proposed awareness sessions and training for everyone concerned, as we routinely include this support in our service, regardless of the number of guards deployed.
However, no authorised representative was prepared to formally endorse the rules that the guards were nevertheless expected to enforce in the name of “security”.
The security team was therefore required to maintain operational continuity through experience, informal instructions and constant adaptation. In practice, SDS was carrying a security framework that the organisation itself had never formally accepted.
Our repeated insistence on clarifying responsibilities and obtaining formal approval gradually became a source of tension. What should have been regarded as a legitimate security requirement was increasingly perceived as an inconvenience. Ultimately, that insistence contributed to the deterioration and breakdown of the relationship.
The end of the relationship is not presented here as a commercial grievance or as an act of retaliation. SDS refers to this experience solely because the underlying security issue was never resolved during our involvement.
Our concern has always been, and remains, the safety of those who work in, visit or use a sensitive site where security responsibilities have not been formally established.But it cannot assume the authority of the organisation it protects.
Security cannot be subcontracted before authority has been exercised.
From presence to protection
Before asking how many guards are required, an organisation should first consider:
- What are the identified risks?
- What are the credible threats?
- How should the site be divided into operational and security zones?
- Who may enter each area, and under what conditions?
- Who must be alerted when an incident occurs?
- What actions must follow that alert?
- Which situations could place personnel, visitors or operations at risk?
Only after answering these questions can the organisation formalise its security rules, establish an SOP, define the guards’ mission and determine the necessary investment in passive and technical security.

