Security Planning | 2026-09-02 | 20 min read

Decision Guide: Security Service SLA Standards for BC Businesses

A practical BC guide to defining security service SLA scope, response times, patrol evidence, reporting, escalation, privacy, reviews, and remedies.

A security service-level agreement, often shortened to a security service SLA, turns a proposal such as "provide patrols and alarm response" into a set of operating commitments that a client and provider can actually review.

For a property manager, contractor, facility operator, strata council, event organizer, or business owner in British Columbia, a useful SLA should answer five questions:

  1. What work is included - and excluded?
  2. What result or activity will be measured?
  3. Which record is the accepted source of evidence?
  4. Who acts when a target is missed or an incident occurs?
  5. What review, correction, credit, or termination process applies?

The numbers must fit the site. A mobile alarm response target for a rural Fraser Valley property cannot be copied from a stationed-guard target inside a single building. Patrol frequency for a locked storefront should not be borrowed from a construction yard with several gates and equipment areas.

This guide explains how to build a practical security SLA for BC operations without relying on vague promises or invented industry standards.

This article is general procurement and security-planning information, not legal advice. Contract rights and enforceability depend on the final wording, the facts, and applicable law. Have qualified legal and insurance advisers review material agreements and risk-transfer clauses.

Quick Answer

A strong security service SLA defines scope, staffing, response processes, patrol requirements, reporting, escalation, compliance, data handling, performance review, and remedies in measurable terms.

Do not ask only, "What is your response time?" Ask:

  • When does the response clock start?
  • Does the target cover acknowledgement, dispatch, arrival, or on-site action?
  • How is arrival verified?
  • What site, hours, and service tier does the target cover?
  • Which conditions pause or exclude the clock?
  • Who receives an exception notice?
  • What happens after a miss?

There is no single correct response time, patrol frequency, fill rate, or report deadline for every security assignment. Use the actual property, route, operating hours, access process, risk, staffing model, and budget to set achievable targets.

In This Guide

What Is a Security Service SLA?

A security service SLA is the part of a security agreement that describes the expected level of service and how performance will be measured.

It may appear as:

  • a section in the main service agreement
  • a schedule or appendix
  • a statement of work
  • a site-specific service-level schedule
  • a set of key performance indicators attached to post orders

The label matters less than the content. The Government of Canada's procurement guidance says a statement of work should clearly identify requirements, deliverables, schedules, tasks, and responsibilities so suppliers understand what is expected. That same clarity is valuable in a private security contract. See CanadaBuys guidance on reviewing a statement of work.

An SLA does not guarantee that no incident will occur. It also does not replace:

  • a site risk assessment
  • detailed post orders
  • an emergency response plan
  • the client's health and safety responsibilities
  • insurance requirements
  • privacy procedures
  • police, fire, or emergency services
  • legal review of the agreement

Think of the SLA as the measurement layer. The service agreement creates the commercial relationship, the scope states what is being purchased, post orders tell personnel what to do, and the SLA explains how the parties will judge delivery.

The 12 Sections a Useful Security SLA Should Cover

SLA section | What the buyer should define

Parties, sites, and term | Legal names, service addresses, start date, term, renewal, and notice details

Scope of service | Guard posts, patrol areas, access duties, alarm response, exclusions, and service hours

Post orders | Site instructions, routes, restricted areas, emergency procedures, and approval process

Staffing | Required posts, qualifications, relief coverage, call-out procedure, and supervisor responsibility

Performance measures | The small set of KPIs that reflect the work actually purchased

Measurement rules | Start and stop points, denominator, time zone, data source, owner, and permitted exceptions

Reporting | Daily activity, incident, patrol, attendance, and performance-review records

Escalation | Severity levels, notification order, communication channels, and backup contacts

Client responsibilities | Access credentials, hazard information, current contacts, approvals, and safe site access

Data and privacy | GPS, photos, visitor data, video, retention, access, security, and deletion rules

Change and review | Review frequency, scope-change process, seasonal changes, and post-incident updates

Remedies and exit | Correction plan, cure period, credits if negotiated, repeated-failure process, and termination rights

The most common drafting mistake is mixing these items into a few general paragraphs. A better structure separates commercial terms from operational instructions and measurement rules.

Define What the Provider Will Do

List the service by site, post, schedule, and duty. Depending on the assignment, that may include:

  • controlling one approved entrance during specified hours
  • completing a defined exterior patrol route
  • checking selected doors, gates, fencing, parking areas, or equipment zones
  • recording visitors, contractors, or vehicles under the client's approved process
  • responding to alarm notifications under agreed dispatch instructions
  • documenting observations and incidents
  • notifying the client or emergency services under an escalation matrix

Define What the Provider Will Not Do

Boundaries are as important as duties. The agreement should identify tasks outside the security scope, such as maintenance, technical inspections, property management, cash handling, moving equipment, or entering unsafe areas unless separately assessed and authorized.

For a broader provider review, use Zentra's guide to choosing a security company in BC and security guard hiring checklist.

Attach Post Orders and Control Changes

Post orders should describe how the assignment works at ground level. Include the approval process and version date. If a client manager informally changes a patrol route by text message, the contract record and the guard's current instruction can drift apart.

A simple control rule helps: operational changes become active only after an authorized contact confirms them through the agreed channel and the post orders are updated.

How to Define Security KPIs That Can Be Audited

A KPI is useful only if two people reviewing the same records would reach the same result.

Every KPI should have:

  1. a clear purpose
  2. a precise definition
  3. a numerator and denominator where a percentage is used
  4. a start and stop event where time is measured
  5. one accepted evidence source
  6. an owner responsible for review
  7. an exception and dispute process
  8. a review period
  9. a response when the target is missed

Use a small set of decision-useful measures rather than a dashboard full of activity counts.

KPI | Better definition format | Evidence source | Important qualification

Shift coverage | Percentage of scheduled post-hours staffed by an authorized worker | Approved schedule and verified attendance record | Define lateness, relief handoff, and client-approved cancellation

Patrol completion | Completed required patrols divided by scheduled patrols | Checkpoint, GPS, or signed patrol record | Define partial rounds, unsafe areas, and authorized route changes

Response time | Time from a named trigger to a named completion point | Dispatch and arrival records | Separate acknowledgement, dispatch, travel, and on-site action

Incident notification | Time from confirmed incident classification to initial client notice | Dispatch or communication log | Life-safety calls may proceed directly to 911 while client notice follows

Report timeliness | Reports submitted on time divided by reports due | Reporting system timestamp | Define report type, deadline, and what counts as complete

Supervisor review | Required quality reviews completed during the period | Supervisor audit record | Measure substance, not only a check-box visit

Corrective action | Agreed actions closed by their due dates | Corrective-action register | Define who can approve an extension

Illustrative placeholders such as [X minutes], [X patrols per shift], or [X% per month] are safer during planning than presenting one number as an industry rule. Final targets should be tested against actual route time, site access, staffing, weather exposure, travel distance, and reporting workload.

Response-Time Standards: Define the Whole Clock

"Response within 15 minutes" is not a complete service level. It does not say what starts the clock, which response is being timed, or what conditions count as arrival.

For an On-Site Guard

Possible stages include:

  1. incident detected or reported
  2. guard acknowledges the call
  3. guard reaches the assigned zone
  4. guard assesses from a safe position
  5. guard notifies the correct contact
  6. required report is opened or completed

A large warehouse, hospital campus, event venue, or construction project may require separate targets for acknowledgement and arrival at the assigned location.

For Mobile Patrol or Alarm Response

Possible stages include:

  1. alarm or service request received by the agreed contact point
  2. request verified as eligible under the service
  3. patrol unit dispatched
  4. responder arrives at the approved site access point
  5. site check begins, where safe and authorized
  6. keyholder or client update is sent
  7. response report is completed

Travel time across Chilliwack, Abbotsford, Langley, Hope, the Fraser Valley, or Metro Vancouver can vary with distance, traffic, road conditions, weather, unit availability, and access delays. The SLA should not hide these operational realities. It should define a realistic service area or response tier and state how exceptions are recorded.

If the site needs a person immediately available, compare on-site security guards with mobile patrol. For after-hours activations, review Zentra's alarm response service and Fraser Valley mobile-patrol-versus-guard decision guide.

Define Exclusions Without Creating a Loophole

Examples may include:

  • unsafe or prohibited access
  • emergency-service control of the scene
  • client-supplied codes, keys, or directions that are missing or incorrect
  • a client-requested hold or cancellation
  • road closure or extraordinary travel disruption
  • events outside the agreed service area or service window

An exclusion should require documentation. The provider should record what happened, when it occurred, who was notified, and whether a revised estimate or corrective action is needed.

Build the Escalation Ladder Before an Incident

An escalation ladder should be short enough to use during a real shift and detailed enough to remove guessing.

Example level | Situation | First action | Notification path

Level 1 - routine | Minor access question or non-urgent site issue | Follow post orders and record the outcome | Site contact or supervisor under normal reporting process

Level 2 - service exception | Missed checkpoint, late relief, unavailable access, or equipment issue | Protect continuity, notify supervision, and document exception | Provider supervisor and designated client contact

Level 3 - significant incident | Visible property damage, confirmed unauthorized entry, serious disturbance, or major safety concern | Keep a safe position, follow emergency procedures, preserve observations | Emergency services where appropriate, then client and operations contacts

Level 4 - life safety | Fire, medical emergency, violence, or crime in progress | Call 911 and follow approved safety procedures | Emergency services immediately; internal and client notice in parallel when safe

These labels are examples, not a universal security-industry classification. The client and provider should define the levels that fit the site.

For each level, record:

  • who has authority to classify the issue
  • who is contacted first
  • the primary and backup contact methods
  • how long to wait before using the backup contact
  • which situations require 911
  • whether the guard stays, withdraws, preserves the area, or continues other assigned duties
  • when the next update is due
  • which report is required

Review the contact list on a set schedule and whenever a client contact, tenant, project phase, or operating hour changes.

Reporting, Documentation, and Privacy

A professional security SLA should leave the client with more than an invoice and a verbal assurance that patrols happened.

Daily or Shift Reporting

Depending on the service, a daily activity or shift report may record:

  • shift start and end
  • personnel or unit identifier
  • assigned areas checked
  • access activity
  • patrol times
  • doors, gates, fencing, lighting, or equipment observations within scope
  • exceptions and missed tasks
  • client instructions received
  • notifications and handoff notes

Incident Reporting

Define what makes an event reportable. The agreement can set an immediate initial-notification process for urgent matters and a separate deadline for the complete written report.

A useful incident report normally identifies:

  • date, time, and location
  • how the matter was detected
  • factual observations
  • actions taken
  • people or services notified
  • photos or attachments where appropriate
  • reference numbers, if applicable
  • follow-up recommendation or handoff

Avoid language that assumes a cause or legal conclusion. "Rear door showed visible damage" is more reliable than declaring who caused the damage without evidence.

For a deeper reporting standard, see what a property security check report should include.

Performance Reporting

A weekly or monthly review may compare:

  • required and completed shifts
  • required and completed patrols
  • response records by service tier
  • report timeliness
  • service exceptions
  • incident patterns
  • open corrective actions
  • approved changes to post orders

The review should explain exceptions, not bury them in an average. A 100% monthly patrol-completion score can still hide a serious missed round during the property's highest-risk period.

GPS, Photos, Video, and Personal Information

Checkpoint tools, GPS records, visitor logs, incident photos, and video can improve verification, but they can also contain employee, visitor, tenant, or customer information.

British Columbia's Personal Information Protection Act governs many private-sector organizations. The Office of the Information and Privacy Commissioner for BC also provides employee privacy guidance that discusses monitoring technologies, including GPS.

The SLA or related privacy schedule should identify:

  • what information is collected
  • the operational purpose
  • who can view it
  • where it is stored
  • how it is protected
  • how long it is retained
  • when it is deleted
  • how access or correction requests are handled
  • how a privacy or security incident is escalated

Collecting more data is not automatically better. Use evidence that is proportionate to the service and document the privacy responsibility of both client and provider.

BC Compliance Items to Verify Before Signing

An SLA should not treat basic compliance as optional performance.

Security Business and Worker Licensing

Under BC's Security Services Act, a person generally must hold a valid security business licence to carry on a security business, and a licensed security business must not employ or engage a person for security work unless that person holds the required security worker licence or an exemption applies.

The Province provides a security industry licensing hub and information on rules for licensed security businesses and rules for licensed workers.

The contract should say who verifies licences, how often status is checked, what happens if a licence expires, and whether the client can request evidence.

Insurance

BC's Security Services Regulation requires a security business licensee to maintain at least $1 million in general liability insurance. That is a statutory minimum, not a recommendation that $1 million is adequate for every site.

The buyer, insurer, landlord, general contractor, or procurement policy may require higher limits or additional coverage. Confirm:

  • policy type and limit
  • insurer and policy period
  • certificate requirements
  • additional-insured wording where appropriate
  • notice expectations for cancellation or material change
  • automobile coverage if vehicles are used
  • whether subcontracted services are covered

Have an insurance professional review whether the coverage matches the assignment.

WorkSafeBC Status

WorkSafeBC explains that a clearance letter can confirm whether a business or contractor is registered and paying required premiums. Buyers can obtain a WorkSafeBC clearance letter and should follow WorkSafeBC's guidance on when letters are needed.

The procurement file can require current clearance at onboarding and at appropriate intervals during a longer agreement.

Uniform, Conduct, Equipment, and Subcontracting

The agreement should require compliance with applicable law, licence conditions, uniform and equipment rules, and the Security Industry Code of Conduct. It should also disclose whether another provider or subcontractor may perform any part of the work and what approval, licensing, insurance, privacy, and reporting standards will apply.

Remedies, Service Credits, and Dispute Handling

Not every missed KPI is the same. A delayed non-urgent summary and an uncovered critical post should not automatically receive the same response.

A practical remedy ladder may include:

  1. documented exception and explanation
  2. immediate operational correction
  3. supervisor review
  4. root-cause analysis
  5. written corrective-action plan with dates and owners
  6. added training, supervision, or staffing adjustment
  7. service credit if the parties negotiated one
  8. escalation to senior contacts
  9. termination or other contractual remedy for repeated or material failure

If service credits are used, define:

  • the exact trigger
  • how performance is calculated
  • the claim process
  • exclusions
  • whether credits are automatic
  • monthly caps
  • interaction with other rights or remedies
  • treatment of repeated failures

Avoid copying a percentage from an unrelated template. Credits, liability limits, indemnities, insurance, dispute resolution, and termination language require legal review. The operational team can define what happened; qualified counsel should determine how the contract allocates legal and financial consequences.

Buyer Decision Table: Match the SLA to the Service Model

Security need | Likely service model | SLA items that deserve extra attention

Continuous entrance, lobby, gate, or public-facing duty | On-site guard | Shift coverage, relief handoff, attendance, access decisions, incident escalation

Several documented checks at a locked property | Mobile patrol | Visit windows, route and checkpoint definition, partial-round rules, proof of attendance

After-hours alarm activations | Alarm response | Call intake, dispatch acceptance, service area, arrival definition, access delays, keyholder updates

Construction gate, tools, materials, or equipment | Construction security | Project phases, gate hours, contractor access, changing hazards, equipment zones, weekend coverage

Venue entrance, guest flow, or temporary event | Event security | Deployment time, post map, organizer authority, prohibited items policy, closing and incident handoff

Multi-site commercial portfolio | Blended guard and patrol plan | Site-specific schedules, consistent reporting, exception visibility, portfolio-level review

Zentra provides security services that can combine security guards, mobile patrol, alarm response, construction security, and event security where the site requires a blended plan.

For property-focused assignments, compare Zentra's commercial property security approach. Where alarm or sprinkler impairment creates a separate life-safety monitoring requirement, review fire watch security as its own defined scope.

Zentra Field Note: Measure the Handoffs

Security performance often drifts at the handoff points rather than during the obvious patrol.

Examples include:

  • the alarm company sends a call but the dispatch clock is unclear
  • a relief guard arrives but the outgoing guard leaves before a proper handoff
  • a client changes a gate code but the post orders are not updated
  • a patrol finds damage but the right contact is unavailable
  • an incident report is submitted but no one owns the follow-up

An SLA should measure these transitions. Define when responsibility moves from the client to the provider, from dispatch to the responder, from one shift to the next, and from incident reporting to corrective action.

The quiet handoffs are where a clear contract becomes a working operating system.

Security SLA Buyer Checklist

Before approving a proposal or renewal, confirm:

  • Every site, post, route, and service window is identified.
  • Included and excluded duties are clear.
  • Current post orders are attached or scheduled for approval before launch.
  • Staffing, relief, call-out, and supervisor responsibilities are defined.
  • Each KPI has one definition and one accepted evidence source.
  • Response-time clocks have precise start and stop points.
  • Patrol targets match the actual route and site conditions.
  • Client-supplied access, hazard, and contact responsibilities are written down.
  • Incident notification and written-report deadlines are separate.
  • Escalation contacts have backups and review dates.
  • GPS, photos, video, visitor data, and retention are covered by a privacy process.
  • Security business and worker licensing will be verified.
  • Insurance evidence and required limits have been reviewed.
  • WorkSafeBC clearance has been considered.
  • Change control, performance reviews, corrective action, and remedies are defined.
  • Renewal, rate change, notice, dispute, and termination terms have been reviewed.
  • Legal and insurance advisers have reviewed material risk-transfer terms.

Download the Security Service SLA Buyer Checklist

How Zentra Handles Security Service Planning

Zentra starts with the assignment rather than a generic KPI sheet.

1. Clarify the Operating Need

The first discussion covers the property or event, service dates, operating hours, access points, high-priority areas, known concerns, client contacts, and reporting expectations.

2. Match the Service Model

The site may need an on-site guard, mobile patrol, alarm response, temporary coverage, or a blended plan. A continuous access-control duty should not be disguised as an occasional patrol, and a low-exposure locked property should not automatically be sold full-time coverage.

3. Turn Scope Into Site Instructions

Before coverage begins, duties, route or post expectations, restricted areas, safe-access limits, incident steps, and communication contacts should be documented in the service plan and post orders.

4. Agree on Useful Reporting

Reporting should match the buyer's decision needs. That may include shift activity, patrol observations, access notes, incident reports, photos where appropriate, and escalation records.

5. Review Changes

Construction phases, tenants, delivery patterns, operating hours, event layouts, alarm contacts, and property risks can change. The service scope and measurement rules should be reviewed when the operation changes, not only after a complaint.

Final service levels depend on the confirmed site, safe access, staffing, travel conditions, approved duties, and written agreement. Zentra does not present one response time or patrol frequency as suitable for every client.

About This Guide

This guide was prepared by Zentra Protection for BC business owners, property managers, contractors, facility teams, strata decision-makers, and event organizers reviewing security-service proposals or renewals.

It reflects the practical questions that should be resolved before guards, patrols, alarm response, or reporting requirements are turned into measurable service terms. Official BC and federal sources were reviewed on September 2, 2026. The article separates legal requirements from illustrative procurement examples and does not claim that one KPI target fits every site.

Zentra Protection is a licensed security company based in Chilliwack and a member of the Chilliwack Chamber of Commerce. Review Zentra's Chilliwack security service coverage or visit the Security Intelligence blog for related planning guides.

Official Sources and Further Reading

Final Thoughts

A strong security service SLA is not a page of aggressive penalties or a borrowed response-time promise. It is a shared operating standard.

The scope tells the provider what work matters. The post orders guide the people delivering it. The KPI definitions show how performance will be measured. The reports provide evidence. The escalation ladder directs action. The review process keeps the agreement aligned as the site changes.

If you are reviewing guard, patrol, construction, event, or alarm-response coverage in British Columbia, start by writing down the site, schedule, duties, decision-critical reports, and escalation contacts. Then build the SLA around those facts.

Contact Zentra Protection to discuss a practical security service plan for a business, property, construction site, or event in BC.

Frequently Asked Questions

What is a security service SLA?

A security service SLA is the part of a security agreement that defines measurable service expectations, evidence sources, escalation steps, review processes, and remedies. It should connect directly to the scope of work and site-specific post orders.

Is there a standard security guard response time in BC?

No single response time fits every BC security assignment. A stationed guard, a mobile patrol unit, and an alarm responder have different starting points, travel requirements, access conditions, and duties. The agreement should define a realistic target for the specific site and service model.

What should a security SLA measure?

Useful measures may include shift coverage, patrol completion, response stages, incident-notification time, report timeliness, supervisor review, and corrective-action closure. Each measure needs a precise definition, evidence source, owner, exception rule, and review period.

Should a security SLA include patrol frequency?

Yes, when patrols are part of the service. Define the route, required areas or checkpoints, number or timing of rounds, permitted variations, partial-round rules, evidence source, and treatment of unsafe or inaccessible areas.

How should alarm response time be calculated?

Separate the stages: call receipt, eligibility or verification, dispatch, arrival at the approved access point, site check, client update, and report completion. The contract should state which stage the SLA measures and how delays or exclusions are documented.

What reports should a security provider supply?

The reporting package should match the service. It may include daily activity or shift reports, patrol records, incident reports, attendance exceptions, escalation logs, supervisor reviews, and monthly KPI summaries. Deadlines and required content should be written into the agreement.

Can GPS and checkpoint data be used as proof of patrol?

They can support proof of service, but the parties should also address privacy, purpose, access, security, retention, accuracy, and deletion. BC privacy requirements may apply to employee, visitor, tenant, or customer information contained in those records.

What BC compliance documents should a buyer request?

A buyer should consider evidence of the security business licence, required worker licences, insurance, and WorkSafeBC status. Additional documents may be appropriate depending on the property, contract, insurer, landlord, general contractor, or procurement policy.

Should a security SLA include service credits?

It may, but credits are a commercial and legal choice rather than a universal requirement. If used, define the trigger, calculation, claim process, exclusions, cap, repeated-failure treatment, and relationship to other remedies. Obtain legal advice on the final clause.

How often should a security SLA be reviewed?

Set a regular review schedule and require an earlier review when the site, hours, risk, tenant mix, project phase, access process, or service model changes. The right cadence depends on the complexity and duration of the assignment.

Related Zentra Services