Skip to content

Security Watch

A guard-facing view of what is happening that should not be.

The hard part of security monitoring is not detection, it is volume: a system that reports everything unusual reports mostly nothing, and gets ignored by the third shift. This app is built around deciding what is worth a guard's attention.

Who it is for

Guards on shiftThe board — open incidents, in priority order
Whoever reviews the nightThe incident history and how each was resolved
Whoever sets it upThe settings page, on the admin side under Your Apps

Before it is useful

Zones to watch. The app only looks at zones you mark as monitored in its settings, and it does nothing until at least one is. Mark the sensitive ones restricted as well, and say who is allowed in — by entity, or by a label their tag carries.

Operating hours on the venue, so "after hours" means something. By default a zone is armed whenever its venue is closed and stands down when it opens. You can override that per tenant or per zone: armed at all times, armed in a custom window, or not armed at all. A zone with no hours anywhere is never armed by schedule; it is judged against its own habits instead.

Tags on the people who are meant to be there. Two of the detectors — restricted zones and out-of-habit — reason about who is present, and need a tag bound to a person for that. After-hours presence also counts people seen by a radar or people counter, so a zone with a counting sensor is watched even when nobody carries a tag.

The master switch. The app is off by default and its sweep does nothing until you turn it on.

What it watches for

The detectors run every five minutes and look for a small number of specific things rather than general strangeness. Each can be switched off individually.

Severity
Panic buttonA registered panic button pressed in the last few minutes, or any button-capable device pressed within a monitored zoneCritical, always — nothing suppresses it
After-hours presenceSomebody in an armed zone. Counts people, from tags or counting sensors; ignores assets and anyone whitelistedCritical if the zone is restricted, else warning
Unexpected activityFor a zone with no hours: presence at an hour when, over the last fortnight, it has never been usedWarning
Restricted zoneSomebody in a restricted zone who is not on its allowed list. A tag bound to no person is never allowedCritical while armed, else warning
Unknown deviceA BLE device nobody registered, heard best by a monitored zone's gateway, and lingering — there for five minutes and still there. A phone walking past is not an intruderWarning
Blind spotEvery gateway covering a monitored zone is offline — the app says it cannot see rather than reporting all-clearCritical while armed, else warning
HeatTemperature in a monitored zone at or above 45 °C, or up 5 °C on the previous hour. A fire announces itself by the rate of rise before the levelCritical, always

The blind spot is the one most systems get wrong. A zone with no working gateway looks exactly like an empty zone, and reporting it as empty is worse than reporting nothing.

Out of habit

The last signal is the interesting one: somebody doing something they do not normally do. A person in a room they have no history in over the last month, or a room in use at an hour nobody has used it in weeks.

This is a triage candidate, not an incident. It goes to an AI judge with the context — is the zone sensitive, is this person a regular nearby, are the room's regulars present too, is there a booking, what does the hour say — and only becomes an incident if the answer is that a head of security would want to know now. Each situation is judged once a day, at most five new ones a sweep, and every verdict is kept so you can see what it decided and why.

The reasoning is deliberately about this situation rather than a per-person watch list. Omaya does not keep a list of which rooms each person is allowed in; it asks whether what just happened makes sense.

It needs AI enabled for the app, and an AI configuration for your organisation. Without one, out-of-habit candidates are never incidents — the other detectors are unaffected.

Incidents

An incident persists by fingerprint: the same situation recurring is the same incident, not a new one every sweep. It stays open until a person resolves it — a situation that stops being detected is marked cleared but keeps its place on the board, because the guard has not closed it yet. A situation that comes back after being resolved is a new incident.

Each new or escalated incident gets a short narration from the AI — what it most likely is, and the first thing to do, from a fixed list — filled in shortly after it appears. The AI decides nothing here; it reads the evidence and writes two lines.

A guard can acknowledge an incident, take it, add notes, resolve it, and reopen it. The board is green, orange or red: red for any open critical incident, orange for open warnings only.

Who hears about it. Every app user granted Security Watch gets a push for each new or escalated incident. Critical incidents — or all of them, if you prefer — also go to the escalation recipients: app users or administrators you pick, by email, SMS or WhatsApp, and optionally a Telegram chat. Recipients are people, not typed-in addresses, resolved at send time, so a rota change reaches the right person without anyone editing the app.

Whitelists

A whitelist entry says a person or a device may be somewhere — one zone or anywhere — on which days and between which times. The windows cross midnight properly, which matters for a night shift. A whitelisted person does not raise after-hours presence; they can still raise a restricted-zone incident if they are not on that zone's allowed list.

When it disappoints

Nothing ever fires. The master switch is off, no zone is monitored, or the venue has no operating hours so no zone is ever armed.

Everything fires. The people who are legitimately there are not tagged, or not whitelisted, or the zone is armed at all times when you meant after hours.

Out-of-habit never produces anything. AI is off for the app, or the organisation has no AI configuration. Check the OAIA page.

A zone reports nothing at all. Check whether it is a blind spot — the app will say so, and that is a gateway problem rather than a security one.

A cleared incident is still on the board. It is meant to be. Resolve it.

Last updated:

Omaya platform documentation