Commercial building security works as a set of layers: site design, doors and hardware, access rules, lighting, intrusion detection, video, human response, incident procedures and ongoing maintenance. No checklist can promise that an event will not occur. A useful review instead helps property managers understand what exists, what purpose each measure serves, who responds, what has failed or changed and where a qualified assessment may be needed.
Use this guide to organize a walkthrough and provider conversations for Sacramento offices, retail centers, industrial properties, medical buildings, multifamily common areas and other commercial sites. Adapt it to the property's tenants, hours, public access, deliveries, parking, neighborhood context and contractual obligations. Do not publish completed security details or sensitive floor plans broadly; control access to records that could expose system locations, credentials or response procedures.
1. Define the review scope and decision owners
Identify the property, buildings, exterior areas, systems and operating periods included. Name the owner representative, property manager, facilities contact, tenant contacts and any security, information-technology, legal, insurance or risk stakeholders who should participate. Decide whether the exercise is an internal inventory, a provider site survey or a formal assessment by a qualified professional. Those deliverables are not interchangeable.
- Current tenant roster, public hours and after-hours operations
- Critical rooms, high-value areas and business continuity priorities
- Known incidents, near misses, false alarms and recurring complaints
- Lease or contract responsibilities for common and tenant spaces
- Who can authorize changes, release records and approve emergency work
- Where sensitive drawings, credentials, video and reports will be stored
2. Inventory the site perimeter and approaches
Walk the property during daytime and after dark when it is safe and authorized to do so. Record vehicle entrances, pedestrian approaches, parking, loading, alleys, fences, gates, landscaping, utility areas, roof access and neighboring conditions. Look for damaged barriers, uncontrolled shortcuts, hiding areas, obstructed views, missing signs and lighting outages. The objective is not to label a property safe or unsafe from one visit; it is to create a documented maintenance and design list for appropriate review.
Confirm who owns adjacent lights, sidewalks, shared drives or fencing before assigning corrections. Avoid trimming, installing barriers or changing accessibility routes without proper review. For vehicle barriers, gates and public approaches, qualified designers and contractors should consider emergency access, pedestrian safety, accessibility, fire-department needs, drainage and applicable permits. Security goals do not override life-safety or accessible-egress obligations.
3. Review every exterior opening
Create a door and opening schedule with a unique ID, location, function, normal hours and responsible tenant or manager. Include storefront doors, service doors, loading doors, gates, roof hatches, windows and other accessible openings. Check visible condition of frames, hinges, closers, latches, locks, strikes, panic or exit hardware, glazing and weather protection without disabling or altering a life-safety component. Record doors that prop open, fail to latch or are routinely bypassed and escalate urgent concerns through the property's responsible professionals.
- Does each opening have a defined public, tenant, delivery or emergency purpose?
- Does the door close and latch consistently under normal use?
- Are keys, codes and credentials issued through a documented process?
- Are former employees, vendors and tenants removed promptly from access?
- Are mechanical and electronic components assigned to an owner and maintenance plan?
- Are emergency release, egress and fire-alarm interfaces reviewed by qualified parties?
California's Contractors State License Board C-28 classification includes certain lock and security equipment work, including electronic access-control equipment, while other classifications or state-regulated activities can apply to low-voltage, alarm, electrical or fire-alarm scopes. The correct credential depends on what is contracted. Coordinate physical-opening work with commercial door and gate providers, and keep regulated life-safety scopes with appropriate fire protection providers. Ask every provider to identify the exact legal business and credential associated with its work, then verify it with the appropriate state agency.
4. Audit keys, credentials and access administration
List key systems, cards, fobs, mobile credentials, codes, intercoms and visitor processes. Document who can issue, change and revoke access; how approvals are recorded; which roles receive master or after-hours privileges; and how audits are reviewed. Shared codes and untracked keys make offboarding difficult. Establish a repeatable employee, tenant and contractor departure checklist and schedule periodic privilege reviews for long-standing access.
For electronic systems, confirm administrator ownership, multifactor authentication where supported, backups, software and license status, time synchronization, update responsibility and an export process. Avoid giving every vendor permanent broad remote access. Coordinate with the organization's IT or cybersecurity team before placing controllers, intercoms or other connected devices on a network. Access logs can contain sensitive information, so retention and access should follow an approved business and legal policy.
5. Verify intrusion-alarm purpose and response
For each alarm area, identify doors, windows, motion devices, glass-break devices, panic or hold-up functions, schedules, partitions, communication paths and the monitoring arrangement. Verify the call list, passcodes, authorized users and instructions for police, guard, manager or tenant notification. Test and service only through authorized procedures; an informal test can create a false dispatch or leave an area unprotected.
The City of Sacramento Police Department states that Chapter 8.36 requires an alarm user permit and an alarm company permit for covered alarm activity. It also notes that a video system that does not signal police does not require an alarm user permit, while a monitored video connection that signals police does. Confirm current requirements for the actual system and address through the City's alarm-permit information. Keep permit, contact and system records current, and investigate false alarms rather than treating fees as the only issue.
6. Review video surveillance against defined objectives
Write the purpose of each camera before judging its view. Wide situational awareness, identification at an entrance, transaction review, license-plate capture and remote verification require different placement and image detail. Check current views in representative daylight and night conditions, not just live thumbnails during a provider visit. Note glare, headlights, shadows, vegetation, displays, dirty housings, blocked views, camera movement and whether the recorded image—not only live video—meets the intended purpose.
Document recorder or cloud ownership, administrator access, health monitoring, storage estimates, actual retention, export procedure, time synchronization and who can release footage. Set retention and disclosure rules with appropriate legal and privacy input; this checklist does not prescribe a period or determine where cameras may be placed. Coordinate networked cameras with IT. Change vendor defaults, restrict privileges, maintain updates and consider network segmentation consistent with the organization's cybersecurity program.
7. Inspect lighting and visibility as maintained systems
Record outages, damaged fixtures, inconsistent controls, extreme glare, deep shadows and vegetation or stored materials that obstruct intended views. Evaluate routes used by employees and visitors, entrances, parking, loading, waste areas and equipment yards. Lighting design affects security, energy use, neighbors, cameras and accessibility. A qualified provider should select equipment and controls for the site rather than assuming that maximum brightness is always the correct solution.
Assign inspection frequency and a repair workflow. Photocells, time clocks, network controls and emergency or backup systems need clear ownership. If a project adds circuits, changes controls or mounts fixtures on building or site elements, determine electrical, permit and property-approval requirements. Coordinate camera and lighting changes so a new fixture does not wash out an image or create reflections through glazing.
8. Evaluate guards, patrols and response roles
Standing guards, reception security, mobile patrol, alarm response and remote monitoring serve different purposes. Define the desired posts, hours, routes, checkpoints, visitor duties, incident reporting, escalation and prohibited actions before seeking prices. A patrol visit is not continuous coverage; a camera is not a physical response; a guard should not be assigned undefined responsibilities that conflict with training, policy or law.
California's Bureau of Security and Investigative Services regulates private patrol operators and security guards and provides an online license-verification service. Verify the proposed company and applicable personnel credentials, then review insurance, supervision, relief staffing, training relevant to the assignment and sample reports. For a layered system, document how officers, the monitoring center, property staff and public emergency services exchange information without assuming any response outcome.
9. Protect connected security systems
Cameras, access control, intercoms and intrusion panels may connect to local networks or cloud services. Inventory devices, owners, administrative accounts, integrations and remote-support paths. Coordinate password policy, multifactor authentication, software and firmware updates, backups, logging, vendor access and network design with qualified IT or cybersecurity personnel. The Cybersecurity and Infrastructure Security Agency recommends changing default passwords and using multifactor authentication as foundational steps; implementation must fit the organization's systems and risk program.
- Remove default, shared and former-user administrator credentials
- Use named roles and least-necessary privileges where the platform supports them
- Document vendor and remote access, approval and expiration
- Keep supported software and device updates in a managed process
- Back up configurations and test restoration appropriate to the system
- Monitor device health, storage, communications and important audit events
- Plan ownership and data export before changing providers
10. Test procedures, not just devices
Write incident and emergency procedures around actual roles. Employees should know how to report an issue, whom to contact and when to use emergency services, but they should not be expected to investigate danger. Confirm after-hours contacts, building access for responders, tenant notification, evidence preservation and business-continuity handoffs. Coordinate plans with appropriate public agencies and qualified advisors; do not invent police, fire or medical response commitments.
Run authorized tabletop exercises that do not expose sensitive details or generate false alarms. Review what information was available, whether contacts worked and which procedures were ambiguous. After a real event, preserve relevant records under approved policy and hold a lessons-learned review. Security improvements should be tied to documented observations, not fear-based claims or guarantees that one product will eliminate risk.
11. Create a prioritized action register
For each finding, record the location, observed condition, intended function, interim action if authorized, responsible party, target date and completion evidence. Separate maintenance repairs, administrative changes, professional assessments and capital projects. Rank priorities using both likelihood and consequence with the owner's risk team rather than copying a generic severity label. Revisit open items after tenant changes, incidents, renovations and provider transitions.
- Address urgent life-safety or operational concerns through the responsible qualified party.
- Restore failed existing functions such as doors that do not latch or cameras that no longer record.
- Correct access and contact administration gaps.
- Obtain specialist assessment where the cause or solution is uncertain.
- Develop scope and budget for approved capital improvements.
- Verify completed work, update records and add recurring maintenance.
12. Request comparable Sacramento security proposals
Give providers a controlled summary of goals, property type, included areas, known systems, operating hours, desired deliverables and constraints. Avoid distributing unnecessary sensitive details during early outreach. Require a site survey before final scope, an equipment or staffing schedule, responsibility matrix, assumptions, exclusions, recurring fees, service terms, warranty, data ownership and credential information. Score proposals on fit, evidence and lifecycle support rather than choosing only from the lowest initial price.
Use the Sacramento commercial security directory to identify companies, with separate directory paths for security guard services, video surveillance, access control and commercial locksmiths. A listing is a starting point, not an endorsement or verification. Confirm the provider, license status, insurance, scope, references and contract directly before sharing sensitive site information or authorizing work.
Sources and official resources
These links are provided for reference and do not imply an endorsement.
- Alarm permits (Sacramento Police Department)
- Verify a BSIS license (California Bureau of Security and Investigative Services)
- Private Patrol Operator fact sheet (California Bureau of Security and Investigative Services)
- C-28 Lock and Security Equipment classification (California Contractors State License Board)
- Four cybersecurity goals (Cybersecurity and Infrastructure Security Agency)