Getting Started
This page takes a brand-new Patrol deployment from switched-off to a working guardhouse in a handful of steps: enable the module, decide who can do what, describe your property (sites, zones, gates, posts), add your guards, and then walk through a real first day — logging an activity, checking in a visitor, and filing an incident. No prior experience with Patrol is assumed.
Key concepts before you start
Four ideas explain almost everything about how Patrol behaves. Keep them in mind and the rest of the module makes sense.
- Append-only records. Once you submit an activity, incident or handover, it can never be silently edited or deleted. Corrections are made by amending, which keeps the original and adds a new version. This is what makes Patrol a trustworthy legal record rather than an editable notepad.
- Reference numbers. Every important record gets a human-readable number
the moment it is created —
EVT-2026-0001for a blotter entry,INC-2026-0001for an incident,VIS-2026-0001for a visit. Use these when you talk about a record. - Privacy by default. Patrol deliberately has no field for a government ID number, ID photo, or date of birth. You verify identity visually and move on. This protects both your organisation and your visitors.
- Sites tie everything together. A site is a physical location (a building, subdivision, or compound). Locations, routes, shifts and reports all hang off a site. A default site called Main Site already exists, so you can start without configuring anything.
Before you begin — checklist
| Requirement | Who provides it | Why |
|---|---|---|
| An ERPat staff account you can sign in with | Your ERPat administrator | Every Patrol screen (except public reporting) requires a signed-in staff session. |
| The Patrol module enabled | Administrator (Step 1) | Until module_patrol is on, no Patrol menu or permission appears. |
| Patrol permissions on your role | Administrator (Step 2) | Each screen is gated by a permission key; without it the menu item is hidden. |
| Incident-alert recipients (optional) | Administrator (Step 5) | Severity and escalation alerts ship with no recipients so nobody is spammed. |
Step 1 — Enable the module
An administrator turns Patrol on once, for the whole tenant.
- Sign in as an administrator and open Settings → Manage Modules.
- Find Patrol in the Security category and switch it On.
This sets the
module_patrolflag that gates the entire module and all of its background jobs. - Refresh the page. A Patrol item (shield icon) now appears in the left menu, and the Patrol permission keys become available in the Roles editor.
Step 2 — Grant Patrol permissions to roles
Patrol has a rich set of on/off permission keys, all in the Security: Patrol category of the Roles editor. Rather than tick them one by one, think in terms of three roles — guard, supervisor, and administrator / DPO — and use the recipes below as a starting point. Administrators bypass every check automatically, so you only need to grant these to non-admin roles.
Front-line guard
What a guard on shift needs to do their job at the gate and on the property — but not the ability to delete records, view restricted incidents, or manage the roster.
| Permission key | What it lets the guard do |
|---|---|
patrol | Access the module at all (the Enable/module gate). |
patrol_dashboard | See the Patrol dashboard on sign-in. |
patrol_log, patrol_log_create, patrol_log_update | Read the blotter, add entries, and amend their own entries. |
patrol_visitor, patrol_visitor_create, patrol_visitor_update | Check visitors in and out and update a visit. |
patrol_incident, patrol_incident_create | See the incident register and raise a new incident. |
patrol_run, patrol_run_execute | Start a patrol round and scan checkpoints. |
patrol_handover, patrol_handover_acknowledge | File and acknowledge shift handovers. |
patrol_asset_assign | Sign equipment (radios, keys) out and back in. |
Shift supervisor
Everything a guard can do, plus the ability to move incidents through their lifecycle, handle evidence, manage the roster and shifts, and pull reports.
| Permission key | What it adds |
|---|---|
patrol_incident_update, patrol_incident_acknowledge, patrol_incident_close | Update, acknowledge, and close/reopen incidents; add people involved and follow-up tasks. |
patrol_evidence_view, patrol_evidence_manage | Open restricted incidents, and add evidence with chain-of-custody entries. |
patrol_shift, patrol_shift_create, patrol_shift_update | Plan shifts and assign guards to them. |
patrol_guard, patrol_guard_create, patrol_guard_update, patrol_guard_delete | Maintain the guard roster and license records. |
patrol_route, patrol_route_create, patrol_route_update, patrol_route_delete | Build patrol routes and their checkpoints. |
patrol_asset (+ create/update/delete) | Maintain the equipment register. |
patrol_location (+ create/update/delete) | Maintain sites, zones, gates, and posts. |
patrol_report_export | Export the daily activity CSV and the incident-register PDF. |
patrol_public_report_triage | Triage public/anonymous security reports and convert them to incidents. |
Administrator / Data Protection Officer
Compliance-sensitive controls that should sit with a small number of trusted people — typically your administrator or Data Protection Officer.
patrol_legal_hold— place or release a legal hold that blocks deletion and retention sweeps.patrol_retention— define and activate data-retention policies (Governance).patrol_privacy_request— manage data-subject (privacy) requests.patrol_disclosure— record when data is disclosed to third parties.patrol_ai,patrol_ai_approve— request and approve AI suggestions (only relevant if AI-assist is switched on; it ships off).
Step 3 — Describe your property (Sites, Zones, Gates, Posts)
Open Patrol → Locations. This one screen has a tab for each level of the location hierarchy. You can operate Patrol using only the pre-made Main Site, but describing your property properly makes routes, shifts and reports far more useful.
| Level | What it represents | Key fields |
|---|---|---|
| Site | A whole location — a building, compound, or subdivision. | Name, a short unique code, time zone. |
| Zone | An area inside a site — lobby, basement, Tower B, perimeter. | Name, parent site. |
| Gate | An entry/exit point. | Name, site/zone, direction (in, out, or both). |
| Post | A guard position. | Name, site/zone, type (fixed, roving, or gate). |
- On the Sites tab, either keep Main Site or add your own
site with a name, unique code (for example
HQ), and time zone. - Switch to the Zones tab and add the areas inside each site.
- Add your Gates (choose the correct direction) and your Posts (choose fixed, roving, or gate).
You can come back and expand this at any time — nothing here is locked once you start using the module.
Step 4 — Add your guards
Open Patrol → Shifts and go to the Guards tab (the guard roster). A guard record can either link to an existing ERPat staff account or stand alone for an outsourced agency officer who has no login.
- Click Add Guard. Either pick a linked staff user, or type a full name for an external/agency guard (one of the two is required).
- Fill in the optional details — guard number, agency, rank — and choose which sites the guard covers.
- Save, then use the license action on the guard to record any security-license type, number, and expiry date. Patrol automatically reminds you before a license lapses.
Your first day — a walkthrough
With the module enabled, permissions granted, and at least the Main Site in place, here is exactly what a guard does during a normal shift. Try each of these once to confirm your setup works end-to-end.
1. Log an activity (the digital blotter)
- Open Patrol → Activity Log and click New Entry (Log Activity).
- Choose the site and a category — one of patrol, visitor, maintenance, observation, incident, or note.
- The date and time default to now; change it only if you are recording something that happened earlier. Write a short summary and a fuller narrative of what happened, and note any action taken.
- Attach a photo if it helps, then Submit. The entry receives a reference
like
EVT-2026-0001and is sealed into that day's tamper-evident record. - Made a mistake? Use the pencil / Amend action. Patrol creates a new
version (marked
v2) and keeps the original as "superseded" — you can always see the full history.
2. Check in a visitor
- Open Patrol → Visitors and click Check In Visitor.
- Enter the visitor's name (the only required field), plus the host or unit they are visiting, the purpose, an expected departure time, and a vehicle plate if relevant.
- Verify their ID visually and tick ID visually verified. Do not type an ID number, photograph the ID, or record a birth date — Patrol has no field for those on purpose.
- Save. The visit gets a reference like
VIS-2026-0001and appears in the "currently inside" occupancy list. When the visitor leaves, open the visit and click Check Out. Visitors who stay past their expected departure are flagged as overstays automatically.
3. File an incident
- Open Patrol → Incidents and click Create Incident. (You can also escalate an existing blotter entry into an incident from its detail view.)
- Pick a category and a severity — low, medium (the default), high, or critical — then give the incident a clear title and factual narrative.
- For sensitive matters, tick Restricted so only staff with
patrol_evidence_viewcan open it. If you want the security team notified, tick the send alert option before saving. - Save. The incident receives a reference like
INC-2026-0001and starts its lifecycle at open, moving through acknowledged → investigating → action required → resolved → closed as your team works it. - From the incident's detail view, a supervisor can attach evidence (each file is hashed and given a chain-of-custody trail), add the people involved, and create follow-up tasks.
Step 5 (recommended) — Turn on incident alerts
Patrol registers two notification events but ships them with no recipients, so no alert is sent until an administrator opts people in. Do this once so critical incidents actually reach someone.
- Open Settings → Notifications.
- Find patrol_incident_raised (fired when a guard raises an incident with the alert flag ticked) and patrol_incident_escalated (fired automatically when a critical incident is left unacknowledged), and choose the recipients for each.
Escalation timing is controlled by patrol_escalation_minutes (15 minutes by
default): a critical incident still sitting at open past that window is escalated by
a background job and the patrol_incident_escalated alert is sent.
Where to go next
- Daily Operations — the deeper, day-to-day playbook for the blotter, visitors, incidents, shifts, rounds, and handovers.
- Administration — the full permission reference, location and notification settings, governance/retention, and the AI-assist controls.
- Data & Screen Reference — every screen, field, status, and reference-number prefix at a glance.
- FAQ & Troubleshooting — quick answers to "why can't I…?" questions like editing entries, missing alerts, and restricted incidents.