Video analytics for security monitoring teams
Video analytics turn cameras into sensors: what detection, recognition and behavior tools can really do, why false alarms kill deployments, and the privacy law.

Most surveillance footage is never watched by anyone. It sits on a recorder until something goes wrong and somebody scrubs back through it. Video analytics change what the camera is for: instead of a record you review afterward, it becomes a sensor that interrupts you.
Video analytics detect intrusions, count people, read plates and flag behavior patterns, so a small team can cover more cameras than it could ever watch. The constraint is not the software. It is camera quality, lighting, tuning and false alarms, plus biometric privacy law that in some states carries a private right of action. Budget for the tuning, not just the license.
Why can't a person just watch the monitors?
Because attention does not hold. The most-quoted evidence is a GAO testimony to Congress on securing federal buildings, which put it plainly: "Because watching camera screens is both boring and mesmerizing, the attention of most individuals has degenerated to well below acceptable levels after only 20 minutes of viewing."
Treat that number as directional, not precise. The GAO testimony dates from 2002 and the underlying research is older still, from an era of low-resolution black-and-white cameras. The finding that sustained monitor-watching does not work is well established. The specific twenty-minute figure has been repeated for decades without being re-measured on modern equipment.
The operational point survives the caveat. If your monitoring plan depends on a person catching something on screen four hours into a shift, you do not have a detection system. You have a recording system with a witness.
What can analytics actually detect?
Three families, and they are not equally mature.
Detection: something happened here
- Motion. The oldest and the noisiest. Animals, headlights, blowing branches, a cloud crossing the sun
- Intrusion. Someone entered a zone that should be empty, which is a far more useful question than whether anything moved
- Line crossing. Movement across a virtual boundary, for perimeters and directional counting
- Loitering. Someone stayed in an area past a threshold you set
- Object removal. An item disappeared from the scene
- Abandoned object. An item was left behind, which matters most in transit and public venues
Recognition: this specific thing
- Face matching against a database of known individuals. The most capable and the most regulated
- License plate reading for gate access, investigation and enforcement
- Vehicle classification by type, color and sometimes make
- People counting for occupancy and flow
Behavior: this looks wrong
Crowd density, aggression and fighting detection, running detection. This is the least reliable family and the one vendors demo most enthusiastically. A person running for a bus and a person running from a fight produce similar pixels.
Where does it earn its keep?
Perimeters, first. A fence line at 3am is exactly the problem analytics are good at: an empty scene, a defined zone, an unambiguous event. One operator plus after-hours presence alerts covers a perimeter that would otherwise need several pairs of eyes.
Access control is second, because badge readers are blind to the thing that defeats them. Tailgating detection catches two people entering on one swipe. Plate reading opens the gate for a known vehicle. Neither is possible from the reader alone. Access control beyond badge readers covers where those gaps sit.
Retail buys analytics for two reasons at once. Customer counting and dwell heat maps inform staffing and layout, and the same feed flags the behavior patterns loss prevention cares about. The business case usually closes on the merchandising half. See retail loss prevention for how that pairs with floor coverage.
Then there is everything that is not security at all: occupancy for safety limits, parking availability, PPE compliance on an industrial site. Facilities and safety budgets often fund cameras the security team ends up using.
What has to be true for it to work?
The camera comes first
No software makes up for inadequate video. Face matching needs far more resolution than intrusion detection. Frame rate decides whether a fast subject is captured or smeared. Backlight, night conditions and rapid light changes hurt analytics more than they hurt a human operator.
Field of view is the one most people get wrong. A wide angle that gives good general coverage will not give you the pixels-on-target that recognition needs. If analytics are the plan, place cameras for analytics from the start rather than bolting software onto a layout designed for something else.
Where the processing happens
| Architecture | Gains | Costs |
|---|---|---|
| Edge, on the camera | Low bandwidth, immediate response, works if the link drops | Limited to what the camera's chip can run |
| Server, on site | Heavier analysis across multiple feeds | Network capacity and hardware you own and maintain |
| Cloud | Little local infrastructure, easier to update | Upload bandwidth, ongoing fees, added latency |
| Hybrid | Edge detection for the alert, cloud for the heavy analysis | Two systems to configure and two vendors to blame |
Where the alert lands
An analytics detection that stops at the video management system has not helped anyone. It has to route to whoever is going to respond, and it has to end up in the incident record so the event and the response sit together.
Ask any vendor how their alerts reach a guard's phone and what the incident record looks like afterward. If the answer is a second console for a dispatcher to babysit, you have added a screen, not removed one. The same integration question applies to pairing remote monitoring with mobile patrol and to how an operations center is laid out.
What goes wrong with video analytics?
False alarms, mostly
This is the whole game. Rain, fog, headlights, spiders on the lens, a flag moving in the wind, a maintenance worker doing their job for eleven minutes and tripping the loitering threshold.
Every one of those trains your operators to ignore the alert. Alert fatigue is not a soft problem. It is the mechanism by which a system that works on paper produces a missed intrusion, and it takes weeks of per-camera tuning to get the rate down to something a human will keep responding to.
The same tuning discipline applies to any location-triggered alert. Geofencing without the false alarms covers the identical failure mode on the GPS side.
Accuracy is mostly not about the software
- Camera quality and placement set a ceiling nothing else can raise
- Daylight performance tells you very little about 2am performance
- Precipitation, fog and temperature swings degrade outdoor analytics
- Crowds, clutter and changing backgrounds raise both misses and false hits
- Calibration is per camera, per scene, and it is the step everyone skips
Privacy law, which is where this gets expensive
Biometric analytics are regulated separately from ordinary video in a growing number of places. Illinois is the sharpest example. Under section 15 of the Biometric Information Privacy Act, a private company holding biometric identifiers must publish a written retention policy and destroy the data when the collection purpose is satisfied or within three years of the person's last interaction, whichever comes first.
Section 15(b) goes further. Before collecting, you must inform the subject in writing that biometric data is being collected, state the specific purpose and the length of term, and receive a written release. That is a consent workflow, not a checkbox, and it applies to employees as well as visitors.
Other states and cities regulate or ban face recognition on different terms, and the rules move. Check your own jurisdiction's current statute before you scope a face-matching deployment, and get it in front of counsel rather than in front of an integrator.
Does the math work?
On the benefit side: coverage that does not degrade over a shift, detection while the event is happening instead of during forensic review, an archive you can search by event type rather than by scrubbing, and occupancy and flow data that other departments will pay for.
On the cost side, the license is the small number.
- Camera replacement, if your existing fleet cannot feed the analytics you want
- Processing hardware, storage and network capacity
- Installation and configuration, which is specialist work
- Ongoing tuning as seasons, foliage, lighting and site use change
That last line is the one that gets left out of proposals and then out of budgets. A system tuned once in October behaves differently in June.
Analytics reduce the tedious work and catch the obvious events. They do not decide anything. Every detection still needs a person to verify it and someone on the ground to respond, which means the value depends as much on how fast you can put a guard on the alert as on the detection itself.
Key Takeaways
- Sustained monitor-watching does not work. GAO told Congress attention falls off after 20 minutes.
- Detection analytics are mature, recognition is regulated, behavior analytics are the least reliable.
- Camera quality, placement and lighting set a ceiling the software cannot exceed.
- False alarms, not missed detections, kill deployments. Budget for per-camera tuning.
- Illinois BIPA needs written notice and a signed release before you collect biometric data.
Continue Reading

How to apply for a Florida security guard license
Which FDACS class to file, what goes in the Class D and Class G applications, the fees set in statute, and how the two-year and three-year renewals work.

Best security guard software in 2026: 8 compared
Eight security guard software platforms compared on features, published pricing and who each one fits, with every claim linked to its source.

New York guard license: registration and training
What a New York guard license takes: 8 hours pre-assignment, 16 on the job, 8 in-service a year, the armed track, and what the employer has to file.