Proving a Patrol Actually Happened
You prove a patrol happened by requiring evidence that can only be produced at the checkpoint, at the time. A timestamped scan of a tag fixed to a wall in a stairwell is that evidence. A signature in a logbook is not, because the logbook is portable and the signature can be written at any point during the shift, including all twelve entries at once near the end of it.
This is not a claim about guard dishonesty. Paper patrol logs get completed retrospectively for entirely mundane reasons: the round was walked but the log was filled in afterwards from memory, or two rounds got merged because the second was interrupted. The problem is that the record cannot distinguish those cases from a round that never happened, which means it cannot serve as proof of any of them.
What a client is actually buying
When a client contracts mobile patrol coverage of a warehouse compound at four rounds per night, they are buying deterrence, and deterrence depends on the rounds actually occurring at unpredictable intervals. The patrol log is how they verify they received what they paid for.
This makes patrol verification commercially different from most operational records. Attendance mostly matters internally until something is disputed. Patrol logs get read routinely by clients, which means their credibility is part of the service. An agency that can produce timestamped, location-bound patrol evidence has a genuine differentiator in a tender, and one that cannot is competing on price.
Designing the route rather than the checkpoints
The common mistake is to place checkpoints where it is convenient to mount a tag. The useful approach is to define the route from the risk assessment: which locations, in what sequence, at what frequency, and what the officer should actually do at each.
A checkpoint definition worth having includes the location, its position in the sequence, the expected time window, and the required action. That last element is what separates a meaningful patrol system from an attendance system with extra steps. Required actions might be a photograph of a specific area, a response to a short checklist (is the fire door closed, is the shutter secured), or a note. A scan alone confirms presence. A scan plus a checklist response confirms observation, which is what the client is actually paying for.
Frequency and sequence deserve thought. Fixed-interval patrols at fixed times are predictable, and predictable patrols provide less deterrence than randomised ones. A system that can require four rounds per shift without specifying the exact times, while still flagging if the gaps between them are implausibly short, produces better security than a rigid schedule.
Why the scan token cannot be a static code
A printed QR code containing a fixed string is trivially defeated: photograph it once and scan the photograph from anywhere thereafter. If the patrol system accepts that scan, it has produced a record that is worse than a paper log, because it carries a false air of technical rigour.
The design requirement is that the scan payload cannot be usefully replayed. Approaches include tokens that are unguessable and unique per checkpoint so they cannot be constructed by someone who understands the format, combined with cross-checks against the device location and the scan sequence. If a checkpoint in a basement plant room is scanned while the phone reports a GPS position outside the compound, that is an anomaly worth flagging regardless of whether the token was valid.
NFC tags raise the bar further, since presenting a physical tag to a phone is harder to fake remotely than reading an optical code, though it requires the officer’s device to support it.
Missed checkpoint detection is the actual feature
Everything above produces records. The operational value comes from the system noticing what did not happen.
A patrol round with an expected sequence and expected timing lets the system detect a checkpoint scanned late, a checkpoint skipped entirely, a round abandoned partway, and a round completed implausibly fast for the physical distance involved. Each of those is a different operational signal.
Late and skipped checkpoints during a shift should surface to a supervisor while the shift is still running, because that is when something can be done. A round abandoned at checkpoint three of eight might mean the officer was diverted by something legitimate, or might mean they are unwell, or might mean nothing good. Discovering it the next morning from a report is discovering it too late to matter.
Patterns across shifts are the second-order value. A checkpoint that is consistently missed by every officer usually means the checkpoint is badly placed or the route timing is unrealistic, not that everyone is skipping it. That is a route design problem masquerading as a compliance problem, and it only becomes visible in aggregate.
The link to incidents and risk
A patrol anomaly is often the earliest available signal that something needs attention. An officer who finds a shutter unsecured, photographs it and notes it at checkpoint five has generated something that sits between a routine log entry and a formal incident.
The workflow that works is allowing a patrol observation to escalate into an incident report directly, carrying its evidence with it, rather than requiring the officer to file a separate report from scratch. Friction at that transition is why minor observations go unreported until they become major ones.
The same signal feeds risk assessment. A hazard repeatedly observed at the same location during patrol is evidence that the site risk register is either missing that hazard or that its mitigation is not working. Linking patrol observations to the register is what keeps the register current rather than annual.
How Moxogo implements it
Moxogo Security supports patrol route definition with ordered checkpoints, expected frequency and required actions per checkpoint, including photo capture and checklist responses rather than scan-only confirmation. Checkpoint scan tokens are generated as unguessable per-checkpoint values rather than static readable codes, specifically to prevent the photograph-and-replay defeat, with device location cross-checked against the expected checkpoint position.
Missed and late checkpoint detection runs against the expected route sequence and timing, surfacing anomalies during the shift rather than in a next-day report, and patrol logs compile automatically per shift with their anomalies and captured evidence attached. A patrol observation can escalate into a formal incident record carrying its photos and notes forward, and the resulting patrol and incident history is what feeds site risk register review.
Because patrol runs through the same guard app as clock-in, it inherits the offline queue: scans captured in a basement or plant room hold locally with their timestamp and sync when connectivity returns, which matters because the locations where patrol verification is most valuable are frequently the locations with no signal.
A practical test
Take a patrol log from last month at any site. For any single entry, ask what evidence exists that the officer was at that location at that time, beyond the entry itself. If the entry is its own only evidence, the log is a record of what someone reported rather than a record of what occurred. For most sites that distinction never becomes important. For the one site where a client eventually asks, it becomes the entire conversation.
Frequently Asked Questions
Why is a paper patrol log not proof a patrol happened? Because the log is portable and the entries can be completed at any time during the shift, including all of them at once at the end. The record cannot distinguish a round walked but logged late from a round that never happened, so it cannot serve as evidence of either.
Can a printed QR code be trusted as a checkpoint? Not if it contains a fixed readable string, because it can be photographed once and scanned from anywhere afterwards. Checkpoint tokens need to be unguessable and unique per checkpoint, ideally cross-checked against device location and scan sequence, or implemented as NFC tags which are harder to present remotely.
What should an officer do at a checkpoint besides scan? A required action that confirms observation rather than just presence: a photograph of a specified area, or a response to a short checklist such as whether a fire door is closed or a shutter secured. A scan alone proves someone was there; the checklist proves they looked.
When should a missed checkpoint be raised? During the shift, not in the next day’s report. A round abandoned partway might mean the officer was legitimately diverted, is unwell, or something worse, and all three are situations where a supervisor can act at the time and cannot act retrospectively.
What does it mean if every officer misses the same checkpoint? Usually that the checkpoint is badly placed or the route timing is physically unrealistic, rather than that everyone is skipping it. That is a route design problem visible only in aggregate patterns across shifts, which is why anomaly trending matters as much as individual anomaly alerts.
Related in this series
- Overview: What Does a Security Agency in Singapore Actually Need From an ERP?
- geofenced attendance
- incident management
- site risk registers


