What Does a Security Agency in Singapore Actually Need From an ERP?
A licensed security agency in Singapore needs a system that does six things a general-purpose ERP does not: it has to block a guard from being deployed when a licence or certificate has lapsed, build rosters that respect rest hours and wage floors before anyone reviews them, verify that a clock-in happened at the post rather than at home, prove a patrol was physically walked, capture incidents in a form a client will accept, and turn verified hours into an invoice without anyone retyping them. Miss any one of those and the gap shows up either as a regulatory finding, an unbillable hour, or a client asking for evidence you cannot produce.
That list is unusual. Most ERP platforms assume work happens in one place, on weekday hours, performed by staff whose right to do the job is not itself a tracked, expiring asset. Security manpower breaks all three assumptions at once. Guards work across many client sites on rotating shifts around the clock, their eligibility to stand a specific post depends on documents with expiry dates, and the billable unit is an hour that somebody has to prove actually happened.
This post maps the whole problem. Each section is a summary with a link to a longer piece on that specific area.
Why the security vertical resists generic software
Three constraints compound, and it is the compounding rather than any single constraint that defeats spreadsheets.
The first is regulatory. Agencies and officers are licensed by the Police Licensing and Regulatory Department. Wage floors for the sector come from the Progressive Wage Model administered through the Ministry of Manpower. Agency capability is periodically assessed through the Security Agencies Competency Evaluation. Personal data on guards and clients falls under the Personal Data Protection Act. None of these are optional, and all of them produce evidence requirements.
The second is temporal. A 24-hour post covered by 12-hour shifts needs at least two guards a day, every day, plus rest-day relief, plus cover for medical leave and no-shows. Multiply by the number of posts across every contract and the roster becomes a constraint-satisfaction problem rather than a filling-in exercise.
The third is evidentiary. Almost every commercial and compliance question an agency faces reduces to whether you can prove it. Was the guard licensed on the day they stood that post. Did they clock in at the site. Was the patrol walked or written up in the guardhouse. Were those overtime hours actually worked. Spreadsheets and WhatsApp threads hold information, but they do not hold proof, because anything in them can be edited afterwards with no record of who changed what.
The compliance layer: eligibility as a hard gate
The single highest-consequence function is preventing a non-compliant deployment. An officer whose licence has lapsed standing a post is a regulatory exposure for the agency, not just an administrative slip.
The mechanism that works is a registry of licences and certificates with real expiry dates, an alert ladder that fires at 90, 60, 30 and 7 days before each expiry, and a hard block in the scheduler so an expired document makes a guard ineligible for posts that require it. The alert ladder matters because licence renewal is not instant; a 7-day warning is a crisis, while a 90-day warning is a task. The hard block matters because alerts alone rely on somebody acting on them.
Wage compliance is a separate engine with the same shape. The Progressive Wage Model sets minimum basic monthly wages by officer grade, stepping up on a published schedule. An agency needs to prove compliance per officer, per site and per contract, at points in the past as well as today, which means retaining historical snapshots rather than only the current state.
Agency-level capability assessment and site risk management sit alongside both, and they are where most agencies are weakest because the evidence is qualitative and scattered.
The operations layer: coverage, proof and exceptions
Rostering is where the constraints meet each other. A usable scheduler encodes availability, grade requirements per post, certificate requirements per post, maximum consecutive days, minimum rest between shifts, weekly rest days, overtime caps and client-specific rules such as rotation limits at a single site. It then generates a draft, highlights gaps by severity, and suggests eligible replacements ranked by suitability rather than by who answers the phone first.
The important design point is that constraint checking happens at the moment of assignment, including manual drag-and-drop changes. A system that validates only on generation gets bypassed within a week.
Attendance is the proof layer beneath the roster. Clock-in by mobile GPS inside a site geofence, by QR or NFC at a fixed point, or by biometric terminal in a control room, each with automatic flags for late, early, absent and out-of-geofence events, and a supervisor workflow for the exceptions. Verified attendance is what everything downstream depends on, because an unverified hour cannot be safely paid or billed.
Patrol verification answers a narrower question: was the round walked. Checkpoints with scan tokens, defined routes and frequencies, required actions such as a photo or a checklist response, and automatic detection of missed or late checkpoints. A paper patrol log can be completed in advance from a chair; a timestamped scan at a physical checkpoint cannot.
Incidents are the highest-visibility output an agency produces, because clients read them. Structured capture by incident type and severity, a workflow from report through triage, investigation and closure with timers on each stage, offline drafting for guards without signal, and a client-ready report that holds up when reviewed weeks later.
The commercial layer: from verified hours to cash
Security contracts come in several shapes at once. Retainers bill a fixed monthly amount. Man-month contracts bill a rate against headcount. Man-hour contracts bill from timesheets. Event work is ad hoc. Many agencies run all four, sometimes for the same client, with rate cards that vary by officer grade, shift type, public holiday and overtime multiplier, plus client-specific surcharges.
Revenue leaks at the joins. Overtime worked but not captured. Night differential not applied. A variation order agreed verbally and never priced. A retainer that quietly under-recovers because the contracted headcount rose. Each leak is small and each is invisible without a system that carries verified hours through to invoice lines without a manual retyping step in between.
The field layer: reaching guards where they actually are
None of the above works if guards cannot use it. A guard on a night shift at a logistics yard has a phone, variable signal and no appetite for a desktop portal. That constrains the design: a mobile app that installs without an app-store download, queues clock-ins offline and syncs when signal returns, plus notification channels guards already read. In practice in Singapore that means WhatsApp, with simple keyword replies to confirm a shift or report sickness rather than expecting guards to log in.
The same layer is where analytics becomes operationally useful rather than decorative. A daily fatigue score computed from consecutive working days, weekly hours, night shifts and time since the last rest day turns an abstract welfare concern into a ranked list a supervisor can act on before somebody makes a mistake on post. A morning advisory that leads with expiring licences, today’s coverage gaps, overnight incidents and overtime outliers replaces the ritual of checking six dashboards.
How Moxogo approaches this
Moxogo Security is built on Odoo 19 as a set of modules that install independently and share one data model, so an agency can start with the compliance and rostering core and add patrol, client portal or billing later without re-platforming. The design goals are stated plainly: prevent assignment of guards without valid licences, enforce wage and working-hour rules inside the scheduling logic rather than checking afterwards, and give operations a single live view of coverage. Those are targets the system is engineered against rather than published customer averages, and any agency evaluating it should ask to see them demonstrated against their own contracts and rate cards.
The broader platform context is relevant here. The same CRM, Invoicing Management and Accounting and Finance modules that support Moxogo’s other verticals carry the commercial side of security operations, which is why verified attendance can reach an invoice without an export-and-reimport step.
Where to start
For most agencies the sequence that works is compliance first, rostering second, attendance third. Compliance first because it is the highest-consequence gap and the easiest to demonstrate value on. Rostering second because it is where the daily hours go. Attendance third because it is what makes rostering real and billing accurate. Patrol, client portal and analytics are genuinely valuable and genuinely second-phase.
If you want to work out which of the six areas above is costing you most right now, the practical test is to pick a month that has already closed and try to answer three questions from your existing records: which guards stood posts requiring a certificate that had expired, how many hours were worked but never billed, and how many patrol rounds can you prove were walked. The area where you cannot answer is the area to fix first.
Frequently Asked Questions
Why can a general ERP not handle a security agency? Because general ERP assumes work happens at one location on predictable hours by staff whose eligibility is static. Security manpower involves multiple client sites, 24-hour rotating coverage, and guard eligibility that depends on licences and certificates with expiry dates, which has to gate scheduling rather than sit in a filing cabinet.
What is the highest-risk gap for a Singapore security agency? Deploying an officer whose licence or required certificate has lapsed. It is a regulatory exposure rather than an administrative error, and manual tracking reliably misses expiry windows across a workforce of any size.
What should an agency implement first? Licence and certificate compliance with hard scheduling blocks, then constraint-based rostering, then verified attendance. Patrol verification, client portals and analytics deliver real value but depend on the first three being in place.
How does verified attendance affect billing? It is the foundation of it. Hours that cannot be verified cannot safely be paid or invoiced, so overtime, night differential and public holiday premiums either get missed or get disputed. Carrying verified hours straight through to invoice lines removes the manual step where most billing leakage happens.
Does a guard-facing mobile app need to work offline? Yes. Guards work in basement car parks, plant rooms and logistics yards where signal is unreliable, so clock-ins and incident drafts have to queue locally and sync when connectivity returns. An app that requires live connectivity produces gaps in exactly the records that matter most.
The rest of this series
- How Do You Stop an Unlicensed Guard From Being Deployed?
- Progressive Wage Model Compliance for Security Agencies
- SACE, Risk Registers and Audit Readiness
- Why Spreadsheet Rosters Fail at 24/7 Security Coverage
- Geofenced Clock-In: Ending Buddy Punching in Security
- Proving a Patrol Actually Happened
- Incident Reporting That Survives a Client Audit
- Where Security Contract Billing Leaks Revenue
- The Field Layer: Guard App, WhatsApp and AI Advisories


