Physical security operating domain
DCOS Secure Overview
A governed protective architecture that connects perimeter, access, video, intrusion, visitor, communications and response workflows while preserving local device behavior, privacy and evidence integrity.
- Access
- Open access
- Resource type
- Physical-security product and operating-model overview
- Primary audience
- Owners, security leaders, facility teams, IT and network architects, operations, compliance and delivery partners
- Product scope
- DCOS Secure, DCOS Network, DCOS Operations, Data Fabric and Assurance
Security as an operating system
Integrate the protective domain without flattening its authority.
DCOS Secure is the PrecisionDCOS component for perimeter protection, access control, video surveillance, intrusion detection, visitor management, critical communications, dispatch, security operations and evidence.
It may provide a full PrecisionX reference architecture, operate qualified existing VMS, PACS and intrusion platforms as a managed overlay or modernize selected systems while customer standards remain authoritative. The objective is one governed security operating model from physical event through assessment, response, work, restoration and evidence.
A camera, reader or alarm is not an operating outcome. The outcome is a detected, assessed, communicated, acted-on and evidentially closed event.
Layered protection
Design from site boundary to critical asset.
Site and perimeter
Fencing, gates, vehicle and pedestrian control, lighting, detection, radar or analytics where appropriate, perimeter video, signage and response routes.
Building envelope
Exterior doors, loading and service areas, mantraps where required, glass and opening protection, intercom, access control, video and intrusion state.
Operational areas
Offices, control rooms, electrical and mechanical rooms, storage, receiving, NOC/SOC, sensitive work areas and contractor zones with role-appropriate access and surveillance.
Data halls and customer areas
Layered identity, anti-passback or occupancy rules where required, door state, video, visitor escort, customer segmentation and operational response.
Racks and critical cabinets
Cabinet access, environmental or tamper state, BMC and management-network correlation, maintenance authorization and chain of custody where included.
Communications and response
Radios, dispatch, duress, intercom, mass or targeted notification, emergency contacts, guard or field response, law-enforcement and fire-service coordination as applicable.
Federated security systems
Keep qualified source platforms authoritative while sharing identity, events and evidence.
Scroll horizontally to see the full table.
| Function | Typical authoritative system | PrecisionDCOS integration |
|---|---|---|
| Physical access | PACS and door-controller platform | Identity context, alarm/event intake, access evidence, incident and maintenance linkage |
| Video | VMS and camera platform | Alarm association, live or recorded access within policy, health, retention state and evidentiary references |
| Intrusion | Intrusion panel or integrated security platform | Alarm, trouble, arm/disarm state, dispatch workflow and maintenance evidence |
| Visitor | Visitor-management system or approved site process | Sponsor, identity, access window, escort, acknowledgment and visit record |
| Intercom and duress | Intercom, call station or duress platform | Event intake, location, response, communication and evidence |
| ALPR and vehicle | ALPR or VMS analytics platform | Vehicle event, watchlist workflow, privacy controls and incident association |
| Guard and dispatch | Dispatch, guard-management or service platform | Assignment, acknowledgment, location, response, escalation and closure |
| Identity | Customer or PrecisionDCOS identity service | Role, tenant, employment or contract state, approval and deprovisioning workflow |
| Evidence | Source systems plus governed evidence repository | Linked event, clip/reference, access record, action, work, approval and retention metadata |
PrecisionDCOS does not require all video or security data to be copied into one store. High-volume video and native access records may remain in qualified domain platforms while PrecisionDCOS preserves canonical references, authority, time, retention state and case context.
Event to verified closure
Response is a designed service, not an afterthought.
- 01
Detect
A reader, door, camera, intrusion, duress, intercom, guard or integrated source produces an event.
- 02
Normalize
Preserve source identity, time, priority, quality, location and native event reference.
- 03
Correlate
Relate access, video, facility, network, visitor, maintenance and customer context.
- 04
Assess
Apply the approved severity, procedure, privacy and authority model.
- 05
Communicate
Notify the correct site, customer, guard, NOC/SOC, manager or public-safety contact.
- 06
Dispatch and act
Assign and track response within the approved role and local-system boundary.
- 07
Preserve evidence
Retain source references, clips or exports, access records, communications, approvals and actions under chain-of-custody and retention policy.
- 08
Restore and verify
Confirm the affected device, area, credential and procedure are returned to accepted service.
- 09
Review
Complete incident, problem, corrective-action and control-evidence obligations.
DCOS Secure may be customer-led, co-managed or fully managed. The order defines monitoring hours, event types, dispatch, guard and field coverage, customer approvals, law-enforcement or emergency coordination, evidence responsibility and exclusions.
Security data requires purpose and control
Preserve evidentiary value without creating uncontrolled surveillance.
Purpose and scope
State why video, access, visitor, ALPR, biometrics or other security data is collected and which sites, populations and use cases are included.
Least access
Restrict live view, playback, export, identity search, watchlists and administration by named role, tenant, purpose and case.
Time and lineage
Preserve source time, system time, camera or device identity, export metadata, transformation and case association.
Retention and legal hold
Apply the approved retention schedule, incident hold, customer contract and legal requirement. Do not imply one universal retention period.
Chain of custody
Record who accessed, viewed, exported, transferred, annotated or deleted evidentiary material within the supported source and evidence systems.
Privacy and external claims
Apply customer policy, applicable law and qualified legal review for notice, consent, biometrics, audio, ALPR, employee monitoring, public areas and cross-border processing. Do not make universal legal-compliance claims.
Engineer the complete protective service
Devices, network, policy and response must be accepted together.
Discovery and threat-informed Basis of Design
Define assets, threats, site and customer requirements, operating hours, staffing, privacy, existing platforms, response, life-safety interfaces, evidence and acceptance.
Detailed engineering
Produce device, coverage, door, lock, power, network, storage, identity, integration, event, communication, dispatch, authority and responsibility designs.
Staging and FAT
Configure platforms, identities, roles, events, integrations, retention, health monitoring, reports and representative device behavior before site deployment.
Installation and SAT
Validate field of view, image and lighting, access transactions, door and lock behavior, intrusion zones, intercom and duress, network, time, storage, failover, alarm routing, local behavior and labels.
Operational readiness
Confirm users, guard and dispatch procedures, customer notifications, incident severity, evidence handling, maintenance, spare, backup, restore, privacy, training and service commencement.
Lifecycle operations
Monitor device and storage health, access, alarms, firmware, certificates, configuration, capacity, retention, maintenance, false or nuisance alarms, response performance and end-of-support.
The DCOS Secure Overview includes
- Product and responsibility model
- Perimeter-to-rack protective architecture
- Access-control, video, intrusion and visitor domains
- Intercom, duress and critical communications
- Guard, dispatch and central security operations
- Existing-platform integration
- Identity and credential lifecycle
- Security-network architecture
- Local autonomy and degraded modes
- Event, incident and response lifecycle
- Privacy, retention and chain of custody
- Evidence and assurance integration
- Engineering, FAT, SAT and operational readiness
- Managed-service and lifecycle options
- Shared responsibility and exclusions
Frequently asked
Questions and answers
- Does DCOS Secure replace an existing VMS or access-control platform?
- Not necessarily. Qualified existing systems may remain authoritative under Managed Overlay or Hybrid Modernization. The design must establish supported interfaces, identity, event quality, administrative access, backup, lifecycle, privacy and operating responsibility.
- Can doors operate when the WAN or Cloud service is unavailable?
- The approved local door-controller and access system must continue according to the engineered local mode. Credential cache, lock behavior, egress, fire interface, alarm buffering and restoration are validated for the selected platform and site requirement.
- Does PrecisionX provide guards or licensed security installation?
- PrecisionX may provide, subcontract, coordinate or manage regulated or licensed services where permitted and expressly included. Qualified providers perform work requiring specific licensing or authority. The responsibility and customer-facing service boundary are documented in the order.
- Is video copied into the Data Fabric?
- Not by default. Video ordinarily remains in the qualified VMS or evidence store. PrecisionDCOS can retain health, event, identity, time, case, retention and export references and provide policy-controlled access without duplicating every stream.
- Does access to a security dashboard permit door control?
- No. View, assess, administer and actuate are separate privileges. Door actions require the approved platform role, procedure, authority, event context, logging and life-safety boundary.
Related resources
DCOS Network Architecture
Design the isolated, recoverable network that carries security systems.
Read resourceAssurance and ComplianceAssurance Services Overview
Connect physical-security controls and evidence to the assurance program.
Read resourceArchitecture BriefsAuthority and Safety Boundary Brief
Separate observation, response workflow and security-system actuation.
Read resourceDesign the protective service
Align devices, platforms, people and evidence.
Share the site, existing security systems, response model and protection objectives. PrecisionX will identify the appropriate design, integration and managed-operating scope.
