The short answer
Ask AI for a draft. Check every detail before using it.
A one-page, review-ready handoff organized into active incidents, impaired systems, watch items, pending actions, evidence to preserve, and named follow-up fields.
Five-minute practice · Fictional information only
Make your first draft.
- Open an AI assistant your organization allows for practice with made-up information.
- Copy the complete practice prompt below and paste it into a new chat. Keep the fictional notes as written.
- Compare the answer with the finished example and reviewer corrections. Answers may vary; every factual claim must follow from the notes.
- Keep missing information marked as unknown. This is a practice draft; do not use it as an operating instruction.
Turn the fictional notes below into a handoff under 350 words. Use sections: Active incidents; Impaired systems; Watch items; Pending actions; Evidence or logs to preserve; Open questions. Preserve VERIFIED, UNVERIFIED, ACTION, and QUESTION labels and source references. Use only the notes. Keep expected completion separate from confirmed completion. Do not infer fault, intent, priority, dispatch, or emergency action. Mark missing information “not provided”; missing incident information does not establish that there are no incidents. Label the result “Fictional practice draft — human review required.”
FICTIONAL PRACTICE NOTES — not a real site or operational record
Shift: 1 September 2026, 18:00–22:00. All times are fictional local time.
VERIFIED [LOG-1, 18:00]: DEVICE-A is under scheduled maintenance. Completion is expected at 22:00 and has not been confirmed.
ACTION [TICKET-1, 18:05]: Facilities role to confirm DEVICE-A maintenance status by 22:00.
ACTION [LOG-2, 18:10]: Confirm tomorrow's vendor arrival time by 19:30. Owner: not provided.
UNVERIFIED [NOTE-1, 17:55]: Outgoing role reported a recurring alert at DEVICE-B. No event-log check has been completed. Priority: not provided.
QUESTION [LOG-3, 18:15]: Who owns vendor confirmation? Due time for answering: not provided.
No other information was supplied about active incidents or evidence-preservation requirements.Fit before tools
Use this workflow only when the operating conditions fit.
Use it when
- The current handoff varies by officer or shift.
- Important ownership and deadlines disappear inside narrative notes.
- The organization has approved an AI tool for sanitized administrative drafting.
- An outgoing officer can verify the final draft against source records.
Do not use it
- To summarize an active emergency instead of following the approved command process.
- With raw incident reports, exact vulnerabilities, badge data, personal data, camera locations, credentials, or restricted investigative facts in an unapproved tool.
- To infer intent, blame, threat, or officer performance.
Prepare first
Define the approved input before opening an AI tool.
Inputs to prepare
- A synthetic or sanitized list of open items
- Neutral location labels such as ZONE-A rather than a real sensitive location
- Approved status vocabulary: active, monitoring, awaiting owner, closed
- Role placeholders rather than names
- The required handoff sections and maximum length
Keep out of the workflow
- Names and personal identifiers
- Exact camera, alarm, access, or patrol vulnerabilities
- Badge numbers, credentials, codes, network details, or emergency contacts
- Medical, HR, legal, or active investigative information
- Unverified claims stated as fact
Default rule: If the information boundary is not explicit, do not paste, upload, connect, or transmit the material. Practice with made-up information until the responsible owner approves the tool and information you can use.
Implementation workflow
Complete the work in six reviewable steps.
- 01
Define the handoff contract
Write the required sections before opening an AI tool: time window, active incidents, impaired systems, watch items, pending dispatches, evidence or logs to preserve, owner role, due time, and questions for the incoming supervisor.
- 02
Sanitize the source notes
Replace identities and sensitive locations with stable placeholders. Remove credentials and details that would reveal a weakness. Keep a separate local mapping only if policy allows and the operational process needs it.
- 03
Separate facts from status
Label each note as verified fact, reported but unverified, requested action, or open question. If a note cannot be classified, do not let the model resolve the ambiguity.
- 04
Generate the structured draft
Use the template below. Require the assistant to preserve uncertainty, refuse to invent missing owners or times, and list any incomplete item under Open questions.
- 05
Reconcile against sources
The outgoing officer checks every time, status, owner, and evidence reference against the approved log, ticket, dispatch record, or supervisor direction. Delete unsupported prose.
- 06
Release and close the loop
The outgoing and incoming roles confirm the handoff through the normal process. Record corrections so the template improves without using the AI draft as the system of record.
Copyable working aid
Use this template, then adapt it to the approved workflow.
The template deliberately exposes missing evidence and preserves human approval. Replace bracketed fields; do not paste prohibited information.
ROLE
You are a physical security shift-handoff drafting assistant.
OBJECTIVE
Turn the sanitized notes below into a concise handoff. Do not infer identity, intent, blame, risk, or missing facts.
REQUIRED SECTIONS
1. Active incidents
2. Impaired systems
3. Priority watch items
4. Pending actions: owner role + due time
5. Evidence or logs to preserve
6. Open questions for the incoming supervisor
RULES
- Preserve the labels VERIFIED, UNVERIFIED, ACTION, and QUESTION.
- Write “not provided” for a missing owner, time, or source.
- Do not create emergency instructions.
- Keep the draft under 350 words.
SANITIZED NOTES
[Paste public, synthetic, or approved sanitized notes here.]Worked example
A finished example you can check.
These fictional examples and corrections illustrate the review process. They are not records of real incidents or measured model performance.
Practice a handoff for a completely fictional shift. Compare the draft with the source notes and the reviewer corrections below.
FICTIONAL PRACTICE NOTES — not a real site or operational record Shift: 1 September 2026, 18:00–22:00. All times are fictional local time. VERIFIED [LOG-1, 18:00]: DEVICE-A is under scheduled maintenance. Completion is expected at 22:00 and has not been confirmed. ACTION [TICKET-1, 18:05]: Facilities role to confirm DEVICE-A maintenance status by 22:00. ACTION [LOG-2, 18:10]: Confirm tomorrow's vendor arrival time by 19:30. Owner: not provided. UNVERIFIED [NOTE-1, 17:55]: Outgoing role reported a recurring alert at DEVICE-B. No event-log check has been completed. Priority: not provided. QUESTION [LOG-3, 18:15]: Who owns vendor confirmation? Due time for answering: not provided. No other information was supplied about active incidents or evidence-preservation requirements.
FICTIONAL PRACTICE DRAFT — HUMAN REVIEW REQUIRED Shift: 1 September 2026, 18:00–22:00; fictional local time ACTIVE INCIDENTS Information not provided. This does not confirm that there are no active incidents. IMPAIRED SYSTEMS VERIFIED: DEVICE-A is under scheduled maintenance. Completion is expected at 22:00 and has not been confirmed. [LOG-1, 18:00] WATCH ITEMS UNVERIFIED: Recurring alert at DEVICE-B reported by outgoing role. Event-log verification is outstanding. Priority: not provided. [NOTE-1, 17:55] PENDING ACTIONS ACTION: Confirm DEVICE-A maintenance status. Owner: Facilities role. Due: 22:00. [TICKET-1, 18:05] ACTION: Confirm tomorrow's vendor arrival time. Owner: not provided. Due: 19:30. [LOG-2, 18:10] EVIDENCE OR LOGS TO PRESERVE Requirements not provided. This draft creates no retention instruction. OPEN QUESTIONS QUESTION: Who owns vendor confirmation? Due: not provided. [LOG-3, 18:15] QUESTION: Who will verify the DEVICE-B report, and by when? Not provided. [NOTE-1, 17:55]
- Replace “maintenance complete at 22:00” with “completion expected at 22:00; not confirmed.” LOG-1 gives a forecast.
- Remove an invented vendor-confirmation owner. Facilities is assigned only to TICKET-1.
- Replace “DEVICE-B is faulty” with the unverified report and outstanding event-log check.
- Replace “no active incidents” with “information not provided.” Missing information cannot establish an all-clear.
Quality control
Review the artifact and measure whether it improved the work.
Release checklist
- Every statement maps to an approved source or is labeled unverified.
- No identities, sensitive locations, credentials, or vulnerabilities remain.
- Every open action has an owner role and due time—or explicitly says not provided.
- The draft does not create dispatch, access, or emergency authority.
- The incoming shift can distinguish active facts from watch items and questions.
- A human released the handoff through the approved system of record.
Measures worth tracking
- Percentage of open actions with owner and due time
- Number of unsupported statements removed during review
- Incoming-shift clarification requests per handoff
- Minutes to produce and verify the handoff
- Open items carried across more than one shift without resolution
Stop conditions
Treat these outcomes as failures, not minor editing issues.
The draft converts an unverified note into a fact.
A sensitive location or vulnerability survives sanitization.
An action appears complete because the prose sounds decisive.
The team begins treating the AI output as the official incident or dispatch record.
Escalate instead of improvising: Site-specific risk assessment, emergency action, legal interpretation, employment action, identity determination, biometric use, and consequential access or dispatch decisions require the approved professional and organizational process.
Practical questions
Questions to resolve before operational use.
Can I paste an incident report into a public AI tool?
No. Use only information explicitly approved for that tool. Raw incident reports commonly contain identities, locations, vulnerabilities, evidence, and investigative details that require stricter handling.
Should the AI decide which items are high priority?
No. Provide approved priority labels or escalation rules. The assistant may organize those labels but should not infer operational priority from incomplete notes.
What should be retained?
Follow the organization’s records policy. At minimum for a pilot, keep the sanitized input, prompt version, reviewed output, corrections, approver role, and date outside the AI tool.
Sources and scope
Use authoritative guidance, then apply the organization’s own requirements.
- NIST AI Risk Management Framework Voluntary framework for governing, mapping, measuring, and managing AI risk across the lifecycle.
- NIST Generative AI Profile (NIST AI 600-1) Cross-sector guidance for risks that are unique to or intensified by generative AI.
This guide is vendor-neutral practitioner planning guidance, updated 2026-09-07. It is not a compliance determination, site risk assessment, emergency procedure, or substitute for qualified legal, privacy, cybersecurity, safety, engineering, or security review. Product capabilities and applicable requirements change; verify them with current primary documentation.
Next step
Finished reading? Turn the pattern into practice.
Officer training
Read guideGoverned Prompt Workbench
Open toolProgress is saved only in this browser. Nothing is sent to physicalsecurity.AI.