Insights
Commercial Security & Access Control: A Building Guide
Levaru Operations Team
Most commercial buildings are not broken into. They are walked into. The stairwell door propped open with a fire extinguisher because the smokers got tired of badging back in, the credential still active for an employee who left eleven months ago, the reader on the loading dock that failed in the spring and now just stays unlocked because that was easier than filing a work order — these are the ways people get into buildings that did not intend to let them in. Meanwhile the cameras are recording, the alarm is armed, and the security budget is being spent almost entirely on equipment.
That gap between what a building has and what a building actually does is the subject of this guide. Building security is not a product you install; it is a program you run, and the parts of it that fail are almost never the exciting parts. This is how we approach security services for commercial properties across Northern Virginia, Washington DC, and Maryland — what the layers are, which ones do the real work, who is responsible for what in a multi-tenant building, and where the money is usually misallocated.
What are the layers of commercial building security?
It is useful to think in five layers, roughly in order of how much risk each one actually closes per dollar.
Physical hardening is the doors, locks, frames, glazing, gates, fencing, and lighting. It is the least glamorous layer and the one most often deferred, because a strike plate that no longer seats properly is a maintenance item rather than a security purchase. It is also the layer everything else depends on: a door that does not latch cannot be secured by any system.
Access control is the electronic decision about who may open which door, when. Card readers, mobile credentials, keypads, and the software behind them.
Video surveillance is cameras and recording. Note what this layer does and does not do — it is overwhelmingly a forensic and deterrent layer, not a preventive one. Video tells you what happened. It very rarely stops it.
Detection and alarm is intrusion sensors, door-forced and door-held alarms, glass break, and the monitoring service that receives them. This is the layer that turns an event into a notification while it is still happening.
Human presence is guards, patrols, concierge and lobby staff, and after-hours response. It is by a wide margin the most expensive layer per unit of coverage, and the only one that can exercise judgment.
The common failure pattern is a building that has invested heavily in layers three and five while layers one and two quietly degrade. Cameras get budget because they are visible and easy to justify. Door hardware does not, because nobody has ever been praised for a latch that worked.
How does commercial access control actually work?
An access control system is three things: credentials (what a person carries), readers and locking hardware (what is on the door), and a controller and database (what makes and records the decision).
Credentials have moved considerably. Older buildings in this region still run 125 kHz proximity cards, which are trivially cloneable with equipment that costs less than dinner. Newer installations use encrypted smart credentials, and increasingly mobile credentials on a phone. If your building is still on legacy prox, that is worth knowing — not necessarily worth an emergency replacement, but it should be a line in your capital plan rather than a surprise.
The locking hardware matters more than most owners expect. Electric strikes, magnetic locks, and electrified mortise locks behave differently under power loss, under alarm, and under abuse, and each carries life-safety requirements about free egress that are not optional. A maglock installed without a proper egress path is both a code problem and an inspection finding, and it is a common one.
The database is where the program lives or dies. Every credential is a small standing permission that persists until somebody removes it. Systems accumulate. A ten-year-old building’s credential list, if it has never been audited, will typically contain former employees, departed tenants’ staff, contractors from a completed project, and a handful of entries nobody can identify at all.
Why do credential audits matter more than new hardware?
Because the failure they prevent is the one that actually happens.
A credential audit is a reconciliation: every active credential in the system, matched against a current roster of who should have access to what. In a multi-tenant building that means asking each tenant to confirm their own list, which is the part that takes the time. What it surfaces is consistent — credentials for people who have left, access levels that were granted temporarily for a project and never revoked, and doors whose schedules no longer match how the building is used.
The discipline is not complicated. It is quarterly for most buildings, tied to tenant move-ins and move-outs as they occur, and it costs a few hours of coordination. What makes it rare is that it belongs to nobody by default: the integrator who installed the system left after commissioning, the property manager has a login but not a mandate, and the tenants assume the landlord is tracking it. It sits in exactly the gap that a managed program is supposed to close.
The same logic applies to keys. Buildings that have moved to electronic access often still have a mechanical master key system running underneath it, with no record of who holds what. A building can have a modern access control system and still be, in practice, keyed to a set of keys distributed over two decades.
What should a building expect from cameras and video retention?
Thirty days of retention is the working baseline for most commercial properties — long enough that an incident discovered late in the month still has footage behind it, short enough to be affordable. Some tenant leases, insurers, or regulated tenants will require more; that is worth confirming rather than assuming.
Retention is the easy question. The harder ones are coverage and function.
Coverage means the entries, loading docks, garage levels, elevator lobbies, and any cash- or asset-handling areas are actually in frame — not almost in frame, not covered by a camera whose view is now blocked by a sign installed last year. Coverage decays quietly as buildings change.
Function means every camera is recording today. The single most common finding in a security review is a camera that failed months ago and was never noticed, because nobody looks at a camera until they need it, and the moment they need it is the moment they discover it. This is a maintenance problem wearing a security costume, and it is solved the same way every other maintenance problem is: cameras belong on a preventive maintenance schedule with a verification step, and a failed camera should generate a work order the same way a failed rooftop unit does.
Video also carries obligations. Recording in shared commercial space is generally permissible, but signage expectations, audio recording rules, and retention of footage that becomes evidence all vary — and audio in particular is treated far more restrictively than video in this region. Camera placement into spaces with a reasonable expectation of privacy is a liability question, not a coverage question.
Do you need security guards, and how is that regulated in the DMV?
Guards are the right answer for a specific set of conditions: a lobby that requires a human decision, a property with a genuine incident history, a tenant mix that expects visible presence, or a building where after-hours response times from anyone else are unacceptable. They are the wrong answer as a default, because a single 24/7 post costs more per year than most buildings’ entire electronic security program.
The regulatory picture matters here, and it is where we are precise about what Levaru does and does not do. Security officers in this region must work for licensed security businesses — in Virginia that is regulated through the Department of Criminal Justice Services, with parallel licensing regimes in the District and in Maryland. We manage guard services rather than self-perform them: we vet and contract licensed guard firms, write the post orders, set reporting standards, and supervise performance inside the same program that runs the rest of the building. That is the same hybrid model we use across the regulated trades — the routine layer handled directly, the licensed work performed by qualified licensed firms under our oversight.
What separates a guard program that works from one that does not is almost never the guard. It is the post orders. A post order that says “monitor the lobby” produces a person sitting in a lobby. A post order that specifies the patrol route, the interval, the doors to physically check, what to do when a door is found propped, who to call at 2am, and what gets written down produces a security function. Ask to see the post orders for any building you are evaluating; if they are generic, the program is generic.
Who is responsible for security in a multi-tenant building?
This is the question that causes the most friction, and the answer lives in the lease.
Broadly, the landlord is responsible for the building envelope, common areas, base building access control, and the systems that serve everyone — perimeter doors, lobbies, elevators, garages, stairwells, loading docks. The tenant is responsible for security inside their own premises, including any supplemental access control on their suite door, their own alarm, and the conduct of their own staff and visitors.
The friction lives in the seams. Who deactivates a departing tenant employee’s building credential — the tenant who knows they left, or the landlord who owns the system? Who pays when a tenant wants their suite on the base building system rather than a separate one? Who is liable when a tenant’s contractor props a stairwell door for a week?
None of these are hard once they are decided; all of them are painful when they are decided during an incident. A functioning building answers them in writing, in advance, and tells every tenant the answer at move-in. Reviewing that alongside the certificate of insurance requirements you already collect from tenants and contractors is the natural place to do it, since both are about who carries which risk.
How does security connect to the rest of building operations?
More tightly than most programs treat it.
Nearly every security failure described above is a maintenance failure at heart. A failed reader, a door that no longer latches, a camera that stopped recording, a light out over the dock — each is a work order that nobody filed, usually because there was no obvious place to file it. When security equipment lives outside the building’s maintenance system, it degrades invisibly, and the degradation is only discovered adversarially.
Putting security assets into the same asset register as everything else fixes this structurally. Every reader, camera, panel, and door position switch becomes a tagged asset with a location, a maintenance interval, and a history — the same treatment described in our guide to QR-code asset tagging. A failed device then generates a work order automatically rather than waiting to be noticed, and the credential audit becomes a recurring task rather than an intention.
This is also where security meets emergency planning. Access control is the system that will either help or hinder you during a lockdown, an evacuation, or an after-hours incident, and the time to discover which is not during one. The scenarios in our emergency preparedness guide for property managers all have an access-control dimension: who can get in, who can get out, which doors fail secure and which fail safe, and whether responding agencies can enter without breaking something. Clients on our platform see all of it in one place, because a building’s security posture is not separable from its condition — the CMMS is included with our management, not sold as an add-on.
What goes wrong most often?
A short list, drawn from the patterns above rather than from any one property:
Credentials outlive people. The most common real vulnerability in commercial buildings, and the cheapest to fix.
Doors get defeated by their own users. Propping is a symptom. If a door is being propped daily, the access design is wrong for how people actually move through the building, and no amount of enforcement will outlast the inconvenience.
Equipment fails silently. Cameras, readers, and door contacts all fail without announcing it. Only a verification schedule catches this.
Systems are installed and then orphaned. The integrator commissions the system, hands over a login, and leaves. Two years later nobody knows the software version, whether it is under support, or who has administrative access.
Spending is inverted. Money goes to the visible layers while the door hardware, lighting, and credential hygiene that close most of the real risk are deferred as maintenance.
Security has no place in the compliance calendar. Alarm testing, camera verification, credential audits, and post-order reviews are all recurring obligations with no statutory deadline forcing them, which is exactly why they get skipped. They belong on the same building compliance calendar as the inspections that do have deadlines.
Where should a building start?
Start with an assessment, not a purchase. Walk the perimeter after dark. Pull the credential list and try to identify every entry on it. Test whether every exterior door latches and locks on its own. Pull up each camera and confirm it is recording. Read the post orders if there are guards, and write them if there are not.
That exercise costs nothing but time and will tell you more than a vendor proposal, because it produces a list of your building’s actual gaps rather than a list of a vendor’s actual products. Almost always, the first several items on it are maintenance and administration rather than capital — which is good news, because those are the items you can close this quarter.
If you would like that assessment run for you, and the resulting program managed inside the same operation that maintains the rest of the building, request a proposal and we will walk the property with you.
Frequently asked questions
What is the most common security gap in commercial buildings?
Active credentials belonging to people who no longer need them, and exterior doors that no longer latch reliably. Both are administrative or maintenance issues rather than equipment gaps, which is precisely why they persist — no vendor sells a fix for them, so nobody proposes one.
How often should access credentials be audited?
Quarterly is a reasonable standard for most commercial buildings, with additional reconciliation triggered by tenant move-ins, move-outs, and any project that issued temporary contractor access. The trigger-based audits matter as much as the calendar ones, because that is when the largest batches of credentials go stale.
How long should commercial buildings keep security camera footage?
Thirty days is the common working baseline. Check your leases and your insurance requirements before settling on it — some tenants and some carriers specify longer, and that obligation sits with the building rather than with the tenant who requires it.
Does Levaru provide security guards directly?
No — we manage guard services rather than self-performing them. Security officers in this region must work for licensed security businesses, so we vet and contract licensed firms, write the post orders, set reporting standards, and supervise performance as part of the building’s overall program. You get a managed guard function without taking on another vendor relationship yourself.
Should a building replace legacy proximity cards?
Usually yes, but rarely urgently. Older 125 kHz proximity credentials are easily cloned, so they should be treated as a planned capital item alongside other system upgrades rather than as an emergency. Sequence it with other access control work — replacing credentials and readers at the same time as a controller upgrade costs far less than doing each separately.
Who pays for security in a multi-tenant commercial building?
Base building security — perimeter access control, common area cameras, lobby staffing, and monitoring — is typically a building operating expense recovered through CAM, while anything specific to a tenant’s own premises is that tenant’s cost. The exact split is set by the lease, which is why it is worth confirming in writing before an incident makes it urgent.
Do security systems need preventive maintenance?
Yes, and skipping it is the reason so many buildings discover a failed camera only when they need the footage. Readers, cameras, panels, batteries, and door position switches all belong on a maintenance schedule with a verification step, exactly like mechanical equipment.