Why does duty of care become harder as a property portfolio grows?
A single property can establish clear lines of responsibility. Staff know who manages the building, which security team responds to an alarm, and how an incident should be escalated. A large property portfolio is more complicated.
Hotels, offices, residential developments, construction sites, and shared public spaces each operate differently. They have different opening hours, access arrangements, risk profiles, and populations. The people present may include employees, contractors, security officers, residents, hotel guests, tenants, visitors, and members of the public.
Responsibility may also be distributed between property owners, management companies, facilities teams, tenants, and external security providers. Each party may understand its own role, but no single team automatically has a complete view of what is happening across the property.
The International Labour Organization’s Occupational Safety and Health Convention recognises that organisations operating simultaneously in one workplace need to cooperate in applying safety requirements. It also addresses the need for measures to manage emergencies and accidents.
For a property group, effective duty of care therefore requires more than individual safety measures at each location. It requires a way to connect those measures, understand who may be affected, and coordinate the organisations involved.
Who falls within a property group’s duty of care?
Duty of care is sometimes discussed as if it applies only to direct employees. In a property environment, the practical picture is much wider.
A facilities engineer attending a fault outside normal working hours may be alone in part of a building. A contractor may be working in an area unfamiliar to them. A hotel team may be responsible for guests who do not know the evacuation routes. A residential development may include people who need additional support during an emergency. Security personnel may be expected to respond before the property management team has established the full circumstances.
The appropriate responsibilities depend on the relationship between the organisation, the property, and the people involved. The operational question, however, is immediate: if an event occurs, can the organisation identify who may be affected and communicate with them?
Traditional staff lists do not always reflect the population of a property at a particular moment. Access records, visitor systems, work schedules, and hotel or tenant information may each hold part of the answer. If those sources remain disconnected, the response team may spend valuable time trying to determine who is present.
A stronger duty of care model begins with the ability to define relevant groups and locations before an incident. This allows the organisation to prepare communications, responsibilities, and escalation routes for the people who may need them.
Why do existing security measures still leave gaps?
Most established property groups already have substantial security arrangements. These may include access control, CCTV, alarm systems, patrols, control rooms, emergency plans, and contracted response services.
The problem is rarely the complete absence of protection. It is the separation between different measures.
An access-control alert may remain within a building system. A security officer may report an incident by telephone. A facilities team may coordinate its response through a separate messaging channel. Senior managers may receive updates through emails or calls that do not form part of the operational record.
Each system can perform its intended function while the organisation still lacks a shared view of the event. Teams may receive different versions of what has happened. Important decisions may not be recorded. Responsibility can become unclear when an incident moves beyond the boundaries of one location or contractor.
Individual alarm tools also have a limited role. They can tell a response team that somebody may need help, but they do not automatically establish the wider context, identify other affected people, coordinate several teams, or preserve the complete sequence of the response.
The gap is not necessarily another alarm or communication channel. It is the ability to bring information, people, and actions together when an event crosses operational boundaries.
How should local security teams and central leadership work together?
Local teams are usually best placed to respond first. They understand the site, know the people present, and can assess conditions directly. Central leadership has a different responsibility. It must identify wider consequences, allocate additional support, and understand whether the event presents a risk to other properties or the wider organisation.
Neither perspective is sufficient on its own.
If every decision is centralised, local action may be delayed. If every incident remains local, senior leaders may not learn about a serious event until it has escalated. A property group therefore needs clear thresholds for when an incident remains under local management and when it requires wider coordination.
Those thresholds may consider severity, duration, disruption, public impact, or the number of locations affected. The process should identify who can escalate an event, who assumes responsibility at each level, and what information must accompany the handover.
A shared incident record is central to this model. It gives local responders a place to record developments and actions while allowing authorised managers to follow the event without repeatedly contacting the people managing it. Central teams can provide support without taking control away from those closest to the incident.
The result is a clearer division of responsibility: local teams manage the immediate response, while central leadership maintains oversight, coordinates wider resources, and addresses organisational consequences.
How can one safety framework work across different types of property?
Consistency does not mean requiring every property to follow an identical procedure. It means establishing a common structure that each site can adapt to its own environment.
That structure should define how incidents are reported, assessed, assigned, escalated, and closed. It should also establish what information must be recorded, how affected people are contacted, and how responsibility passes between teams or shifts.
A hotel may need procedures that prioritise guest communication and evacuation. An office building may focus on employees, visitors, and business continuity. A construction site may need to account for changing contractor populations and restricted areas. A residential or retirement community may need plans for people who require additional assistance.
Each location can retain procedures appropriate to its risks while using the same overall method for managing an event.
ISO 45001 provides an international framework for occupational health and safety management. Its central elements include leadership, worker participation, hazard identification, risk assessment, emergency planning, incident investigation, and continual improvement.
A common framework makes testing more meaningful. Instead of confirming only that an alarm works, an exercise can test whether the organisation identifies the correct audience, assigns responsibility, communicates clearly, follows up with people who do not respond, and records the outcome.
It also makes comparison possible. The property group can identify recurring problems across locations, recognise where procedures are working, and apply lessons from one incident to the wider portfolio.
How should property groups balance visibility with privacy?
Effective incident response depends on relevant information, but that does not justify unrestricted access to personal data.
A duty of care platform may process employee details, location information, responses to safety messages, and incident records. The organisation should define why each category of information is needed, when it may be used, who can access it, and how long it should be retained.
The OECD Privacy Guidelines provide internationally recognised principles for handling personal data. These include limiting collection, specifying its purpose, restricting subsequent use, applying reasonable safeguards, and maintaining accountability.
There is no single location-sharing model that will suit every organisation or role. One customer may decide that location should be visible during assigned work or travel. Another may use event-based visibility, allowing it when someone requests monitoring, raises an alarm, or enters an area affected by an incident.
The correct configuration depends on the customer’s operating model, policies, and applicable data-protection requirements. What matters is that the decision is deliberate and clearly communicated.
Privacy and safety should not be treated as opposing objectives. A properly configured system can give authorised responders the information needed during an event while limiting access when there is no operational reason to view it.
What does a unified property duty of care model look like?
A unified model gives the organisation one place to understand what is happening, identify the people who may be affected, and coordinate the response.
When an incident is reported, the response team should be able to create a structured record containing the available facts, location, severity, and responsibilities. Relevant teams should be notified, actions assigned, and updates recorded as the situation develops.
If people need instructions or welfare checks, the organisation should be able to contact the relevant audience by location, role, or group. Responses should show who has acknowledged the message, who has confirmed their status, and who may require follow-up.
When responsibility changes between shifts, sites, or providers, the incoming team should be able to understand the incident without reconstructing it from calls and messages. Once the event is closed, the same record should support an after-action review.
This is the purpose of critical event management. It connects detection, communication, coordination, and resolution rather than treating them as separate activities.
How does AtlasNXT support property groups?
AtlasNXT is a critical event management platform designed to help organisations protect people and coordinate their response across different locations. It brings targeted communication, staff check-ins, incident management, and location-based information into one system.
AtlasNXT Incident Management provides a structured place to record what has happened, assign responsibility, and maintain a timeline of decisions and actions. Local responders and authorised managers can work from the same information while retaining responsibilities appropriate to their roles.
During a wider event, operators can send messages to people based on factors such as their location, role, or group. Check-ins allow recipients to confirm their status or answer a simple welfare question, helping the response team identify who is safe and who may require assistance.
ReachScore™ helps teams prepare before an emergency occurs. It assesses how likely an organisation is to reach its people by identifying potential problems such as missing contact information, disabled notification permissions, or recent communication failures. This allows teams to address communication gaps before an urgent message goes unanswered.
AtlasNXT also supports configurable location privacy. Each customer can determine when location information should be visible, which authorised roles may access it, and how that visibility fits its duty of care policies.
For property groups, the value lies in creating a shared operational picture across the portfolio. Local security and facilities teams can continue to manage events on the ground, while central leadership gains the visibility needed to support them, coordinate wider action, and learn from each response.
Property groups do not necessarily need more individual security measures. They need a way to connect the measures they already have. AtlasNXT helps turn separate alerts, teams, and procedures into a coordinated duty of care capability. Book a free demo.
References
International Labour Organization, Occupational Safety and Health Convention, 1981 (No. 155)
Organisation for Economic Co-operation and Development, OECD Privacy Guidelines


