This article first appeared in the Security Today Active Shooter Handbook, September 2026.
Most campuses have the cameras. Far fewer have tested who can get to them.
Why the first request for video costs more time than it should
Cameras cover entrances, corridors, parking structures, and residence halls. Large districts may operate thousands of them across more than a hundred buildings. When an officer arrives on campus and needs video, the question is rarely whether the footage exists. The real question is how many people stand between the officer and access to it.
In a traditional response, the officer contacts campus police or security, who then reach out to a security operations center, system administrator, or IT staff member with access to the video management system. The process works, but every handoff costs time and the chain is being assembled while the incident is still unfolding.
The most direct solution is to remove those handoffs and give authorized responders a secure way to access the video themselves.
What “first responders have access” actually means
Campuses often use the same language to describe responder access while meaning very different things. At one campus, a responding agency has pre-authorized entry through a federated system. At another, an officer calls the security operations center and asks an operator what is on screen. Both provide information, but only one delivers a true operational capability.
What separates them is a handful of details that look minor until they matter. Credentials that expired. Permissions nobody finalized. Software that is not installed where it is needed. Connectivity that was restricted for good reasons and never revisited. A procedure the people expected to use but have never practiced.
“The middle of a critical incident is not the time to install software, exchange credentials, determine permissions, or decide who is authorized to see what,” says Will Brock of Salient.
Who decides what an outside agency can see
The most common failure is not a permission set that is too restrictive or too broad. It is a decision nobody finished making. Campuses devote significant effort to securing video internally, yet outside responder access often remains an unresolved policy question, until an emergency forces an answer under the worst possible circumstances.
A mature approach settles it in advance through role-based permissions: which agencies may connect, which users are authorized, which cameras or facilities they may see, under what circumstances, and how that activity is logged and audited. Correlating video with access-control events belongs to the same discipline, catching a propped door while it is still a maintenance issue rather than a security one.
“Technology can enforce those decisions, but it cannot make them,” says Brock. “Campus security, IT, legal or risk management, and the responding agencies need to establish the policy together.”
Why responders should not need to know your camera names
Even with permissions settled, dispatch describes a location the way people do. The northeast stairwell by the library. The east hallway. Camera lists often describe that same place as a drop number or an installer’s shorthand, and under pressure someone must translate between the two.
The solution is not simply a better naming convention, although consistent naming still matters for maintenance and investigations. It is a system that does the translating. Mapping places cameras at their real locations with fields of view drawn in, so an authorized user can find the reported area, hover for a live thumbnail, and pull the view forward without knowing what anyone called it.
Thousands of cameras offer little value when the three that matter take minutes to find.
How to find out what will fail before it matters
Scheduled drills test the parts of a plan everyone knows are being tested. A more useful exercise measures the path from request to usable video. Give a responder a location and start the clock. Do the credentials work? Are the permissions, right? Can the user find the area without help? Can they move to adjacent views as the situation changes?
Failures are usually human, not technical. When access depends on one administrator being reachable, that is a single point of failure, not a procedure.
“The purpose of the exercise is not to prove that the system works; it is to discover what will fail while there is still time to fix it,” says Brock.
What a week of work can change
None of those failures needs new hardware to fix. In a week, a campus can bring security, IT, dispatch and the primary responding agency into one room, verify credentials and connectivity, confirm that maps reflect where cameras actually are, and run the timed scenario once. Whatever breaks becomes the priority list. That work will matter more in the first ten minutes of an incident than another camera nobody can find.
Will Brock
Will Brock is an accomplished sales and business leader with nearly 30 years of experience helping organizations leverage technology to solve complex operational and security challenges. Throughout his career, he has built high-performing teams, developed strategic partnerships, and driven growth across the physical security and enterprise technology markets. His experience spans cloud and SaaS solutions, video management, access control, enterprise software, and IT consulting, giving him a broad perspective on helping customers modernize their security operations. He has successfully led enterprise initiatives, expanded channel partner ecosystems, and built lasting relationships with integrators, consultants, technology partners, and end users across North America. A United States Army veteran, Will brings a leadership style rooted in discipline, accountability, and execution.
