Nestack Agent Care
Industries / Administration / Monitoring agent

Facilities AI agent · Alarm and access

Physical Security Monitoring AI Agent

Couple an alarm to the access record and the footage that covers it, hold the candidate event open until an officer dispositions it, and report silence as silence.

4–6 weeksTypical delivery
Your stackDeployment
No auto-closureNamed officer
Agent CareAfter launch

What this agent does

Assembles the candidate event, never the disposition

In
01

An alarm raises, and the agent draws the access record and the footage covering that door and minute.

02

A camera goes dark, and the gap is reported as a gap rather than left to read as a quiet night.

Reason
03

A door is forced, and the alert stays open until a named officer dispositions it or hands it on.

04

An alert ages without a review, and it is escalated rather than allowed to close itself.

05

A badge opens one door twice with nobody leaving between, and that door is marked for a tailgating read.

Decide
06

A door is held open beyond the configured interval, and the propped-door pattern is raised against it.

07

A recording nears the end of its retention window while its event is open, and the agent says so.

Out
08

A credential appears at two sites too close together to travel between, and an officer is given both.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent correlates the signals and holds the candidate event. A named security officer dispositions the alarm, and only that officer closes it.

Example workflow

One alarm, signal to disposition

AgentHuman
1Alarm signal receivedPanel alarms, access transactions, camera health or guard-tour feeds
2Event context assembledThe door, the site it sits on, the credential presented and the minute the signal was raised
3Candidate event draftedThe alarm, the access record beside it, the footage found and completeness
4Controls appliedTime-window checks, camera-health checks, retention checks and completeness confidence
No human action required

Stages 1 to 4 run unaided, and nothing is dispositioned at any of them — the agent is correlating, and the control-room lane opens at the completeness gate.

5DecisionSplits at the completeness gate
Evidence sufficient

Goes to the duty security officer to disposition.

Anything thin

Adds a control-room supervisor read first.

Control-room review

The event is held with its signals, its footage window and the door it sits on.

Disposition · Append evidence · Send to control room
Dispositioned — by a named security officer
6Alarm and case records updatedOnly where write access and records policy allow it
7Outcome evaluatedCorrelation accuracy, footage coverage, reviewer corrections and what the read found
Corrections

Each control-room correction is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Dispositioning an alarm as false or as actual.
Closing an alert because nobody reviewed it.
Naming the person behind a badge as a conclusion.
Running recognition outside your configured policy.
Automation boundaryAgent acts unaided
Correlate each alarm with the access record and the footage window.
Hold the candidate event open until a named officer.
Mark footage nearing the end of its retention while.
Report a dark camera as a gap in the record, never as a quiet door.
Nothing is dispositioned or closed except by a named person, inside the agreed boundaries.
Judging whether a person tailgated a door.
Telling a site the estate was secure overnight.
Setting the priority a panel arms a zone at.
Changes to access rights, doors or schedules.

Example output

One alarm, annotated

Our retail loss-prevention agent works shrink across a trading floor; this record is what one forced door carried into review.

Candidate event · single alarmIllustrative example
Alarm
Recorded as
Signal
Evidence of record
Confidence
Held for
Door forced, perimeter entrance
Correlated with an access record and footage
Door forced
Panel alarm, 3 August 2026
Held undispositioned
The duty security officer, by name
As receivedTaken from the panel log and the access record — it reaches as far as those sources do.
What the record holds Panel alarm log Access record Footage reference
Why no disposition hereWhether the alarm was an actual entry is an officer call, not a model output.
ActionDispositionAppend evidenceSend to control room
What the score decidesBelow the configured threshold an event gets a supervisor read before the officer sees it.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every alarmFrom the door that raised it
03Evidence

Where the evidence is used

Correlation is not identification: the agent holds no biometric and runs no recognition unless your configured policy provides for it, and it names nobody as a conclusion.

01Approved path

An alarm is not an event

A panel signal becomes an event only when a named officer says it is one, and the agent assembles the correlation while that call stays with the officer.

02Human review

What was checked, and not found

No regime sets a disposition clock for a forced door on a private estate, no public register of alarm outcomes was located, no retention period is fixed for us to quote, and every limit on this page is one your own configured policy sets.

04Build an evidence trail

The alarm, the footage covering it and the officer who dispositioned stay together.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Alarm and intrusion sourcesPanels · intrusion feeds
Door and zone alarm signals
Access controlReaders · credential records
Badge and door transactions
Video and camera healthVMS · camera heartbeat
Footage index and retention

Agent

Physical security monitoring

Reads the signals
Correlates the event
Holds for the officer

Case and dispatch systemsGuard tour · ticketing
Disposition and case records
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six cordons between the model and the officer

Six cordons drawn one inside the next. Whatever crosses all of them is named in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to correlation only when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and correlation rules; the retention windows travel with them, because a rule change that widens a window cannot lengthen a recording.Track
L4TraceabilityRecord each alarm, the signals behind it, the door it sits on and every read of the event.Record
L3Officer releaseHold the event for a named security officer; the hold governs release, not whether the door was actually forced.Gate
L2Policy guardrailsTest each event against the door schedules, escort rules and recognition policy you configured; nothing outside that configuration is read.Restrict
L1Confidence thresholdsRoute a thin event to a supervisor read first; an alert that ages unread is escalated, never retired.Require review
Model coreEvent correlated — the alarm, the badge, the footage window and completeness
L1 – L2Test whether an event may stand
L3Puts the disposition in a person's hands
L4 – L5Keep the alarm and the footage behind it
L6Steps back to alert assembly when signals degrade

How Nestack evaluates it

Evaluate the whole assembly — not only the candidate event that comes out.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the event an officer reads
Depth of coverage ▼
E1Final-output evaluationDid the event record what the alarm actually showed?
E2Step-level evaluationDid the agent read the right door, the right minute and the live device list?
E3Tool evaluationDid it read and write the correct alarm record and the correct case?
E4Confidence calibrationDo low-confidence events actually attract more control-room corrections?
E5Slice evaluationHow does performance change across specific site types?
E6Business outcomeHow many events needed a correction before the officer dispositioned?
Floor — the record the estate answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, each pinned to the stage where it first shows.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
KP-03

Stale device list read

The camera list read is not the one now in service.

Stage gathersThe alarms, the badges, the doors and the times
02 · Reasoning2 modes
KP-04

Bound to the wrong door

A signal is tied to a door it never came from.

KP-06

Silence read as all clear

A dark camera is worked as a quiet night.

Stage proposesThe alarms, their records and completeness
03 · Tool / write2 modes
KP-02

Thin event passed forward

An event moves on without the supervisor read.

KP-05

Filed against the wrong site

An alarm lands on a building it did not touch.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
KP-01

Dispositioned, evidence unrecorded

The record shows a disposition but not what supported it.

Stage returnsThe event an officer dispositions and audit reads
05 · Change / Version1 mode
KP-07

Silent correlation regression

A configuration change moves the window, not the alert.

Stage tracksModel, prompt, correlation rules and event fields
Sev-1 · an alarm closed with nobody reading it Sev-2 · wrong footage reaches the event Sev-3 · source degrades, alert held open

Affected slices

Perimeter doors absorb the corrections

A site-level disposition-latency figure can read clean while perimeter doors after hours carry most of the rework. Nestack reports the correction rate by site type, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Perimeter doors after hours7.9%3.6× Review
Loading bays and yard gates5.6%2.6× Review
Shared-tenancy floors3.5%1.6× Watch
Head-office reception1.4%0.6× Normal
Bar: correction-rate lift vs. head-office reception baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

What a swallowed alarm costs

A loop ends when the swallowed alarm has become a case the next release must pass. That suite is what the next alert raised is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Correction rate rises on perimeter doors after hours.

02Diagnose

The door-forced alert that closed itself at three in the morning is read back until one cause remains.

03Improve

Number the change; the alarms that drove it are filed underneath it.

04Verify

Each touched alarm case is run once more, and one red holds it back.

05Learn

It stays on as a standing test, and the retention rules travel with it.

Learn → DetectThe return edge. The next alert is measured against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, event correlation, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Disposition-policy and automation-boundary work.
02Alarm, access and camera sources.
03Alarm-to-footage and retention-window rule mapping.
04Alarm and access ingestion.
05Alarm, door and footage binding.
06Completeness scoring and review routing.
07Officer disposition workflow.
08Video-system integration.
09Correlation and retention cases.
10Guardrails and disposition controls.
11Alarm-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne site, one year ProductionProduction monitoring workflow AdvancedMultiple sites / regions
Introduced at Pilot
Event correlation to your rules
Security officer release
Device-coverage baseline
Introduced at Production
Reporting by site
Disposition workflow in your systems
Approved write-back
Access-and-camera integration
Introduced at Advanced
Multi-site door schedules
Cross-site event packs
Large door estates
Multi-site retention controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, alarm volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your sites and the doors monitored at each Site mapping and alarm captureWeek 1
02Representative alarm, access and footage records Record binding, correlation logic and the event baselineWeek 2
03Your configured policy on recognition and retention Correlation mapping, door binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports Alarm, access and video-source assessment, then integration setupWeek 2
05Alarms you would not want reopened Correlation cases and the evaluation suiteWeek 4
06What no camera record may guarantee Completeness scoring, review routing, guardrails and release controlsWeek 3
07A named security officer to disposition Disposition workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

The spans below are honest working weeks rather than layout, so two of them have to share week five.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Monitoring workflow discovery, door mapping and the automation boundary W2Source integration and the device-coverage baseline W3Event correlation, retention logic and release controls W4Evaluation suite, correlation cases and failure-mode testing W5Video integration, pilot alarms and targeted corrections W6One monitoring year run under the security manager, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. Week five holds a pair because the work does.
At the end of W6When the alarm record validates, Agent Care picks the agent up.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Facilities AI agent

Build a monitoring agent around the alert that closed itself while the estate slept.

Bring us one alarm and the record it left behind. If an alert on your estate can age out unreviewed, then a disposition nobody made is the price of every quiet night. The agent holds no biometric and runs no recognition unless your configured policy provides for it.

Nestack Agents · Alarm monitoringAGT-AF-08 · Agent Care available after launch