Who Should Be Responsible for Your Physical Security Design?

Key Takeaways

  • Physical security design often gets folded into architectural or electrical drawings, while the decisions that determine performance are left unresolved.

  • A device schedule captures equipment. Camera performance, secure credentials, power and network capacity, door coordination, and commissioning still need to be designed.

  • Bringing a dedicated security designer in while the drawings can still change avoids expensive coordination issues later in construction.

  • In leased space, the landlord's base-building security may not cover the tenant's operations, customer requirements, or access to footage and data.

On many commercial projects, physical security design gets folded into the architectural or electrical scope because those teams already control the drawings. The plans may show cameras, card readers, door contacts, and an equipment room. The scope appears covered.

The harder questions may still be unresolved. Will each camera capture the level of detail the owner expects? Can the network and power infrastructure support the system? Who will test the completed system against the design?

Architects and electrical engineers are essential to the process. A dedicated security designer adds a different layer of expertise and coordinates it with their work. Owners, tenants, and corporate security teams need one person accountable for security performance across the drawings and the completed system.

Who owns physical security design on a building project?

Electronic safety and security systems sit in Division 28 of the CSI MasterFormat, Electronic Safety and Security. You can see how that plays out in a published owner's Division 28 master specification, which carries an editing note instructing whoever uses the template to substitute "Architect" or "Engineer" depending on the design professional on that project. On many projects, the Division 28 security specifications are coordinated with the electrical scope because they are treated as low-voltage work.

Coordination alone leaves core security-design questions unresolved. Who has determined whether the cameras will capture useful detail? Who selected the credential technology, defined the access hierarchy, set the network and cyber requirements, coordinated doors and life safety, and will verify performance at closeout? If the answer is that the installer will decide later, the security design has no owner.

A dedicated security designer works alongside the rest of the project team. The architect controls space planning and the door schedule. The electrical engineer coordinates power, pathways, and related infrastructure. Door-hardware specialists address locks, frames, and egress hardware. IT defines network standards and ownership. The security designer connects those decisions to the owner's risks, operating procedures, and performance requirements.

That coordination should begin while the drawings are still moving, not after the walls and door frames are in place.

What a copied security specification can miss

Many security specifications begin with a document from an earlier project or a manufacturer's product specification. A good standard is worth reusing. It still has to be checked against the property in front of you.

On a recent New York City public infrastructure project, a specification named a camera model that had already been discontinued. The same package called for an alarm connection using a telephone landline. Neither requirement reflected the site or the technology available for the project. The team had to raise the questions and propose workable replacements.

Older specifications can also carry outdated assumptions about access credentials, networking, storage, and system integration. A product may still be available and still be the wrong choice for the client's risk, operating model, or future plans.

They can also leave cybersecurity ownership unresolved. Once cameras and controllers are connected, someone must define network segmentation, administrator access, patching responsibility, and end-of-life replacement. Otherwise, an installer connects the devices, IT inherits equipment it did not specify, and nobody owns the system's security after handover.

Security system design is more than placing devices

Security designer reviewing camera, access control, and network locations on commercial building plans

One common shortcut is to select one camera model and place it wherever the floor plan appears to need coverage. That produces a camera count. Whether it produces usable video depends on the scene at each position.

Physical security design services should resolve the decisions behind the symbols on the plans:

  • Camera performance: Select the camera and lens for the scene, lighting, distance, and required level of detail. A camera intended to identify a person has a different job from one used for general situational awareness.

  • Power, network, and storage: Confirm cable-distance limits, switch capacity, power budgets, bandwidth, backup power, and footage-retention requirements.

  • Access control: Specify secure credential technology and define access groups, schedules, and restrictions so the system reflects how the organization actually operates.

  • Doors and system interfaces: Coordinate readers, locks, door-position sensors, request-to-exit devices, intercoms, elevators, fire-alarm interfaces, and the pathways needed to connect them.

  • Testing and handover: Define commissioning, acceptance testing, administrator access, licensing, training, and the documentation the owner receives at closeout.

The equipment schedule should reflect those decisions.

Late coordination turns design gaps into construction problems

Technician coordinating access control wiring and door hardware during commercial construction

Security decisions become more expensive as construction advances.

If a card reader, electrified lock, or door-position sensor was not coordinated before the frame was ordered, the fix may require new hardware or field modifications. If mobile credentials or a video intercom are introduced after rough-in, the project may need new cable, different readers, or another access-control panel. If camera bandwidth and retention were never calculated, the network or recording platform may be undersized before the system is even turned on.

Connextivity generally avoids magnetic locks. Where they are proposed, their release hardware, egress operation, power behavior, and fire-alarm coordination must be resolved as part of the door assembly. NFPA identifies the permitted arrangements in detail. The design team must resolve it before installation.

Some failures do not appear until the building is operating. The access hierarchy may be too broad, footage may be difficult to retrieve, or cameras may not capture the detail staff expected. The building can have a complete device count and still fall short of the client's operational needs.

In leased space, the building security design predates the tenant

Tenants often see a lobby camera, a card reader, and a locked entrance and assume the landlord's system covers their needs. It usually serves the building's needs, which are set by the landlord's risk rather than the tenant's.

A tenant should understand which controls belong to the landlord, which controls the tenant can access, and where responsibility changes hands. The review should address access to video after an incident, credential and reporting requirements, visitor and delivery procedures, cleaning and after-hours access, and protection for interior offices or sensitive rooms.

Those boundaries matter most when an organization handles sensitive information or answers customer security questionnaires. The existing controls may be adequate. A tenant may need additional measures, and the landlord may participate in an upgrade once the gap is documented and tied to the space.

Why independent design matters during procurement

Project team reviewing physical security drawings and specifications for a commercial building

When Connextivity is retained for independent security design, our work can include requirements development, system layouts, performance specifications, bid documents, bidder questions, bid analysis, construction administration, and commissioning.

We generally do not bid the installation on projects where we are serving in that independent design role. The separation allows us to help the client compare proposals against one defined scope, respond to RFIs without protecting an installation margin, and verify that the completed work matches the design.

Architects, engineers, IT teams, landlords, and installers all stay in the process. The security scope arrives with an owner and a clear basis for coordination.

Start while the drawings can still change

The best time to address building security design is before pathways, door frames, network capacity, and finish conditions are fixed. Early decisions are easier to coordinate and less expensive to change.

If your project is already under construction, a design review can still identify the gaps that are practical to correct before closeout. For leased or existing space, a security assessment can establish what is already in place, what the landlord controls, and what your organization needs to add.

Contact Connextivity if you need an independent review of a security scope or a design team that can coordinate with your architect, electrical engineer, IT team, physical security staff, and landlord.

FAQs

Who usually designs the physical security system on a construction project?
The answer varies by project. The scope may be coordinated by the architect, electrical engineer, security integrator, in-house security team, or a dedicated security consultant. The owner should identify the person accountable for security performance across the design and completed system.

Can an electrical engineer design a security system?
Yes, and on many projects the electrical engineer is the one producing the security drawings. What matters is whether that engineer has security-design experience and whether the scope actually assigns the security decisions to them. Owners should confirm who is responsible for camera performance, credential selection, access logic, network and storage requirements, door coordination, and commissioning.

What is the difference between a security assessment and physical security design?
A security assessment identifies risks, vulnerabilities, and priorities in an existing or planned environment. Physical security design translates those requirements into coordinated layouts, specifications, system architecture, procurement documents, and testing criteria.

Do tenants need a security designer if the landlord already has security systems?
It depends on the tenant's risk and customer requirements. A tenant may still need to document what the landlord controls, determine whether footage and access data are available when needed, and add protection for spaces or processes that fall outside the base-building system.

Related articles

Next
Next

What the Hikvision and Dahua Import Ban Means for Your Cameras