Key takeaways
- Define alert tiers by both confidence and consequence, not by model score alone.
- Require fast verification before property-crime dispatch, and keep panic, duress, and life-safety events on a separate path.
- Assign one owner, one backup, and one response clock to every tier.
- Review every false Tier 2 and Tier 3 alert by cause code, then retune thresholds on a fixed cadence.
Start with a four-tier incident ladder
A patrol robot needs a written escalation policy that turns every detection into a small incident workflow. Start with four tiers. Low-confidence anomalies are logged. Medium-confidence events go to rapid human review. High-confidence property events trigger private security dispatch. Life-safety events or clearly verified crimes in progress move to public emergency response.
This is not administrative overhead. It is what keeps the robot credible. The Center for Problem-Oriented Policing reported that, back in 2002, U.S. police responded to about 36 million alarm activations at an estimated annual cost of $1.8 billion, and that false alarms consumed 10 to 25 percent of police calls. The same guide put ordinary false-alarm rates at 94 to 98 percent, with some jurisdictions even higher.
So the answer to the main question is direct. Define alert tiers by both confidence and consequence. Require verification before property-crime dispatch. Name the owner for each handoff. Review every false escalation. Reserve 911 for immediate threats to people, fire, medical need, or a clearly verified violent or criminal event that needs public responders.
What should each alert tier actually mean?

Do not treat the robot's model score as the whole decision. A 0.82 person-detected event in a public lobby at 2 p.m. is not the same as a 0.82 restricted-area intrusion at 2 a.m. Build event confidence from four inputs: model score, sensor corroboration, site context, and persistence across time.
NIST's AI RMF Core says organizations should document risk tolerances, system limits, and how humans oversee AI output. For a patrol robot, that means the threshold table belongs in the SOP, not in a vendor demo or a supervisor's memory. Start with the ladder below, then tune it after 30 to 60 days of real site data.
- Tier 0, 0.00 to 0.39 composite confidence. Log the event, save evidence, and do not wake anyone unless the same rule repeats three times in a short window.
- Tier 1, 0.40 to 0.69, or any single-sensor anomaly in a sensitive area. A human reviews live feeds within 2 minutes and either clears, suppresses, or promotes it.
- Tier 2, 0.70 to 0.89 with corroboration, restricted-area context, or persistent presence. Dispatch a guard, mobile patrol, or on-site security supervisor, keep live monitoring open, and notify the duty manager.
- Tier 3, 0.90 and above, or any event involving visible forced entry, weapon indication, assault, smoke, medical collapse, or human-triggered duress. Call 911, continue live verification, and preserve the full evidence package.
How should verification work before anyone rolls?
Verification should answer two questions within one to two minutes: is the event real, and is anyone in immediate danger? The quickest stack is layered. Review the robot clip, pull fixed-camera views, check access control or door status, and ask the robot for a second look if the target is still present.
According to the Center for Problem-Oriented Policing, verified response commonly relies on visual confirmation, including remote video. Collier County Sheriff's Office says enhanced call verification has cut dispatch requests by 30 to 50 percent, and the added delay averages less than 30 seconds. One short verification step can save a great deal of wasted motion.
Modesto Police requires verified audio, video, or private security confirmation for ordinary burglary alarms, and it warns against asking owners, friends, or neighbors to self-verify because it can be dangerous. Your robot workflow should do the same. Send trained private responders, not curious employees.
Who owns the incident after the robot speaks up?
Shared ownership kills incident response. Every tier needs one named owner, one backup, and a timeout that auto-escalates if the first person does nothing. If the robot posts into a chat room and five people assume someone else has it, you do not have automation. You have drift.
Separate incident ownership from robot maintenance ownership. The security desk decides if the event is real. Facilities unlocks gates or cameras if access is needed. The integrator or support desk steps in only when the event may be sensor fault, map drift, dead battery, or network loss. That separation keeps real incidents moving while technical triage happens in parallel.
- Tier 0 owner: robot operations or the overnight analyst. Their job is evidence retention, suppression of obvious nuisance events, and flagging recurring patterns for review.
- Tier 1 owner: the security operations center operator. They have the clock, they make the verify or dismiss decision, and they escalate if the timer expires.
- Tier 2 owner: the security supervisor or dispatch desk. Facilities supports access, but does not own the incident. The operator stays attached until the responder arrives or the event clears.
- Tier 3 owner: the duty security manager or supervisor trained to speak with 911. Site leadership is informed immediately, but no one gets veto power over the emergency call.
- Technical fault owner: the integrator or support desk. They handle map drift, dead batteries, sensor faults, and network loss in parallel so the security chain stays clean.

Where does private response end and 911 begin?
Keep the public-safety boundary crisp. According to 911.gov, 911 is for situations requiring immediate assistance from police, fire, or ambulance. That is your Tier 3 definition. The robot can surface evidence and location, but a trained human should place the call and stay on it until the PSAP releases them.
Public agencies also care about event type. Modesto Police continues high-priority response for panic, robbery, and duress even when ordinary burglary alarms need verification. Richmond County says the same and explains the split clearly: burglar alarms protect property, while panic, duress, and robbery alarms protect people. That distinction is useful for robot design.
Write the caller script in advance. It should include the exact address, where on the property the robot sees the event, what has been verified live, if anyone appears injured or armed, how responders can enter safely, and who will meet them. If the robot sees only an uncertain property condition with no person and no corroboration, keep the event in private response.
How should false-alarm review work?

False-alarm review is where the workflow gets better. Richmond County Sheriff's Office says that from 2018 to 2021 about 83,000 alarm activations reached the county 911 center, and roughly 20,000 burglar alarms a year led to response, with 98.9 percent proving false. Those numbers are a warning. If you do not review false escalations, your team will slowly stop trusting the robot.
Run a next-business-day review for every false Tier 2 and every Tier 3. Tag the root cause precisely: lighting swing, reflections, wildlife, HVAC motion, cleaning crew, badge mismatch, camera blind spot, map drift, network dropout, dirty lens, or bad rule logic. Then change one thing at a time. Thresholds, schedules, exclusion zones, and sensor fusion should all be versioned so you can see what helped and what hurt.
Run a short weekly meeting for patterns and a monthly threshold review for harder changes. Keep the evidence clips. If a rule change reduces nuisance alerts but also hides real activity, you want to see that quickly.
- False Tier 2 and Tier 3 rate by rule, zone, hour, and weather condition.
- Median time from detection to human verification, and from verification to dispatch.
- Percentage of escalations driven by one sensor only versus fused evidence.
- Repeat nuisance triggers that should move to schedule suppression, masking, or whitelist rules.
- All emergency escalations later downgraded, with the exact reason for the downgrade.
How do you keep the playbook working across sites?
Once you scale beyond one building, the hard part is not navigation. It is keeping the incident vocabulary consistent. Use the same tier names, response clocks, and 911 boundary across sites. Localize only what truly changes: restricted areas, public hours, staffing levels, high-value rooms, weather exposure, and any local verified-response policy.
This is also where the operating model around the robot matters. Service Robot Co. is a full-service commercial robot integrator for US businesses. We are OEM-neutral, so the workflow can start with the site's risk profile instead of a single manufacturer's default settings. That matters for an autonomous patrol robot pilot, a security patrol robot rental, or a broader robot fleet management program.
Because Service Robot Co. can finance, deploy, integrate, train, and service every unit through a nationwide US engineer network, the same team can carry the playbook from site assessment to go-live drills, remote triage, and on-site dispatch support. One vendor for the full lifecycle makes it easier to keep the alert ladder, evidence trail, and response ownership aligned.
Before launch, run three drills at minimum: nuisance loiterer, verified intrusion, and medical emergency. If the team cannot say who acts in the first 30 seconds, 2 minutes, and 10 minutes, the escalation rules are not ready for production.



