How AI can help investigate an unauthorised access incident
A member of staff reports seeing someone in an executive boardroom who does not appear to belong there. When challenged, the person gives no satisfactory explanation.
The immediate question is obvious: who was the person?
But answering it creates several more questions. Were they an employee who had entered an area they were not authorised to access, a contractor or visitor, or someone who should not have been in the building at all? If they were an outsider, how did they get in? Where else have they been? How long have they been on site? Are they still there?
A security team may need answers quickly, followed by a fuller unauthorised access investigation.,
The problem is not necessarily a lack of information. It is that the information needed to reconstruct what happened may be spread across incident reports, access-control logs, CCTV, visitor records and security procedures.
AI could help an investigator bring those sources together, narrow the investigation and build an account that can be checked against the underlying evidence.
Watch: How AI could investigate an unauthorised access incident
Why an unauthorised access investigation can take so long
Most of the systems involved in physical security have been designed to perform a particular job.
A security procedure describes what should happen. An incident report records what somebody saw or reported. An access-control system records access events. CCTV provides visual evidence. A visitor management system records information about guests and contractors.
These systems are valuable individually, but none necessarily answers the investigation question.
An investigator therefore has to assemble the picture.
NPSA describes CCTV as one element of a coordinated security solution and identifies uses including investigating alarm events, tracking an intruder and recording images for subsequent investigation. It also recommends deploying CCTV alongside measures such as automatic access control and intrusion detection.
AI does not need to replace any of these systems. It can instead help interrogate and connect the information they already produce.
For investigations themselves, the quality of the initial record also matters. Our Security Incident Report Template explains how observations, third-party reports, source-supported facts and unknowns can be separated when an incident is recorded.
What an AI-assisted investigation could look like
Consider the original report of somebody being seen in a restricted boardroom.
An investigation might follow this sequence.
1. Establish the initial report
Start with what is actually known. Who reported the person? Where were they seen? At approximately what time? What description was provided? What happened when they were challenged?
The distinction between reported facts and subsequent inference matters throughout the investigation.
2. Establish the relevant time window
The reported sighting provides a starting point for examining events before and after it.
Rather than reviewing every security record for an entire day, the investigator can begin with a defined period and expand it if the evidence requires it.
3. Interrogate access-control events
The next task may be to establish which credentials were used at relevant doors and in what sequence.
AI can help interrogate a large access-control export and identify events that may be relevant to the investigation. This does not establish that an individual did anything wrong. It creates candidates for further review.
4. Identify CCTV candidates
Access events can help narrow the footage that needs to be examined.
For example, if an unusual credential event occurred at a particular door at 14:17, the investigator may need footage from the cameras covering that location shortly before and after the event.
The result is a set of candidate clips or time windows for an authorised person to review.
5. Cross-reference visitor and contractor records
Was a person matching the available information expected on site? Was a contractor booked in? What was the stated purpose of the visit? When were they expected to leave?
This can confirm possibilities or expose discrepancies requiring further investigation.
6. Reconstruct a timeline
The evidence can then be assembled chronologically:
Each part should remain linked to its source rather than becoming an unsupported AI-generated narrative.
7. Identify what is still unknown
A useful investigation account should not simply produce answers. It should identify gaps.
There may be a corridor without CCTV coverage, an access-controlled door through which several people passed together, an inaccurate timestamp or a period during which the person’s location cannot be established.
Those limitations are part of the investigation.
8. Support the investigation report
Once the evidence has been assembled and reviewed, AI can assist with producing a structured draft containing the timeline, source references, outstanding questions and evidence gaps.
The investigator remains responsible for reviewing the evidence and reaching the conclusions.
The access-control problem: thousands of events, one investigation
Access-control data illustrates why this approach could save substantial investigative effort. Imagine an investigator trying to establish how someone moved through a large building.
There might be 50 relevant access-controlled doors. Exporting their activity could produce thousands of rows containing credential identifiers, doors, timestamps and event types.
Somewhere within those records may be a sequence relevant to the investigation. A person can inspect those rows manually, but the task becomes increasingly difficult as the volume grows.
AI can instead interrogate the structured records for particular patterns and produce a smaller set of events for investigation. For example, it might flag:
-
repeated use of the same credential within an unusually short period;
-
unexpected sequences of door events;
-
credentials being used in locations inconsistent with the emerging timeline;
-
records with missing or unexpected identifying information; or
-
contractor credentials apparently being used outside an expected access period.
These are not conclusions of wrongdoing. They are anomalies or investigation candidates that a person can examine. That distinction is important. An unusual access event may have a perfectly legitimate explanation.
AI does not necessarily need to watch the CCTV
Using AI in the investigation does not mean giving an AI model unrestricted access to CCTV. There is another approach.
If analysis of the access-control records indicates that Door 12 at 14:17 is relevant, the system can identify the appropriate camera and time window. An authorised investigator can then retrieve and review the footage. AI has helped determine where to look, rather than deciding what the footage proves.
That design can also preserve existing access permissions. The person following a reference or link to CCTV still needs the appropriate authority to view it.
NPSA guidance recognises CCTV’s role in investigating incidents and tracking intruders, while also stressing the importance of trained operators and site knowledge.
Personal data should be limited to what the investigation needs
Access-control and surveillance records can contain personal data, so introducing another form of processing requires careful consideration.
The ICO states that personal data used by surveillance systems should be adequate, relevant and limited to what is necessary for the purpose. Organisations should identify the minimum amount of personal data required. That creates a useful design question for an AI-assisted investigation:
Does the AI actually need to know the person’s name?
For some stages of an investigation, a credential identifier may be sufficient. The system may be able to analyse the movement of Card ID 84721 without initially knowing who the card belongs to.
Identity can be introduced later if it becomes necessary and appropriate for the investigation.
The same principle applies when connecting information from different systems. Organisations need to consider accuracy, whether the information is excessive, whether it is being used for defined purposes and whether the processing remains necessary and proportionate.
Depending on the deployment and processing involved, organisations will also need to consider their lawful basis, privacy information, security controls and whether a Data Protection Impact Assessment is required.
For organisations considering how to test this type of workflow in a controlled way, our guide to running a safe first AI pilot covers the wider pilot process.
What AI cannot establish
Faster evidence retrieval should not be confused with better judgement.
An AI system might establish that a credential was used at a particular door at 14:17. It might identify footage that an investigator should review. It might show that the same credential subsequently appears at another access point. It cannot reliably establish why the person was there. Nor should an anomaly automatically become an allegation.
Perhaps somebody held a door open. Perhaps a credential was legitimately transferred or replaced. Perhaps a visitor record is incomplete. Perhaps two systems have clocks that are not perfectly synchronised. Those possibilities require investigation. AI can help assemble the available evidence, expose inconsistencies and make gaps visible. Accountable judgement remains with the investigator.
Unauthorised access investigation checklist
When investigating suspected unauthorised physical access, consider recording the following.
Initial report
-
Who reported the incident?
-
What did they actually observe?
-
Where and when did the sighting occur?
-
What description or other identifying information is available?
Immediate security position
-
Could the person still be on site?
-
Is an immediate security response required?
-
Are particularly sensitive areas or assets potentially affected?
Access information
-
Which access points could be relevant?
-
Which credentials were used during the relevant period?
-
Are there unusual sequences, repeated events or other anomalies?
-
Are timestamps consistent between systems?
Visitor and contractor information
-
Who was expected on site?
-
Why were they visiting?
-
What access should they have had?
-
Were credentials still valid and appropriate?
CCTV review
-
Which cameras cover the relevant locations?
-
Which specific time windows need human review?
-
Can movement between locations be established?
-
Where are the gaps in coverage?
Timeline and evidence
-
Which events are confirmed by source records?
-
Which are inferred?
-
Which reports conflict?
-
What remains unknown?
-
Can every material statement in the investigation account be traced back to its source?
The opportunity is between the systems
Procedures tell the security team what should happen. Incident reports record what people report. Access control records events. CCTV provides visual evidence. Visitor management records who was expected on site and why. The investigation requires something different: an account of what happened.
That is where AI could be particularly useful. Applied within a controlled investigation workflow, AI can help interrogate large volumes of records, connect relevant information, identify where human review is needed and assemble a timeline without pretending that uncertainty has disappeared.
The objective is not an autonomous AI investigator. It is to give the security professional a faster route from a reported incident to an evidence-backed account that can be checked against the organisation’s own source information.
SIRV AI is designed around this wider principle: connecting operational information, review, human decision-making and follow-up rather than replacing accountable judgement. Find out more about SIRV AI.
Could this workflow apply to your security operation?
SIRV AI is designed to help safety, security and resilience teams connect existing operational information to review, decision and follow-up, while keeping accountable judgement with people.
"SIRV helped us move beyond basic reporting into a system that actively supports decision-making". Les O'Gorman, Director of Facilities, UCB - Pharma and Life Sciences