Cameras per Operator” Meets Offshore Monitoring — and Security Turns Into a Queue

The biggest risk in modern monitoring isn’t “bad cameras.” It’s bad throughput. When alert volume exceeds human triage capacity, response times explode—then everyone acts surprised when incidents get missed. Add offshore operators without dispatch-ready runbooks, and you don’t just get delays—you get systemic failure modes: wrong jurisdictions, slow escalation, context errors, and accountability gaps. This post explains the problem in plain operational terms and gives you a practical, non-marketing framework to audit and fix it.

13 minutes read
Person monitoring multiple screens with a world map and security cameras in the background

Who this is for

  • Property Managers (U.S. & Canada): multi-residential, condos, mixed-use, commercial portfolios

  • SOC Directors / Security Leaders: internal security operations, enterprise SOC/NOC hybrids

  • RVM Executives (Central Stations / Remote Video Monitoring): ops, quality, scaling, margin control

The uncomfortable truth nobody wants on a sales call

“Cameras per operator” is a vanity metric.

The only metric that predicts whether monitoring works is:

Peak alerts per hour vs. human triage capacity (and what that does to time-to-action).

Because security isn’t a vibe. It’s a race against the clock.

Part 1 — Define the real problem: Operator Oversubscription

The definition (use this internally; it’s clean and defensible)

Operator Oversubscription:
A monitoring operation is oversubscribed when incoming event volume (alerts/hour) exceeds human triage capacity at the response time the customer expects—creating a growing queue (backlog), delayed action, and missed incidents.

Why this happens (the business incentive)

Noise is cheap to generate. Attention is expensive to process.
So the market pressure becomes: pack more cameras per operator to compete on price.

That works only if:

  • most alerts are meaningless, and

  • customers don’t measure outcomes, and

  • nobody asks hard questions after a miss.

Spoiler: those conditions don’t hold forever.

Part 2 — The math that makes “125 cameras” either fine… or insane

Stop counting cameras. Count events.

Step 1: Event inflow (λ)

λ = total alerts/hour reaching the operator
Includes motion events, analytic triggers (person/vehicle), intrusion alarms, door-forced events, intercom calls, etc.

Step 2: Handling time (s)

s = seconds per alert (real workflow, not SOP fantasy)
Open → assess → decide → document → escalate.

Step 3: Capacity (μ)

μ = 3600 / s alerts per hour (theoretical maximum)

In reality, humans need slack (context switching, interruptions, fatigue), so:
μ_safe ≈ μ × (0.6 to 0.8)

The failure condition

If λ > μ_safe, response time doesn’t degrade linearly. It collapses.

That’s queue physics. Not opinion.

A quick “executive reality check”

If alerts average 30 seconds each (often optimistic once you include documentation), then:

  • μ = 3600 / 30 = 120 alerts/hour

  • μ_safe at 70% = 84 alerts/hour

If your operator receives 90 alerts/hour during peak, you are not “busy.”
You are behind—and the backlog will grow until something breaks.

And “something” is usually:

  • missed real incidents (false negatives),

  • inconsistent escalation,

  • shortcut decision-making,

  • burned-out staff and high churn.

Part 3 — Why alerts are mostly noise (and why this is structural)

The macro problem: false alarms dominate the pipeline

Law enforcement has been saying this for decades. A problem-oriented policing guide reports an Arlington, Texas example where 99% of alarm calls proved false, and alarm calls accounted for 19% of all dispatched calls for service in 2001. (Pop Center)

An SDM Magazine article citing SIAC framing reported residential false dispatch rates around 0.2–0.25 (dispatch every 4–5 years) and around 0.3 nationwide for residential, with slightly more than 1 for commercial accounts per year. (SDM Magazine)
(That’s dispatch metrics, not video alerts/hour—but it proves the same economic reality: most alarm activity is not crime.)

The Monitoring Association (TMA) summarizes the same pressure and cites RSPNDR data suggesting only 0.25% of alarms are crimes that would realistically require police intervention. (tma.us)

The micro problem: “motion detection” is a noise factory unless engineered

Even major camera/analytics vendors openly document the nuisance sources and the need for filtering:

  • swaying foliage

  • small animals

  • light beams / passing car headlights

  • harsh rain/snow conditions (and other environmental triggers) (Axis Documentation)

So if your operating model assumes “alerts = incidents,” it’s not a monitoring model—it’s a spam inbox.

Part 4 — Residential vs Commercial: why “site type” changes the math

You asked for public benchmarks like “residential = X alerts/hour.” Those don’t exist in a trustworthy universal way, because scene design and configuration dominate.

But executives can still understand the drivers.

Residential complexes (condos / multi-residential) often produce:

  • high baseline motion (residents, deliveries, guests, pets)

  • ambiguous-but-relevant behaviors (tailgating into secure doors, loitering in lobbies, parking garage drift)

  • night-time IR nuisance (bugs close to lens, reflections, glare)

Net: lower “severity,” higher “volume,” more context needed.

Commercial / industrial sites often produce:

  • peaky operational motion (shift change, deliveries, contractors)

  • fewer people—but higher consequence anomalies

  • more perimeter triggers (wind-driven motion, foliage, weather, headlights)

Net: lower baseline volume on good design days, but higher risk when something is real.

Key point: site type isn’t your KPI. It’s your noise profile.

Part 5 — Now add offshore monitoring: not immoral, but full of hidden failure modes

Offshore staffing (including teams in the Philippines) is common for cost and coverage reasons. This is not a moral argument.

This is an operational argument:

When you combine extreme camera loads + offshore operators + weak dispatch design, you introduce failure modes that look like “random mistakes,” but are actually structural.

5.1 Dispatch reality in the U.S.: “Just call 911” is not a workflow

The U.S. National 911 Program states that, with few exceptions, 911 calls cannot be transferred to other towns/cities/states, and the best option to get help in another jurisdiction is calling the local 10-digit number for law enforcement where assistance is needed. (911.gov)

Translation:

  • If your operator is offshore (or even out-of-state), “call 911” may route based on the caller’s location/network.

  • If the incident is in another jurisdiction, you need the right local number and the right address packet.

If your provider doesn’t have a verified jurisdiction contact list per site, they don’t have a dispatch plan. They have hope.

5.2 VoIP + location issues: routing can fail in predictable ways

The FCC warns that VoIP 911 calls may not automatically transmit the caller’s number/location the way traditional 911 does, and users should understand limitations. (Federal Communications Commission)
Broader FCC/NG911 documentation also notes that if location information is wrong or not updated, the call may be routed to the wrong PSAP, delaying response. (911.gov)

For monitoring centers using VoIP or “nomadic” setups, this matters.

5.3 Canada-specific: VoIP 9-1-1 limitations are explicitly regulated

In Canada, the CRTC requires VoIP providers to notify users of the nature and limitations of 9-1-1 emergency calling with VoIP services. (CRTC)

And Canada is mid-transition to Next Generation 9-1-1 (NG9-1-1), which the CRTC describes as a new and improved 9-1-1 service. (CRTC)
That’s progress—but it also means “how calls route” and “how data is shared” is a moving operational environment.

5.4 Cross-border reality (U.S. ↔ Canada): transfers often fall back to 10-digit lines

A cross-border 9-1-1 data sharing report notes that 9-1-1 calls near the border can be answered by the “wrong” country’s PSAP, and transfers between U.S. and Canada PSAPs are typically routed through 10-digit telephone lines, which means they don’t arrive with the same 9-1-1 data. (npstc.org)

If you manage properties near borders (or monitor across North America), your dispatch workflow must handle this.

5.5 Local context isn’t optional — it’s the difference between escalation and paralysis

Offshore teams face unavoidable context gaps:

  • What is “normal” at this building at 2 a.m. on a Friday?

  • Which entrance is the service door vs. resident entrance?

  • Is that a recurring contractor? A tenant move-in? A known issue?

  • What local rules govern trespass, loitering, or “who can be asked to leave”?

Without site context, operators tend to:

  • over-escalate (costly, annoying, leads to churn), or

  • under-escalate (the liability event).

5.6 Accountability and QA degrade unless engineered

Distance increases the need for:

  • QA sampling (case review)

  • operator coaching loops

  • consistent decision trees

  • incident tagging

  • clear ownership of outcomes

If the provider can’t show you audit trails and improvement cycles, offshore becomes a black box: “Trust us, we watched it.”

5.7 Human performance limits don’t disappear because wages are lower

There’s a reason control room human factors guidance exists: performance, health, wellbeing, and workload design affect outcomes. (National Protective Security Authority)

Research literature also discusses vigilance decline and missed detections in prolonged monitoring contexts (the “attention problem”). (ScienceDirect)

So the risk isn’t “Philippines.”
The risk is asking any human to do a superhuman job while drowning them in noise.

Part 6 — The combined failure mode: Oversubscription + Offshore = “Latency + Context Loss + Dispatch Friction”

Here’s the simplest way to explain it to an executive team:

  1. Oversubscription creates a queue → slow time-to-first-look

  2. Offshore adds context loss → slower decisions, more uncertainty

  3. Dispatch friction adds call routing/jurisdiction delays → slower action

  4. Result: the rare real incident arrives… and gets processed like just another alert

This is how “monitoring” becomes footage collection instead of prevention/response.

Part 7 — The Executive Scorecard: how to audit any monitoring provider (U.S. & Canada)

If you’re a property manager or security leader, you want contracts and reporting that force reality.

The 12 questions that expose the truth

  1. Show me alerts/hour by site by hour-of-day (last 30 days).

  2. What is median and P95 time-to-action during peak hours?

  3. What is the operator’s alerts/hour load during peak?

  4. What is your average handling time per alert (including documentation)?

  5. What percent of alerts are deemed actionable (and how is that labeled/verified)?

  6. What is your backlog size at peak (queued unreviewed alerts)?

  7. What is your QA program—how many cases reviewed per operator per week?

  8. When operators are offshore, who places the emergency call and how do you ensure correct jurisdiction routing? (If they say “we call 911,” follow up with #9.) (911.gov)

  9. Do you maintain a site-specific 10-digit jurisdiction contact list, and when was it last verified? (911.gov)

  10. Do you have a site packet: address, cross streets, entry instructions, camera-to-zone map?

  11. What’s your escalation ladder (who gets called second/third if nobody answers)?

  12. What’s your policy for environmental nuisance triggers (rain/snow/foliage/headlights) and how do you tune it? (Axis Documentation)

If they can’t answer these with data, you’re not buying monitoring. You’re buying a story.

Part 8 — Fix patterns (non-vendor specific): how mature operations actually reduce risk

Fix Pattern A: Reduce noise at the source (the cheapest win)

This is “boring engineering,” and it works:

  • detection zones

  • schedules

  • masking known nuisance areas

  • reposition cameras

  • tune sensitivity

  • use filters for foliage/light beams/small animals where supported (Axis Documentation)

Rule: you don’t scale humans against noise. You eliminate noise.

Fix Pattern B: Classify before you escalate (prioritize like public safety does)

Public safety is moving toward prioritization frameworks (because resources are limited). TMA’s AVS-01 standard is explicitly designed to help classify alarms to assist with call prioritization and resource allocation. (tma.us)

You don’t need to be implementing AVS-01 formally to adopt the mindset:

  • not all alerts are equal

  • escalation should be tied to evidence quality and threat cues

  • score the event before you wake a manager or dispatch responders

Fix Pattern C: Build a dispatch-ready runbook (mandatory if offshore is involved)

Minimum viable runbook per site:

  1. Local jurisdiction numbers (10-digit), plus backup contacts (911.gov)

  2. Verified civic address, cross streets, entry/gate details

  3. Camera-to-zone map

  4. Escalation ladder with time limits

  5. Scripted call template (“what to say in 20 seconds”)

  6. Incident timeline logging (alert → review → decision → call placed → outcome)

If a provider doesn’t have this, you’re paying them to improvise under pressure.

Fix Pattern D: Create an SLA that matches reality (time-to-action, not “coverage”)

Most contracts talk about:

  • “24/7 monitoring”

  • “trained staff”

  • “incident response”

Executives should demand operational SLAs:

  • Median time-to-first-look

  • P95 time-to-action

  • Maximum backlog thresholds

  • Monthly QA reporting

Because the queue doesn’t care that your SOC is “24/7.”

Fix Pattern E: Governance cadence (because conditions change)

Buildings change. Tenants change. Lighting changes. Seasons change.
Noise profiles drift.

So you need:

  • monthly nuisance review

  • top 10 cameras by alert volume

  • tuning/maintenance actions tracked

  • seasonal re-baselines (especially winter glare/snow and summer foliage)

Part 9 — A 30-day wartime plan (property managers + SOC + RVM execs can all run this)

Week 1: Instrument the truth

  • Pull alert logs (hourly)

  • Measure handling time (real samples)

  • Compute operator load during peak

  • Establish baseline: median & P95 time-to-action

Week 2: Kill the top 20% nuisance sources (the 80/20)

  • Identify top 10 cameras/zones generating alerts

  • Apply zoning/scheduling/filtering

  • Fix obvious camera placement and lighting issues

  • Re-measure alerts/hour

Week 3: Dispatch engineering (especially for offshore)

  • Build site packets and contact lists

  • Verify jurisdiction numbers

  • Run tabletop drills (mock incidents)

  • Add escalation ladder time limits

Week 4: Lock it into governance + contract language

  • Publish monthly report format

  • Set SLA targets for time-to-action

  • Define QA cadence and escalation accountability

  • Reallocate staffing based on peak load, not camera count

Part 10 — What to put in RFPs and contracts (copy/paste language)

Operational reporting requirement
“Provider will report per site: hourly alert volume, median and 95th percentile time-to-action, backlog during peak, and QA sampling rate, monthly.”

Dispatch readiness requirement
“Provider will maintain a site-specific dispatch runbook including local jurisdiction 10-digit contact numbers and verified site access instructions, and will test contacts quarterly.” (911.gov)

Offshore transparency requirement
“Provider will disclose operator location model and define the escalation mechanism used to contact local emergency services and/or local responders.”

This forces maturity without insulting anyone.

FAQs  

Is offshore monitoring inherently bad?

No. It can be effective if the provider is dispatch-engineered, context-equipped, and QA-managed. The risk comes when offshore is used as a cost hack without runbooks and without performance metrics.

Can an offshore operator “just call 911” for a North American incident?

Not as a dependable plan. In the U.S., 911 guidance explicitly notes that calls generally can’t be transferred across jurisdictions and recommends using local 10-digit numbers for the jurisdiction needing assistance. (911.gov)
Cross-border transfers between U.S. and Canada PSAPs also often fall back to 10-digit lines. (npstc.org)
Design the workflow accordingly.

Why do providers push high camera-per-operator ratios?

Because most alerts are nuisance, and margin pressure rewards whoever can process noise cheapest. But public safety and industry data show nuisance volume is enormous, and only a small fraction of alarms reflect actual crimes. (Pop Center)

What’s a “safe” number of cameras per operator?

There is no universal number. “Safe” depends on alerts/hour, handling time, and response targets. Two buildings with 50 cameras can produce totally different workloads based on environment and configuration.

What metrics should property managers demand?

Alerts/hour by hour-of-day, median and P95 time-to-action, backlog size, actionable rate, and a documented dispatch runbook.

We already have analytics—why is noise still a problem?

Because environmental triggers are real (foliage, small animals, light beams, heavy rain/snow), and vendors explicitly document the need for filters and tuning to reduce false alarms. (Axis Documentation)

Quick Glossary (keep this in your internal docs)

  • RVM (Remote Video Monitoring): live/near-live event review and escalation from cameras, often after-hours.

  • SOC (Security Operations Center): the team/process that triages security signals and coordinates response.

  • PSAP: Public Safety Answering Point (the 9-1-1 call center).

  • λ (Lambda): alert inflow rate (alerts/hour).

  • μ (Mu): processing capacity (alerts/hour).

  • P95: the 95th percentile—what “bad days” look like, not the average.

  • AVS-01: an alarm validation scoring standard used to classify alarms for call prioritization. (tma.us)

  • Operator oversubscription: inflow exceeds human capacity → backlog → delayed/missed response.

Conclusion  

If you manage properties or run a SOC/RVM operation in the U.S. or Canada, the strategic risk isn’t “do we have cameras?”

It’s this:

Can we prove time-to-action during peak load—especially when operators are offshore and dispatch is jurisdiction-bound?

If your provider can’t show:

  • alerts/hour distribution,

  • P95 time-to-action,

  • backlog under peak,

  • and a dispatch-ready runbook,

then the operation is built on optimism.

And optimism is not a security strategy.

References (selected)

  • U.S. National 911 Program – calling 911 for another jurisdiction and 10-digit numbers (911.gov)

  • FCC – VoIP and 911 limitations (Federal Communications Commission)

  • CRTC – VoIP 9-1-1 obligations in Canada (CRTC)

  • CRTC – Next Generation 9-1-1 overview / decisions (CRTC)

  • NPSTC – cross-border 9-1-1 data sharing and 10-digit transfer realities (npstc.org)

  • POP Center – false burglar alarms, Arlington example, alarm calls share (Pop Center)

  • SDM Magazine – SIAC dispatch rate framing residential vs commercial (SDM Magazine)

  • TMA – impact of false alarms; RSPNDR 0.25% figure (tma.us)

  • NPSA – Human Factors in CCTV control rooms best practice guide (National Protective Security Authority)

  • Axis – motion detection filtering and false alarm reduction guidance (Axis Documentation)

  • CCTV vigilance / change blindness literature examples (ScienceDirect)

Security is like insurance—until you need it, you don’t think about it.

But when something goes wrong? Break-ins, theft, liability claims—suddenly, it’s all you think about.

ArcadianAI upgrades your security to the AI era—no new hardware, no sky-high costs, just smart protection that works.
→ Stop security incidents before they happen 
→ Cut security costs without cutting corners 
→ Run your business without the worry
Because the best security isn’t reactive—it’s proactive. 

Is your security keeping up with the AI era? Book a free demo today.