Why data center security is a different discipline than commercial guarding
A data center guard post looks, at a glance, like any other lobby or loading-dock assignment: a uniformed officer, a desk, a badge reader. What's actually happening at that post is closer to being an unpaid extension of the facility's compliance program. The officer is a control — a line item an auditor will test — not just a deterrent.
That distinction matters because most general commercial security training doesn't cover it. A retail guard is trained to watch for shoplifting and de-escalate a disturbance. A data center guard has to know why a badge holder standing at a mantrap vestibule still gets stopped and visually verified before the second door releases, why an escorted vendor can never be left alone on the raised floor even for two minutes, and why "the badge worked, so I let them through" is the wrong answer during a SOC 2 walkthrough.
Colocation operators, hyperscale campuses, and enterprise-owned facilities all converge on the same requirement: officers who function as a human control layer sitting next to the electronic access system, not officers who are simply stationed near it.
Calvis is a marketplace that connects data center operators and colocation tenants with independently licensed security agencies experienced in controlled-access, audit-driven environments — it is not itself a guard company or a licensed security provider. Every officer placed through the network works for a state-licensed agency that Calvis has vetted for this specific type of post.
What data center security guards actually do
Access control coordination with biometric and mantrap systems
Most colocation suites and hyperscale data halls use two-factor or biometric entry — a badge plus a fingerprint or iris scan, sometimes a mantrap vestibule with two interlocked doors that never open simultaneously. The electronic system does the authentication. The guard's job is the verification layer the system can't do on its own: confirming the person standing at the door is actually the person the badge or biometric read says they are, watching the vestibule camera as the inner door releases, and flagging anything that doesn't match.
Officers are almost never issued the facility's own access credentials. That separation is deliberate — it keeps the guard function auditable as an independent control rather than folding it into the same system it's supposed to be checking.
Tailgating and piggybacking prevention
Tailgating — a second, unbadged person following a badge holder through a door before it closes — is the single most common physical-access failure mode auditors test for. Turnstiles and anti-passback systems catch some of it electronically, but the alarm still needs a human response: someone has to walk to the door, check the camera, determine whether a second person actually got through, and write down what happened.
An officer's job here is procedural, not reactive: check every alert inside a defined response window, verify what the footage actually shows, and close the loop with a timestamped incident record — even when the alarm turns out to be a false trigger from a badge holder carrying a box through the door. Auditors care as much about the documented response as they do about the number of real intrusions, which is usually zero.
Escort-required visitor and vendor protocols
Data centers run on least-privilege access: nobody moves through the facility unescorted unless they hold a badge for that specific area. Vendors doing hardware installs, HVAC contractors, cabling techs, and even client representatives visiting their own cage typically fall under an escort-required policy. The officer checks the visitor against a pre-approved list before they clear the lobby, escorts them floor-to-floor for the duration of the visit, and logs entry and exit times.
This is where a lot of facilities get burned by undertrained guards: an escort who steps away "for a minute" while the vendor finishes a cable pull has just created an unescorted-access event that no camera can undo after the fact. Agencies experienced with this post train officers to treat the escort obligation as continuous, not a check-in-check-out formality.
SOC 2, ISO 27001, and customer-audit evidence
SOC 2 Type II and ISO 27001 both include physical-access controls in scope, and both frameworks expect the operator to produce evidence the controls are actually enforced — not just documented in a policy binder. That evidence is largely generated at the guard post: visitor logs, escort records, access exception reports, tailgate-alert dispositions, and patrol logs with timestamps.
Colocation tenants often run their own audit cycles on top of the facility's, which means a single lobby post may need to support several different customers' compliance evidence simultaneously — a bank's PCI-DSS assessor, a healthcare tenant's HIPAA business-associate review, and the facility operator's own SOC 2 Type II report, all pulling from the same visitor log. Guards don't own the compliance program, but sloppy logging at the post is one of the fastest ways to generate an audit finding that has nothing to do with the electronic security stack.
CCTV monitoring and incident response
Officers assigned to a security operations center (SOC) desk or a combined guard/monitoring post watch camera feeds across the perimeter, data halls, and generator yard, and respond to door-forced, motion, and access-exception alarms. The response has to be fast enough to matter — most facilities set a target window (commonly under two minutes) for physically checking an alarm — and it has to end in a written record, not a silently cleared light on a panel.
Perimeter, vehicle-gate, and generator-yard coverage
Campus-scale facilities — hyperscale build-to-suit sites in particular — staff a perimeter and vehicle gate separately from the interior mantrap posts, checking arriving vehicles and drivers against a pre-cleared list. Generator and fuel-security posts get extra attention during severe weather, since an unstaffed generator yard during a grid event is exactly the failure mode a facility can't afford.
Background-check depth for cleared personnel
Not every data center post requires the same screening. Facility managers should think of it as a tiered requirement, not a single bar:
| Screening tier | Typical requirement | Common at |
|---|---|---|
| Standard state license | State security guard license, 7-year criminal history check, SSN trace | General colocation lobby and escort posts |
| Facility-enhanced screening | Standard license plus employer-run background check, drug screen, and reference verification specific to the site | Multi-tenant carrier hotels, financial-sector colocation floors |
| Tenant-driven elevated screening | Extended criminal history lookback, credit check in some states, sometimes a polygraph or continuous-monitoring enrollment | Facilities with financial trading infrastructure, healthcare-regulated tenants |
| Government-cloud / regulated-workload screening | Requirements that can include U.S. citizenship, extended federal-style background review, and in some cases a favorable suitability or clearance-adjacent determination | Hyperscale campuses hosting government-cloud regions |
The last tier is worth flagging separately: some hyperscale capacity now serves government-cloud regions or defense-adjacent workloads where officers need to clear more than a standard background check — occasionally including U.S. citizenship as a hard requirement. If your facility has that kind of tenant, say so explicitly when sourcing coverage. Agencies that already carry officers who meet elevated screening standards can staff the post immediately; agencies that don't will need lead time to run the additional screening, and that lead time is not something you want to discover during a compliance deadline.
24/7 staffing models for data centers
Data centers don't tolerate an unstaffed shift change, which pushes almost every facility toward continuous coverage rather than business-hours-only posts. The common models:
- •Standing 24/7 fixed posts — lobby, mantrap, and SOC desk staffed around the clock with a fixed relief schedule. This is the default for any facility carrying SOC 2 Type II certification, since a coverage gap during an off-hours audit sample is a finding waiting to happen.
- •Layered coverage — a fixed lobby/mantrap post plus a roving perimeter and generator-yard patrol on a set circuit, common at hyperscale campuses too large for a single static post to cover.
- •Construction-to-occupancy transition — many hyperscale build sites staff perimeter and material-security posts during construction, then convert the same post to mantrap coordination and escort duties once the facility goes live and tenants start moving equipment in. Sourcing one agency that can carry that transition avoids a hard staffing cutover on move-in day.
- •Surge coverage for maintenance and migrations — added shifts layered on top of standing posts during hardware migrations, planned maintenance windows, or the run-up to an audit, then scaled back down once the window closes.
Colocation vs. enterprise-owned facility staffing
| Factor | Multi-tenant colocation | Enterprise-owned facility |
|---|---|---|
| Who sets the access policy | Facility operator, often layered with each tenant's own rules | Single owner sets one policy for the whole building |
| Escort requirements | Usually strict — one tenant's vendor can't wander into another tenant's cage | Depends on internal policy; often less rigid between departments |
| Audit exposure | Multiple tenants' audit cycles can pull from the same lobby log | Typically one certification program (SOC 2, ISO 27001) to support |
| Visitor volume | High — dozens of vendors and client reps across tenants in a given week | Lower and more predictable |
| Guard-to-tenant coordination | Officer needs each tenant's approved-visitor list, not just the building's | Single approved-visitor list |
Multi-tenant carrier hotels put more coordination load on the guard post itself — a single lobby may be the access-control choke point for a dozen colocation customers, each running its own approved-visitor list and audit cycle on the same shared entry.
How to evaluate a data center security agency
- •Ask for data center-specific experience, not just a general license. A commercial guard license doesn't teach mantrap discipline or escort continuity — ask how many current placements are in controlled-access technology environments.
- •Confirm the agency's tailgate-response process produces a written record every time, not just when something is actually found. Auditors want to see the process ran, not just that nothing bad happened.
- •Check screening depth against your tenant mix. If you host regulated workloads, ask upfront whether the agency has officers who already meet elevated screening standards.
- •Verify the agency's licensing in your state — every legitimate security agency carries an active state license and its own liability insurance, and should produce both on request.
- •Ask how they handle a construction-to-occupancy transition if your facility is still being built out, so staffing doesn't have to restart from zero at move-in.
Post your data center security requirement and get matched with licensed agencies experienced in controlled-access, compliance-driven environments. For the full service breakdown, see data center security services.
If you're comparing vetted agencies by metro, the best data center security companies directory covers agency track records city by city, including Dallas, Chicago, and Phoenix — three of the fastest-growing colocation and hyperscale markets in the country.
For related reading, see security guard services, the security guard cost guide, and our industry security guide.