Facilities, Physical Security & Access Control Policy

Keep the campus open enough to serve. Secure enough to protect.

The JR Institute intends to protect people, facilities, research, records, equipment, vehicles, and infrastructure through proportionate security, controlled access, respectful visitor management, and coordinated emergency response.

Developing Framework

This page presents a planned public standard. Final access zones, credential systems, staffing, surveillance practices, visitor procedures, and security authorities should be established before active campus operations.

Policy Purpose

Security should reduce risk without undermining dignity, accessibility, or institutional culture.

Research campuses may include public spaces, offices, executive areas, laboratories, data centers, archives, vehicle facilities, receiving areas, residences, and critical infrastructure.

Each area should receive security controls based on actual risk, operational need, privacy, accessibility, and emergency response requirements.

Core Principles

Layered protection, clear authority, and respectful access.

01

Risk-Based Security

Match barriers, staffing, monitoring, credentials, and response to the sensitivity of each area.

02

Least Necessary Access

Grant access according to role, location, schedule, training, and demonstrated operational need.

03

Visitor Accountability

Welcome authorized guests while preserving identity verification, escort, destination, and departure records.

04

Privacy-Aware Monitoring

Use cameras, logs, alarms, and analytics only for legitimate security purposes with defined access and retention.

05

Professional Response

Security personnel should be trained in de-escalation, emergency care, communication, accessibility, and lawful authority.

06

Continuous Review

Test systems, review incidents, correct vulnerabilities, and update access when roles or risks change.

Scope

This policy is intended to apply to Institute-owned, leased, operated, or controlled buildings, grounds, parking areas, laboratories, data centers, archives, residences, vehicles, docks, aviation areas, events, and temporary work locations.

Security Zones and Facility Classification

Facilities should be divided into zones based on public access, operational sensitivity, research risk, privacy, critical infrastructure, executive use, and emergency function.

  • Public: areas open during designated hours
  • Controlled: areas requiring staff or approved visitor access
  • Restricted: laboratories, data, archives, utilities, or security-sensitive operations
  • Critical: spaces whose compromise could create severe safety, continuity, or security consequences

Credentials, Keys, Badges, and Access Rights

Access credentials should be issued to identified persons, limited to authorized areas and times, and reviewed when duties change.

Lost, stolen, duplicated, shared, or compromised keys and credentials should be reported immediately. Access should be disabled promptly when employment, assignment, contract, or visitor authorization ends.

Tailgating, credential sharing, door propping, or bypassing access controls should not be treated as harmless convenience.

Visitors, Contractors, and Guests

Visitors may be required to register, verify identity, state their destination, accept site rules, wear identification, remain with an escort, and return credentials at departure.

Contractor access should be coordinated with the responsible department and may require insurance, safety training, background review, tool control, restricted hours, or supervised work.

Cameras, Alarms, Logs, and Security Monitoring

Monitoring systems should serve defined safety, security, access, asset-protection, or incident-investigation purposes.

Camera placement, audio recording, analytics, facial recognition, license-plate systems, and retention should receive legal, privacy, and governance review.

Restricted and Critical Areas

Laboratories, data centers, archives, utility rooms, communications systems, aviation areas, security offices, executive spaces, and hazardous-material storage may require enhanced authorization.

Controls may include dual authorization, access logging, escorts, biometric verification, surveillance, alarm response, inventory checks, or limitations on personal devices and photography.

Mail, Packages, Freight, and Deliveries

Deliveries should be directed through approved receiving points and screened according to size, source, destination, contents, hazard, and security risk.

Suspicious packages, damaged containers, unknown substances, unapproved chemicals, or unexpected high-value deliveries should be isolated and reported.

Events, Dignitary Visits, and Executive Protection

Large gatherings, controversial speakers, high-profile visitors, donor events, executive travel, demonstrations, and public programs may require a written security plan.

Planning should address entry, screening, crowd flow, accessibility, medical response, evacuation, communications, transportation, privacy, protests, and coordination with public agencies.

Weapons, Threats, and Prohibited Items

The Institute should establish written rules governing weapons, explosives, hazardous materials, drones, surveillance devices, controlled tools, and other items that may create safety or security risks.

Any exception for authorized law-enforcement, licensed security, research, ceremonial, or operational purposes should be documented and subject to specific control.

Security Incidents and Reporting

Unauthorized entry, threats, violence, suspicious behavior, theft, vandalism, lost credentials, surveillance concerns, tampering, or access-control failures should be reported promptly.

Response should include immediate safety action, preservation of evidence, access review, notification, investigation, coordination with authorities when appropriate, and corrective action.

Framework date: July 2026

Security Lifecycle

Assess, authorize, monitor, respond, and improve.

  • Assess the space. Identify people, assets, hazards, privacy needs, and consequences of compromise.
  • Authorize access. Grant the minimum access needed and document exceptions.
  • Monitor proportionately. Use logs, alarms, patrols, and cameras where justified.
  • Respond professionally. Protect life, de-escalate, preserve evidence, and coordinate with emergency services.
  • Improve controls. Review incidents, remove obsolete access, repair systems, and strengthen weak points.
Security Questions or Concerns

Report suspicious activity, access failures, threats, or unsafe facility conditions.

Inquiries may concern credentials, visitors, cameras, restricted areas, deliveries, events, executive security, lost property, threats, or suspected unauthorized access.

Submit a Physical Security Inquiry

Identify the location, date, people involved, access concern, immediate risk, and available supporting information.

Contact the Institute