Risk-Based Security
Match barriers, staffing, monitoring, credentials, and response to the sensitivity of each area.
The JR Institute intends to protect people, facilities, research, records, equipment, vehicles, and infrastructure through proportionate security, controlled access, respectful visitor management, and coordinated emergency response.
This page presents a planned public standard. Final access zones, credential systems, staffing, surveillance practices, visitor procedures, and security authorities should be established before active campus operations.
Research campuses may include public spaces, offices, executive areas, laboratories, data centers, archives, vehicle facilities, receiving areas, residences, and critical infrastructure.
Each area should receive security controls based on actual risk, operational need, privacy, accessibility, and emergency response requirements.
Match barriers, staffing, monitoring, credentials, and response to the sensitivity of each area.
Grant access according to role, location, schedule, training, and demonstrated operational need.
Welcome authorized guests while preserving identity verification, escort, destination, and departure records.
Use cameras, logs, alarms, and analytics only for legitimate security purposes with defined access and retention.
Security personnel should be trained in de-escalation, emergency care, communication, accessibility, and lawful authority.
Test systems, review incidents, correct vulnerabilities, and update access when roles or risks change.
This policy is intended to apply to Institute-owned, leased, operated, or controlled buildings, grounds, parking areas, laboratories, data centers, archives, residences, vehicles, docks, aviation areas, events, and temporary work locations.
Facilities should be divided into zones based on public access, operational sensitivity, research risk, privacy, critical infrastructure, executive use, and emergency function.
Access credentials should be issued to identified persons, limited to authorized areas and times, and reviewed when duties change.
Lost, stolen, duplicated, shared, or compromised keys and credentials should be reported immediately. Access should be disabled promptly when employment, assignment, contract, or visitor authorization ends.
Tailgating, credential sharing, door propping, or bypassing access controls should not be treated as harmless convenience.
Visitors may be required to register, verify identity, state their destination, accept site rules, wear identification, remain with an escort, and return credentials at departure.
Contractor access should be coordinated with the responsible department and may require insurance, safety training, background review, tool control, restricted hours, or supervised work.
Monitoring systems should serve defined safety, security, access, asset-protection, or incident-investigation purposes.
Camera placement, audio recording, analytics, facial recognition, license-plate systems, and retention should receive legal, privacy, and governance review.
Laboratories, data centers, archives, utility rooms, communications systems, aviation areas, security offices, executive spaces, and hazardous-material storage may require enhanced authorization.
Controls may include dual authorization, access logging, escorts, biometric verification, surveillance, alarm response, inventory checks, or limitations on personal devices and photography.
Deliveries should be directed through approved receiving points and screened according to size, source, destination, contents, hazard, and security risk.
Suspicious packages, damaged containers, unknown substances, unapproved chemicals, or unexpected high-value deliveries should be isolated and reported.
Large gatherings, controversial speakers, high-profile visitors, donor events, executive travel, demonstrations, and public programs may require a written security plan.
Planning should address entry, screening, crowd flow, accessibility, medical response, evacuation, communications, transportation, privacy, protests, and coordination with public agencies.
The Institute should establish written rules governing weapons, explosives, hazardous materials, drones, surveillance devices, controlled tools, and other items that may create safety or security risks.
Any exception for authorized law-enforcement, licensed security, research, ceremonial, or operational purposes should be documented and subject to specific control.
Unauthorized entry, threats, violence, suspicious behavior, theft, vandalism, lost credentials, surveillance concerns, tampering, or access-control failures should be reported promptly.
Response should include immediate safety action, preservation of evidence, access review, notification, investigation, coordination with authorities when appropriate, and corrective action.
Framework date: July 2026
Inquiries may concern credentials, visitors, cameras, restricted areas, deliveries, events, executive security, lost property, threats, or suspected unauthorized access.
Identify the location, date, people involved, access concern, immediate risk, and available supporting information.
Contact the Institute