UVU Independent External Review — After-Action Report on the Sept 10, 2025 TPUSA Event (158 pp.) (Part 2 of 2)

Charlie Kirk / Tyler Robinson Case — Court Transcripts & Filings

158

2

2026-09-25

Document text

UVU Independent External Review — After-Action Report on the Sept 10, 2025 TPUSA Event (158 pp.) (Part 2 of 2)
Primary document, NOT a court record: commissioned and published by Utah Valley University, the host institution; conducted by Robert L. Davis LLC, Doherty Advisory LLC, The Lake Forest Group and Brownstein Hyatt Farber Schreck LLP. Ten key findings on event planning, security and emergency response, addressing both UVU and Turning Point USA. Released Sept 25, 2026 (PDF dated Sept 24, 2026; SHA-256 d237c79ce10400c90b3f2c827ad197aec3ff4d5824e3ac87856b608d56db8f93). Text extracted from the published PDF (https://www.uvu.edu/externalreview/docs/after-action-report.pdf).

expectations. Formal adoption of the document, coupled with 
a recurring review cycle, would provide greater clarity while preserving flexibility for future updates. 
 
Threat Reporting, Intake, and Case Documentation 
UVU has established multiple reporting pathways intended to encourage early identification and 
reporting of concerning behavior. Reporting mechanisms include: 
▪ BAT online reporting portal 
▪ EthicsPoint reporting system which includes anonymous reporting options 
▪ "Report and Support" reporting website 
▪ Maxient reporting form  
▪ UVU tipline  
▪ Direct reporting to university personnel 
▪ UVU Police reporting channels 
 
Interviewees reported significant increases in utilization of the "Report and Support" website, 
suggesting growing awareness of available reporting resources and increased willingness among UVU 
community members to report concerns. 
 
The BAT utilizes Maxient as its centralized case management and documentation platform. Case files 
include referrals, supporting documentation, investigative information, risk assessments, intervention 
plans, and follow-up activities. The use of a centralized case management system supports continuity, 
accountability, historical review, and multidisciplinary coordination. UVU’s documentation and case 
management practices are generally consistent with accepted higher education standards.37 
 
Upon receipt of a referral, BAT members gather and review information from a variety of sources to 
develop a comprehensive understanding of the circumstances and behaviors of concern. Depending on 
the nature of the case, information may be obtained from incident reports, police reports, conduct 
records, prior BAT cases, faculty and staff observations, interviews with the individual of concern, family 
members, friends, and other relevant sources. Team members are expected to share pertinent 
information with the BAT and contribute relevant background information regarding cases under 
review. 
 
 
37  Maxient. Work Collaboratively. https://www.maxient.com/#1459304968060-3fec7f26-d472. Accessed June 6, 2026.  
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
95 
Following collection and review of available information, the BAT utilizes the National Association for 
Behavioral Intervention and Threat Assessment (NABITA) Risk Rubric — an evidence-based threat 
assessment tool — to assess the level of concern presented by the individual or situation and to guide 
appropriate intervention and management strategies. Risk determinations are documented in case 
records along with the factors that informed the assessment. This structured approach to information 
gathering, multidisciplinary review, documentation, and risk assessment is consistent with accepted 
higher education threat assessment and behavioral intervention practices.38 The BAT appropriately 
utilizes the NABITA Rubric as a case prioritization and decision-support tool rather than as a clinical or 
predictive determination of future violence. 
 
NABITA emphasizes: 
▪ Early identification of concerning behavior 
▪ Structured assessment of risk using evidence-based practices 
▪ Documentation and information sharing within legal and ethical guidelines 
▪ Development of individualized intervention and safety plans 
▪ Ongoing monitoring until the concern has been resolved 
 
For campus police departments and higher education institutions, NABITA's guidance complements 
standards from organizations such as International Association of Campus Law Enforcement 
Administrators (IACLEA) by focusing on behavioral intervention and multidisciplinary threat assessment 
rather than solely on law enforcement operations.39 
 
 
6.2 Information Sharing, OSINT, and Protective Intelligence 
Information sharing is central to effective behavioral threat assessment and threat management. 
Institutions are often required to evaluate fragmented information from multiple sources, including 
student affairs, human resources, faculty, campus police, mental health resources, conduct records, 
online activity, external law enforcement partners, and community reports. Effective programs rely on 
lawful and appropriate information sharing that allows multidisciplinary teams to identify patterns, 
evaluate context, and develop coordinated intervention and management strategies. 
 
Interviews consistently described a culture of open information sharing among BAT members. 
Participants indicated that members trust one another and actively contribute information from their 
respective areas of responsibility. The BAT also benefits from strong relationships with UVUPD and 
external law enforcement partners, including access to information resources through the Utah SIAC. 
 
The BAT appropriately utilizes established privacy exceptions, including the Family Educational Rights 
and Privacy Act (FERPA), U.S. federal law that protects the privacy of student education records, as well 
as health and safety provisions, when circumstances warrant information sharing for safety purposes. 
Team leadership demonstrated a strong understanding of the distinction between protected 
educational records and observable behaviors that may be relevant to safety assessments.  
 
 
38  Randazzo, M. R., & Plummer, E. (2009). Implementing behavioral threat assessment on campus. NABITA. 
39  National Behavioral Intervention Team Association. (2025). About NaBITA. https://www.nabita.org/ 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
96 
Integration of Open-Source Information 
Threat assessment and management teams benefit from incorporating information from multiple 
sources, including institutional records, stakeholder reports, law enforcement information, and publicly 
available online content. Contemporary threat assessment research demonstrates that many individuals 
who engage in targeted violence may never communicate a direct threat. Instead, warning behaviors 
often emerge through grievances, fixation, leakage, stalking, target-focused communications, escalating 
anger, and online activity. As a result, effective threat assessment programs routinely consider both 
institutional information and relevant open-source information when evaluating elevated-risk cases. 
 
Open-source research can be particularly valuable in cases involving alleged stalking, fixation, or 
targeted harassment. Publicly available information may help the team identify, document, and assess 
behavioral patterns such as repeated or escalating contact, efforts to gain physical proximity, 
surveillance or information gathering, use of multiple communication methods, rejection of requests to 
stop, threats or intimidation, underlying grievance or fixation, access to weapons, and any known 
history of violence or prior stalking behavior.40 When documented and assessed appropriately, this 
information can strengthen risk evaluation, intervention planning, and protective decision-making. 
 
UVU possesses several resources that support intelligence gathering and information awareness, 
including Campus Sonar, Sprout Social, Meltwater, law enforcement databases, and access to the Utah 
SIAC. These resources provide valuable visibility into media coverage, public sentiment, social media 
discussions, criminal justice information, and threat-related intelligence. 
 
However, these capabilities are primarily designed to monitor broader conversations, media reporting, 
and institutional issues rather than conduct subject-focused protective intelligence investigations. When 
a specific individual becomes the focus of a BAT assessment, there is no formalized process, dedicated 
capability, or specialized platform for conducting comprehensive open-source investigations of that 
individual. Such investigations may include detailed reviews of publicly available social media activity, 
online communications, civil and criminal court records, litigation history, public records, prior law 
enforcement contacts, affiliations, and other information relevant to assessing risk and identifying 
warning behaviors. 
 
Open-source information is gathered on an informal and case-by-case basis, often relying upon the 
initiative of individual BAT members or law enforcement personnel. Responsibility for collecting, 
analyzing, documenting, and integrating open-source information is distributed among multiple 
stakeholders without a clearly defined protective intelligence function supporting the BAT. 
 
Although UVU’s broader intelligence and OSINT capabilities are addressed elsewhere in this report,  
this issue is distinct because it relates specifically to subject-focused research in BAT cases. A more 
structured approach to subject-focused OSINT and protective intelligence investigations would 
strengthen risk evaluation, contextual understanding, case documentation, and intervention planning 
for elevated-risk individuals. 
 
 
 
40  Meloy, J. R., & Hoffmann, J. (Eds.). (2021). International Handbook of Threat Assessment (2nd ed.). Oxford University Press; 
Association of Threat Assessment Professionals. (2018). Risk factors for stalking and violence. ATAP. 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
97 
6.3 Integration with Security Planning and Protective Measures 
The BAT's primary focus is behavioral intervention, support, and conduct-related concerns rather than 
event security planning or protective security decision-making. This distinction is understandable from 
an organizational perspective. However, contemporary threat assessment and management programs 
increasingly emphasize the importance of connecting behavioral assessment findings to protective 
security planning when circumstances warrant. 
 
The Project Team found limited evidence that threat assessment findings are routinely integrated into 
event security planning, security screening decisions, or other protective measures. This does not mean 
the BAT should become an event-security body or law enforcement operational unit. Rather, it means 
that when BAT cases, threat reports, or behavioral concerns intersect with major events, public 
gatherings, controversial or high-profile speakers, protective details, or identifiable targets, UVU would 
benefit from a defined process for ensuring that relevant information is shared with appropriate 
security, emergency management, and event-planning personnel.41 
 
 
6.4 Training, Professional Development, and Continuous Improvement 
Training represents one of the BAT's greatest strengths. The Project Team reviewed records 
demonstrating participation in numerous threat assessment, violence prevention, behavioral 
intervention, FERPA, Title IX, case management, suicide assessment, and higher education safety 
training programs over many years. In addition, UVU requires employees to complete annual 
compliance training covering topics such as: 
▪ Workplace conduct 
▪ FERPA 
▪ Cybersecurity 
▪ Free speech 
▪ Harassment and discrimination 
▪ Campus Security Authority responsibilities, as applicable 
 
Importantly, completion of required training is tied to employee performance evaluations and merit pay 
considerations. This creates a meaningful incentive for participation and reinforces a culture of 
compliance and accountability. 
 
The BAT has also demonstrated a commitment to professional development through participation in 
NABITA training programs, Stetson Law conferences, Utah Safety Summit programs, and other 
educational opportunities. While UVU's engagement with NABITA has been substantial and beneficial, 
the assessment identified an opportunity to broaden participation in training opportunities with 
external professional organizations and other subject matter experts focused specifically on threat 
assessment and threat management.  
 
 
41  Fein, R. & Vossekuil, B. (1998). Protective Intelligence & Threat Assessment Investigations: A Guide for State and Local Law 
Enforcement Officials. U. S. Department of Justice, Office of Justice Programs, National Institute of Justice: Washington, D.C. 
https://www.ojp.gov/library/publications/protective-intelligence-and-threat-assessment-investigations-guide0? 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
98 
NABITA provides valuable guidance related to higher education behavioral intervention and case 
management. Association of Threat Assessment Professionals (ATAP)42 — a multidisciplinary 
organization dedicated to threat assessment, protective intelligence, stalking, workplace violence, 
targeted violence prevention, and threat management — complements NABITA by providing exposure 
to a broader multidisciplinary community that includes law enforcement, mental health professionals, 
prosecutors, protective intelligence practitioners, workplace violence specialists, and threat 
management professionals. Participation in43 both organizations would provide BAT members with 
access to emerging practices, current case studies, peer networks, and evolving threat assessment 
methodologies.44 
 
In our assessment, UVU’s investment in BAT-related training is a significant strength. Expanded 
participation in ATAP and similar multidisciplinary threat management organizations would supplement 
UVU’s existing higher education-focused training and provide additional exposure to protective 
intelligence, stalking, workplace violence, targeted violence prevention, and threat management 
practices. 
 
 
6.5 Intervention Resources and Related Policies 
An effective threat assessment and management program depends not only on assessment capabilities, 
but also on access to intervention resources.45 UVU maintains robust support services for both students 
and employees. Students have access to Mental Health Services that provide assessment and treatment 
for a variety of concerns, including anxiety, depression, trauma, grief, substance abuse, and relationship 
issues. Services include individual counseling, group counseling, and crisis support resources, along with 
free access to TimelyCare, a third-party mental health support service. 
 
Employees have access to the Employee Assistance Program (EAP) through ComPsych, which provides 
counseling services, crisis support, referral services, and additional mental health resources for 
employees and their dependents. These resources provide the BAT with important intervention options 
and support prevention-focused case management strategies. They also reinforce the principle that 
threat assessment and management is often most effective when it incorporates support, treatment, 
conflict resolution, and resource referral in addition to traditional security measures. The Project Team 
also notes the importance of maintaining strong communication pathways between the BAT, Mental 
Health Services, and EAP providers when circumstances permit and legal obligations require 
coordination regarding safety concerns, threats, or duty-to-warn considerations.46  
 
42  Association of Threat Assessment Professionals. https://www.atapworldwide.org/page/desertswchapter, Accessed May 28, 
2026.  
43  The BAT Chair has since joined ATAP, a positive step consistent with the Project Team’s recommendation.  
44  International Association of Campus Law Enforcement Administrators. (2025). Operational readiness and threat mitigation 
in higher education. IACLEA; Okada, D. T., & Pollard, J. W. (2021). Community-based threat assessment and higher 
education. Journal of College Student Psychotherapy, 35(4), 406–417. https://doi.org/10.1080/87568225.2020.1753609; 
Michaelis, D. (2019). Notes from the field: The value of threat assessment teams. National Institute of Justice. National 
Institute of Justice. 
45  UVU People and Culture. Benefits. EAP Program. https://www.uvu.edu/peopleandculture/division/index.html. 
46  FBI. Making Prevention a Reality 2017. 
https://bn.knowledgebank.criminaljustice.ny.gov/system/files/documents/2021/06/making-prevention-a-reality-
02_fbi.pdf. Accessed May 28, 2026; Utah Code § 78B‑3‑502. 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
99 
Clinical and Forensic Psychology Consultation 
One of the foundational principles of the U.S. Secret Service National Threat Assessment Center 
(NTAC) model is that threat assessment is a behavioral investigative process — not a mental health 
diagnosis or psychiatric evaluation.47 A clinical diagnosis is a mental health condition identified by a 
qualified healthcare professional using established diagnostic criteria.48 An individual is considered to be 
posing a threat when their behaviors, communications, or actions indicate an increased likelihood that 
they may engage in targeted violence or other harmful acts.49 
 
Student Mental Health Services and the Employee Assistance Program provide important treatment, 
counseling, crisis support, and referral resources. These services are essential to a prevention-focused 
threat assessment and management program. However, counseling and EAP services are not the same 
as violence risk assessment or forensic consultation. 
 
A licensed clinical or forensic psychologist trained in violence risk assessment can provide specialized 
consultation to the BAT when cases involve elevated concern, complex behavioral patterns, potential 
violence, stalking, fixation, return-to-campus decisions, or conditions for continued enrollment or 
employment. This type of expertise ensures objectivity and can help the team evaluate whether a threat 
appears transient or substantive, assess the likelihood of escalation, identify appropriate interventions, 
consider whether law enforcement involvement is warranted, and inform decisions regarding continued 
enrollment, employment status, campus access, or return to campus. The Project Team acknowledges 
that a NABITA-trained clinical mental health counselor is a member of the BAT. Access to an external 
evaluator is also recommended to ensure objectivity and clearly delineate the evaluator’s role.  
 
This role differs from counseling, which focuses primarily on symptom reduction, treatment, and client 
well-being. Threat assessment is fundamentally a risk-management and public safety function. While 
counseling centers and EAP providers may offer valuable support and treatment, a licensed clinical or 
forensic psychologist trained in violence risk assessment brings specialized expertise in evaluating 
threats, applying structured assessment tools, advising multidisciplinary teams, and supporting 
institutional decision-making.50 
 
In the Project Team’s assessment, UVU has strong counseling, mental health, and EAP resources, further 
strengthened by the presence of a NABITA-trained licensed clinical mental health counselor on the BAT. 
This provides the team with valuable clinical perspective and behavioral health expertise as part of its 
multidisciplinary assessment process. For elevated-risk or particularly complex cases, the BAT would also 
benefit from reliable access to an external clinical or forensic psychologist with specialized training in 
violence risk assessment. Such consultation can supplement the team’s internal expertise by providing 
an independent perspective, specialized assessment capabilities, and additional support for 
 
47  Fein, et al. Threat Assessment in Schools a Guide to Managing Threatening Situations and Creating Safe School Climates. 
United States Secret Service and the United States Department of Education. July 2024.   
https://www.ed.gov/sites/ed/files/admins/lead/safety/threatassessmentguide.pdf. 
48  American Psychiatric Association. (2022). Diagnostic and statistical manual of mental disorders (5th ed., text rev.; DSM-5-
TR). American Psychiatric Publishing. 
49  National Behavioral Intervention Team Association. (2024). NABITA practice standards.  
50  NABITA, Building an Individualized Threat Management Plan, notes that violence risk assessments should inform long-term 
threat management plans, risk mitigation strategies, and stakeholder engagement.   
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
100 
consequential decisions involving risk management, campus access, continued enrollment or 
employment, and return to campus. 
 
Related Policies and Institutional Framework 
The Project Team reviewed several policies and procedures that support UVU's violence prevention and 
behavioral intervention framework, including: 
▪ Title IX Sexual Harassment Policy #162 
▪ Discrimination and Harassment Policy #165 
▪ Abusive Coaching Practices Policy #166 
▪ Student Safety Intervention Protocol  
▪ Workplace Conduct Policy #326 
▪ Staff Grievance Policy #335 
▪ Performance Management and Development for Full-Time Staff Employees Policy #371 
▪ Faculty Sanction and Dismissal for Cause Policy #649  
 
Collectively, these policies are comprehensive, well-written, and generally aligned with accepted higher 
education practices and applicable legal requirements. However, the BAT is referenced in only a limited 
number of these documents despite the broad range of behaviors routinely reviewed by the team. 
Greater integration of BAT referral pathways and consultation responsibilities across institutional 
policies would help reinforce awareness, improve reporting consistency, and strengthen 
multidisciplinary coordination.  
 
In the Project Team’s assessment, UVU has strong intervention resources and a supportive policy 
framework. The primary opportunity is to more fully connect those resources, policies, and referral 
pathways to the BAT’s role so that community members and institutional partners understand when to 
consult the BAT, how to report concerns, and how multidisciplinary coordination will occur. 
 
 
 
 
 
 
Recommendations related to the issues addressed in this section are included in Section 9. 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
101 
7. Post-Incident Recovery, Corrective Actions, and 
Preparedness Enhancements 
The September 10 incident required UVU to address immediate recovery needs, support affected 
students and employees, respond to public concern, identify lessons learned, and begin strengthening 
emergency preparedness systems. This section summarizes post-incident recovery measures and 
corrective actions initiated or proposed after the incident. 
 
UVU and its partners took several meaningful steps after September 10, particularly in support of 
students, campus safety awareness, crisis communications planning, emergency preparedness training, 
and interagency coordination. At the same time, the Project Team identified opportunities to strengthen 
formal after-action processes, first responder wellness support, corrective-action tracking, and 
integration of post-incident lessons into sustained preparedness improvements. 
 
 
7.1 Post-Incident Recovery and Community Support 
Post-incident recovery is an important component of emergency management. Following a traumatic 
campus incident, effective recovery efforts typically include timely support for students, employees, 
families, first responders, dispatchers, witnesses, and others directly or indirectly affected. Recovery 
may involve reunification or temporary support locations, mental health resources, victim assistance 
services, trauma-informed communications, academic or workplace accommodations, and ongoing 
outreach after the immediate crisis has passed. 
 
Following the September 10 incident, UVU and its partners took steps to support students and members 
of the campus community. The Alumni Building was opened as a temporary location for individuals who 
could not immediately leave campus or who needed a place to go, to include individuals needing 
transportation because their vehicles or other modes of transportation were locked down within the 
campus crime scene areas, and those who could not gain access to keys and other personal belongings 
left behind on campus as they fled the scene. The American Red Cross was contacted to support 
sheltering if needed, although a shelter was not activated because the need did not materialize. 
 
Mental health support was also mobilized. UVU Mental Health Services made trained licensed therapists 
available to speak with students, and additional support was sought from community providers. Support 
included psychological first aid and post-trauma resources. Mental health support was active for 
approximately two weeks and then decreased as demand declined. The FBI Victim Assistance Program 
also became involved quickly after the incident and provided additional support resources. 
 
These efforts reflected an appropriate recognition that students, witnesses, and other campus 
community members needed access to immediate and short-term support services. The involvement of 
UVU Mental Health Services, community providers, and the FBI Victim Assistance Program was a 
strength. To evaluate these efforts fully, UVU would benefit from compiling available utilization data, 
outreach records, after-action observations, and feedback from students, employees, and service 
providers regarding what support was used, what needs were unmet, and what resources may be 
needed in future incidents. 
 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
102 
7.2 Support for UVUPD Personnel and First Responders 
Post-incident support should include 
sworn personnel, dispatchers, emergency 
management staff, communications 
personnel, and other employees directly 
involved in the response. First responders 
may experience operational stress, 
trauma exposure, investigative 
constraints, public scrutiny, and difficulty 
decompressing after a major incident. 
These effects can be compounded when 
responders must continue working in the 
same environment where the incident occurred, respond to related protests or public activity, and avoid 
discussing investigative details while the criminal case remains active and judicial proceedings are 
underway. 
 
Information provided during the review indicates that some peer-support activity occurred after the 
incident. However, the Project Team also identified concern that post-incident support for responding 
UVUPD personnel was less formalized and less visible than the support provided to students and the 
broader campus community. At least one responding officer described difficulty processing the incident, 
frustration with the absence of a formal internal department review process that could have provided 
some opportunity to process what personnel experienced, and a perception that institutional follow-up 
with officers was limited. 
 
These observations should not be understood as criticism of any individual. Rather, they indicate that 
UVU’s recovery framework would benefit from a more structured responder-support process after 
major incidents. Such a process should include timely wellness check-ins, peer support, access to 
confidential mental health resources, opportunities for facilitated decompression, supervisor follow-up, 
and a formal after-action process that allows responders to identify what worked, what was difficult, 
and what support is needed going forward. 
 
In our assessment, responder support should be incorporated into UVU’s post-incident recovery 
framework. Supporting responders is not only a wellness issue; it is also connected to employee 
retention, morale, operational readiness, organizational trust, and institutional learning. A 
comprehensive post-incident recovery plan should include the people who responded to the incident as 
well as the people affected by it. 
 
 
7.3 Awareness, Training, and Preparedness Improvements 
After the incident, UVU initiated or advanced several campus safety awareness and preparedness 
efforts. These efforts included updating classroom posters addressing active shooter, bomb threat, fire, 
medical emergency, and other emergency scenarios. UVU also developed new employee training 
through its learning management system focused on campus safety and active-threat preparedness. 
According to information provided during the review, UVU uses an active shooter training video 
originally developed by the University of Utah and provided for use in the Utah System of Higher 
Education. 


After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
104 
The Project Team reviewed an in-progress draft of UVU’s Crisis Readiness Plan and Guidebook 2026.  
The draft Guidebook is comprehensive and represents an important post-incident improvement. It 
establishes a crisis management framework, identifies emergency and crisis levels, addresses roles and 
responsibilities for life-safety alerts, includes coordination with external agencies, identifies major crisis 
categories, establishes media relations protocols, and includes procedures for lockdowns and post-crisis 
review. The inclusion of pre-drafted and legally reviewed “shelf statements” in a Digital Go Bag is also a 
meaningful improvement because it can help UVU communicate more quickly while verified facts are 
still being gathered. 
 
As UVU finalizes the Guidebook, the University should consider cross-walking the crisis categories in the 
Guidebook with the broader incident categories identified in the Emergency Operations Plan and other 
foreseeable emergency scenarios that may require rapid institutional communication. This would help 
ensure that the Guidebook, Emergency Operations Plan, emergency communications templates, training 
materials, and operational response procedures are aligned across a full range of incidents. 
 
UVU should also use the finalization process to clarify decision-making authority and standardize 
terminology across the Guidebook, Emergency Operations Plan, emergency alert templates, training 
materials, and public-facing instructions. The draft Guidebook appropriately emphasizes speed for life-
safety alerts, but shared unilateral authority can create ambiguity if more than one person is authorized 
to act at the same level. UVU would benefit from identifying a primary decision-maker and designated 
backups for emergency notifications and crisis communications. 
 
The Guidebook also reflects UVU’s decision to use Avoid, Deny, Defend, Aid as its active-assailant 
response protocol. The University is in the process of updating its policy and protocol documents to 
reflect this, including the Emergency Operations Plan and related emergency management, crisis 
communications, training, exercise, and scripted message materials so they consistently use Avoid, 
Deny, Defend, Aid and align related terms such as “lockdown” and “shelter.” 
 
The value of the Guidebook will depend on implementation. Once finalized, UVU should train relevant 
personnel on the Guidebook, test it through realistic tabletop and functional exercises, integrate it with 
EOC procedures and emergency notification templates, and include crisis communications in after-
action improvement tracking. Scenario-based exercises will be particularly important to ensure that the 
plan works under time pressure, with incomplete information, and during events involving competing 
operational, legal, reputational, and life-safety considerations. 
 
 
7.5 Interagency Security and Preparedness Enhancements 
Several important interagency security and preparedness enhancements were initiated or proposed 
after the September 10 incident. These actions are directly responsive to lessons identified during the 
assessment and should be sustained, formalized, and incorporated into UVU’s future planning for major 
events and emergency response. 
 
Commissioner Beau Mason of the Utah Department of Public Safety assigned a DPS member on the SIAC 
team responsibility to focus on locating and analyzing available information associated with safety 
concerns for Utah’s institutions of higher education. Commissioner Mason also requested that each 
Utah institution of higher education designate at least one representative to participate in a new 
working group intended to support regular interaction, information sharing, and coordination among 

After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
106 
new technologies that will enhance data integration and analysis capacities which, in turn, will help to 
improve situational awareness, improve response times, and enhance criminal case investigation 
effectiveness and social media monitoring. University of Utah Chief Safety Officer Squires advised he has 
already committed two University of Utah DPS staff members to join in the efforts of this center on a 
full-time basis. This promising move stands to assist not only both of their own departments to 
collaborate more effectively in their efforts to provide for public safety in Salt Lake City and at the 
University of Utah but also has the potential to provide an additional criminal intelligence resource for 
institutions of higher education throughout Utah.   
 
The City of Orem Police Chief B.J. Robinson advised that OPD and UVU have taken steps to formalize 
their existing informal mutual aid relationship through a written mutual aid agreement. This agreement 
should define roles, request procedures, command coordination, resource sharing, specialized 
capabilities, communications expectations, cost-recovery protocols, and support for major events and 
emergency incidents. 
 
OPD’s aerial drone capability should also be considered as part of future event planning when 
appropriate and legally permissible. Chief Robinson advised that OPD would have provided drone 
support had the resource been requested and had OPD known more in advance about event details, 
including the specific location of the event. Future event planning should include early identification of 
specialized resources available from partner agencies, including drones, tactical teams, traffic-control 
assets, fire and EMS staging, emergency management personnel, and investigative support. 
 
Orem Fire Chief Marc Sanderson advised that he had spoken with Chief Robinson about approaching 
UVU to conduct a joint active shooter training exercise. This proposed exercise should include UVUPD, 
OPD, Orem Fire, Orem Emergency Management, and other appropriate local partners. It should test the 
Incident Command System, unified command, emergency medical response, victim search and rescue, 
building sweeps, emergency communications, Command Post operations, Emergency Operations Center 
coordination, traffic control, and public information coordination. 
 
Orem Emergency Management Director Keith Stevenson also advised that his office is willing to assist 
UVU with future emergency management policy development, training, and preparedness efforts. UVU 
should actively incorporate Orem Emergency Management into future planning, exercises, and after-
action improvement tracking, particularly for major events with elevated security concerns or large 
public attendance. 
 
As UVU continues post-incident preparedness enhancements, it should also consider whether no-cost 
CISA resources could support physical security review, cybersecurity preparedness, tabletop exercises, 
targeted violence prevention, and broader campus resilience planning. 
 
In the Project Team’s assessment, these local and statewide interagency efforts are a meaningful 
strength and provide UVU with important opportunities to enhance its own preparedness. The 
opportunity is not only to monitor these efforts, but to participate in them proactively, as UVU’s General 
Counsel is doing, identify other appropriate UVU representatives who should become engaged as 
recommendations are ultimately being implemented statewide, and incorporate relevant tools, 
resources, intelligence-sharing practices, and lessons learned into UVU’s Security Assessments, Event 
Action Plans, emergency management processes, threat assessment work, mutual aid planning, and 
corrective-action tracking. 






After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
113 
Policy 425 also addresses the concern commonly referred to as “fronting.” Section 3.4 defines fronting 
as “permitting or aiding an external use under the guise that the activity is a University or a cosponsored 
event for the purposes of avoiding contracts, risk management, or Event Services review, payments, or 
other requirements or conditions applicable to external events.” This provision is intended to prevent 
external organizations from avoiding the procedural, financial, insurance, and risk-management 
requirements that apply to external events, including significant security fees that might be 
appropriately assessed. 
 
The fronting provision is important because event classification affects how the University evaluates 
risk, assigns responsibilities, imposes conditions, coordinates with organizers, and documents 
obligations. If an external organization is effectively controlling or sponsoring an event, but the event is 
processed as a University or co-sponsored event without appropriate documentation, the University 
may lose the benefit of external-use agreements, insurance verification, cost recovery, indemnification 
provisions, and formal review procedures. At the same time, the entity that is being “fronted” may 
benefit from avoiding considerable costs associated with the event. The question is often whether an 
event is really being held at the request of a club or other internal university entity or whether an 
external organization is using the internal entity to avoid paying appropriate costs.  
 
At the same time, event classification must be applied consistently and, in a content-neutral manner.  
A public university may not reclassify, burden, or deny an event because of disagreement with the 
speaker’s viewpoint or anticipated public reaction. However, the University may apply neutral policy 
requirements related to sponsorship, facility use, contracting, insurance, cost allocation, risk 
management, and operational review when those requirements are grounded in objective criteria and 
applied consistently across events. 
 
Key Legal Takeaways 
Policy 425’s fronting provision is an important risk-management and compliance tool. UVU should 
ensure that event classification decisions are documented, consistently applied, and based on objective 
criteria regarding sponsorship, control, facility use, and external involvement. Clear application of Policy 
425 helps preserve constitutional neutrality while also ensuring that contracts, insurance, cost 
allocation, Event Services review, and risk-management requirements are not bypassed when external 
entities are involved. 
 
 
8.3 First Amendment Considerations 
Public University Obligations Regarding Free Speech 
As a public university, UVU is required to protect lawful expressive activity regardless of the popularity 
or controversy of the viewpoint being expressed. UVU states its commitment to protection of First 
Amendment rights in its Policy 161, Freedom of Speech. The University's role is not to endorse or 
oppose particular viewpoints, but rather to provide a lawful environment in which protected speech 
may occur. These obligations become particularly significant when events involve political figures, 
controversial speakers, or issues that may generate strong public reactions. The September 10 TPUSA 
event presented many of the challenges public universities routinely face when balancing constitutional 
freedoms with safety and operational concerns. 
 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
114 
Controversial Speakers 
Public institutions generally may not deny access to facilities, cancel events, or impose burdens on 
speakers because of disagreement with the speaker's views or because others oppose those views. 
Anticipated controversy, public criticism, or the possibility of protests does not diminish First 
Amendment protections. Universities may, however, take reasonable steps to address legitimate safety 
concerns associated with an event, provided those measures are based on objective security 
considerations rather than the content of the speech itself. 
 
Time, Place, and Manner Restrictions 
Although public institutions must protect speech rights, they may impose reasonable, content-neutral 
restrictions concerning the time, place, and manner of expressive activities. Such restrictions must serve 
legitimate governmental interests, be narrowly tailored, and leave open alternative opportunities for 
expression. These principles are particularly relevant when evaluating venue selection, crowd 
management, protest activity, access-control measures, and event logistics. They are also reflected in 
Utah law, which recognizes outdoor areas of public university campuses as traditional public forums 
entitled to heightened constitutional protection. Section 4.2.2 of UVU Policy 161 provides for time, 
place, and manner restrictions. 
 
Security Fees and Viewpoint Neutrality 
Courts have consistently held that security-related decisions must remain viewpoint neutral. Institutions 
may not impose costs, restrictions, or conditions based upon the anticipated reaction to a speaker's 
message or the controversial nature of a viewpoint. As a result, universities must be able to 
demonstrate that security decisions are grounded in objective risk factors, documented planning 
considerations, and consistent institutional practices. Any security fee assessed must be based on 
objective, content-neutral criteria that eliminates arbitrary discretion by university officials.52 
 
Key Legal Takeaways 
The First Amendment significantly limits the ability of public universities to restrict speakers, deny event 
requests, or impose burdens based on anticipated controversy. Consequently, event planning processes 
must be capable of distinguishing between legitimate safety concerns and viewpoint-based 
considerations. Well-documented, objective, and consistently applied decision-making processes are 
essential to maintaining both constitutional compliance and public confidence. 
 
 
8.4 Firearms and Security Screening Considerations 
Utah Campus Carry Laws 
While prohibition of firearms on college campuses is permissible under the Second Amendment,53 Utah 
law broadly permits lawful concealed firearm possession on public college and university campuses. On 
September 10, 2025 an individual 18 years of age or older, with a concealed weapon permit, could carry 
 
52  Leadership Institute et al. v. Stokes et al., 2024 CV 01 87, U.S. District Court of New Mexico 
53  Wade v. Univ. of Michigan, 145 S.Ct. 1923, No. 24-773 (2025) (cert. denied). 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
115 
a weapon on a Utah campus, either open or concealed.54 At present, any individual 21 years of age or 
older, and not legally disqualified from possessing a firearm, can carry a concealed weapon on a Utah 
campus, with or without a concealed weapon permit.55 Unlike many states, Utah does not provide 
public institutions with independent authority to prohibit lawful firearm possession on campus property. 
Accordingly, UVU's ability to regulate firearms during campus events is substantially more limited than 
that of institutions operating in jurisdictions with different statutory frameworks. 
 
State Preemption 
Utah maintains strong state preemption over firearms regulation. Public institutions generally may not 
adopt firearms restrictions beyond those authorized by state law. Decisions regarding firearm 
possession and regulation are largely reserved to the State Legislature. This legal framework limits the 
University's discretion to implement security measures that might otherwise be available in other states. 
 
Weapons Screening Limitations 
Because of Utah's statutory framework, the use of weapons screening measures presents unique legal 
and operational challenges. Security practices commonly employed at public events elsewhere—
including temporary event-specific firearm prohibitions—may not be available to public universities in 
Utah. While screening may be used to identify who has a weapon, it may not result in prohibiting 
possession of the weapon inside the venue. As a result, readers from outside Utah should recognize that 
some security measures frequently discussed following high-profile incidents may not have been legally 
available to UVU. 
 
Key Legal Takeaways 
Utah's firearms laws significantly constrain the security options available to public universities. As a 
practical matter, institutions must rely more heavily on threat assessment, intelligence gathering, venue 
planning, staffing decisions, and other preventive security measures than universities operating in states 
that authorize broader firearm restrictions or screening programs. 
 
 
8.5 Clery Act and Emergency Notification Considerations 
Timely Warnings 
The Jeanne Clery Campus Safety Act requires higher education institutions to issue timely warnings 
regarding certain crimes that pose a serious or continuing threat to the campus community. These 
warnings are intended to provide members of the campus community with information necessary to 
make informed decisions regarding their safety. 
 
Emergency Notifications 
The Clery Act separately requires emergency notifications when an institution confirms a significant 
emergency or dangerous situation involving an immediate threat to the health or safety of students or 
employees. These notifications are intended to be issued without unnecessary delay while considering 
 
54  HB 128, Utah Code § 76-11-205.5 (2025) 
55  HB 84, Utah Code § 76-11-205.5 (2026) 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
116 
the needs of emergency response efforts. UVU's Annual Security and Fire Safety Report incorporates 
these requirements through its Emergency Operations Plan and Emergency Communications Plan.  
 
Emergency Communications Obligations 
Emergency notifications must provide timely, accurate, and actionable information to affected 
populations. In rapidly evolving incidents, institutions must make decisions based on incomplete 
information while balancing public safety concerns, operational realities, and evolving investigative 
facts. The events of September 10, 2025 demonstrate the challenges institutions face when 
communicating during a dynamic and uncertain incident. As circumstances evolve, maintaining 
consistency, clarity, and public understanding becomes increasingly difficult but remains critically 
important. 
 
Documentation Requirements 
The Clery Act and UVU policy require the institution to maintain records relating to emergency 
preparedness, emergency response procedures, testing, exercises, and after-action reviews. UVU's 
Emergency Operations Plan and Annual Security Report contain detailed provisions governing these 
responsibilities, including documentation of exercises, lessons learned, and corrective actions.  
 
Key Legal Takeaways 
The Clery Act does not merely require institutions to communicate during emergencies; it requires them 
to maintain policies, systems, training, and documentation capable of supporting effective emergency 
communications. The quality of emergency communications is often evaluated not only by the speed of 
notification, but also by the accuracy, consistency, and clarity of information provided throughout an 
incident. 
 
 
8.6 Legal Review of Findings and Recommendations 
Brownstein Hyatt Farber Schreck LLP reviewed the findings and recommendations contained in this 
report and determined that they are generally consistent with applicable federal and state law, including 
the Jeanne Clery Campus Safety Act, Utah statutory requirements applicable to public institutions of 
higher education, and relevant constitutional considerations governing free expression and public safety 
on university campuses. 
 
 
Recommendations related to the issues addressed in this section are included in Section 9. 












After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
129 
Appendices 
Appendix A: Project Team Bios 
 
Core Law Enforcement and Security Risk Management Team 
Robert L. Davis, Project Manager, Law Enforcement Operations Specialist 
President, Robert L. Davis, LLC; Former Chief of Police, San Jose, California;  
Former President, Major Cities Chiefs Association 
Rob Davis brings more than 30 years of law enforcement leadership experience, 
including service as Chief of Police for the City of San Jose — one of the nation’s 
largest municipal departments, along with 15 years of consulting experience. He is 
widely recognized for strengthening operational readiness and response, leading 
complex incident assessments, improving investigative processes, strengthening media interaction 
capabilities, and assessing training curriculums and methodologies. Rob has directed high-stakes 
assessments for public agencies and universities nationwide.   
 
Matthew W. Doherty, Targeted Violence and Threat Assessment and Management Specialist 
Founder and Managing Principal, Doherty Advisory 
Matt Doherty is a nationally recognized authority in behavioral threat assessment and 
management, targeted violence, workplace violence prevention, and organizational 
security practices. He draws on more than four decades of distinguished service in 
both government and the private sector, including leadership of the U.S. Secret 
Service National Threat Assessment Center. Matt has led threat management 
practices for global consulting firms and continues to advise organizations seeking to strengthen 
violence-prevention programs and mitigate risk.   
 
G. Michael Verden, Security Operations and Emergency Management Specialist 
CEO and Founder, The Lake Forest Group 
Mike Verden is a prominent security strategist with deep expertise in event security, 
protective intelligence, and emergency preparedness. As CEO and Founder of The 
Lake Forest Group and former operational leader within the Major Events Division, 
Dignitary Protection Division, and Presidential Protection Division of the U.S. Secret 
Service, he has directed complex risk assessments for NSSEs, major venues, 
universities, corporations, and government entities, and has also served as an expert witness reviewing 
security plans and threat intelligence for the Ben Shapiro event at the University of Minnesota. Mike 
brings extensive experience designing resilient security programs and plans that align operational needs 
with industry best practices.   
 

After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
130 
Core Brownstein Team 
John Suthers, Legal Counsel and Project Manager for the Brownstein Team 
Shareholder, Brownstein Hyatt Farber Schreck, LLP; Former Mayor, Colorado 
Springs; Former Colorado Attorney General; Former United States Attorney 
John Suthers brings nearly five decades of legal, public safety, government, and 
investigative experience to the project team. He has served as a Deputy District 
Attorney, Chief Deputy District Attorney, and elected District Attorney for Colorado’s 
Fourth Judicial District. He also served as Executive Director of the Colorado 
Department of Corrections, United States Attorney for the District of Colorado, Attorney General of 
Colorado from 2005 to 2015, and Mayor of Colorado Springs from 2015 to 2023. Mr. Suthers has 
extensive experience conducting external and internal investigations, including matters involving school 
and campus safety. Following the 2007 shooting at Virginia Tech University, he served as co-chair of the 
National Association of Attorneys General Task Force on School and Campus Safety. As United States 
Attorney for Colorado, he conducted a review of the Columbine Commission report in response to a 
petition by parents of students killed at Columbine High School. In 2024, he was part of a Brownstein 
team that conducted an external review of a double homicide in a residence hall at the University of 
Colorado, Colorado Springs. Mr. Suthers earned his J.D. from the University of Colorado School of Law in 
1977 and his B.A., cum laude, from the University of Notre Dame in 1974. 
 
Jason Dunn, Legal Counsel  
Shareholder, Brownstein Hyatt Farber Schreck, LLP; Former U.S. Attorney;  
Former Deputy Attorney General of Colorado 
Jason Dunn has been practicing law for 25 years. He served as Deputy Attorney 
General of Colorado and as US Attorney for Colorado. As a seasoned counselor and 
litigator, he has led and advised on some of the most high-profile private and 
governmental investigations in Colorado. He is chair of Brownstein‘s Attorney General 
Practice and its Government Investigations and White Collar Defense Group. Mr. Dunn’s extensive 
experience in conducting external and internal investigations includes work for the University of 
Colorado. He earned his J.D. from the University of Colorado Law School, his M.P.A. from the University 
of Colorado Graduate School of Public Affairs, and his B.S. from the University of Colorado College of 
Business.  
 
Max Porteus, Legal Counsel 
Max Porteus is a litigation associate whose practice focuses on handling complex 
disputes, including trial level and appellate litigation, internal and government 
investigations, and high stakes commercial matters. His work spans litigation strategy, 
complex briefing, and advising clients in investigations and disputes from inception 
through appeal. He previously clerked for Justice Carlos A. Samour, Jr. of the Colorado 
Supreme Court. He earned his J.D. from the University of Denver Sturm College of 
Law, Order of the Coif, and his B.A. from the University of Denver.  
 
 

After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
131 
Advisory Board 
Brent Herron, Subject Matter Expert: Campus Safety 
Brent Herron is a nationally recognized expert in campus safety, emergency 
operations, and threat management with more than 30 years of experience in higher 
education and federal protective operations. He served as the University of North 
Carolina System’s Senior Associate Vice President for Campus Safety and Emergency 
Operations, leading systemwide initiatives across 16 universities and directing major 
programs in policing, emergency management, and behavioral threat assessment. 
Prior to his higher education leadership role, Brent spent 21 years with the U.S. Secret Service, 
supporting and supervising technical security operations for multiple NSSEs. He currently advises the 
UNC System on policy, preparedness, major-incident response, and interagency coordination. 
 
Chris Brenner, Subject Matter Expert: Open-Source Intelligence  
Chris Brenner is an investigations and intelligence specialist with more than 15 years 
of experience applying advanced OSINT tools and methodologies to support complex 
investigations and threat assessments. As Associate Managing Director and Director 
of Technology at 221B Partners, he leads OSINT-driven research, deep and dark web 
analysis, and data visualization to support clients across corporate, government, and 
nonprofit sectors. He is Open-Source Certified (OSC) by the OSMOSIS Association, 
where he serves on the Board of Advisors, and is an active member of ATAP, InfraGard, and OSAC. 
 
Heather Czyzewicz, Subject Matter Expert: Security Technology 
Heather Czyzewicz is a security technology specialist with extensive experience 
helping organizations implement scalable, interoperable physical security solutions. 
She leverages strong industry partnerships, continuous technology research, and 
cross-market expertise to guide clients in selecting and deploying effective, budget-
aligned systems. Heather currently serves as Business Development Manager for 
Sound Incorporated, where she advances integrated technology strategies and 
strengthens organizational readiness across diverse sectors. 
 
James A. Konieczny, Subject Matter Expert: Counter Sniper Tactics 
James Konieczny is a retired U.S. Secret Service Special Agent with 25 years of federal 
service and deep expertise in counter-sniper operations for high-risk environments. He 
spent two decades in the USSS Counter Sniper Unit — later serving as an instructor — 
where he trained agents in long-range precision shooting, weapons proficiency, and 
advanced counter sniper tactics. James has supported protective missions for four U.S. 
Presidents and led counter sniper teams during multiple NSSEs. 
 
Michelle Hoy-Watkins, Psy.D., ABPP, Licensed Clinical Psychologist 
Michelle Hoy-Watkins, Psy.D., ABPP is a Licensed Clinical Psychologist with more than 
25 years of experience in clinical, forensic, and police and public safety psychology. 
She is Board Certified in Police and Public Safety Psychology and has provided 
psychological services, wellness programs, threat assessments, and consultative 
support to numerous law enforcement agencies, including the Chicago Police 

After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
132 
Department, Illinois State Police, and Northwestern University Police. Dr. Hoy-Watkins previously led 
Northwestern University’s threat assessment program and has extensive experience conducting forensic 
evaluations and working in federal and state correctional and mental health institutions. She currently 
serves as a consultant to state and national threat assessment teams and holds multiple leadership roles 
within the International Association of Chiefs of Police and the American Psychological Association. 
 
John A. Gill, Subject Matter Expert: Crisis Communications and Public Affairs  
John Gill is an accomplished crisis communications and public affairs leader with more 
than 30 years of experience guiding high-stakes messaging, media coordination, and 
stakeholder engagement at the highest levels of government and the private sector. 
His career includes senior roles in the White House and the U.S. Secret Service, where 
he led the agency’s public affairs and crisis communications programs during the post-
9/11 era. John has managed complex security, continuity, and executive 
communication efforts across global operations, bringing a steady, trusted voice to organizations facing 
sensitive or rapidly evolving events. He is known for his clarity, integrity, and ability to translate complex 
operational issues into decisive, credible communication strategies. 
 
 
Communications Lead 
Vicky Froderman, Senior Advisor, Research and Reporting 
Vicky Froderman has a career rooted in communications, with long-standing expertise 
in writing, messaging, research, and producing high-quality materials for senior 
leaders and diverse audiences. For the past 20 years, her work has focused on security 
risk management and workplace violence prevention, where she has applied those 
skills to complex, high-stakes assessments and sensitive client matters. She has 
contributed to hundreds of assessments, including the Virginia Beach mass shooting 
review, supporting multidisciplinary teams through interviews, document review, report development, 
editing, quality control, and the organization and presentation of findings and recommendations. Vicky 
brings clarity, precision, and analytic discipline to complex engagements, helping ensure that 
conclusions are well-supported and communicated clearly and consistently. 
 

After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
133 
Appendix B: Incident Command System (ICS) 
Roles and Responsibilities 
The Incident Command System (ICS) is a standardized management framework used to coordinate 
personnel, resources, communications, and decision-making during emergencies and planned events. 
While the specific structure may expand or contract depending on the complexity of an incident, the 
following positions are commonly used within ICS-compliant organizations. 
 
Incident Commander (IC) 
The Incident Commander has overall responsibility for managing the incident and establishing incident 
objectives and priorities. The IC directs response activities, authorizes resource requests, approves 
strategic decisions, and serves as the primary decision-maker throughout the incident. Typical 
responsibilities include: 
▪ Establishing incident objectives and priorities 
▪ Approving operational strategies and response actions 
▪ Requesting additional resources and mutual aid when necessary 
▪ Coordinating with executive leadership 
▪ Maintaining overall situational awareness 
▪ Authorizing incident closure and "all clear" notifications 
 
Public Information Officer (PIO) 
The Public Information Officer serves as the official communications representative during an incident 
and is responsible for developing, coordinating, and disseminating information to internal and external 
audiences. Typical responsibilities include: 
▪ Preparing public statements and media releases 
▪ Coordinating communications with stakeholders and families 
▪ Monitoring media coverage and public messaging 
▪ Supporting emergency notification activities 
▪ Ensuring consistent and accurate information is released 
 
Liaison Officer (LNO) 
The Liaison Officer serves as the primary point of contact for assisting agencies, partner organizations, 
and external stakeholders supporting incident operations. Typical responsibilities include: 
▪ Coordinating with responding public safety agencies 
▪ Facilitating information sharing between organizations 
▪ Assisting with mutual aid coordination 
▪ Participating in planning meetings 
▪ Communicating resource needs and capabilities among partner agencies 
 
Safety Officer (SO) 
The Safety Officer monitors incident operations and advises leadership regarding safety concerns 
affecting responders, staff, students, visitors, and other stakeholders. Typical responsibilities include: 
▪ Identifying and evaluating safety hazards 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
134 
▪ Monitoring responder safety and operational risks 
▪ Coordinating with law enforcement and emergency responders 
▪ Assessing evacuation routes and assembly locations 
▪ Recommending corrective actions when unsafe conditions exist 
 
Operations Section Chief 
The Operations Section Chief manages tactical activities and directs personnel engaged in incident 
response operations. Typical responsibilities include: 
▪ Supervising operational resources 
▪ Implementing incident objectives 
▪ Coordinating field activities 
▪ Monitoring operational progress 
▪ Reporting status updates to command staff 
 
Planning Section Chief 
The Planning Section Chief is responsible for collecting, evaluating, and disseminating information 
needed to support incident management. Typical responsibilities include: 
▪ Maintaining situational awareness 
▪ Tracking incident status and resources 
▪ Developing Incident Action Plans 
▪ Documenting operational activities 
▪ Supporting future operational planning 
 
Logistics Section Chief 
The Logistics Section Chief provides facilities, personnel, equipment, communications, and other 
resources necessary to support incident operations. Typical responsibilities include: 
▪ Acquiring and distributing resources 
▪ Coordinating communications systems 
▪ Supporting personnel needs 
▪ Managing facilities and equipment 
▪ Tracking resource availability 
 
Finance and Administration Section Chief 
The Finance and Administration Section Chief manages financial, procurement, documentation, and 
administrative functions associated with incident operations. Typical responsibilities include: 
▪ Tracking incident-related costs 
▪ Managing procurement activities 
▪ Documenting personnel time and expenses 
▪ Supporting reimbursement processes 
▪ Maintaining incident financial records 
 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
135 
Appendix C: OSINT and Protective Intelligence 
Technical Considerations 
This appendix provides additional technical considerations related to open-source intelligence, social 
media monitoring, subject-focused research, protective intelligence, and investigative governance. These 
considerations support the findings and recommendations in Section 5.3. 
 
1. Social Listening, Media Monitoring, and Protective Intelligence 
Universities may use several types of tools and processes to support safety, communications, and threat 
assessment functions. These capabilities overlap but are not interchangeable. 
 
Social listening tools help monitor public online discussion, sentiment, event-related activity, and 
institutional reputation. Media monitoring tools help track traditional and online media coverage. Law 
enforcement databases support criminal justice and public safety inquiries. Protective intelligence and 
OSINT investigative tools support deeper research into specific persons, groups, threats, or behaviors of 
concern. 
 
A mature program defines the purpose, owner, workflow, documentation requirements, and escalation 
path for each capability. 
 
2. Subject-Focused OSINT 
Subject-focused OSINT may be appropriate when a specific individual, group, communication, or 
behavior of concern requires additional assessment. Depending on the circumstances, this may include 
review of: 
▪ Publicly available social media activity 
▪ Online communications 
▪ Public records 
▪ Civil and criminal court records 
▪ Litigation history 
▪ Prior law enforcement contacts 
▪ Publicly available affiliations or networks 
▪ Grievances, fixation, leakage, or target-focused communications 
▪ Event-related threats or concerning statements 
▪ Information from law enforcement, fusion center, or intelligence-sharing partners 
 
The purpose of subject-focused OSINT is to support risk assessment, case management, intervention 
planning, event security, and protective decision-making. It should not be conducted casually, 
inconsistently, or without appropriate documentation and oversight. 
 
3. Governance and Documentation 
OSINT-related procedures should address: 
▪ Who may conduct OSINT research. 
▪ What circumstances justify subject-focused OSINT. 
▪ What sources may be reviewed. 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
136 
▪ What approvals are required. 
▪ How findings are documented. 
▪ How information is validated. 
▪ How screenshots or other records are preserved. 
▪ How irrelevant or sensitive information is handled. 
▪ How long information is retained. 
▪ Who receives findings. 
▪ How findings are incorporated into BAT, UVUPD, emergency management, or event-planning 
decisions. 
▪ How legal, privacy, and institutional policy issues are reviewed. 
 
4. Investigative Accounts and Operational Security 
Threat assessment-related OSINT should not be conducted using personal social media accounts. Use  
of personal accounts may create operational security, privacy, documentation, attribution, and 
investigative integrity concerns. 
 
Where OSINT research is authorized, institutions should consider approved investigative accounts, 
controlled research environments, standardized documentation practices, and supervisory oversight. 
Policies and procedures may address operational security practices, preservation of content, authorized 
platforms, account management, and methods for preventing inadvertent exposure of personal or 
institutional information. 
 
More advanced operational security considerations may include controlled workstations, approved 
internet environments, virtual research environments, attribution management, and specialized 
investigative tools. These capabilities should be implemented only with appropriate legal, privacy, 
cybersecurity, procurement, and supervisory review. 
 
5. Specialized OSINT and Protective Intelligence Platforms 
UVU may evaluate dedicated OSINT, protective intelligence, or threat intelligence platforms designed  
to support subject-focused investigations, identity resolution, monitoring, case documentation, and 
intelligence reporting. Platform evaluation should be based on institutional need, legal requirements, 
privacy considerations, cybersecurity, data retention, auditability, integration with existing case-
management systems, training needs, and cost. 
 
Examples of industry-recognized enterprise platforms used in OSINT, protective intelligence, or threat 
intelligence contexts include Ontic,56 Liferaft,57 Babel Street,58 Flashpoint,59 Fivecast,60 Skopenow61 and 
other similar tools. This list is not a recommendation or endorsement of any vendor. Any vendor 
 
56  https://ontic.co/ 
57  https://liferaftlabs.com/ 
58  https://www.babelstreet.com/ 
59  https://flashpoint.io/ 
60  https://www.fivecast.com/ 
61  https://www.skopenow.com/ 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
137 
evaluation should be conducted through UVU’s normal procurement, legal, privacy, and cybersecurity 
review processes. 
 
6. Deep Web, Dark Web, and Alternative Platforms 
Some protective intelligence inquiries may require awareness of information outside mainstream social 
media or traditional web searches. Depending on the matter, relevant information may appear on 
alternative social media platforms, online forums, message boards, encrypted or semi-private 
communities, deep web sources, or dark web environments. 
 
These sources present heightened legal, ethical, operational security, cybersecurity, privacy, and safety 
considerations. They should be accessed only by trained personnel or qualified external resources using 
approved methods, documented procedures, and appropriate legal, cybersecurity, privacy, and 
supervisory oversight. 
 
Operational security policies and investigative procedures should address, as appropriate, the 
authorized use of VPNs or proxies, Tor62 and other dark web access methods, virtual machines, 
controlled or segregated internet connections, so-called “dirty” internet connections, air-gapped 
workstations, agency-managed investigative or “sock puppet” accounts, enterprise-managed attribution 
tools, and forensic preservation methods. The level of technical control should be based on the nature 
of the inquiry, the sensitivity of the matter, the risk to personnel or the institution, and applicable legal 
and policy requirements. 
 
UVU should not rely on ad hoc searches, personal devices, personal social media accounts, or informal 
access methods for official protective intelligence inquiries involving deep web, dark web, or alternative-
platform research. Any use of these sources should occur within a defined governance framework that 
addresses authorization, training, documentation, retention, evidence preservation, source validation, 
reporting, and dissemination of findings. 
 
7. Analyst Qualifications and Training 
Personnel conducting OSINT or protective intelligence work should receive training in lawful and ethical 
collection, source evaluation, documentation, reporting, privacy, operational security, and threat 
assessment integration. 
 
When evaluating internal OSINT analyst staffing or external vendors, UVU may consider recognized 
training and certification programs. The OSMOSIS Association’s Open-Source Certification is one 
example of a credential that evaluates OSINT-related knowledge across core areas such as critical 
thinking, tradecraft, reporting, and laws and ethics.63 Certification should not be the only qualification 
considered, but it may help identify baseline expertise. 
 
8. Integration with BAT, Event Planning, and Emergency Management 
OSINT and protective intelligence are most valuable when integrated into decision-making. Procedures 
should clarify how relevant information is shared with: 
 
62  https://www.torproject.org/ 
63  https://osmosisassociation.org/certifications/ 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
138 
▪ Behavioral Assessment Team members 
▪ UVUPD 
▪ Emergency Management 
▪ Event Services 
▪ Communications 
▪ Legal Counsel 
▪ SIAC or other law enforcement partners 
▪ Event security planners 
▪ Executive leadership when appropriate 
 
For elevated-risk events, protective intelligence findings may inform venue selection, staffing, access 
control, screening, credentialing, protest management, communications planning, mutual aid requests, 
and Event Action Plans. For BAT cases, findings may inform risk assessment, intervention planning, 
monitoring, outreach, documentation, and protective measures. 
 
9. Relationship with SIAC and External Partners 
SIAC is an important resource for threat-related intelligence, suspicious activity reporting, criminal 
intelligence, targeted violence prevention, and information sharing. UVU should continue leveraging 
SIAC for pre-event threat assessments, threat management consultation, training, information sharing, 
and support for elevated-risk cases. 
 
UVU should also define when and how SIAC, local law enforcement, state partners, or qualified external 
OSINT resources may be engaged to support specific cases or events. 
 
10. Leveraging SIAC’s Existing Intelligence and Information-Sharing Platform 
A potential opportunity exists for UVU to leverage SIAC’s existing intelligence and information-sharing 
technology to support threat management, protective intelligence, suspicious activity reporting, major-
event planning, and information sharing. SIAC currently uses Kaseware as part of its investigations, 
intelligence, and information-sharing environment. Because SIAC already has this capability in place, 
UVU may not need to develop or procure a wholly separate platform to improve access to certain 
intelligence workflows, analytical support, or information-sharing processes. 
 
This appendix does not recommend or endorse a specific vendor. Rather, the relevance of Kaseware is 
that SIAC already uses the platform in support of its fusion center mission. UVU should explore whether 
SIAC’s existing environment can support appropriate collaboration involving threat information, 
suspicious activity reports, investigative leads, intelligence products, event-related intelligence, and 
other information relevant to campus safety. 
 
A structured discovery process involving UVU, SIAC, UVUPD, Emergency Management, the Behavior 
Assessment Team, Legal Counsel, and other appropriate stakeholders would help determine the most 
appropriate operating model. That process should evaluate whether UVU would benefit from direct 
platform access, a dedicated tenant, a shared collaborative environment, a SIAC-managed workflow, or 
another structure that supports operational needs while preserving appropriate access controls, 
auditability, data ownership, privacy protections, and organizational independence. 
 
 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
139 
The discovery process should address, at a minimum: 
▪ What types of threat, suspicious activity, event-security, or protective intelligence information  
UVU would submit to or receive from SIAC. 
▪ Which UVU personnel, if any, should have direct access to the platform. 
▪ Whether UVU should operate within a dedicated tenant, a shared collaboration space, or a SIAC-
managed process. 
▪ How access controls, audit logs, role-based permissions, retention rules, and data ownership would 
be managed. 
▪ How sensitive student, employee, law enforcement, and behavioral threat assessment information 
would be protected. 
▪ How information-sharing procedures would be documented through memoranda of understanding, 
operating procedures, or other agreements. 
▪ How intelligence products or investigative leads would be incorporated into Security Assessments, 
Event Action Plans, BAT processes, Emergency Operations Center operations, and public safety 
decision-making. 
▪ How legal, privacy, cybersecurity, procurement, and records-retention requirements would be 
reviewed before implementation. 
 
UVU and SIAC may also wish to evaluate whether specialized OSINT tools, such as OSINT Combine’s 
NexusXplore or similar platforms, should be deployed through SIAC, UVU, or a hybrid model. A SIAC-
supported model may allow UVU to benefit from SIAC’s existing intelligence mission, analytical 
personnel, public safety relationships, and information-sharing processes without requiring UVU to 
independently develop and sustain a specialized OSINT capability. A UVU-based or hybrid model may be 
appropriate if UVU determines that it needs more direct control over intake, documentation, event 
planning, or case-support workflows. 
 
Any use of OSINT tools should remain subject to the governance principles described in this appendix, 
including clear authorization, trained users, approved investigative methods, documentation standards, 
privacy review, legal review, cybersecurity review, retention rules, and supervisory oversight. 
 
In the Project Team’s assessment, UVU should explore whether SIAC’s existing Kaseware environment, 
SIAC’s analytical capabilities, and appropriate OSINT tools can support a more collaborative and 
intelligence-informed approach to campus safety. The goal should not be technology acquisition for its 
own sake, but improved information sharing, better threat awareness, stronger documentation, more 
coordinated investigations, and more informed decision-making for threat assessment, major-event 
planning, and incident response. 
 
 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
140 
Appendix D: Event Security Planning and Protective Measures 
Reference Guide 
D.1: Event Security Planning Framework for High-Profile Events 
The level of security planning associated with an event should be commensurate with the event's risk 
profile, anticipated attendance, venue characteristics, public visibility, and threat environment. While 
every event does not require the same degree of planning, the following elements are commonly 
incorporated into comprehensive event security programs. 
 
Security Assessment 
Event planning begins with identifying potential threats, assessing vulnerabilities, evaluating potential 
consequences, and determining appropriate mitigation measures. Factors often considered include 
anticipated attendance, protest activity, speaker profile, venue characteristics, historical incidents, and 
intelligence information. 
 
Security Planning and Coordination 
Effective event security planning integrates venue management, law enforcement, security personnel, 
emergency management, communications personnel, event organizers, and executive protection 
representatives. Planning activities commonly include coordination meetings, site visits, 
communications planning, contingency planning, and assignment of responsibilities. 
 
Executive Protection Considerations 
For high-profile speakers and guests, planning often includes advance site assessments, protective 
intelligence reviews, secure arrival and departure procedures, route planning, communications 
protocols, medical contingencies, and emergency evacuation procedures. 
 
Access Control and Credentialing 
Depending on the event's risk profile, organizations may implement ticketing systems, staff and 
contractor credentialing procedures, controlled access points, prohibited-items policies, screening 
procedures, and guest verification processes. 
 
Screening Operations and Staffing Considerations 
When screening operations are implemented, organizations should clearly define roles and 
responsibilities for security personnel, event staff, and law enforcement officers. Screening personnel 
should receive training on prohibited-items policies, screening procedures, ADA accommodations,  
de-escalation techniques, communications protocols, and escalation procedures. 
 
In many event environments, primary screening functions are performed by trained security personnel 
or event staff, with law enforcement personnel available to provide supervisory support, respond to 
incidents, address prohibited or illegal items, and manage enforcement actions when necessary. This 
approach allows law enforcement resources to remain available for incident response, crowd 
management, intelligence functions, and other security responsibilities while maintaining effective 
screening operations. 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
141 
Security Staffing and Deployment 
Security plans typically identify staffing levels, supervisory responsibilities, fixed posts, mobile patrols, 
crowd management personnel, emergency response resources, and command personnel. Staffing 
requirements should be informed by the event's size, complexity, and risk profile. 
 
Intelligence and Situational Awareness 
Event planning may incorporate intelligence gathering, social media monitoring, open-source 
intelligence (OSINT), law enforcement information sharing, protective intelligence activities, and real-
time situational awareness measures. 
 
Emergency Response Planning 
Security plans should identify emergency procedures for medical emergencies, fires, severe weather, 
disturbances, active assailant incidents, evacuations, shelter-in-place situations, and other foreseeable 
contingencies. 
 
Traffic and Perimeter Management 
Planning may include arrival and departure routes, emergency vehicle access, parking management, 
pedestrian flow, temporary barriers, road closures, and perimeter control measures. 
 
Command and Communications 
Events benefit from clearly defined command structures, communications plans, coordination 
procedures, and incident escalation protocols. Larger events may warrant the establishment of a 
command post or integration with emergency management structures. 
 
Post-Event Review 
Following significant events, organizations should conduct structured debriefings to identify lessons 
learned, evaluate operational effectiveness, document challenges, and capture opportunities for future 
improvement, including an After-Action Review. 
 
 
D.2: Event Screening Operations Planning Considerations  
For major events, high-profile speakers, controversial events, or events with elevated security concerns, 
UVU should consider developing written screening procedures that address attendees, bags, containers, 
vendors, deliveries, equipment, vehicles, staff, VIPs, officials, emergency responders, and event 
participants. Screening procedures should be tailored to the event’s risk profile, venue, expected 
attendance, crowd flow, legal constraints, staffing levels, and available equipment. Written screening 
procedures should address:  
▪ Screening authority and conditions of entry 
▪ Permitted and prohibited items 
▪ Bag and container restrictions 
▪ Entry-point layout and queuing 
▪ Staffing assignments and supervisory roles 
▪ Law enforcement support and escalation procedures 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
142 
▪ Equipment selection, testing, calibration, and backup methods 
▪ Signage and pre-event communications 
▪ Medical, ADA, VIP, official, vendor, delivery, staff, emergency responder, and participant exceptions 
▪ Documentation, incident reporting, and post-event review 
 
For bag and container screening, UVU should consider: 
▪ Clearly posting signage regarding bag checks and prohibited items. 
▪ Communicating bag restrictions, including size, before the event through websites, ticketing 
language, social media, email, and event materials. 
▪ Using clear-bag policies for selected events when legally permissible and operationally appropriate. 
▪ Inspecting bags and containers before entry to the venue. 
▪ Using tables or other screening stations to support efficient screening. 
▪ Providing appropriate tools, lighting, and protective measures for screening personnel. 
▪ Establishing express lanes for attendees with no bags or items requiring inspection. 
▪ Creating designated lanes for medical devices, mobility devices, diaper bags, staff, vendors, 
participants, and equipment. 
 
If hand-held metal detectors, walk-through magnetometers, X-ray screening, weapons-detection 
systems, or other screening equipment are used, UVU should ensure that personnel are trained on 
equipment use, alarm resolution, secondary screening, calibration, and escalation procedures. Sufficient 
equipment and staffing should be provided to reduce entry delays and avoid crowding at screening 
points. 
 
If pat-downs are used, UVU should develop written procedures in consultation with legal counsel. 
Procedures should address privacy, dignity, consent or conditions of entry, gender-related 
considerations, witness procedures, semi-private screening locations, refusal procedures, 
documentation, and law enforcement support. Personnel conducting pat downs should receive 
specialized training, including sensitivity training and instruction on respectful, nondiscriminatory 
screening practices. 
 
Screening procedures should be tested before major events. Testing may include equipment checks, 
staffing rehearsals, tabletop exercises, entry-flow simulations, and controlled penetration testing or  
red-team exercises designed to evaluate whether screening procedures are understood and effective. 
Results should be documented and used to improve procedures, staffing, equipment deployment, 
communications, and training. 
 
 
D.3: Access Control, Ticketing, and Credentialing Considerations 
Access control, ticketing, and credentialing are core components of event security planning. These 
functions help determine who may enter an event, where individuals may go once inside the event 
footprint, what restrictions apply, and how event organizers, security personnel, and law enforcement 
will manage authorized and unauthorized access. 
 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
143 
Access-control planning should be based on the event’s risk profile, anticipated attendance, venue 
configuration, public visibility, speaker or guest profile, threat environment, legal considerations, and 
operational capacity. For elevated-risk events, planners should evaluate whether the venue can support 
controlled entry, ticket verification, credentialing, screening, designated entry and exit points, 
restricted-access areas, and controlled movement between public and non-public spaces. 
 
Access-control measures may include: 
▪ Defined event boundaries 
▪ Designated entry and exit points 
▪ Ticket verification 
▪ Credentialing procedures 
▪ Restricted-access zones 
▪ Staff and vendor check-in points 
▪ Media check-in areas 
▪ VIP or speaker access controls 
▪ Emergency responder access points 
▪ Controlled delivery areas 
▪ Re-entry rules 
▪ Late-entry procedures 
▪ Conditions of entry 
▪ Prohibited-items policies 
▪ Screening procedures, when legally permissible and operationally appropriate 
 
Access-control plans should address both normal operations and exceptions. Exceptions may include 
medical needs, ADA-related accommodations, emergency responder access, credentialed media, staff 
and vendor access, VIP movement, late-arriving participants, and emergency conditions. Plans should 
also identify how unauthorized access, fraudulent credentials, refusal to comply with conditions of 
entry, prohibited items, disruptive behavior, or suspicious activity will be handled. 
 
Ticketing should be treated as a security and planning tool, not solely as an administrative or 
attendance-management function. Ticketing systems can support crowd management, occupancy 
control, staffing decisions, access-control planning, emergency egress planning, fraud prevention, 
accountability, and real-time situational awareness. For major or elevated-risk events, ticketing data 
should help planners evaluate expected attendance, peak arrival times, crowd-density concerns, venue 
suitability, staffing requirements, and emergency response needs. 
 
When outside event organizers manage ticketing or registration, UVU should consider requiring advance 
and continuing access to ticketing or registration data. This may include projected attendance, total 
registrations, ticket distribution, VIP or special-access lists, staff and volunteer lists, vendor lists, media 
lists, waitlist information, and expected arrival patterns. Access to this information supports more 
accurate planning and reduces uncertainty regarding crowd size, staffing, screening, credentialing, and 
emergency operations. 
 
Credentialing provides an additional layer of access control by allowing planners to distinguish between 
public areas, restricted areas, controlled-access zones, VIP areas, media areas, technical areas, back-of-
house spaces, command posts, emergency operations areas, and other secure locations. A credentialing 
plan should define who is authorized to access each area, how credentials will be issued and verified, 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
144 
what access levels are permitted, and how unauthorized access will be handled. Credentials may 
include: 
▪ Staff badges 
▪ Contractor or vendor passes 
▪ Media credentials 
▪ Law enforcement or emergency responder credentials 
▪ VIP or speaker access passes 
▪ Volunteer credentials 
▪ Digital tickets or passes 
▪ Parking credentials 
▪ Technical or production credentials 
▪ Command post or operations credentials 
 
Credentialing plans should identify access levels, credential design, issuing authority, verification 
procedures, expiration times, replacement procedures, lost-credential protocols, and procedures for 
revoking or denying access. For larger or elevated-risk events, planners should consider whether 
credentials need to be color-coded, role-specific, date-specific, zone-specific, or integrated with 
electronic access-control systems. 
 
Access-control and credentialing personnel should receive clear instructions before the event. Written 
post orders should identify the purpose of each access point, who is authorized to enter, what 
credentials or tickets are valid, what exceptions apply, how issues should be escalated, and who has 
authority to resolve disputes. Personnel should also be trained to recognize suspicious behavior, 
fraudulent credentials, tailgating, unauthorized attempts to enter restricted areas, and conditions 
requiring law enforcement support. 
 
Event access-control plans should also address late gate opening, re-entry, and any circumstances in 
which screening or ticketing operations may be modified. If screening, ticketing, or credential 
verification is part of the security plan, those controls should not be discontinued simply to expedite 
entry unless the change has been reviewed and approved through the event command structure. If  
re-entry is restricted, exceptions should be defined in advance for medical, ADA-related, childcare, 
operational, or emergency circumstances. 
 
Because access control, screening, prohibited-items policies, firearms issues, bag restrictions, and 
conditions of entry may raise legal considerations, UVU should coordinate with legal counsel when 
developing event-specific access control and credentialing procedures for events held on public 
University property. 
 
 
D.4: Common Event Security Posts and Functions 
Effective event security operations rely on clearly defined security posts, assigned responsibilities, 
established reporting relationships, and coordinated communications. The specific number and type of 
posts should be based on the event's risk profile, venue characteristics, attendance, threat environment, 
and operational objectives. 
 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
145 
Supervisory Posts 
Supervisors provide leadership, oversight, and operational coordination for designated areas of 
responsibility. Supervisors monitor personnel performance, respond to incidents requiring additional 
authority, coordinate resource deployment, and serve as the primary link between field personnel and 
command staff. Common practice is to assign supervisors responsibility for defined geographic zones or 
functional areas to ensure timely response and effective span of control. 
 
Access Control and Screening Posts 
Access-control personnel regulate entry into controlled or restricted areas and help ensure compliance 
with event security procedures. Responsibilities may include validating tickets, credentials, badges, or 
passes; monitoring entry points; enforcing access restrictions; screening for prohibited items; managing 
attendee queues; and reporting suspicious behavior or security concerns. These posts often serve as the 
first layer of event security and may incorporate personnel, technology, physical barriers, or screening 
equipment depending on the event's risk profile. 
 
Crowd Management Posts 
Crowd-management personnel monitor attendee behavior, crowd density, and pedestrian movement 
patterns. These personnel help facilitate orderly ingress and egress, identify congestion points, assist 
with wayfinding, intervene in minor disturbances, and support emergency evacuation procedures when 
necessary. Crowd management positions are particularly important in high-density areas, event 
entrances and exits, gathering locations, and areas where protests or demonstrations may occur. 
 
Stage and VIP Protection Posts 
Stage and VIP protection personnel are responsible for protecting speakers, performers, executives, 
dignitaries, and other protected individuals. These posts help maintain secure buffer zones, monitor 
audience behavior near the stage, control access to restricted areas, coordinate with executive 
protection personnel, and respond to disruptions or security concerns involving protected individuals. 
 
Perimeter Security Posts 
Perimeter security personnel monitor the boundaries of the event area and help prevent unauthorized 
access. Depending on the venue, these posts may monitor fencing, barricades, gates, pedestrian access 
points, parking areas, natural barriers, or designated protest areas. Perimeter personnel also help 
identify vulnerabilities, detect suspicious activity, and provide early warning of emerging issues outside 
the primary event footprint. 
 
Roving Patrol Posts 
Roving patrol personnel provide mobile security coverage throughout the event area. These personnel 
may patrol on foot, bicycle, vehicle, or other authorized means and are often responsible for monitoring 
conditions, identifying hazards, responding to minor incidents, and providing visible deterrence. 
Roving personnel also support situational awareness by identifying developing issues before they 
escalate into larger incidents. 
 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
146 
Parking and Traffic Posts 
Parking and traffic personnel assist with vehicle access, pedestrian safety, traffic flow, emergency 
vehicle routes, parking management, and ingress and egress operations. These positions help reduce 
congestion, improve safety, and facilitate emergency response access when necessary. 
 
Command Post Personnel 
Command post personnel provide operational oversight, resource coordination, communications 
support, intelligence sharing, and incident management functions. These personnel maintain situational 
awareness, coordinate field resources, document significant activities, and support decision-making 
throughout the event. 
 
Emergency Response Teams 
Emergency Response Teams (ERTs) provide surge capacity and rapid response capabilities for incidents 
requiring additional personnel. These teams may respond to disturbances, medical emergencies, crowd-
control issues, evacuations, suspicious activity, or other security concerns requiring immediate 
intervention. The use of designated response teams can improve operational flexibility and help event 
organizers manage incidents without disrupting broader event operations. 
 
Key Principles 
Regardless of the specific security model employed, effective event security operations generally 
incorporate three foundational principles: 
▪ Clearly defined posts with assigned responsibilities and accountability. 
▪ Appropriate supervisory oversight and span of control. 
▪ Integration with the Incident Command System (ICS), Event Action Plan (EAP), and emergency 
response procedures. 
 
 
D.5 Protective Operations Considerations for Outdoor Events 
This appendix provides operational considerations for outdoor events involving high-profile speakers, 
controversial events, large crowds, or other circumstances that may require enhanced protective 
planning. These details should be treated as sensitive security information and distributed only to 
personnel with a need to know. 
 
Pre-event planning should include a coordinated walk-through involving UVUPD, event organizers, 
emergency management, local law enforcement partners, and any executive protection detail assigned 
to the speaker or VIP. The walk-through should address: 
▪ Arrival and departure points 
▪ Line-of-sight concerns 
▪ Elevated positions and rooftops 
▪ Building, room, and window access 
▪ Potential protester locations 
▪ Security post locations 
▪ External law enforcement support 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
147 
▪ Communications capabilities 
▪ Emergency access and egress routes 
▪ Protective movement routes 
▪ Crowd placement and barriers 
▪ Contingency plans for relocation, evacuation, lockdown, or shelter-in-place 
 
When an outdoor event presents line-of-sight or elevated-position concerns, UVUPD should evaluate 
whether the event can be moved indoors or whether the identified risks can be reasonably mitigated.  
If the event remains outdoors, security planning should include control or monitoring of buildings, 
rooftops, windows, stairways, ladders, parking structures, tree lines, and other areas that overlook the 
event site. Where staffing is limited, UVU should consider physical screening, line-of-sight obstruction, 
restricted access areas, or mutual aid support to reduce exposure. 
 
Arrival and departure areas for speakers, VIPs, and other protectees should be planned to minimize 
public visibility and unnecessary exposure. When appropriate, protective planning may include 
controlled entry points, screened movement routes, vehicle placement, temporary barriers, canopies  
or tents, parking structures, or other measures that reduce visibility and improve control of the area. 
 
UVUPD should also consider whether staffing plans provide sufficient fixed-post coverage and mobile 
response capacity. Fixed posts may be needed to control key access points, while mobile officers may be 
needed to respond to incidents without leaving critical posts unattended. Staffing limitations should be 
addressed through advance planning, mutual aid agreements, and coordination with nearby law 
enforcement partners or university police agencies. 
 
Training for UVUPD and partner agencies should address protective operations for high-profile outdoor 
events, including line-of-sight assessment, elevated-position concerns, site control, access control, 
coordination with executive protection details, communications, and event-specific response planning. 
Joint training with local agencies and nearby university police departments would support a more 
coordinated response during major events. 
 
 
D.6: Traffic, Parking, and Perimeter Security Considerations 
Traffic, parking, and perimeter security are important components of event security planning, 
particularly for outdoor events, large gatherings, controversial speakers, and events involving elevated 
security concerns. Effective planning helps facilitate safe movement of people and vehicles, maintain 
emergency access, reduce congestion, establish event boundaries, and mitigate security risks associated 
with unauthorized access or vehicle-related threats. 
 
Traffic Management 
Traffic management plans should address the movement of vehicles and pedestrians before, during,  
and after an event. Planning considerations may include: 
▪ Arrival and departure routes 
▪ Traffic-control points 
▪ Road closures and detours 
▪ Shuttle operations 
▪ Rideshare pick-up and drop-off locations 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
148 
▪ Accessible parking and ADA accommodations 
▪ Loading and delivery access 
▪ Emergency vehicle routes 
▪ Post-event departure operations 
▪ Coordination with local law enforcement, transportation agencies, parking vendors, and public 
works departments may be necessary for larger events. 
 
Parking Operations 
Parking areas are often the first and last points of interaction attendees have with an event and should 
be considered part of the overall security footprint. Parking plans may address: 
▪ Parking-lot capacity and overflow procedures 
▪ Alternate parking locations 
▪ Pedestrian routes from parking areas to the venue 
▪ Lighting and visibility 
▪ Parking-lot patrols 
▪ CCTV coverage 
▪ Suspicious-activity reporting procedures 
▪ Vehicle access controls 
▪ Emergency response access 
 
Depending on the event's risk profile, parking areas may warrant dedicated staffing, roving patrols, 
temporary surveillance measures, or periodic security inspections. 
 
Perimeter Security 
Perimeter security measures establish the boundaries of the event and help control the movement of 
attendees, staff, vendors, media personnel, and vehicles. The objective is to create a secure and 
manageable environment while maintaining safe access and emergency egress. Perimeter security 
measures may include: 
▪ Temporary fencing 
▪ Barricades 
▪ Gates 
▪ Designated entry and exit points 
▪ Controlled-access zones 
▪ Restricted areas 
▪ Vehicle-control points 
▪ Security staffing 
▪ Signage and wayfinding 
 
The level of perimeter security should be proportional to the event's risk profile, venue characteristics, 
attendance, and threat environment. 
 
Vehicle Mitigation and Protective Barriers 
For outdoor events, planners may consider physical measures designed to reduce the risk of 
unauthorized vehicle access or vehicle-related attacks. Depending on the venue and threat assessment, 
these measures may include: 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
149 
▪ Bollards 
▪ Planters 
▪ Jersey barriers 
▪ Water-filled barriers 
▪ Vehicle barricades 
▪ Temporary fencing systems 
▪ Crash-rated gates 
▪ Vehicle-control points 
▪ Heavy vehicles positioned as protective barriers 
 
When evaluating protective barriers, planners should consider vehicle approach routes, vehicle speed, 
pedestrian density, emergency access requirements, and appropriate standoff distances from 
attendees, structures, and critical infrastructure. The selection of barrier systems should balance 
security requirements, operational needs, emergency access, aesthetics, and the overall attendee 
experience. 
 
Parking and Perimeter Patrols 
Parking areas and perimeter zones should be incorporated into security patrol plans. Depending on the 
size and nature of the event, patrol resources may include: 
▪ Law enforcement personnel 
▪ Security officers 
▪ Roving foot patrols 
▪ Bicycle patrols 
▪ Vehicle patrols 
▪ CCTV monitoring 
▪ Drone or aerial observation resources where legally permissible 
 
Patrol personnel can help identify suspicious activity, monitor crowd movement, detect perimeter 
vulnerabilities, respond to incidents, and provide visible deterrence. 
 
Signage and Wayfinding 
Signage serves both operational and security functions. Effective signage helps reduce confusion, 
improve crowd flow, communicate security procedures, and support emergency operations. Signage 
considerations may include: 
▪ Parking directions 
▪ Shuttle locations 
▪ Designated entrances and exits 
▪ Accessible routes 
▪ Emergency exits 
▪ Restricted access areas 
▪ Prohibited items notifications 
▪ Screening requirements 
▪ Emergency contact information 
▪ Suspicious-activity reporting information 
 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
150 
Information should be communicated through multiple channels whenever practical, including websites, 
social media, event communications, parking areas, transit points, pedestrian routes, and venue 
entrances. 
 
Key Planning Considerations 
Traffic, parking, and perimeter planning efforts are most effective when they: 
▪ Support safe and efficient movement of attendees. 
▪ Maintain emergency vehicle access and operational flexibility. 
▪ Integrate with event security, access control, and emergency-response plans. 
▪ Provide clear communication and wayfinding. 
▪ Establish reasonable protection against foreseeable risks. 
▪ Balance security needs with the overall event experience. 
 
 
D.7: Fixed and Temporary Site Security Measures 
Fixed and temporary site security measures help define event boundaries, control movement, support 
screening operations, protect pedestrian areas, reduce unauthorized access, and improve emergency 
response coordination. These measures should be selected based on the event’s risk profile, venue 
characteristics, anticipated attendance, crowd movement, traffic patterns, public visibility, threat 
environment, and emergency response needs. Site security measures may include: 
▪ Temporary fencing 
▪ Gates 
▪ Barricades 
▪ Stanchions 
▪ Concrete barriers 
▪ Water-filled barriers 
▪ Bollards 
▪ Planters 
▪ Vehicles used as protective barriers 
▪ Signage 
▪ Access-control points 
▪ Screening areas 
▪ Controlled delivery points 
▪ Restricted access zones 
▪ Vehicle-control points 
▪ Lighting 
▪ Cameras or temporary surveillance measures 
 
For outdoor events, physical controls should help establish a clear and manageable event footprint. 
These measures can direct attendees to approved entrances, separate pedestrians from vehicles, 
protect screening areas, create buffer zones between the event site and adjacent roads, and help 
personnel identify unauthorized access or perimeter breaches. 
 
Temporary fencing and barricades should be used in a way that supports both security and life safety. 
Barriers should not obstruct emergency exits, emergency vehicle access, evacuation routes, ADA-
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
151 
accessible paths, or responder staging areas. Any fencing or barricade plan should be reviewed for 
crowd-flow, emergency egress, accessibility, and operational feasibility. 
 
When roads remain open near an event site, planners should evaluate whether temporary barriers are 
sufficient or whether additional measures are needed, such as law enforcement staffing, road closures, 
traffic-control points, vehicle screening, or alternate pedestrian routing. If temporary barricades are 
used to control roads or vehicle access points, they should be staffed, monitored, or otherwise 
incorporated into the security plan. 
 
Vehicle-related risk should also be considered for outdoor events, high-density pedestrian areas, and 
venues adjacent to active roadways. Depending on the Security Assessment and venue configuration, 
planners may consider bollards, planters, Jersey barriers, water-filled barriers, concrete barriers, gates, 
vehicle-control points, or strategically positioned heavy vehicles. Barrier selection should account for 
vehicle approach routes, potential vehicle speed, pedestrian density, standoff distance, emergency 
access, aesthetics, and the overall attendee experience. 
 
Physical controls should be coordinated with access control, screening, traffic, parking, communications, 
and emergency response plans. For example, a fencing plan should align with designated entry points, 
screening queues, credentialing locations, emergency exits, command post access, delivery routes, and 
responder access points. Similarly, vehicle barriers should be placed in a way that protects attendees 
while preserving the ability of emergency vehicles to reach the venue. 
 
Site security measures should also account for vendors, deliveries, staff, event participants, media, VIPs, 
emergency responders, and people requiring ADA-related accommodations. Designated entry points, 
delivery checkpoints, staff lanes, equipment routes, and accessible paths should be identified in advance 
and communicated to personnel responsible for access control. 
 
Temporary measures should be inspected before, during, and after the event. Personnel should check 
for gaps, damaged barriers, unsecured gates, blocked exits, unstaffed access points, unauthorized 
movement through restricted areas, and changes in crowd behavior or traffic patterns that require 
adjustments. Any changes to the site-security layout during an event should be communicated through 
the event command structure. 
 
 
D.8: Announcements and Scripted Response Protocol Messages  
HOLD 
PA, phone, text, email, signage, and voicemail: HOLD, HOLD, HOLD! THIS IS NOT A TEST! We are 
responding to a report of (problem) at (location). Calmly and quickly clear the hallways and remain in 
your current room, office, classroom, or general area. Continue normal activity unless otherwise 
directed. Remain in your location until given the ALL CLEAR. Watch for additional information and 
updates. (Send message three times, two minutes apart.) 
 
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at 
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two 
minutes apart.) 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
152 
LOCKDOWN 
PA, phone, text, email, signage, and voicemail: LOCKDOWN, LOCKDOWN, LOCKDOWN! THIS IS NOT A 
TEST! We are responding to a report of (problem) at (location). The facility will be in LOCKDOWN. Calmly 
and quickly move to the nearest Safe Room,64 lock the door, and remain there until given the ALL CLEAR. 
Watch for additional information and updates. (Send message three times, two minutes apart.)  
  
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at 
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two 
minutes apart.) 
 
EVACUATE  
PA, phone, text, email, signage, and voicemail: EVACUATE, EVACUATE, EVACUATE! THIS IS NOT A TEST! 
Calmly and quickly EVACUATE the building using all available exits. Move away from the building to your 
designated Assembly Area and remain there until given the ALL CLEAR. Watch for additional information 
and updates. (Send message three times, two minutes apart.)  
  
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at 
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two 
minutes apart.) 
 
SECURE65  
PA, phone, text, email, signage, and voicemail: SECURE, SECURE, SECURE! THIS IS NOT A TEST! We are 
responding to a report of (problem) at (location). Calmly and quickly SECURE inside the building using all 
available entrances. Move to the nearest Safe Room and lock the door. Remain there until given the ALL 
CLEAR. Watch for additional information and updates. (Send message three times, two minutes apart.)  
  
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at 
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two 
minutes apart.) 
 
SHELTER 
PA, phone, text, email, signage, and voicemail: SHELTER, SHELTER, SHELTER! THIS IS NOT A TEST! We are 
responding to a report of (problem) at (location). Please SHELTER and take precautions until given the 
ALL CLEAR. Watch for additional information and updates. (Send message three times, two minutes 
apart.)  
  
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at 
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two 
minutes apart.) 
  
 
64  A safe room refers to a designated place of refuge that offers enhanced security during an armed-intruder event; where 
storm protection is intended, FEMA defines a safe room as a hardened structure designed to meet FEMA criteria and 
provide near-absolute protection during extreme wind events. 
65  Secure is the rapid and safe movement of people from outdoor areas into a facility or other safer indoor location when the 
source of danger is outside. FEMA states that Secure (also known as Reverse Evacuation) is used “to rapidly and safely move 
people inside a facility when it would be dangerous to remain outside,” such as when people are on playgrounds, sports 
fields, or at an outdoor event and the danger is outside. 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
153 
ACTIVE ASSAILANT  
PA, phone, text, email, signage, and voicemail: ACTIVE ASSAILANT, ACTIVE ASSAILANT, ACTIVE 
ASSAILANT! THIS IS NOT A TEST! A subject with a weapon is in the building. Calmly and quickly move to 
the nearest Safe Room, lock the door, and remain there until given the ALL CLEAR. If you are not in the 
building, stay away and wait for the ALL CLEAR notification. Watch for additional information and 
updates. (Send message three times, two minutes apart.)  
 
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at 
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two 
minutes apart.) 
 
 
D.9: Physical Security Technology Technical Considerations 
This appendix provides additional technical context regarding physical security technologies referenced 
in Section 5.2. These considerations are intended to support future planning, budgeting, system 
evaluation, and implementation decisions. 
 
Integrated Security Management 
A mature campus security technology environment may integrate access control, video surveillance, 
intrusion detection, panic alarms, lockdown capabilities, public address systems, mapping, and mass 
notification tools. Integration can allow defined events, such as a forced door, panic alarm, duress 
activation, or intrusion alarm, to trigger associated video, location information, maps, automated alerts, 
and response workflows. 
 
An integrated or unified platform can help Dispatch and command personnel view relevant alarm and 
video information through a common graphical user interface. This can reduce the need to monitor 
multiple disconnected systems and improve response coordination. 
 
Access Control System Considerations 
UVU uses an industry-recognized access-control system. Future access-control planning may include: 
▪ Enterprise-wide credential audits 
▪ Deactivation of expired or unauthorized badges 
▪ Role-based access by building, room, day, time, and operational need 
▪ Defined approval authority for card issuance and access levels 
▪ Oversight by Human Resources, student records, or other authoritative systems 
▪ Integration with student records, employment records, contractor records, or visitor-management 
systems where feasible 
▪ Automated updates or deactivation when student, employee, contractor, or visitor status changes 
▪ Cardholder image capture and verification at selected critical access points 
▪ Evaluation of whether select access points should remain controlled 24 hours a day 
▪ Use of visible visitor or contractor badges where appropriate 
▪ Evaluation of turnstiles or other access-control measures for selected high-control areas 
 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
154 
Any consideration of biometric authentication, facial recognition, or advanced identity verification 
should include legal review, privacy review, accessibility considerations, cybersecurity evaluation, data 
governance, retention policies, and community impact considerations. 
 
Access Control and Video Integration 
Integration between the access-control system and video management system can allow alarms, door-
forced events, door-held-open events, or access-denied events to call up associated video. This can help 
Dispatch or authorized personnel confirm what occurred, identify who was present, and determine what 
response is needed. 
 
If UVU retains separate access-control and video platforms, integration between those systems may be 
pursued through available manufacturer tools or application programming interfaces. If UVU evaluates 
replacement platforms in the future, unified systems may be considered as part of a broader technology 
roadmap. Any vendor-specific decision should be based on operational requirements, lifecycle cost, 
cybersecurity, integration capability, maintenance burden, training needs, procurement requirements, 
and long-term support. 
 
Video Surveillance Coverage and Modernization 
Information provided during the review indicated that camera coverage does not extend to all interior 
and exterior campus areas. Future expansion should be guided by risk and operational need, including: 
▪ Building entrances and exits 
▪ Major pedestrian pathways 
▪ Event venues and outdoor gathering areas 
▪ Parking areas and vehicle access points 
▪ Elevated areas, rooftops, balconies, and terraces 
▪ Public-facing service areas 
▪ Emergency routes and staging areas 
▪ Areas with prior incidents or recurring security concerns 
 
A camera standard for new installations can simplify maintenance and improve system performance. 
Standards may address manufacturer compatibility, camera type, resolution, low-light capability, field of 
view, on-board analytics, cybersecurity, environmental rating, retention needs, and compatibility with 
the video management system. 
 
Video Analytics 
Selected video analytics may support security operations when properly configured, tested, and 
monitored. Potential analytics include: 
▪ Perimeter or virtual-fence detection 
▪ License plate recognition in vehicle areas 
▪ Restricted-area or rooftop intrusion detection 
▪ Object-left-behind detection 
▪ Anti-tailgating detection 
▪ Fall detection 
▪ Occupancy or crowd-density detection 
▪ Traffic-flow or pedestrian-flow monitoring 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
155 
▪ Wrong-way movement detection 
▪ Speed monitoring 
▪ Loitering detection 
▪ Crowd detection thresholds 
▪ Weapons-detection analytics where legally permissible, operationally justified, and actively 
monitored 
 
Analytics should be evaluated based on reliability, false alarm rates, privacy impact, legal requirements, 
monitoring capacity, integration with response workflows, and usefulness to Dispatch or command 
personnel. 
 
Video Storage, Retention, and Resilience 
Video surveillance planning should account for server capacity, storage needs, retention periods, system 
performance, and resilience. Potential considerations include: 
▪ Replacement planning for aging cameras and servers. 
▪ Storage expansion to support added cameras or higher-resolution video. 
▪ Retention policies aligned with operational, investigative, legal, and privacy requirements. 
▪ Off-site or cloud-based backup where appropriate. 
▪ Protection against natural disasters, theft, cybersecurity incidents, and site-specific system failures. 
 
Dispatch Monitoring and Event Views 
For large campus events, programmed camera views can help Dispatch and command personnel 
monitor priority areas. These may include: 
▪ Event site overview 
▪ Speaker or stage area 
▪ Crowd entry and exit points 
▪ Protest areas 
▪ Rooftops and elevated positions 
▪ Parking areas and vehicle routes 
▪ Emergency response routes 
▪ Command post access points 
▪ Restricted areas 
▪ Building entrances near the event 
 
Event Action Plans should identify who will monitor these feeds, how observations will be 
communicated, what conditions require escalation, and how video will be preserved during or after  
an incident. 
 
Panic Alarms, Duress Devices, and Emergency Call Points 
Panic alarms, duress devices, and emergency call points may be considered for selected locations  
based on risk and operational need. Potential locations include: 
▪ Public-facing administrative offices 
▪ People and Culture or Human Resources offices 
▪ Student Life and student service areas 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
156 
▪ Event venues 
▪ Cash-handling locations 
▪ Isolated exterior locations 
▪ Parking areas 
▪ Areas with recurring conflicts or safety concerns 
 
These systems should include clear location information, Dispatch monitoring, defined response 
procedures, regular testing, user training, and integration with video where feasible. 
 
Emergency Call Boxes 
Exterior emergency call boxes may be considered in selected areas where direct emergency 
communication is needed. Common features include visible blue lights, emergency call buttons, direct 
connection to Dispatch, and associated camera coverage where feasible. Placement decisions should  
be based on lighting, pedestrian routes, parking areas, isolated locations, call volume, mobile-phone 
coverage, accessibility, maintenance, and integration with Dispatch response procedures. 
 
Aerial Observation and Partner Agency Support 
Drone or aerial observation capabilities may support situational awareness during large outdoor events, 
demonstrations, searches, or major incidents when legally permissible and operationally appropriate. If 
UVU does not maintain this capability internally, mutual aid agreements or interagency procedures may 
identify partner agencies that can provide aerial observation support. 
 
Planning considerations include legal authority, privacy, flight restrictions, operator certification, request 
procedures, command integration, video sharing, evidence preservation, and public communications. 
 
 
D.10: Post-Event Review Considerations 
Post-event review is an important component of continuous improvement. Following significant events, 
elevated-risk events, incidents, or events involving unusual operational challenges, UVU should conduct 
a structured review to identify lessons learned, evaluate operational effectiveness, document 
challenges, and capture opportunities to improve future planning. 
 
Post-event reviews may range from a brief hotwash to a formal after-action review, depending on the 
event’s size, complexity, risk profile, and whether incidents occurred. Reviews should be conducted 
soon enough after the event that participants can provide accurate observations, but with enough 
structure to ensure the review is useful, documented, and tied to corrective action. 
 
A post-event review may examine: 
▪ Pre-event planning and coordination 
▪ Risk assessment and intelligence information 
▪ Venue selection and site layout 
▪ Access control, ticketing, credentialing, and screening 
▪ Staffing levels and post assignments 
▪ Supervisory structure and span of control 
▪ Command structure and decision-making 
After-Action Report for Utah Valley University 
 
 
 
 
 
 
 
 
157 
▪ Communications among event personnel, UVUPD, university leadership, and external responders 
▪ Emergency notification and public messaging 
▪ Crowd management and attendee behavior 
▪ Protest activity or counter-event activity 
▪ Traffic, parking, shuttle, and rideshare operations 
▪ Emergency vehicle access 
▪ Perimeter security and barrier placement 
▪ Medical response 
▪ Fire, EMS, and law enforcement coordination 
▪ Vendor, media, VIP, and delivery access 
▪ ADA-related accommodations 
▪ Incident documentation 
▪ Technology performance 
▪ Public feedback, student feedback, and stakeholder concerns 
▪ Post-event departure and site closure 
 
Reviews should include the personnel and stakeholders most directly involved in planning and 
operations. Depending on the event, participants may include UVUPD, emergency management, event 
organizers, facilities, communications personnel, legal counsel, student affairs, parking and 
transportation, local law enforcement, fire, EMS, contracted security, venue staff, and representatives 
from the sponsoring organization. The review should distinguish between: 
▪ What was planned 
▪ What actually occurred 
▪ What worked well 
▪ What created challenges   
▪ What should be changed before future events  
 
The process should include both operational observations and attendee-facing issues, such as confusion 
about entry points, prohibited items, emergency messaging, parking, crowd movement, or event 
closure. 
 
When incidents or significant disruptions occur, UVU should preserve relevant records before they are 
overwritten, deleted, or dispersed. Records may include event plans, staffing rosters, post orders, radio 
audio and logs, Dispatch records, emergency messages, surveillance video, photographs, incident 
reports, ticketing data, credentialing records, public communications, social media monitoring 
summaries, and correspondence with external partners. 
 
Post-event reviews should result in documented corrective actions. Corrective actions should identify 
the issue, recommended improvement, responsible owner, priority level, target completion date, 
resource needs, and follow-up process. Items that require policy changes, training, technology 
investment, mutual aid coordination, legal review, or budget approval should be tracked until resolved. 
 
For recurring events or future events involving similar risks, lessons learned should be incorporated into 
event templates, planning checklists, training materials, post orders, emergency message templates, 
access-control plans, and tabletop exercises. This helps ensure that lessons are institutionalized and not 
dependent on individual memory or informal knowledge.