Document text
UVU Independent External Review — After-Action Report on the Sept 10, 2025 TPUSA Event (158 pp.) (Part 2 of 2)
Primary document, NOT a court record: commissioned and published by Utah Valley University, the host institution; conducted by Robert L. Davis LLC, Doherty Advisory LLC, The Lake Forest Group and Brownstein Hyatt Farber Schreck LLP. Ten key findings on event planning, security and emergency response, addressing both UVU and Turning Point USA. Released Sept 25, 2026 (PDF dated Sept 24, 2026; SHA-256 d237c79ce10400c90b3f2c827ad197aec3ff4d5824e3ac87856b608d56db8f93). Text extracted from the published PDF (https://www.uvu.edu/externalreview/docs/after-action-report.pdf).
expectations. Formal adoption of the document, coupled with
a recurring review cycle, would provide greater clarity while preserving flexibility for future updates.
Threat Reporting, Intake, and Case Documentation
UVU has established multiple reporting pathways intended to encourage early identification and
reporting of concerning behavior. Reporting mechanisms include:
▪ BAT online reporting portal
▪ EthicsPoint reporting system which includes anonymous reporting options
▪ "Report and Support" reporting website
▪ Maxient reporting form
▪ UVU tipline
▪ Direct reporting to university personnel
▪ UVU Police reporting channels
Interviewees reported significant increases in utilization of the "Report and Support" website,
suggesting growing awareness of available reporting resources and increased willingness among UVU
community members to report concerns.
The BAT utilizes Maxient as its centralized case management and documentation platform. Case files
include referrals, supporting documentation, investigative information, risk assessments, intervention
plans, and follow-up activities. The use of a centralized case management system supports continuity,
accountability, historical review, and multidisciplinary coordination. UVU’s documentation and case
management practices are generally consistent with accepted higher education standards.37
Upon receipt of a referral, BAT members gather and review information from a variety of sources to
develop a comprehensive understanding of the circumstances and behaviors of concern. Depending on
the nature of the case, information may be obtained from incident reports, police reports, conduct
records, prior BAT cases, faculty and staff observations, interviews with the individual of concern, family
members, friends, and other relevant sources. Team members are expected to share pertinent
information with the BAT and contribute relevant background information regarding cases under
review.
37 Maxient. Work Collaboratively. https://www.maxient.com/#1459304968060-3fec7f26-d472. Accessed June 6, 2026.
After-Action Report for Utah Valley University
95
Following collection and review of available information, the BAT utilizes the National Association for
Behavioral Intervention and Threat Assessment (NABITA) Risk Rubric — an evidence-based threat
assessment tool — to assess the level of concern presented by the individual or situation and to guide
appropriate intervention and management strategies. Risk determinations are documented in case
records along with the factors that informed the assessment. This structured approach to information
gathering, multidisciplinary review, documentation, and risk assessment is consistent with accepted
higher education threat assessment and behavioral intervention practices.38 The BAT appropriately
utilizes the NABITA Rubric as a case prioritization and decision-support tool rather than as a clinical or
predictive determination of future violence.
NABITA emphasizes:
▪ Early identification of concerning behavior
▪ Structured assessment of risk using evidence-based practices
▪ Documentation and information sharing within legal and ethical guidelines
▪ Development of individualized intervention and safety plans
▪ Ongoing monitoring until the concern has been resolved
For campus police departments and higher education institutions, NABITA's guidance complements
standards from organizations such as International Association of Campus Law Enforcement
Administrators (IACLEA) by focusing on behavioral intervention and multidisciplinary threat assessment
rather than solely on law enforcement operations.39
6.2 Information Sharing, OSINT, and Protective Intelligence
Information sharing is central to effective behavioral threat assessment and threat management.
Institutions are often required to evaluate fragmented information from multiple sources, including
student affairs, human resources, faculty, campus police, mental health resources, conduct records,
online activity, external law enforcement partners, and community reports. Effective programs rely on
lawful and appropriate information sharing that allows multidisciplinary teams to identify patterns,
evaluate context, and develop coordinated intervention and management strategies.
Interviews consistently described a culture of open information sharing among BAT members.
Participants indicated that members trust one another and actively contribute information from their
respective areas of responsibility. The BAT also benefits from strong relationships with UVUPD and
external law enforcement partners, including access to information resources through the Utah SIAC.
The BAT appropriately utilizes established privacy exceptions, including the Family Educational Rights
and Privacy Act (FERPA), U.S. federal law that protects the privacy of student education records, as well
as health and safety provisions, when circumstances warrant information sharing for safety purposes.
Team leadership demonstrated a strong understanding of the distinction between protected
educational records and observable behaviors that may be relevant to safety assessments.
38 Randazzo, M. R., & Plummer, E. (2009). Implementing behavioral threat assessment on campus. NABITA.
39 National Behavioral Intervention Team Association. (2025). About NaBITA. https://www.nabita.org/
After-Action Report for Utah Valley University
96
Integration of Open-Source Information
Threat assessment and management teams benefit from incorporating information from multiple
sources, including institutional records, stakeholder reports, law enforcement information, and publicly
available online content. Contemporary threat assessment research demonstrates that many individuals
who engage in targeted violence may never communicate a direct threat. Instead, warning behaviors
often emerge through grievances, fixation, leakage, stalking, target-focused communications, escalating
anger, and online activity. As a result, effective threat assessment programs routinely consider both
institutional information and relevant open-source information when evaluating elevated-risk cases.
Open-source research can be particularly valuable in cases involving alleged stalking, fixation, or
targeted harassment. Publicly available information may help the team identify, document, and assess
behavioral patterns such as repeated or escalating contact, efforts to gain physical proximity,
surveillance or information gathering, use of multiple communication methods, rejection of requests to
stop, threats or intimidation, underlying grievance or fixation, access to weapons, and any known
history of violence or prior stalking behavior.40 When documented and assessed appropriately, this
information can strengthen risk evaluation, intervention planning, and protective decision-making.
UVU possesses several resources that support intelligence gathering and information awareness,
including Campus Sonar, Sprout Social, Meltwater, law enforcement databases, and access to the Utah
SIAC. These resources provide valuable visibility into media coverage, public sentiment, social media
discussions, criminal justice information, and threat-related intelligence.
However, these capabilities are primarily designed to monitor broader conversations, media reporting,
and institutional issues rather than conduct subject-focused protective intelligence investigations. When
a specific individual becomes the focus of a BAT assessment, there is no formalized process, dedicated
capability, or specialized platform for conducting comprehensive open-source investigations of that
individual. Such investigations may include detailed reviews of publicly available social media activity,
online communications, civil and criminal court records, litigation history, public records, prior law
enforcement contacts, affiliations, and other information relevant to assessing risk and identifying
warning behaviors.
Open-source information is gathered on an informal and case-by-case basis, often relying upon the
initiative of individual BAT members or law enforcement personnel. Responsibility for collecting,
analyzing, documenting, and integrating open-source information is distributed among multiple
stakeholders without a clearly defined protective intelligence function supporting the BAT.
Although UVU’s broader intelligence and OSINT capabilities are addressed elsewhere in this report,
this issue is distinct because it relates specifically to subject-focused research in BAT cases. A more
structured approach to subject-focused OSINT and protective intelligence investigations would
strengthen risk evaluation, contextual understanding, case documentation, and intervention planning
for elevated-risk individuals.
40 Meloy, J. R., & Hoffmann, J. (Eds.). (2021). International Handbook of Threat Assessment (2nd ed.). Oxford University Press;
Association of Threat Assessment Professionals. (2018). Risk factors for stalking and violence. ATAP.
After-Action Report for Utah Valley University
97
6.3 Integration with Security Planning and Protective Measures
The BAT's primary focus is behavioral intervention, support, and conduct-related concerns rather than
event security planning or protective security decision-making. This distinction is understandable from
an organizational perspective. However, contemporary threat assessment and management programs
increasingly emphasize the importance of connecting behavioral assessment findings to protective
security planning when circumstances warrant.
The Project Team found limited evidence that threat assessment findings are routinely integrated into
event security planning, security screening decisions, or other protective measures. This does not mean
the BAT should become an event-security body or law enforcement operational unit. Rather, it means
that when BAT cases, threat reports, or behavioral concerns intersect with major events, public
gatherings, controversial or high-profile speakers, protective details, or identifiable targets, UVU would
benefit from a defined process for ensuring that relevant information is shared with appropriate
security, emergency management, and event-planning personnel.41
6.4 Training, Professional Development, and Continuous Improvement
Training represents one of the BAT's greatest strengths. The Project Team reviewed records
demonstrating participation in numerous threat assessment, violence prevention, behavioral
intervention, FERPA, Title IX, case management, suicide assessment, and higher education safety
training programs over many years. In addition, UVU requires employees to complete annual
compliance training covering topics such as:
▪ Workplace conduct
▪ FERPA
▪ Cybersecurity
▪ Free speech
▪ Harassment and discrimination
▪ Campus Security Authority responsibilities, as applicable
Importantly, completion of required training is tied to employee performance evaluations and merit pay
considerations. This creates a meaningful incentive for participation and reinforces a culture of
compliance and accountability.
The BAT has also demonstrated a commitment to professional development through participation in
NABITA training programs, Stetson Law conferences, Utah Safety Summit programs, and other
educational opportunities. While UVU's engagement with NABITA has been substantial and beneficial,
the assessment identified an opportunity to broaden participation in training opportunities with
external professional organizations and other subject matter experts focused specifically on threat
assessment and threat management.
41 Fein, R. & Vossekuil, B. (1998). Protective Intelligence & Threat Assessment Investigations: A Guide for State and Local Law
Enforcement Officials. U. S. Department of Justice, Office of Justice Programs, National Institute of Justice: Washington, D.C.
https://www.ojp.gov/library/publications/protective-intelligence-and-threat-assessment-investigations-guide0?
After-Action Report for Utah Valley University
98
NABITA provides valuable guidance related to higher education behavioral intervention and case
management. Association of Threat Assessment Professionals (ATAP)42 — a multidisciplinary
organization dedicated to threat assessment, protective intelligence, stalking, workplace violence,
targeted violence prevention, and threat management — complements NABITA by providing exposure
to a broader multidisciplinary community that includes law enforcement, mental health professionals,
prosecutors, protective intelligence practitioners, workplace violence specialists, and threat
management professionals. Participation in43 both organizations would provide BAT members with
access to emerging practices, current case studies, peer networks, and evolving threat assessment
methodologies.44
In our assessment, UVU’s investment in BAT-related training is a significant strength. Expanded
participation in ATAP and similar multidisciplinary threat management organizations would supplement
UVU’s existing higher education-focused training and provide additional exposure to protective
intelligence, stalking, workplace violence, targeted violence prevention, and threat management
practices.
6.5 Intervention Resources and Related Policies
An effective threat assessment and management program depends not only on assessment capabilities,
but also on access to intervention resources.45 UVU maintains robust support services for both students
and employees. Students have access to Mental Health Services that provide assessment and treatment
for a variety of concerns, including anxiety, depression, trauma, grief, substance abuse, and relationship
issues. Services include individual counseling, group counseling, and crisis support resources, along with
free access to TimelyCare, a third-party mental health support service.
Employees have access to the Employee Assistance Program (EAP) through ComPsych, which provides
counseling services, crisis support, referral services, and additional mental health resources for
employees and their dependents. These resources provide the BAT with important intervention options
and support prevention-focused case management strategies. They also reinforce the principle that
threat assessment and management is often most effective when it incorporates support, treatment,
conflict resolution, and resource referral in addition to traditional security measures. The Project Team
also notes the importance of maintaining strong communication pathways between the BAT, Mental
Health Services, and EAP providers when circumstances permit and legal obligations require
coordination regarding safety concerns, threats, or duty-to-warn considerations.46
42 Association of Threat Assessment Professionals. https://www.atapworldwide.org/page/desertswchapter, Accessed May 28,
2026.
43 The BAT Chair has since joined ATAP, a positive step consistent with the Project Team’s recommendation.
44 International Association of Campus Law Enforcement Administrators. (2025). Operational readiness and threat mitigation
in higher education. IACLEA; Okada, D. T., & Pollard, J. W. (2021). Community-based threat assessment and higher
education. Journal of College Student Psychotherapy, 35(4), 406–417. https://doi.org/10.1080/87568225.2020.1753609;
Michaelis, D. (2019). Notes from the field: The value of threat assessment teams. National Institute of Justice. National
Institute of Justice.
45 UVU People and Culture. Benefits. EAP Program. https://www.uvu.edu/peopleandculture/division/index.html.
46 FBI. Making Prevention a Reality 2017.
https://bn.knowledgebank.criminaljustice.ny.gov/system/files/documents/2021/06/making-prevention-a-reality-
02_fbi.pdf. Accessed May 28, 2026; Utah Code § 78B‑3‑502.
After-Action Report for Utah Valley University
99
Clinical and Forensic Psychology Consultation
One of the foundational principles of the U.S. Secret Service National Threat Assessment Center
(NTAC) model is that threat assessment is a behavioral investigative process — not a mental health
diagnosis or psychiatric evaluation.47 A clinical diagnosis is a mental health condition identified by a
qualified healthcare professional using established diagnostic criteria.48 An individual is considered to be
posing a threat when their behaviors, communications, or actions indicate an increased likelihood that
they may engage in targeted violence or other harmful acts.49
Student Mental Health Services and the Employee Assistance Program provide important treatment,
counseling, crisis support, and referral resources. These services are essential to a prevention-focused
threat assessment and management program. However, counseling and EAP services are not the same
as violence risk assessment or forensic consultation.
A licensed clinical or forensic psychologist trained in violence risk assessment can provide specialized
consultation to the BAT when cases involve elevated concern, complex behavioral patterns, potential
violence, stalking, fixation, return-to-campus decisions, or conditions for continued enrollment or
employment. This type of expertise ensures objectivity and can help the team evaluate whether a threat
appears transient or substantive, assess the likelihood of escalation, identify appropriate interventions,
consider whether law enforcement involvement is warranted, and inform decisions regarding continued
enrollment, employment status, campus access, or return to campus. The Project Team acknowledges
that a NABITA-trained clinical mental health counselor is a member of the BAT. Access to an external
evaluator is also recommended to ensure objectivity and clearly delineate the evaluator’s role.
This role differs from counseling, which focuses primarily on symptom reduction, treatment, and client
well-being. Threat assessment is fundamentally a risk-management and public safety function. While
counseling centers and EAP providers may offer valuable support and treatment, a licensed clinical or
forensic psychologist trained in violence risk assessment brings specialized expertise in evaluating
threats, applying structured assessment tools, advising multidisciplinary teams, and supporting
institutional decision-making.50
In the Project Team’s assessment, UVU has strong counseling, mental health, and EAP resources, further
strengthened by the presence of a NABITA-trained licensed clinical mental health counselor on the BAT.
This provides the team with valuable clinical perspective and behavioral health expertise as part of its
multidisciplinary assessment process. For elevated-risk or particularly complex cases, the BAT would also
benefit from reliable access to an external clinical or forensic psychologist with specialized training in
violence risk assessment. Such consultation can supplement the team’s internal expertise by providing
an independent perspective, specialized assessment capabilities, and additional support for
47 Fein, et al. Threat Assessment in Schools a Guide to Managing Threatening Situations and Creating Safe School Climates.
United States Secret Service and the United States Department of Education. July 2024.
https://www.ed.gov/sites/ed/files/admins/lead/safety/threatassessmentguide.pdf.
48 American Psychiatric Association. (2022). Diagnostic and statistical manual of mental disorders (5th ed., text rev.; DSM-5-
TR). American Psychiatric Publishing.
49 National Behavioral Intervention Team Association. (2024). NABITA practice standards.
50 NABITA, Building an Individualized Threat Management Plan, notes that violence risk assessments should inform long-term
threat management plans, risk mitigation strategies, and stakeholder engagement.
After-Action Report for Utah Valley University
100
consequential decisions involving risk management, campus access, continued enrollment or
employment, and return to campus.
Related Policies and Institutional Framework
The Project Team reviewed several policies and procedures that support UVU's violence prevention and
behavioral intervention framework, including:
▪ Title IX Sexual Harassment Policy #162
▪ Discrimination and Harassment Policy #165
▪ Abusive Coaching Practices Policy #166
▪ Student Safety Intervention Protocol
▪ Workplace Conduct Policy #326
▪ Staff Grievance Policy #335
▪ Performance Management and Development for Full-Time Staff Employees Policy #371
▪ Faculty Sanction and Dismissal for Cause Policy #649
Collectively, these policies are comprehensive, well-written, and generally aligned with accepted higher
education practices and applicable legal requirements. However, the BAT is referenced in only a limited
number of these documents despite the broad range of behaviors routinely reviewed by the team.
Greater integration of BAT referral pathways and consultation responsibilities across institutional
policies would help reinforce awareness, improve reporting consistency, and strengthen
multidisciplinary coordination.
In the Project Team’s assessment, UVU has strong intervention resources and a supportive policy
framework. The primary opportunity is to more fully connect those resources, policies, and referral
pathways to the BAT’s role so that community members and institutional partners understand when to
consult the BAT, how to report concerns, and how multidisciplinary coordination will occur.
Recommendations related to the issues addressed in this section are included in Section 9.
After-Action Report for Utah Valley University
101
7. Post-Incident Recovery, Corrective Actions, and
Preparedness Enhancements
The September 10 incident required UVU to address immediate recovery needs, support affected
students and employees, respond to public concern, identify lessons learned, and begin strengthening
emergency preparedness systems. This section summarizes post-incident recovery measures and
corrective actions initiated or proposed after the incident.
UVU and its partners took several meaningful steps after September 10, particularly in support of
students, campus safety awareness, crisis communications planning, emergency preparedness training,
and interagency coordination. At the same time, the Project Team identified opportunities to strengthen
formal after-action processes, first responder wellness support, corrective-action tracking, and
integration of post-incident lessons into sustained preparedness improvements.
7.1 Post-Incident Recovery and Community Support
Post-incident recovery is an important component of emergency management. Following a traumatic
campus incident, effective recovery efforts typically include timely support for students, employees,
families, first responders, dispatchers, witnesses, and others directly or indirectly affected. Recovery
may involve reunification or temporary support locations, mental health resources, victim assistance
services, trauma-informed communications, academic or workplace accommodations, and ongoing
outreach after the immediate crisis has passed.
Following the September 10 incident, UVU and its partners took steps to support students and members
of the campus community. The Alumni Building was opened as a temporary location for individuals who
could not immediately leave campus or who needed a place to go, to include individuals needing
transportation because their vehicles or other modes of transportation were locked down within the
campus crime scene areas, and those who could not gain access to keys and other personal belongings
left behind on campus as they fled the scene. The American Red Cross was contacted to support
sheltering if needed, although a shelter was not activated because the need did not materialize.
Mental health support was also mobilized. UVU Mental Health Services made trained licensed therapists
available to speak with students, and additional support was sought from community providers. Support
included psychological first aid and post-trauma resources. Mental health support was active for
approximately two weeks and then decreased as demand declined. The FBI Victim Assistance Program
also became involved quickly after the incident and provided additional support resources.
These efforts reflected an appropriate recognition that students, witnesses, and other campus
community members needed access to immediate and short-term support services. The involvement of
UVU Mental Health Services, community providers, and the FBI Victim Assistance Program was a
strength. To evaluate these efforts fully, UVU would benefit from compiling available utilization data,
outreach records, after-action observations, and feedback from students, employees, and service
providers regarding what support was used, what needs were unmet, and what resources may be
needed in future incidents.
After-Action Report for Utah Valley University
102
7.2 Support for UVUPD Personnel and First Responders
Post-incident support should include
sworn personnel, dispatchers, emergency
management staff, communications
personnel, and other employees directly
involved in the response. First responders
may experience operational stress,
trauma exposure, investigative
constraints, public scrutiny, and difficulty
decompressing after a major incident.
These effects can be compounded when
responders must continue working in the
same environment where the incident occurred, respond to related protests or public activity, and avoid
discussing investigative details while the criminal case remains active and judicial proceedings are
underway.
Information provided during the review indicates that some peer-support activity occurred after the
incident. However, the Project Team also identified concern that post-incident support for responding
UVUPD personnel was less formalized and less visible than the support provided to students and the
broader campus community. At least one responding officer described difficulty processing the incident,
frustration with the absence of a formal internal department review process that could have provided
some opportunity to process what personnel experienced, and a perception that institutional follow-up
with officers was limited.
These observations should not be understood as criticism of any individual. Rather, they indicate that
UVU’s recovery framework would benefit from a more structured responder-support process after
major incidents. Such a process should include timely wellness check-ins, peer support, access to
confidential mental health resources, opportunities for facilitated decompression, supervisor follow-up,
and a formal after-action process that allows responders to identify what worked, what was difficult,
and what support is needed going forward.
In our assessment, responder support should be incorporated into UVU’s post-incident recovery
framework. Supporting responders is not only a wellness issue; it is also connected to employee
retention, morale, operational readiness, organizational trust, and institutional learning. A
comprehensive post-incident recovery plan should include the people who responded to the incident as
well as the people affected by it.
7.3 Awareness, Training, and Preparedness Improvements
After the incident, UVU initiated or advanced several campus safety awareness and preparedness
efforts. These efforts included updating classroom posters addressing active shooter, bomb threat, fire,
medical emergency, and other emergency scenarios. UVU also developed new employee training
through its learning management system focused on campus safety and active-threat preparedness.
According to information provided during the review, UVU uses an active shooter training video
originally developed by the University of Utah and provided for use in the Utah System of Higher
Education.
After-Action Report for Utah Valley University
104
The Project Team reviewed an in-progress draft of UVU’s Crisis Readiness Plan and Guidebook 2026.
The draft Guidebook is comprehensive and represents an important post-incident improvement. It
establishes a crisis management framework, identifies emergency and crisis levels, addresses roles and
responsibilities for life-safety alerts, includes coordination with external agencies, identifies major crisis
categories, establishes media relations protocols, and includes procedures for lockdowns and post-crisis
review. The inclusion of pre-drafted and legally reviewed “shelf statements” in a Digital Go Bag is also a
meaningful improvement because it can help UVU communicate more quickly while verified facts are
still being gathered.
As UVU finalizes the Guidebook, the University should consider cross-walking the crisis categories in the
Guidebook with the broader incident categories identified in the Emergency Operations Plan and other
foreseeable emergency scenarios that may require rapid institutional communication. This would help
ensure that the Guidebook, Emergency Operations Plan, emergency communications templates, training
materials, and operational response procedures are aligned across a full range of incidents.
UVU should also use the finalization process to clarify decision-making authority and standardize
terminology across the Guidebook, Emergency Operations Plan, emergency alert templates, training
materials, and public-facing instructions. The draft Guidebook appropriately emphasizes speed for life-
safety alerts, but shared unilateral authority can create ambiguity if more than one person is authorized
to act at the same level. UVU would benefit from identifying a primary decision-maker and designated
backups for emergency notifications and crisis communications.
The Guidebook also reflects UVU’s decision to use Avoid, Deny, Defend, Aid as its active-assailant
response protocol. The University is in the process of updating its policy and protocol documents to
reflect this, including the Emergency Operations Plan and related emergency management, crisis
communications, training, exercise, and scripted message materials so they consistently use Avoid,
Deny, Defend, Aid and align related terms such as “lockdown” and “shelter.”
The value of the Guidebook will depend on implementation. Once finalized, UVU should train relevant
personnel on the Guidebook, test it through realistic tabletop and functional exercises, integrate it with
EOC procedures and emergency notification templates, and include crisis communications in after-
action improvement tracking. Scenario-based exercises will be particularly important to ensure that the
plan works under time pressure, with incomplete information, and during events involving competing
operational, legal, reputational, and life-safety considerations.
7.5 Interagency Security and Preparedness Enhancements
Several important interagency security and preparedness enhancements were initiated or proposed
after the September 10 incident. These actions are directly responsive to lessons identified during the
assessment and should be sustained, formalized, and incorporated into UVU’s future planning for major
events and emergency response.
Commissioner Beau Mason of the Utah Department of Public Safety assigned a DPS member on the SIAC
team responsibility to focus on locating and analyzing available information associated with safety
concerns for Utah’s institutions of higher education. Commissioner Mason also requested that each
Utah institution of higher education designate at least one representative to participate in a new
working group intended to support regular interaction, information sharing, and coordination among
After-Action Report for Utah Valley University
106
new technologies that will enhance data integration and analysis capacities which, in turn, will help to
improve situational awareness, improve response times, and enhance criminal case investigation
effectiveness and social media monitoring. University of Utah Chief Safety Officer Squires advised he has
already committed two University of Utah DPS staff members to join in the efforts of this center on a
full-time basis. This promising move stands to assist not only both of their own departments to
collaborate more effectively in their efforts to provide for public safety in Salt Lake City and at the
University of Utah but also has the potential to provide an additional criminal intelligence resource for
institutions of higher education throughout Utah.
The City of Orem Police Chief B.J. Robinson advised that OPD and UVU have taken steps to formalize
their existing informal mutual aid relationship through a written mutual aid agreement. This agreement
should define roles, request procedures, command coordination, resource sharing, specialized
capabilities, communications expectations, cost-recovery protocols, and support for major events and
emergency incidents.
OPD’s aerial drone capability should also be considered as part of future event planning when
appropriate and legally permissible. Chief Robinson advised that OPD would have provided drone
support had the resource been requested and had OPD known more in advance about event details,
including the specific location of the event. Future event planning should include early identification of
specialized resources available from partner agencies, including drones, tactical teams, traffic-control
assets, fire and EMS staging, emergency management personnel, and investigative support.
Orem Fire Chief Marc Sanderson advised that he had spoken with Chief Robinson about approaching
UVU to conduct a joint active shooter training exercise. This proposed exercise should include UVUPD,
OPD, Orem Fire, Orem Emergency Management, and other appropriate local partners. It should test the
Incident Command System, unified command, emergency medical response, victim search and rescue,
building sweeps, emergency communications, Command Post operations, Emergency Operations Center
coordination, traffic control, and public information coordination.
Orem Emergency Management Director Keith Stevenson also advised that his office is willing to assist
UVU with future emergency management policy development, training, and preparedness efforts. UVU
should actively incorporate Orem Emergency Management into future planning, exercises, and after-
action improvement tracking, particularly for major events with elevated security concerns or large
public attendance.
As UVU continues post-incident preparedness enhancements, it should also consider whether no-cost
CISA resources could support physical security review, cybersecurity preparedness, tabletop exercises,
targeted violence prevention, and broader campus resilience planning.
In the Project Team’s assessment, these local and statewide interagency efforts are a meaningful
strength and provide UVU with important opportunities to enhance its own preparedness. The
opportunity is not only to monitor these efforts, but to participate in them proactively, as UVU’s General
Counsel is doing, identify other appropriate UVU representatives who should become engaged as
recommendations are ultimately being implemented statewide, and incorporate relevant tools,
resources, intelligence-sharing practices, and lessons learned into UVU’s Security Assessments, Event
Action Plans, emergency management processes, threat assessment work, mutual aid planning, and
corrective-action tracking.
After-Action Report for Utah Valley University
113
Policy 425 also addresses the concern commonly referred to as “fronting.” Section 3.4 defines fronting
as “permitting or aiding an external use under the guise that the activity is a University or a cosponsored
event for the purposes of avoiding contracts, risk management, or Event Services review, payments, or
other requirements or conditions applicable to external events.” This provision is intended to prevent
external organizations from avoiding the procedural, financial, insurance, and risk-management
requirements that apply to external events, including significant security fees that might be
appropriately assessed.
The fronting provision is important because event classification affects how the University evaluates
risk, assigns responsibilities, imposes conditions, coordinates with organizers, and documents
obligations. If an external organization is effectively controlling or sponsoring an event, but the event is
processed as a University or co-sponsored event without appropriate documentation, the University
may lose the benefit of external-use agreements, insurance verification, cost recovery, indemnification
provisions, and formal review procedures. At the same time, the entity that is being “fronted” may
benefit from avoiding considerable costs associated with the event. The question is often whether an
event is really being held at the request of a club or other internal university entity or whether an
external organization is using the internal entity to avoid paying appropriate costs.
At the same time, event classification must be applied consistently and, in a content-neutral manner.
A public university may not reclassify, burden, or deny an event because of disagreement with the
speaker’s viewpoint or anticipated public reaction. However, the University may apply neutral policy
requirements related to sponsorship, facility use, contracting, insurance, cost allocation, risk
management, and operational review when those requirements are grounded in objective criteria and
applied consistently across events.
Key Legal Takeaways
Policy 425’s fronting provision is an important risk-management and compliance tool. UVU should
ensure that event classification decisions are documented, consistently applied, and based on objective
criteria regarding sponsorship, control, facility use, and external involvement. Clear application of Policy
425 helps preserve constitutional neutrality while also ensuring that contracts, insurance, cost
allocation, Event Services review, and risk-management requirements are not bypassed when external
entities are involved.
8.3 First Amendment Considerations
Public University Obligations Regarding Free Speech
As a public university, UVU is required to protect lawful expressive activity regardless of the popularity
or controversy of the viewpoint being expressed. UVU states its commitment to protection of First
Amendment rights in its Policy 161, Freedom of Speech. The University's role is not to endorse or
oppose particular viewpoints, but rather to provide a lawful environment in which protected speech
may occur. These obligations become particularly significant when events involve political figures,
controversial speakers, or issues that may generate strong public reactions. The September 10 TPUSA
event presented many of the challenges public universities routinely face when balancing constitutional
freedoms with safety and operational concerns.
After-Action Report for Utah Valley University
114
Controversial Speakers
Public institutions generally may not deny access to facilities, cancel events, or impose burdens on
speakers because of disagreement with the speaker's views or because others oppose those views.
Anticipated controversy, public criticism, or the possibility of protests does not diminish First
Amendment protections. Universities may, however, take reasonable steps to address legitimate safety
concerns associated with an event, provided those measures are based on objective security
considerations rather than the content of the speech itself.
Time, Place, and Manner Restrictions
Although public institutions must protect speech rights, they may impose reasonable, content-neutral
restrictions concerning the time, place, and manner of expressive activities. Such restrictions must serve
legitimate governmental interests, be narrowly tailored, and leave open alternative opportunities for
expression. These principles are particularly relevant when evaluating venue selection, crowd
management, protest activity, access-control measures, and event logistics. They are also reflected in
Utah law, which recognizes outdoor areas of public university campuses as traditional public forums
entitled to heightened constitutional protection. Section 4.2.2 of UVU Policy 161 provides for time,
place, and manner restrictions.
Security Fees and Viewpoint Neutrality
Courts have consistently held that security-related decisions must remain viewpoint neutral. Institutions
may not impose costs, restrictions, or conditions based upon the anticipated reaction to a speaker's
message or the controversial nature of a viewpoint. As a result, universities must be able to
demonstrate that security decisions are grounded in objective risk factors, documented planning
considerations, and consistent institutional practices. Any security fee assessed must be based on
objective, content-neutral criteria that eliminates arbitrary discretion by university officials.52
Key Legal Takeaways
The First Amendment significantly limits the ability of public universities to restrict speakers, deny event
requests, or impose burdens based on anticipated controversy. Consequently, event planning processes
must be capable of distinguishing between legitimate safety concerns and viewpoint-based
considerations. Well-documented, objective, and consistently applied decision-making processes are
essential to maintaining both constitutional compliance and public confidence.
8.4 Firearms and Security Screening Considerations
Utah Campus Carry Laws
While prohibition of firearms on college campuses is permissible under the Second Amendment,53 Utah
law broadly permits lawful concealed firearm possession on public college and university campuses. On
September 10, 2025 an individual 18 years of age or older, with a concealed weapon permit, could carry
52 Leadership Institute et al. v. Stokes et al., 2024 CV 01 87, U.S. District Court of New Mexico
53 Wade v. Univ. of Michigan, 145 S.Ct. 1923, No. 24-773 (2025) (cert. denied).
After-Action Report for Utah Valley University
115
a weapon on a Utah campus, either open or concealed.54 At present, any individual 21 years of age or
older, and not legally disqualified from possessing a firearm, can carry a concealed weapon on a Utah
campus, with or without a concealed weapon permit.55 Unlike many states, Utah does not provide
public institutions with independent authority to prohibit lawful firearm possession on campus property.
Accordingly, UVU's ability to regulate firearms during campus events is substantially more limited than
that of institutions operating in jurisdictions with different statutory frameworks.
State Preemption
Utah maintains strong state preemption over firearms regulation. Public institutions generally may not
adopt firearms restrictions beyond those authorized by state law. Decisions regarding firearm
possession and regulation are largely reserved to the State Legislature. This legal framework limits the
University's discretion to implement security measures that might otherwise be available in other states.
Weapons Screening Limitations
Because of Utah's statutory framework, the use of weapons screening measures presents unique legal
and operational challenges. Security practices commonly employed at public events elsewhere—
including temporary event-specific firearm prohibitions—may not be available to public universities in
Utah. While screening may be used to identify who has a weapon, it may not result in prohibiting
possession of the weapon inside the venue. As a result, readers from outside Utah should recognize that
some security measures frequently discussed following high-profile incidents may not have been legally
available to UVU.
Key Legal Takeaways
Utah's firearms laws significantly constrain the security options available to public universities. As a
practical matter, institutions must rely more heavily on threat assessment, intelligence gathering, venue
planning, staffing decisions, and other preventive security measures than universities operating in states
that authorize broader firearm restrictions or screening programs.
8.5 Clery Act and Emergency Notification Considerations
Timely Warnings
The Jeanne Clery Campus Safety Act requires higher education institutions to issue timely warnings
regarding certain crimes that pose a serious or continuing threat to the campus community. These
warnings are intended to provide members of the campus community with information necessary to
make informed decisions regarding their safety.
Emergency Notifications
The Clery Act separately requires emergency notifications when an institution confirms a significant
emergency or dangerous situation involving an immediate threat to the health or safety of students or
employees. These notifications are intended to be issued without unnecessary delay while considering
54 HB 128, Utah Code § 76-11-205.5 (2025)
55 HB 84, Utah Code § 76-11-205.5 (2026)
After-Action Report for Utah Valley University
116
the needs of emergency response efforts. UVU's Annual Security and Fire Safety Report incorporates
these requirements through its Emergency Operations Plan and Emergency Communications Plan.
Emergency Communications Obligations
Emergency notifications must provide timely, accurate, and actionable information to affected
populations. In rapidly evolving incidents, institutions must make decisions based on incomplete
information while balancing public safety concerns, operational realities, and evolving investigative
facts. The events of September 10, 2025 demonstrate the challenges institutions face when
communicating during a dynamic and uncertain incident. As circumstances evolve, maintaining
consistency, clarity, and public understanding becomes increasingly difficult but remains critically
important.
Documentation Requirements
The Clery Act and UVU policy require the institution to maintain records relating to emergency
preparedness, emergency response procedures, testing, exercises, and after-action reviews. UVU's
Emergency Operations Plan and Annual Security Report contain detailed provisions governing these
responsibilities, including documentation of exercises, lessons learned, and corrective actions.
Key Legal Takeaways
The Clery Act does not merely require institutions to communicate during emergencies; it requires them
to maintain policies, systems, training, and documentation capable of supporting effective emergency
communications. The quality of emergency communications is often evaluated not only by the speed of
notification, but also by the accuracy, consistency, and clarity of information provided throughout an
incident.
8.6 Legal Review of Findings and Recommendations
Brownstein Hyatt Farber Schreck LLP reviewed the findings and recommendations contained in this
report and determined that they are generally consistent with applicable federal and state law, including
the Jeanne Clery Campus Safety Act, Utah statutory requirements applicable to public institutions of
higher education, and relevant constitutional considerations governing free expression and public safety
on university campuses.
Recommendations related to the issues addressed in this section are included in Section 9.
After-Action Report for Utah Valley University
129
Appendices
Appendix A: Project Team Bios
Core Law Enforcement and Security Risk Management Team
Robert L. Davis, Project Manager, Law Enforcement Operations Specialist
President, Robert L. Davis, LLC; Former Chief of Police, San Jose, California;
Former President, Major Cities Chiefs Association
Rob Davis brings more than 30 years of law enforcement leadership experience,
including service as Chief of Police for the City of San Jose — one of the nation’s
largest municipal departments, along with 15 years of consulting experience. He is
widely recognized for strengthening operational readiness and response, leading
complex incident assessments, improving investigative processes, strengthening media interaction
capabilities, and assessing training curriculums and methodologies. Rob has directed high-stakes
assessments for public agencies and universities nationwide.
Matthew W. Doherty, Targeted Violence and Threat Assessment and Management Specialist
Founder and Managing Principal, Doherty Advisory
Matt Doherty is a nationally recognized authority in behavioral threat assessment and
management, targeted violence, workplace violence prevention, and organizational
security practices. He draws on more than four decades of distinguished service in
both government and the private sector, including leadership of the U.S. Secret
Service National Threat Assessment Center. Matt has led threat management
practices for global consulting firms and continues to advise organizations seeking to strengthen
violence-prevention programs and mitigate risk.
G. Michael Verden, Security Operations and Emergency Management Specialist
CEO and Founder, The Lake Forest Group
Mike Verden is a prominent security strategist with deep expertise in event security,
protective intelligence, and emergency preparedness. As CEO and Founder of The
Lake Forest Group and former operational leader within the Major Events Division,
Dignitary Protection Division, and Presidential Protection Division of the U.S. Secret
Service, he has directed complex risk assessments for NSSEs, major venues,
universities, corporations, and government entities, and has also served as an expert witness reviewing
security plans and threat intelligence for the Ben Shapiro event at the University of Minnesota. Mike
brings extensive experience designing resilient security programs and plans that align operational needs
with industry best practices.
After-Action Report for Utah Valley University
130
Core Brownstein Team
John Suthers, Legal Counsel and Project Manager for the Brownstein Team
Shareholder, Brownstein Hyatt Farber Schreck, LLP; Former Mayor, Colorado
Springs; Former Colorado Attorney General; Former United States Attorney
John Suthers brings nearly five decades of legal, public safety, government, and
investigative experience to the project team. He has served as a Deputy District
Attorney, Chief Deputy District Attorney, and elected District Attorney for Colorado’s
Fourth Judicial District. He also served as Executive Director of the Colorado
Department of Corrections, United States Attorney for the District of Colorado, Attorney General of
Colorado from 2005 to 2015, and Mayor of Colorado Springs from 2015 to 2023. Mr. Suthers has
extensive experience conducting external and internal investigations, including matters involving school
and campus safety. Following the 2007 shooting at Virginia Tech University, he served as co-chair of the
National Association of Attorneys General Task Force on School and Campus Safety. As United States
Attorney for Colorado, he conducted a review of the Columbine Commission report in response to a
petition by parents of students killed at Columbine High School. In 2024, he was part of a Brownstein
team that conducted an external review of a double homicide in a residence hall at the University of
Colorado, Colorado Springs. Mr. Suthers earned his J.D. from the University of Colorado School of Law in
1977 and his B.A., cum laude, from the University of Notre Dame in 1974.
Jason Dunn, Legal Counsel
Shareholder, Brownstein Hyatt Farber Schreck, LLP; Former U.S. Attorney;
Former Deputy Attorney General of Colorado
Jason Dunn has been practicing law for 25 years. He served as Deputy Attorney
General of Colorado and as US Attorney for Colorado. As a seasoned counselor and
litigator, he has led and advised on some of the most high-profile private and
governmental investigations in Colorado. He is chair of Brownstein‘s Attorney General
Practice and its Government Investigations and White Collar Defense Group. Mr. Dunn’s extensive
experience in conducting external and internal investigations includes work for the University of
Colorado. He earned his J.D. from the University of Colorado Law School, his M.P.A. from the University
of Colorado Graduate School of Public Affairs, and his B.S. from the University of Colorado College of
Business.
Max Porteus, Legal Counsel
Max Porteus is a litigation associate whose practice focuses on handling complex
disputes, including trial level and appellate litigation, internal and government
investigations, and high stakes commercial matters. His work spans litigation strategy,
complex briefing, and advising clients in investigations and disputes from inception
through appeal. He previously clerked for Justice Carlos A. Samour, Jr. of the Colorado
Supreme Court. He earned his J.D. from the University of Denver Sturm College of
Law, Order of the Coif, and his B.A. from the University of Denver.
After-Action Report for Utah Valley University
131
Advisory Board
Brent Herron, Subject Matter Expert: Campus Safety
Brent Herron is a nationally recognized expert in campus safety, emergency
operations, and threat management with more than 30 years of experience in higher
education and federal protective operations. He served as the University of North
Carolina System’s Senior Associate Vice President for Campus Safety and Emergency
Operations, leading systemwide initiatives across 16 universities and directing major
programs in policing, emergency management, and behavioral threat assessment.
Prior to his higher education leadership role, Brent spent 21 years with the U.S. Secret Service,
supporting and supervising technical security operations for multiple NSSEs. He currently advises the
UNC System on policy, preparedness, major-incident response, and interagency coordination.
Chris Brenner, Subject Matter Expert: Open-Source Intelligence
Chris Brenner is an investigations and intelligence specialist with more than 15 years
of experience applying advanced OSINT tools and methodologies to support complex
investigations and threat assessments. As Associate Managing Director and Director
of Technology at 221B Partners, he leads OSINT-driven research, deep and dark web
analysis, and data visualization to support clients across corporate, government, and
nonprofit sectors. He is Open-Source Certified (OSC) by the OSMOSIS Association,
where he serves on the Board of Advisors, and is an active member of ATAP, InfraGard, and OSAC.
Heather Czyzewicz, Subject Matter Expert: Security Technology
Heather Czyzewicz is a security technology specialist with extensive experience
helping organizations implement scalable, interoperable physical security solutions.
She leverages strong industry partnerships, continuous technology research, and
cross-market expertise to guide clients in selecting and deploying effective, budget-
aligned systems. Heather currently serves as Business Development Manager for
Sound Incorporated, where she advances integrated technology strategies and
strengthens organizational readiness across diverse sectors.
James A. Konieczny, Subject Matter Expert: Counter Sniper Tactics
James Konieczny is a retired U.S. Secret Service Special Agent with 25 years of federal
service and deep expertise in counter-sniper operations for high-risk environments. He
spent two decades in the USSS Counter Sniper Unit — later serving as an instructor —
where he trained agents in long-range precision shooting, weapons proficiency, and
advanced counter sniper tactics. James has supported protective missions for four U.S.
Presidents and led counter sniper teams during multiple NSSEs.
Michelle Hoy-Watkins, Psy.D., ABPP, Licensed Clinical Psychologist
Michelle Hoy-Watkins, Psy.D., ABPP is a Licensed Clinical Psychologist with more than
25 years of experience in clinical, forensic, and police and public safety psychology.
She is Board Certified in Police and Public Safety Psychology and has provided
psychological services, wellness programs, threat assessments, and consultative
support to numerous law enforcement agencies, including the Chicago Police
After-Action Report for Utah Valley University
132
Department, Illinois State Police, and Northwestern University Police. Dr. Hoy-Watkins previously led
Northwestern University’s threat assessment program and has extensive experience conducting forensic
evaluations and working in federal and state correctional and mental health institutions. She currently
serves as a consultant to state and national threat assessment teams and holds multiple leadership roles
within the International Association of Chiefs of Police and the American Psychological Association.
John A. Gill, Subject Matter Expert: Crisis Communications and Public Affairs
John Gill is an accomplished crisis communications and public affairs leader with more
than 30 years of experience guiding high-stakes messaging, media coordination, and
stakeholder engagement at the highest levels of government and the private sector.
His career includes senior roles in the White House and the U.S. Secret Service, where
he led the agency’s public affairs and crisis communications programs during the post-
9/11 era. John has managed complex security, continuity, and executive
communication efforts across global operations, bringing a steady, trusted voice to organizations facing
sensitive or rapidly evolving events. He is known for his clarity, integrity, and ability to translate complex
operational issues into decisive, credible communication strategies.
Communications Lead
Vicky Froderman, Senior Advisor, Research and Reporting
Vicky Froderman has a career rooted in communications, with long-standing expertise
in writing, messaging, research, and producing high-quality materials for senior
leaders and diverse audiences. For the past 20 years, her work has focused on security
risk management and workplace violence prevention, where she has applied those
skills to complex, high-stakes assessments and sensitive client matters. She has
contributed to hundreds of assessments, including the Virginia Beach mass shooting
review, supporting multidisciplinary teams through interviews, document review, report development,
editing, quality control, and the organization and presentation of findings and recommendations. Vicky
brings clarity, precision, and analytic discipline to complex engagements, helping ensure that
conclusions are well-supported and communicated clearly and consistently.
After-Action Report for Utah Valley University
133
Appendix B: Incident Command System (ICS)
Roles and Responsibilities
The Incident Command System (ICS) is a standardized management framework used to coordinate
personnel, resources, communications, and decision-making during emergencies and planned events.
While the specific structure may expand or contract depending on the complexity of an incident, the
following positions are commonly used within ICS-compliant organizations.
Incident Commander (IC)
The Incident Commander has overall responsibility for managing the incident and establishing incident
objectives and priorities. The IC directs response activities, authorizes resource requests, approves
strategic decisions, and serves as the primary decision-maker throughout the incident. Typical
responsibilities include:
▪ Establishing incident objectives and priorities
▪ Approving operational strategies and response actions
▪ Requesting additional resources and mutual aid when necessary
▪ Coordinating with executive leadership
▪ Maintaining overall situational awareness
▪ Authorizing incident closure and "all clear" notifications
Public Information Officer (PIO)
The Public Information Officer serves as the official communications representative during an incident
and is responsible for developing, coordinating, and disseminating information to internal and external
audiences. Typical responsibilities include:
▪ Preparing public statements and media releases
▪ Coordinating communications with stakeholders and families
▪ Monitoring media coverage and public messaging
▪ Supporting emergency notification activities
▪ Ensuring consistent and accurate information is released
Liaison Officer (LNO)
The Liaison Officer serves as the primary point of contact for assisting agencies, partner organizations,
and external stakeholders supporting incident operations. Typical responsibilities include:
▪ Coordinating with responding public safety agencies
▪ Facilitating information sharing between organizations
▪ Assisting with mutual aid coordination
▪ Participating in planning meetings
▪ Communicating resource needs and capabilities among partner agencies
Safety Officer (SO)
The Safety Officer monitors incident operations and advises leadership regarding safety concerns
affecting responders, staff, students, visitors, and other stakeholders. Typical responsibilities include:
▪ Identifying and evaluating safety hazards
After-Action Report for Utah Valley University
134
▪ Monitoring responder safety and operational risks
▪ Coordinating with law enforcement and emergency responders
▪ Assessing evacuation routes and assembly locations
▪ Recommending corrective actions when unsafe conditions exist
Operations Section Chief
The Operations Section Chief manages tactical activities and directs personnel engaged in incident
response operations. Typical responsibilities include:
▪ Supervising operational resources
▪ Implementing incident objectives
▪ Coordinating field activities
▪ Monitoring operational progress
▪ Reporting status updates to command staff
Planning Section Chief
The Planning Section Chief is responsible for collecting, evaluating, and disseminating information
needed to support incident management. Typical responsibilities include:
▪ Maintaining situational awareness
▪ Tracking incident status and resources
▪ Developing Incident Action Plans
▪ Documenting operational activities
▪ Supporting future operational planning
Logistics Section Chief
The Logistics Section Chief provides facilities, personnel, equipment, communications, and other
resources necessary to support incident operations. Typical responsibilities include:
▪ Acquiring and distributing resources
▪ Coordinating communications systems
▪ Supporting personnel needs
▪ Managing facilities and equipment
▪ Tracking resource availability
Finance and Administration Section Chief
The Finance and Administration Section Chief manages financial, procurement, documentation, and
administrative functions associated with incident operations. Typical responsibilities include:
▪ Tracking incident-related costs
▪ Managing procurement activities
▪ Documenting personnel time and expenses
▪ Supporting reimbursement processes
▪ Maintaining incident financial records
After-Action Report for Utah Valley University
135
Appendix C: OSINT and Protective Intelligence
Technical Considerations
This appendix provides additional technical considerations related to open-source intelligence, social
media monitoring, subject-focused research, protective intelligence, and investigative governance. These
considerations support the findings and recommendations in Section 5.3.
1. Social Listening, Media Monitoring, and Protective Intelligence
Universities may use several types of tools and processes to support safety, communications, and threat
assessment functions. These capabilities overlap but are not interchangeable.
Social listening tools help monitor public online discussion, sentiment, event-related activity, and
institutional reputation. Media monitoring tools help track traditional and online media coverage. Law
enforcement databases support criminal justice and public safety inquiries. Protective intelligence and
OSINT investigative tools support deeper research into specific persons, groups, threats, or behaviors of
concern.
A mature program defines the purpose, owner, workflow, documentation requirements, and escalation
path for each capability.
2. Subject-Focused OSINT
Subject-focused OSINT may be appropriate when a specific individual, group, communication, or
behavior of concern requires additional assessment. Depending on the circumstances, this may include
review of:
▪ Publicly available social media activity
▪ Online communications
▪ Public records
▪ Civil and criminal court records
▪ Litigation history
▪ Prior law enforcement contacts
▪ Publicly available affiliations or networks
▪ Grievances, fixation, leakage, or target-focused communications
▪ Event-related threats or concerning statements
▪ Information from law enforcement, fusion center, or intelligence-sharing partners
The purpose of subject-focused OSINT is to support risk assessment, case management, intervention
planning, event security, and protective decision-making. It should not be conducted casually,
inconsistently, or without appropriate documentation and oversight.
3. Governance and Documentation
OSINT-related procedures should address:
▪ Who may conduct OSINT research.
▪ What circumstances justify subject-focused OSINT.
▪ What sources may be reviewed.
After-Action Report for Utah Valley University
136
▪ What approvals are required.
▪ How findings are documented.
▪ How information is validated.
▪ How screenshots or other records are preserved.
▪ How irrelevant or sensitive information is handled.
▪ How long information is retained.
▪ Who receives findings.
▪ How findings are incorporated into BAT, UVUPD, emergency management, or event-planning
decisions.
▪ How legal, privacy, and institutional policy issues are reviewed.
4. Investigative Accounts and Operational Security
Threat assessment-related OSINT should not be conducted using personal social media accounts. Use
of personal accounts may create operational security, privacy, documentation, attribution, and
investigative integrity concerns.
Where OSINT research is authorized, institutions should consider approved investigative accounts,
controlled research environments, standardized documentation practices, and supervisory oversight.
Policies and procedures may address operational security practices, preservation of content, authorized
platforms, account management, and methods for preventing inadvertent exposure of personal or
institutional information.
More advanced operational security considerations may include controlled workstations, approved
internet environments, virtual research environments, attribution management, and specialized
investigative tools. These capabilities should be implemented only with appropriate legal, privacy,
cybersecurity, procurement, and supervisory review.
5. Specialized OSINT and Protective Intelligence Platforms
UVU may evaluate dedicated OSINT, protective intelligence, or threat intelligence platforms designed
to support subject-focused investigations, identity resolution, monitoring, case documentation, and
intelligence reporting. Platform evaluation should be based on institutional need, legal requirements,
privacy considerations, cybersecurity, data retention, auditability, integration with existing case-
management systems, training needs, and cost.
Examples of industry-recognized enterprise platforms used in OSINT, protective intelligence, or threat
intelligence contexts include Ontic,56 Liferaft,57 Babel Street,58 Flashpoint,59 Fivecast,60 Skopenow61 and
other similar tools. This list is not a recommendation or endorsement of any vendor. Any vendor
56 https://ontic.co/
57 https://liferaftlabs.com/
58 https://www.babelstreet.com/
59 https://flashpoint.io/
60 https://www.fivecast.com/
61 https://www.skopenow.com/
After-Action Report for Utah Valley University
137
evaluation should be conducted through UVU’s normal procurement, legal, privacy, and cybersecurity
review processes.
6. Deep Web, Dark Web, and Alternative Platforms
Some protective intelligence inquiries may require awareness of information outside mainstream social
media or traditional web searches. Depending on the matter, relevant information may appear on
alternative social media platforms, online forums, message boards, encrypted or semi-private
communities, deep web sources, or dark web environments.
These sources present heightened legal, ethical, operational security, cybersecurity, privacy, and safety
considerations. They should be accessed only by trained personnel or qualified external resources using
approved methods, documented procedures, and appropriate legal, cybersecurity, privacy, and
supervisory oversight.
Operational security policies and investigative procedures should address, as appropriate, the
authorized use of VPNs or proxies, Tor62 and other dark web access methods, virtual machines,
controlled or segregated internet connections, so-called “dirty” internet connections, air-gapped
workstations, agency-managed investigative or “sock puppet” accounts, enterprise-managed attribution
tools, and forensic preservation methods. The level of technical control should be based on the nature
of the inquiry, the sensitivity of the matter, the risk to personnel or the institution, and applicable legal
and policy requirements.
UVU should not rely on ad hoc searches, personal devices, personal social media accounts, or informal
access methods for official protective intelligence inquiries involving deep web, dark web, or alternative-
platform research. Any use of these sources should occur within a defined governance framework that
addresses authorization, training, documentation, retention, evidence preservation, source validation,
reporting, and dissemination of findings.
7. Analyst Qualifications and Training
Personnel conducting OSINT or protective intelligence work should receive training in lawful and ethical
collection, source evaluation, documentation, reporting, privacy, operational security, and threat
assessment integration.
When evaluating internal OSINT analyst staffing or external vendors, UVU may consider recognized
training and certification programs. The OSMOSIS Association’s Open-Source Certification is one
example of a credential that evaluates OSINT-related knowledge across core areas such as critical
thinking, tradecraft, reporting, and laws and ethics.63 Certification should not be the only qualification
considered, but it may help identify baseline expertise.
8. Integration with BAT, Event Planning, and Emergency Management
OSINT and protective intelligence are most valuable when integrated into decision-making. Procedures
should clarify how relevant information is shared with:
62 https://www.torproject.org/
63 https://osmosisassociation.org/certifications/
After-Action Report for Utah Valley University
138
▪ Behavioral Assessment Team members
▪ UVUPD
▪ Emergency Management
▪ Event Services
▪ Communications
▪ Legal Counsel
▪ SIAC or other law enforcement partners
▪ Event security planners
▪ Executive leadership when appropriate
For elevated-risk events, protective intelligence findings may inform venue selection, staffing, access
control, screening, credentialing, protest management, communications planning, mutual aid requests,
and Event Action Plans. For BAT cases, findings may inform risk assessment, intervention planning,
monitoring, outreach, documentation, and protective measures.
9. Relationship with SIAC and External Partners
SIAC is an important resource for threat-related intelligence, suspicious activity reporting, criminal
intelligence, targeted violence prevention, and information sharing. UVU should continue leveraging
SIAC for pre-event threat assessments, threat management consultation, training, information sharing,
and support for elevated-risk cases.
UVU should also define when and how SIAC, local law enforcement, state partners, or qualified external
OSINT resources may be engaged to support specific cases or events.
10. Leveraging SIAC’s Existing Intelligence and Information-Sharing Platform
A potential opportunity exists for UVU to leverage SIAC’s existing intelligence and information-sharing
technology to support threat management, protective intelligence, suspicious activity reporting, major-
event planning, and information sharing. SIAC currently uses Kaseware as part of its investigations,
intelligence, and information-sharing environment. Because SIAC already has this capability in place,
UVU may not need to develop or procure a wholly separate platform to improve access to certain
intelligence workflows, analytical support, or information-sharing processes.
This appendix does not recommend or endorse a specific vendor. Rather, the relevance of Kaseware is
that SIAC already uses the platform in support of its fusion center mission. UVU should explore whether
SIAC’s existing environment can support appropriate collaboration involving threat information,
suspicious activity reports, investigative leads, intelligence products, event-related intelligence, and
other information relevant to campus safety.
A structured discovery process involving UVU, SIAC, UVUPD, Emergency Management, the Behavior
Assessment Team, Legal Counsel, and other appropriate stakeholders would help determine the most
appropriate operating model. That process should evaluate whether UVU would benefit from direct
platform access, a dedicated tenant, a shared collaborative environment, a SIAC-managed workflow, or
another structure that supports operational needs while preserving appropriate access controls,
auditability, data ownership, privacy protections, and organizational independence.
After-Action Report for Utah Valley University
139
The discovery process should address, at a minimum:
▪ What types of threat, suspicious activity, event-security, or protective intelligence information
UVU would submit to or receive from SIAC.
▪ Which UVU personnel, if any, should have direct access to the platform.
▪ Whether UVU should operate within a dedicated tenant, a shared collaboration space, or a SIAC-
managed process.
▪ How access controls, audit logs, role-based permissions, retention rules, and data ownership would
be managed.
▪ How sensitive student, employee, law enforcement, and behavioral threat assessment information
would be protected.
▪ How information-sharing procedures would be documented through memoranda of understanding,
operating procedures, or other agreements.
▪ How intelligence products or investigative leads would be incorporated into Security Assessments,
Event Action Plans, BAT processes, Emergency Operations Center operations, and public safety
decision-making.
▪ How legal, privacy, cybersecurity, procurement, and records-retention requirements would be
reviewed before implementation.
UVU and SIAC may also wish to evaluate whether specialized OSINT tools, such as OSINT Combine’s
NexusXplore or similar platforms, should be deployed through SIAC, UVU, or a hybrid model. A SIAC-
supported model may allow UVU to benefit from SIAC’s existing intelligence mission, analytical
personnel, public safety relationships, and information-sharing processes without requiring UVU to
independently develop and sustain a specialized OSINT capability. A UVU-based or hybrid model may be
appropriate if UVU determines that it needs more direct control over intake, documentation, event
planning, or case-support workflows.
Any use of OSINT tools should remain subject to the governance principles described in this appendix,
including clear authorization, trained users, approved investigative methods, documentation standards,
privacy review, legal review, cybersecurity review, retention rules, and supervisory oversight.
In the Project Team’s assessment, UVU should explore whether SIAC’s existing Kaseware environment,
SIAC’s analytical capabilities, and appropriate OSINT tools can support a more collaborative and
intelligence-informed approach to campus safety. The goal should not be technology acquisition for its
own sake, but improved information sharing, better threat awareness, stronger documentation, more
coordinated investigations, and more informed decision-making for threat assessment, major-event
planning, and incident response.
After-Action Report for Utah Valley University
140
Appendix D: Event Security Planning and Protective Measures
Reference Guide
D.1: Event Security Planning Framework for High-Profile Events
The level of security planning associated with an event should be commensurate with the event's risk
profile, anticipated attendance, venue characteristics, public visibility, and threat environment. While
every event does not require the same degree of planning, the following elements are commonly
incorporated into comprehensive event security programs.
Security Assessment
Event planning begins with identifying potential threats, assessing vulnerabilities, evaluating potential
consequences, and determining appropriate mitigation measures. Factors often considered include
anticipated attendance, protest activity, speaker profile, venue characteristics, historical incidents, and
intelligence information.
Security Planning and Coordination
Effective event security planning integrates venue management, law enforcement, security personnel,
emergency management, communications personnel, event organizers, and executive protection
representatives. Planning activities commonly include coordination meetings, site visits,
communications planning, contingency planning, and assignment of responsibilities.
Executive Protection Considerations
For high-profile speakers and guests, planning often includes advance site assessments, protective
intelligence reviews, secure arrival and departure procedures, route planning, communications
protocols, medical contingencies, and emergency evacuation procedures.
Access Control and Credentialing
Depending on the event's risk profile, organizations may implement ticketing systems, staff and
contractor credentialing procedures, controlled access points, prohibited-items policies, screening
procedures, and guest verification processes.
Screening Operations and Staffing Considerations
When screening operations are implemented, organizations should clearly define roles and
responsibilities for security personnel, event staff, and law enforcement officers. Screening personnel
should receive training on prohibited-items policies, screening procedures, ADA accommodations,
de-escalation techniques, communications protocols, and escalation procedures.
In many event environments, primary screening functions are performed by trained security personnel
or event staff, with law enforcement personnel available to provide supervisory support, respond to
incidents, address prohibited or illegal items, and manage enforcement actions when necessary. This
approach allows law enforcement resources to remain available for incident response, crowd
management, intelligence functions, and other security responsibilities while maintaining effective
screening operations.
After-Action Report for Utah Valley University
141
Security Staffing and Deployment
Security plans typically identify staffing levels, supervisory responsibilities, fixed posts, mobile patrols,
crowd management personnel, emergency response resources, and command personnel. Staffing
requirements should be informed by the event's size, complexity, and risk profile.
Intelligence and Situational Awareness
Event planning may incorporate intelligence gathering, social media monitoring, open-source
intelligence (OSINT), law enforcement information sharing, protective intelligence activities, and real-
time situational awareness measures.
Emergency Response Planning
Security plans should identify emergency procedures for medical emergencies, fires, severe weather,
disturbances, active assailant incidents, evacuations, shelter-in-place situations, and other foreseeable
contingencies.
Traffic and Perimeter Management
Planning may include arrival and departure routes, emergency vehicle access, parking management,
pedestrian flow, temporary barriers, road closures, and perimeter control measures.
Command and Communications
Events benefit from clearly defined command structures, communications plans, coordination
procedures, and incident escalation protocols. Larger events may warrant the establishment of a
command post or integration with emergency management structures.
Post-Event Review
Following significant events, organizations should conduct structured debriefings to identify lessons
learned, evaluate operational effectiveness, document challenges, and capture opportunities for future
improvement, including an After-Action Review.
D.2: Event Screening Operations Planning Considerations
For major events, high-profile speakers, controversial events, or events with elevated security concerns,
UVU should consider developing written screening procedures that address attendees, bags, containers,
vendors, deliveries, equipment, vehicles, staff, VIPs, officials, emergency responders, and event
participants. Screening procedures should be tailored to the event’s risk profile, venue, expected
attendance, crowd flow, legal constraints, staffing levels, and available equipment. Written screening
procedures should address:
▪ Screening authority and conditions of entry
▪ Permitted and prohibited items
▪ Bag and container restrictions
▪ Entry-point layout and queuing
▪ Staffing assignments and supervisory roles
▪ Law enforcement support and escalation procedures
After-Action Report for Utah Valley University
142
▪ Equipment selection, testing, calibration, and backup methods
▪ Signage and pre-event communications
▪ Medical, ADA, VIP, official, vendor, delivery, staff, emergency responder, and participant exceptions
▪ Documentation, incident reporting, and post-event review
For bag and container screening, UVU should consider:
▪ Clearly posting signage regarding bag checks and prohibited items.
▪ Communicating bag restrictions, including size, before the event through websites, ticketing
language, social media, email, and event materials.
▪ Using clear-bag policies for selected events when legally permissible and operationally appropriate.
▪ Inspecting bags and containers before entry to the venue.
▪ Using tables or other screening stations to support efficient screening.
▪ Providing appropriate tools, lighting, and protective measures for screening personnel.
▪ Establishing express lanes for attendees with no bags or items requiring inspection.
▪ Creating designated lanes for medical devices, mobility devices, diaper bags, staff, vendors,
participants, and equipment.
If hand-held metal detectors, walk-through magnetometers, X-ray screening, weapons-detection
systems, or other screening equipment are used, UVU should ensure that personnel are trained on
equipment use, alarm resolution, secondary screening, calibration, and escalation procedures. Sufficient
equipment and staffing should be provided to reduce entry delays and avoid crowding at screening
points.
If pat-downs are used, UVU should develop written procedures in consultation with legal counsel.
Procedures should address privacy, dignity, consent or conditions of entry, gender-related
considerations, witness procedures, semi-private screening locations, refusal procedures,
documentation, and law enforcement support. Personnel conducting pat downs should receive
specialized training, including sensitivity training and instruction on respectful, nondiscriminatory
screening practices.
Screening procedures should be tested before major events. Testing may include equipment checks,
staffing rehearsals, tabletop exercises, entry-flow simulations, and controlled penetration testing or
red-team exercises designed to evaluate whether screening procedures are understood and effective.
Results should be documented and used to improve procedures, staffing, equipment deployment,
communications, and training.
D.3: Access Control, Ticketing, and Credentialing Considerations
Access control, ticketing, and credentialing are core components of event security planning. These
functions help determine who may enter an event, where individuals may go once inside the event
footprint, what restrictions apply, and how event organizers, security personnel, and law enforcement
will manage authorized and unauthorized access.
After-Action Report for Utah Valley University
143
Access-control planning should be based on the event’s risk profile, anticipated attendance, venue
configuration, public visibility, speaker or guest profile, threat environment, legal considerations, and
operational capacity. For elevated-risk events, planners should evaluate whether the venue can support
controlled entry, ticket verification, credentialing, screening, designated entry and exit points,
restricted-access areas, and controlled movement between public and non-public spaces.
Access-control measures may include:
▪ Defined event boundaries
▪ Designated entry and exit points
▪ Ticket verification
▪ Credentialing procedures
▪ Restricted-access zones
▪ Staff and vendor check-in points
▪ Media check-in areas
▪ VIP or speaker access controls
▪ Emergency responder access points
▪ Controlled delivery areas
▪ Re-entry rules
▪ Late-entry procedures
▪ Conditions of entry
▪ Prohibited-items policies
▪ Screening procedures, when legally permissible and operationally appropriate
Access-control plans should address both normal operations and exceptions. Exceptions may include
medical needs, ADA-related accommodations, emergency responder access, credentialed media, staff
and vendor access, VIP movement, late-arriving participants, and emergency conditions. Plans should
also identify how unauthorized access, fraudulent credentials, refusal to comply with conditions of
entry, prohibited items, disruptive behavior, or suspicious activity will be handled.
Ticketing should be treated as a security and planning tool, not solely as an administrative or
attendance-management function. Ticketing systems can support crowd management, occupancy
control, staffing decisions, access-control planning, emergency egress planning, fraud prevention,
accountability, and real-time situational awareness. For major or elevated-risk events, ticketing data
should help planners evaluate expected attendance, peak arrival times, crowd-density concerns, venue
suitability, staffing requirements, and emergency response needs.
When outside event organizers manage ticketing or registration, UVU should consider requiring advance
and continuing access to ticketing or registration data. This may include projected attendance, total
registrations, ticket distribution, VIP or special-access lists, staff and volunteer lists, vendor lists, media
lists, waitlist information, and expected arrival patterns. Access to this information supports more
accurate planning and reduces uncertainty regarding crowd size, staffing, screening, credentialing, and
emergency operations.
Credentialing provides an additional layer of access control by allowing planners to distinguish between
public areas, restricted areas, controlled-access zones, VIP areas, media areas, technical areas, back-of-
house spaces, command posts, emergency operations areas, and other secure locations. A credentialing
plan should define who is authorized to access each area, how credentials will be issued and verified,
After-Action Report for Utah Valley University
144
what access levels are permitted, and how unauthorized access will be handled. Credentials may
include:
▪ Staff badges
▪ Contractor or vendor passes
▪ Media credentials
▪ Law enforcement or emergency responder credentials
▪ VIP or speaker access passes
▪ Volunteer credentials
▪ Digital tickets or passes
▪ Parking credentials
▪ Technical or production credentials
▪ Command post or operations credentials
Credentialing plans should identify access levels, credential design, issuing authority, verification
procedures, expiration times, replacement procedures, lost-credential protocols, and procedures for
revoking or denying access. For larger or elevated-risk events, planners should consider whether
credentials need to be color-coded, role-specific, date-specific, zone-specific, or integrated with
electronic access-control systems.
Access-control and credentialing personnel should receive clear instructions before the event. Written
post orders should identify the purpose of each access point, who is authorized to enter, what
credentials or tickets are valid, what exceptions apply, how issues should be escalated, and who has
authority to resolve disputes. Personnel should also be trained to recognize suspicious behavior,
fraudulent credentials, tailgating, unauthorized attempts to enter restricted areas, and conditions
requiring law enforcement support.
Event access-control plans should also address late gate opening, re-entry, and any circumstances in
which screening or ticketing operations may be modified. If screening, ticketing, or credential
verification is part of the security plan, those controls should not be discontinued simply to expedite
entry unless the change has been reviewed and approved through the event command structure. If
re-entry is restricted, exceptions should be defined in advance for medical, ADA-related, childcare,
operational, or emergency circumstances.
Because access control, screening, prohibited-items policies, firearms issues, bag restrictions, and
conditions of entry may raise legal considerations, UVU should coordinate with legal counsel when
developing event-specific access control and credentialing procedures for events held on public
University property.
D.4: Common Event Security Posts and Functions
Effective event security operations rely on clearly defined security posts, assigned responsibilities,
established reporting relationships, and coordinated communications. The specific number and type of
posts should be based on the event's risk profile, venue characteristics, attendance, threat environment,
and operational objectives.
After-Action Report for Utah Valley University
145
Supervisory Posts
Supervisors provide leadership, oversight, and operational coordination for designated areas of
responsibility. Supervisors monitor personnel performance, respond to incidents requiring additional
authority, coordinate resource deployment, and serve as the primary link between field personnel and
command staff. Common practice is to assign supervisors responsibility for defined geographic zones or
functional areas to ensure timely response and effective span of control.
Access Control and Screening Posts
Access-control personnel regulate entry into controlled or restricted areas and help ensure compliance
with event security procedures. Responsibilities may include validating tickets, credentials, badges, or
passes; monitoring entry points; enforcing access restrictions; screening for prohibited items; managing
attendee queues; and reporting suspicious behavior or security concerns. These posts often serve as the
first layer of event security and may incorporate personnel, technology, physical barriers, or screening
equipment depending on the event's risk profile.
Crowd Management Posts
Crowd-management personnel monitor attendee behavior, crowd density, and pedestrian movement
patterns. These personnel help facilitate orderly ingress and egress, identify congestion points, assist
with wayfinding, intervene in minor disturbances, and support emergency evacuation procedures when
necessary. Crowd management positions are particularly important in high-density areas, event
entrances and exits, gathering locations, and areas where protests or demonstrations may occur.
Stage and VIP Protection Posts
Stage and VIP protection personnel are responsible for protecting speakers, performers, executives,
dignitaries, and other protected individuals. These posts help maintain secure buffer zones, monitor
audience behavior near the stage, control access to restricted areas, coordinate with executive
protection personnel, and respond to disruptions or security concerns involving protected individuals.
Perimeter Security Posts
Perimeter security personnel monitor the boundaries of the event area and help prevent unauthorized
access. Depending on the venue, these posts may monitor fencing, barricades, gates, pedestrian access
points, parking areas, natural barriers, or designated protest areas. Perimeter personnel also help
identify vulnerabilities, detect suspicious activity, and provide early warning of emerging issues outside
the primary event footprint.
Roving Patrol Posts
Roving patrol personnel provide mobile security coverage throughout the event area. These personnel
may patrol on foot, bicycle, vehicle, or other authorized means and are often responsible for monitoring
conditions, identifying hazards, responding to minor incidents, and providing visible deterrence.
Roving personnel also support situational awareness by identifying developing issues before they
escalate into larger incidents.
After-Action Report for Utah Valley University
146
Parking and Traffic Posts
Parking and traffic personnel assist with vehicle access, pedestrian safety, traffic flow, emergency
vehicle routes, parking management, and ingress and egress operations. These positions help reduce
congestion, improve safety, and facilitate emergency response access when necessary.
Command Post Personnel
Command post personnel provide operational oversight, resource coordination, communications
support, intelligence sharing, and incident management functions. These personnel maintain situational
awareness, coordinate field resources, document significant activities, and support decision-making
throughout the event.
Emergency Response Teams
Emergency Response Teams (ERTs) provide surge capacity and rapid response capabilities for incidents
requiring additional personnel. These teams may respond to disturbances, medical emergencies, crowd-
control issues, evacuations, suspicious activity, or other security concerns requiring immediate
intervention. The use of designated response teams can improve operational flexibility and help event
organizers manage incidents without disrupting broader event operations.
Key Principles
Regardless of the specific security model employed, effective event security operations generally
incorporate three foundational principles:
▪ Clearly defined posts with assigned responsibilities and accountability.
▪ Appropriate supervisory oversight and span of control.
▪ Integration with the Incident Command System (ICS), Event Action Plan (EAP), and emergency
response procedures.
D.5 Protective Operations Considerations for Outdoor Events
This appendix provides operational considerations for outdoor events involving high-profile speakers,
controversial events, large crowds, or other circumstances that may require enhanced protective
planning. These details should be treated as sensitive security information and distributed only to
personnel with a need to know.
Pre-event planning should include a coordinated walk-through involving UVUPD, event organizers,
emergency management, local law enforcement partners, and any executive protection detail assigned
to the speaker or VIP. The walk-through should address:
▪ Arrival and departure points
▪ Line-of-sight concerns
▪ Elevated positions and rooftops
▪ Building, room, and window access
▪ Potential protester locations
▪ Security post locations
▪ External law enforcement support
After-Action Report for Utah Valley University
147
▪ Communications capabilities
▪ Emergency access and egress routes
▪ Protective movement routes
▪ Crowd placement and barriers
▪ Contingency plans for relocation, evacuation, lockdown, or shelter-in-place
When an outdoor event presents line-of-sight or elevated-position concerns, UVUPD should evaluate
whether the event can be moved indoors or whether the identified risks can be reasonably mitigated.
If the event remains outdoors, security planning should include control or monitoring of buildings,
rooftops, windows, stairways, ladders, parking structures, tree lines, and other areas that overlook the
event site. Where staffing is limited, UVU should consider physical screening, line-of-sight obstruction,
restricted access areas, or mutual aid support to reduce exposure.
Arrival and departure areas for speakers, VIPs, and other protectees should be planned to minimize
public visibility and unnecessary exposure. When appropriate, protective planning may include
controlled entry points, screened movement routes, vehicle placement, temporary barriers, canopies
or tents, parking structures, or other measures that reduce visibility and improve control of the area.
UVUPD should also consider whether staffing plans provide sufficient fixed-post coverage and mobile
response capacity. Fixed posts may be needed to control key access points, while mobile officers may be
needed to respond to incidents without leaving critical posts unattended. Staffing limitations should be
addressed through advance planning, mutual aid agreements, and coordination with nearby law
enforcement partners or university police agencies.
Training for UVUPD and partner agencies should address protective operations for high-profile outdoor
events, including line-of-sight assessment, elevated-position concerns, site control, access control,
coordination with executive protection details, communications, and event-specific response planning.
Joint training with local agencies and nearby university police departments would support a more
coordinated response during major events.
D.6: Traffic, Parking, and Perimeter Security Considerations
Traffic, parking, and perimeter security are important components of event security planning,
particularly for outdoor events, large gatherings, controversial speakers, and events involving elevated
security concerns. Effective planning helps facilitate safe movement of people and vehicles, maintain
emergency access, reduce congestion, establish event boundaries, and mitigate security risks associated
with unauthorized access or vehicle-related threats.
Traffic Management
Traffic management plans should address the movement of vehicles and pedestrians before, during,
and after an event. Planning considerations may include:
▪ Arrival and departure routes
▪ Traffic-control points
▪ Road closures and detours
▪ Shuttle operations
▪ Rideshare pick-up and drop-off locations
After-Action Report for Utah Valley University
148
▪ Accessible parking and ADA accommodations
▪ Loading and delivery access
▪ Emergency vehicle routes
▪ Post-event departure operations
▪ Coordination with local law enforcement, transportation agencies, parking vendors, and public
works departments may be necessary for larger events.
Parking Operations
Parking areas are often the first and last points of interaction attendees have with an event and should
be considered part of the overall security footprint. Parking plans may address:
▪ Parking-lot capacity and overflow procedures
▪ Alternate parking locations
▪ Pedestrian routes from parking areas to the venue
▪ Lighting and visibility
▪ Parking-lot patrols
▪ CCTV coverage
▪ Suspicious-activity reporting procedures
▪ Vehicle access controls
▪ Emergency response access
Depending on the event's risk profile, parking areas may warrant dedicated staffing, roving patrols,
temporary surveillance measures, or periodic security inspections.
Perimeter Security
Perimeter security measures establish the boundaries of the event and help control the movement of
attendees, staff, vendors, media personnel, and vehicles. The objective is to create a secure and
manageable environment while maintaining safe access and emergency egress. Perimeter security
measures may include:
▪ Temporary fencing
▪ Barricades
▪ Gates
▪ Designated entry and exit points
▪ Controlled-access zones
▪ Restricted areas
▪ Vehicle-control points
▪ Security staffing
▪ Signage and wayfinding
The level of perimeter security should be proportional to the event's risk profile, venue characteristics,
attendance, and threat environment.
Vehicle Mitigation and Protective Barriers
For outdoor events, planners may consider physical measures designed to reduce the risk of
unauthorized vehicle access or vehicle-related attacks. Depending on the venue and threat assessment,
these measures may include:
After-Action Report for Utah Valley University
149
▪ Bollards
▪ Planters
▪ Jersey barriers
▪ Water-filled barriers
▪ Vehicle barricades
▪ Temporary fencing systems
▪ Crash-rated gates
▪ Vehicle-control points
▪ Heavy vehicles positioned as protective barriers
When evaluating protective barriers, planners should consider vehicle approach routes, vehicle speed,
pedestrian density, emergency access requirements, and appropriate standoff distances from
attendees, structures, and critical infrastructure. The selection of barrier systems should balance
security requirements, operational needs, emergency access, aesthetics, and the overall attendee
experience.
Parking and Perimeter Patrols
Parking areas and perimeter zones should be incorporated into security patrol plans. Depending on the
size and nature of the event, patrol resources may include:
▪ Law enforcement personnel
▪ Security officers
▪ Roving foot patrols
▪ Bicycle patrols
▪ Vehicle patrols
▪ CCTV monitoring
▪ Drone or aerial observation resources where legally permissible
Patrol personnel can help identify suspicious activity, monitor crowd movement, detect perimeter
vulnerabilities, respond to incidents, and provide visible deterrence.
Signage and Wayfinding
Signage serves both operational and security functions. Effective signage helps reduce confusion,
improve crowd flow, communicate security procedures, and support emergency operations. Signage
considerations may include:
▪ Parking directions
▪ Shuttle locations
▪ Designated entrances and exits
▪ Accessible routes
▪ Emergency exits
▪ Restricted access areas
▪ Prohibited items notifications
▪ Screening requirements
▪ Emergency contact information
▪ Suspicious-activity reporting information
After-Action Report for Utah Valley University
150
Information should be communicated through multiple channels whenever practical, including websites,
social media, event communications, parking areas, transit points, pedestrian routes, and venue
entrances.
Key Planning Considerations
Traffic, parking, and perimeter planning efforts are most effective when they:
▪ Support safe and efficient movement of attendees.
▪ Maintain emergency vehicle access and operational flexibility.
▪ Integrate with event security, access control, and emergency-response plans.
▪ Provide clear communication and wayfinding.
▪ Establish reasonable protection against foreseeable risks.
▪ Balance security needs with the overall event experience.
D.7: Fixed and Temporary Site Security Measures
Fixed and temporary site security measures help define event boundaries, control movement, support
screening operations, protect pedestrian areas, reduce unauthorized access, and improve emergency
response coordination. These measures should be selected based on the event’s risk profile, venue
characteristics, anticipated attendance, crowd movement, traffic patterns, public visibility, threat
environment, and emergency response needs. Site security measures may include:
▪ Temporary fencing
▪ Gates
▪ Barricades
▪ Stanchions
▪ Concrete barriers
▪ Water-filled barriers
▪ Bollards
▪ Planters
▪ Vehicles used as protective barriers
▪ Signage
▪ Access-control points
▪ Screening areas
▪ Controlled delivery points
▪ Restricted access zones
▪ Vehicle-control points
▪ Lighting
▪ Cameras or temporary surveillance measures
For outdoor events, physical controls should help establish a clear and manageable event footprint.
These measures can direct attendees to approved entrances, separate pedestrians from vehicles,
protect screening areas, create buffer zones between the event site and adjacent roads, and help
personnel identify unauthorized access or perimeter breaches.
Temporary fencing and barricades should be used in a way that supports both security and life safety.
Barriers should not obstruct emergency exits, emergency vehicle access, evacuation routes, ADA-
After-Action Report for Utah Valley University
151
accessible paths, or responder staging areas. Any fencing or barricade plan should be reviewed for
crowd-flow, emergency egress, accessibility, and operational feasibility.
When roads remain open near an event site, planners should evaluate whether temporary barriers are
sufficient or whether additional measures are needed, such as law enforcement staffing, road closures,
traffic-control points, vehicle screening, or alternate pedestrian routing. If temporary barricades are
used to control roads or vehicle access points, they should be staffed, monitored, or otherwise
incorporated into the security plan.
Vehicle-related risk should also be considered for outdoor events, high-density pedestrian areas, and
venues adjacent to active roadways. Depending on the Security Assessment and venue configuration,
planners may consider bollards, planters, Jersey barriers, water-filled barriers, concrete barriers, gates,
vehicle-control points, or strategically positioned heavy vehicles. Barrier selection should account for
vehicle approach routes, potential vehicle speed, pedestrian density, standoff distance, emergency
access, aesthetics, and the overall attendee experience.
Physical controls should be coordinated with access control, screening, traffic, parking, communications,
and emergency response plans. For example, a fencing plan should align with designated entry points,
screening queues, credentialing locations, emergency exits, command post access, delivery routes, and
responder access points. Similarly, vehicle barriers should be placed in a way that protects attendees
while preserving the ability of emergency vehicles to reach the venue.
Site security measures should also account for vendors, deliveries, staff, event participants, media, VIPs,
emergency responders, and people requiring ADA-related accommodations. Designated entry points,
delivery checkpoints, staff lanes, equipment routes, and accessible paths should be identified in advance
and communicated to personnel responsible for access control.
Temporary measures should be inspected before, during, and after the event. Personnel should check
for gaps, damaged barriers, unsecured gates, blocked exits, unstaffed access points, unauthorized
movement through restricted areas, and changes in crowd behavior or traffic patterns that require
adjustments. Any changes to the site-security layout during an event should be communicated through
the event command structure.
D.8: Announcements and Scripted Response Protocol Messages
HOLD
PA, phone, text, email, signage, and voicemail: HOLD, HOLD, HOLD! THIS IS NOT A TEST! We are
responding to a report of (problem) at (location). Calmly and quickly clear the hallways and remain in
your current room, office, classroom, or general area. Continue normal activity unless otherwise
directed. Remain in your location until given the ALL CLEAR. Watch for additional information and
updates. (Send message three times, two minutes apart.)
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two
minutes apart.)
After-Action Report for Utah Valley University
152
LOCKDOWN
PA, phone, text, email, signage, and voicemail: LOCKDOWN, LOCKDOWN, LOCKDOWN! THIS IS NOT A
TEST! We are responding to a report of (problem) at (location). The facility will be in LOCKDOWN. Calmly
and quickly move to the nearest Safe Room,64 lock the door, and remain there until given the ALL CLEAR.
Watch for additional information and updates. (Send message three times, two minutes apart.)
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two
minutes apart.)
EVACUATE
PA, phone, text, email, signage, and voicemail: EVACUATE, EVACUATE, EVACUATE! THIS IS NOT A TEST!
Calmly and quickly EVACUATE the building using all available exits. Move away from the building to your
designated Assembly Area and remain there until given the ALL CLEAR. Watch for additional information
and updates. (Send message three times, two minutes apart.)
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two
minutes apart.)
SECURE65
PA, phone, text, email, signage, and voicemail: SECURE, SECURE, SECURE! THIS IS NOT A TEST! We are
responding to a report of (problem) at (location). Calmly and quickly SECURE inside the building using all
available entrances. Move to the nearest Safe Room and lock the door. Remain there until given the ALL
CLEAR. Watch for additional information and updates. (Send message three times, two minutes apart.)
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two
minutes apart.)
SHELTER
PA, phone, text, email, signage, and voicemail: SHELTER, SHELTER, SHELTER! THIS IS NOT A TEST! We are
responding to a report of (problem) at (location). Please SHELTER and take precautions until given the
ALL CLEAR. Watch for additional information and updates. (Send message three times, two minutes
apart.)
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two
minutes apart.)
64 A safe room refers to a designated place of refuge that offers enhanced security during an armed-intruder event; where
storm protection is intended, FEMA defines a safe room as a hardened structure designed to meet FEMA criteria and
provide near-absolute protection during extreme wind events.
65 Secure is the rapid and safe movement of people from outdoor areas into a facility or other safer indoor location when the
source of danger is outside. FEMA states that Secure (also known as Reverse Evacuation) is used “to rapidly and safely move
people inside a facility when it would be dangerous to remain outside,” such as when people are on playgrounds, sports
fields, or at an outdoor event and the danger is outside.
After-Action Report for Utah Valley University
153
ACTIVE ASSAILANT
PA, phone, text, email, signage, and voicemail: ACTIVE ASSAILANT, ACTIVE ASSAILANT, ACTIVE
ASSAILANT! THIS IS NOT A TEST! A subject with a weapon is in the building. Calmly and quickly move to
the nearest Safe Room, lock the door, and remain there until given the ALL CLEAR. If you are not in the
building, stay away and wait for the ALL CLEAR notification. Watch for additional information and
updates. (Send message three times, two minutes apart.)
PA, phone, text, email, signage, and voicemail: ALL CLEAR, ALL CLEAR, ALL CLEAR. The incident at
(location) has been resolved and it is safe to return to normal activity. (Send message three times, two
minutes apart.)
D.9: Physical Security Technology Technical Considerations
This appendix provides additional technical context regarding physical security technologies referenced
in Section 5.2. These considerations are intended to support future planning, budgeting, system
evaluation, and implementation decisions.
Integrated Security Management
A mature campus security technology environment may integrate access control, video surveillance,
intrusion detection, panic alarms, lockdown capabilities, public address systems, mapping, and mass
notification tools. Integration can allow defined events, such as a forced door, panic alarm, duress
activation, or intrusion alarm, to trigger associated video, location information, maps, automated alerts,
and response workflows.
An integrated or unified platform can help Dispatch and command personnel view relevant alarm and
video information through a common graphical user interface. This can reduce the need to monitor
multiple disconnected systems and improve response coordination.
Access Control System Considerations
UVU uses an industry-recognized access-control system. Future access-control planning may include:
▪ Enterprise-wide credential audits
▪ Deactivation of expired or unauthorized badges
▪ Role-based access by building, room, day, time, and operational need
▪ Defined approval authority for card issuance and access levels
▪ Oversight by Human Resources, student records, or other authoritative systems
▪ Integration with student records, employment records, contractor records, or visitor-management
systems where feasible
▪ Automated updates or deactivation when student, employee, contractor, or visitor status changes
▪ Cardholder image capture and verification at selected critical access points
▪ Evaluation of whether select access points should remain controlled 24 hours a day
▪ Use of visible visitor or contractor badges where appropriate
▪ Evaluation of turnstiles or other access-control measures for selected high-control areas
After-Action Report for Utah Valley University
154
Any consideration of biometric authentication, facial recognition, or advanced identity verification
should include legal review, privacy review, accessibility considerations, cybersecurity evaluation, data
governance, retention policies, and community impact considerations.
Access Control and Video Integration
Integration between the access-control system and video management system can allow alarms, door-
forced events, door-held-open events, or access-denied events to call up associated video. This can help
Dispatch or authorized personnel confirm what occurred, identify who was present, and determine what
response is needed.
If UVU retains separate access-control and video platforms, integration between those systems may be
pursued through available manufacturer tools or application programming interfaces. If UVU evaluates
replacement platforms in the future, unified systems may be considered as part of a broader technology
roadmap. Any vendor-specific decision should be based on operational requirements, lifecycle cost,
cybersecurity, integration capability, maintenance burden, training needs, procurement requirements,
and long-term support.
Video Surveillance Coverage and Modernization
Information provided during the review indicated that camera coverage does not extend to all interior
and exterior campus areas. Future expansion should be guided by risk and operational need, including:
▪ Building entrances and exits
▪ Major pedestrian pathways
▪ Event venues and outdoor gathering areas
▪ Parking areas and vehicle access points
▪ Elevated areas, rooftops, balconies, and terraces
▪ Public-facing service areas
▪ Emergency routes and staging areas
▪ Areas with prior incidents or recurring security concerns
A camera standard for new installations can simplify maintenance and improve system performance.
Standards may address manufacturer compatibility, camera type, resolution, low-light capability, field of
view, on-board analytics, cybersecurity, environmental rating, retention needs, and compatibility with
the video management system.
Video Analytics
Selected video analytics may support security operations when properly configured, tested, and
monitored. Potential analytics include:
▪ Perimeter or virtual-fence detection
▪ License plate recognition in vehicle areas
▪ Restricted-area or rooftop intrusion detection
▪ Object-left-behind detection
▪ Anti-tailgating detection
▪ Fall detection
▪ Occupancy or crowd-density detection
▪ Traffic-flow or pedestrian-flow monitoring
After-Action Report for Utah Valley University
155
▪ Wrong-way movement detection
▪ Speed monitoring
▪ Loitering detection
▪ Crowd detection thresholds
▪ Weapons-detection analytics where legally permissible, operationally justified, and actively
monitored
Analytics should be evaluated based on reliability, false alarm rates, privacy impact, legal requirements,
monitoring capacity, integration with response workflows, and usefulness to Dispatch or command
personnel.
Video Storage, Retention, and Resilience
Video surveillance planning should account for server capacity, storage needs, retention periods, system
performance, and resilience. Potential considerations include:
▪ Replacement planning for aging cameras and servers.
▪ Storage expansion to support added cameras or higher-resolution video.
▪ Retention policies aligned with operational, investigative, legal, and privacy requirements.
▪ Off-site or cloud-based backup where appropriate.
▪ Protection against natural disasters, theft, cybersecurity incidents, and site-specific system failures.
Dispatch Monitoring and Event Views
For large campus events, programmed camera views can help Dispatch and command personnel
monitor priority areas. These may include:
▪ Event site overview
▪ Speaker or stage area
▪ Crowd entry and exit points
▪ Protest areas
▪ Rooftops and elevated positions
▪ Parking areas and vehicle routes
▪ Emergency response routes
▪ Command post access points
▪ Restricted areas
▪ Building entrances near the event
Event Action Plans should identify who will monitor these feeds, how observations will be
communicated, what conditions require escalation, and how video will be preserved during or after
an incident.
Panic Alarms, Duress Devices, and Emergency Call Points
Panic alarms, duress devices, and emergency call points may be considered for selected locations
based on risk and operational need. Potential locations include:
▪ Public-facing administrative offices
▪ People and Culture or Human Resources offices
▪ Student Life and student service areas
After-Action Report for Utah Valley University
156
▪ Event venues
▪ Cash-handling locations
▪ Isolated exterior locations
▪ Parking areas
▪ Areas with recurring conflicts or safety concerns
These systems should include clear location information, Dispatch monitoring, defined response
procedures, regular testing, user training, and integration with video where feasible.
Emergency Call Boxes
Exterior emergency call boxes may be considered in selected areas where direct emergency
communication is needed. Common features include visible blue lights, emergency call buttons, direct
connection to Dispatch, and associated camera coverage where feasible. Placement decisions should
be based on lighting, pedestrian routes, parking areas, isolated locations, call volume, mobile-phone
coverage, accessibility, maintenance, and integration with Dispatch response procedures.
Aerial Observation and Partner Agency Support
Drone or aerial observation capabilities may support situational awareness during large outdoor events,
demonstrations, searches, or major incidents when legally permissible and operationally appropriate. If
UVU does not maintain this capability internally, mutual aid agreements or interagency procedures may
identify partner agencies that can provide aerial observation support.
Planning considerations include legal authority, privacy, flight restrictions, operator certification, request
procedures, command integration, video sharing, evidence preservation, and public communications.
D.10: Post-Event Review Considerations
Post-event review is an important component of continuous improvement. Following significant events,
elevated-risk events, incidents, or events involving unusual operational challenges, UVU should conduct
a structured review to identify lessons learned, evaluate operational effectiveness, document
challenges, and capture opportunities to improve future planning.
Post-event reviews may range from a brief hotwash to a formal after-action review, depending on the
event’s size, complexity, risk profile, and whether incidents occurred. Reviews should be conducted
soon enough after the event that participants can provide accurate observations, but with enough
structure to ensure the review is useful, documented, and tied to corrective action.
A post-event review may examine:
▪ Pre-event planning and coordination
▪ Risk assessment and intelligence information
▪ Venue selection and site layout
▪ Access control, ticketing, credentialing, and screening
▪ Staffing levels and post assignments
▪ Supervisory structure and span of control
▪ Command structure and decision-making
After-Action Report for Utah Valley University
157
▪ Communications among event personnel, UVUPD, university leadership, and external responders
▪ Emergency notification and public messaging
▪ Crowd management and attendee behavior
▪ Protest activity or counter-event activity
▪ Traffic, parking, shuttle, and rideshare operations
▪ Emergency vehicle access
▪ Perimeter security and barrier placement
▪ Medical response
▪ Fire, EMS, and law enforcement coordination
▪ Vendor, media, VIP, and delivery access
▪ ADA-related accommodations
▪ Incident documentation
▪ Technology performance
▪ Public feedback, student feedback, and stakeholder concerns
▪ Post-event departure and site closure
Reviews should include the personnel and stakeholders most directly involved in planning and
operations. Depending on the event, participants may include UVUPD, emergency management, event
organizers, facilities, communications personnel, legal counsel, student affairs, parking and
transportation, local law enforcement, fire, EMS, contracted security, venue staff, and representatives
from the sponsoring organization. The review should distinguish between:
▪ What was planned
▪ What actually occurred
▪ What worked well
▪ What created challenges
▪ What should be changed before future events
The process should include both operational observations and attendee-facing issues, such as confusion
about entry points, prohibited items, emergency messaging, parking, crowd movement, or event
closure.
When incidents or significant disruptions occur, UVU should preserve relevant records before they are
overwritten, deleted, or dispersed. Records may include event plans, staffing rosters, post orders, radio
audio and logs, Dispatch records, emergency messages, surveillance video, photographs, incident
reports, ticketing data, credentialing records, public communications, social media monitoring
summaries, and correspondence with external partners.
Post-event reviews should result in documented corrective actions. Corrective actions should identify
the issue, recommended improvement, responsible owner, priority level, target completion date,
resource needs, and follow-up process. Items that require policy changes, training, technology
investment, mutual aid coordination, legal review, or budget approval should be tracked until resolved.
For recurring events or future events involving similar risks, lessons learned should be incorporated into
event templates, planning checklists, training materials, post orders, emergency message templates,
access-control plans, and tabletop exercises. This helps ensure that lessons are institutionalized and not
dependent on individual memory or informal knowledge.