One schedule gets published. A different one runs the day.

Scheduling is decided once, in advance. Dispatch is decided all day, at the post. What that distance costs a 24/7 security operation, and what is still yours to decide about it.

WX
WorkAxle
Security operations
TL;DR

In a 24/7 security operation, scheduling and dispatch are two different jobs. Scheduling is decided once, in advance, against forecast demand. Dispatch is decided all day, at the post, by whoever is closest to the problem, and it is constrained first by who is cleared for that post rather than by who is free. When the system only records the shift after it ends, those decisions get reassembled the next morning out of radio calls, a spreadsheet and somebody's memory, and that reassembly is where unbillable overtime, late-surfacing break violations and grievances come from. An operational cockpit closes the distance by making the dispatch board the input rather than the report: the move writes the time segment, eligibility is filtered by certificate, the rule a decision crosses is named while the shift is running, and every override carries an account and a timestamp. Four questions separate the two kinds of system, and they work on any vendor.

In a 24/7 security operation, the schedule you published is a forecast. Somewhere in the first shift it stops describing the day that is actually happening.

Somebody called in sick at five. A line opened on short notice. Weather moved a bank of flights and an officer ended up somewhere nobody planned for.

None of that is a planning failure. It is the job.

The question worth twenty minutes is smaller and harder than how to plan better. When that decision gets made at the post, at four in the morning, by a supervisor with a radio, where does it get written down?

In this post:

  • Workforce scheduling and dispatch are not the same job
  • Who can move is settled before where they move
  • Then the decision has to become a timecard
  • The schedule nobody publishes
  • And the rules underneath it move too
  • What an operational cockpit actually means
  • Four questions to ask every vendor at GSX

Workforce scheduling and dispatch are not the same job

A large screening or guarding operation does not build a roster by guessing. It builds against real demand: volume by terminal, by checkpoint, by line, a whole season ahead. Coverage gets planned at the level the work happens rather than at the level the company is organised.

That is scheduling. It is a plan-time activity, and it can be excellent.

Dispatch is what happens to the plan. It is a decision-time activity, taken under time pressure, on incomplete information, by the person standing closest to the problem. It has a different unit of work, a different clock, and different constraints.

Most workforce platforms were built for the first job. They get asked to do the second one anyway.

SchedulingDispatch
When it is decidedWeeks ahead, against forecast demandDuring the shift, at the post
Who decidesA planner looking at the whole operationWhoever is standing closest to the problem
The binding constraintHours, cost and agreement limitsWho is cleared for that post
How long there is to decideDaysMinutes
What a mistake costsA worse plan next weekAn uncovered post, or a grievance

Who can move is settled before where they move

This is the constraint that makes security different from almost every other workforce problem.

Moving a person is not a staffing decision. It is a compliance decision taken in under two minutes. Not every officer is cleared for every post: licence class, site-specific training, government clearance, armed or unarmed. The set of people you are allowed to move is smaller than the set of people who are free, and it is smaller in a different way at every post.

So "who is available" is the wrong question. "Who is available and cleared for this post, right now" is the only safe one.

On a phone, with a post uncovered and a supervisor waiting, it is also the easiest thing in the operation to get wrong by hand.

Then the decision has to become a timecard

An officer starts the day on a screening lane and moves to a perimeter post after lunch. Three things moved with them, and they are not the same thing.

The location moved. The pay conditions moved. The compliance clock moved. All of it at two in the afternoon, not at the end of the shift.

If the system stores a shift as one indivisible block, that move becomes a manual correction somewhere downstream. Somebody rebuilds the timecard later and hopes the premium math survives payroll.

That correction is where the margin goes. Hours nobody could bill. Premiums found after the fact instead of decided in the moment. Days of back-office work every pay period spent making the record agree with the day.

The same twelve-hour tour, stored as one shift and stored as segments One officer works from six in the morning to six in the evening and changes post at two in the afternoon. Stored as a single indivisible shift, the record holds one location and one rate for the whole tour, so the change at two has nowhere to live and the timecard is corrected by hand afterwards. Stored as time-stamped segments, the tour is two pieces split at two in the afternoon: a screening lane segment and a perimeter post segment, each carrying its own location, role and pay conditions on the minutes actually worked. One officer, one tour, changing post at 2pm 6am81012246pm Stored as one shift One shift, one location, one rate The 2pm change leaves no trace here. Somebody rebuilds the timecard afterwards. Stored as time-stamped segments Screening lane Perimeter post Each segment carries its own location, role and pay conditions on the minutes worked. post change

The same tour, twice. Nothing about the officer's day changed between the two rows. What changed is whether the system had anywhere to put the moment the day moved.

The schedule nobody publishes

Which is how an operation ends up carrying two.

There is the published schedule. And there is the real one, the one living in a radio call, a note, a spreadsheet on a supervisor's laptop and somebody's memory. Both are honest records of something. Only one of them is what happened, and it is not the one that went out on Monday.

Nobody chose that. It is what a 24/7 operation does when the tool it was given is built to record the shift after the shift is over.

The cost is latency. A break window closes and nobody notices until the next morning, and by then it is not a missed break, it is a grievance under a collective agreement. A replacement covers a post and the proof that they were cleared for it arrives after they have already stood on it.

The visible cost is the incident. The invisible cost is the reconciliation, and the reconciliation happens every single pay period.

Two routes from the same decision to the record of it When the dispatch board is not the system of record, a decision made at the post travels through a radio call, a note and a spreadsheet, then through somebody's memory, and only becomes a timecard when it is rebuilt the next morning, so the record arrives a pay period late. When the board is the input, the same decision writes the segment, the timecard and the audit trail in one action, and the record arrives at the moment the decision is made. When the board is not the system of record Decision made at the post A radio call, a note, a spreadsheet Somebody’s memory Timecard rebuilt the next morning The record lands a pay period after the decision. When the board is the input Decision made on the board The segment, the timecard and the audit trail, written by that same action The record lands at the moment the decision is made.

Both routes start with the same call by the same supervisor. The difference is how many hands the record passes through before anyone can act on it, and how late it arrives.

And the rules underneath it move too

Then an agreement gets renegotiated and an overtime threshold moves.

On a legacy platform that is a change request and a wait. Until it lands, schedulers work around a rule the system still enforces the old way, which means the workaround is now undocumented as well.

This is where better scheduling stops being the answer. The rate in the contract is fixed until renewal. You cannot roster your way out of a threshold that changed on Tuesday.

What is still yours to decide is how the rules are held, and how fast the people making decisions find out what the rules now say.

What an operational cockpit actually means

Four things separate a system that runs the operation from one that records it.

  1. It models the operation, not the org chart. A dispatcher does not think in departments. They think in posts, lines, lobbies and perimeters. When the structure on the screen reads airport, terminal, checkpoint, line, nobody has to translate an operational decision into HR language before they can act on it.
  2. It treats a shift as a container, not an atom. Move an officer between posts and the time segment writes itself, carrying the new location, the new role and the pay conditions that apply there, on the minutes actually worked.
  3. It is where dispatchers act, not where they look. Most real-time dashboards are windows. They show what somebody typed into a back office an hour ago. When the board is the input, the schedule update, the time entry and the audit trail come out of the action instead of being entered a second time afterwards.
  4. It computes compliance now, not tomorrow. Eligibility is filtered by certificate, so whoever you move is qualified to stand there. Break status is a colour on a card while the shift is still running rather than a report on Thursday.

None of that means the system stops you. It flags the rule, names the threshold that was crossed, and a human decides. The override is logged with the account that made it and the time it was made.

We built it that way on purpose. A system that hard-stops a supervisor in the middle of a shift is a system a supervisor learns to work around, and then you have lost the decision and the record of it.

Read those four back and the first two are where most platforms stop, because both are data-model decisions taken years before anyone drew a dispatch screen. That is the part that has to be built from the bottom. WorkAxle sits between the HR system and the payroll run, which is where scheduling, time capture and the compliance rules all live in one engine. Collective agreements, jurisdictional rules and client-specific post requirements run as configuration rather than as exceptions somebody has to remember to apply. Rules are effective-dated to the day the contract changes, and after onboarding a customer's own team maintains them. It is running now in airport screening operations, across multiple collective agreements.

Four questions to ask every vendor at GSX

Including us. If a vendor cannot answer these standing in their own booth, you have learned something worth the walk.

  1. An officer changes post mid-shift. Does the pay follow the minutes?
  2. It is four in the morning. Does it show who is cleared, or only who is free?
  3. The agreement changes. Do you edit the rule, or open a ticket?
  4. A decision crosses a rule. Does it name the rule, and record who decided?

Close those four and the week changes shape. The reconciliation does not happen, because there is nothing left to reconcile. The premium already landed on the right minutes. Every override already carries a name and a reason. When a client or an auditor asks how coverage held last month, you are not building the answer under pressure. You are opening it.

A plan is decided once. An operation is decided all day. What you actually get to choose is whether those decisions are written where they happen, or reassembled on Monday out of what people remember.

Beyond the Schedule, Monday at two

On Monday, September 14 at 2:00 PM, Mat Diab sits down with Youssouf Camara, VP of IT Solutions at GardaWorld, on the X Stage at GSX 2026 in Atlanta. Twenty minutes, on the exhibit floor, no slides to speak of.

Youssouf leads technology for large-scale regulated aviation security operations. He is going to walk through a day of it, and what he went looking for when he went looking for a system to run it.

Then bring us the shift that went wrong. Booth 4218, all three days.

Frequently asked.

What is the difference between workforce scheduling and dispatch?

Scheduling is a plan-time activity. A roster is built in advance against forecast demand, at the level the work happens: site, building, post, line. Dispatch is a decision-time activity. It is what happens to that plan during the shift when somebody is absent, when volume moves, or when a post has to be re-covered, and it is decided by whoever is closest to the problem. The two carry different constraints. Scheduling is optimised against demand and cost. Dispatch is constrained first by eligibility, because in a security operation not every officer is cleared for every post, so who you are allowed to move is a smaller set than who is free. Most workforce management platforms were built for scheduling and are asked to carry dispatch as well.

What is an operational cockpit in security operations?

An operational cockpit is a live view of the workforce, the locations and the operational reality that a dispatcher acts on directly, rather than a report that describes the shift after it ends. Four things separate it from a digitised schedule. It models the operation rather than the org chart, so the structure on screen reads site, building, post and line. It treats a shift as a container of time-stamped segments rather than one indivisible block, so a mid-shift move carries its own location, role and pay conditions. It is the input surface, so the schedule update, the time entry and the audit trail are produced by the dispatcher's action instead of being entered a second time afterwards. And it computes compliance during the shift, so eligibility is filtered by certificate and break status is visible on the board while there is still time to act on it.

Why does a mid-shift post change turn into a payroll problem?

Because three things change at once and none of them is the shift. When an officer moves from one post to another mid-shift, the location changes, the pay conditions change, and the compliance clock changes, and all of it happens at the moment of the move rather than at the end of the shift. A system that stores a shift as a single indivisible block has nowhere to put that, so the change becomes a manual timecard correction made later by somebody reconstructing the day. That correction is where unbillable hours and after-the-fact premiums come from. A system that stores a shift as time-stamped segments writes the new location, role and pay conditions onto the minutes actually worked at the moment the move happens.

How should a security operation handle a collective agreement change in its workforce system?

Hold the rule as configuration with an effective date rather than as code. When a collective agreement moves an overtime threshold, the change has a date on which it starts applying, and it usually applies to one work unit rather than to the whole operation. On a platform where labour rules live in a rule engine that the customer's own team maintains, the rule is updated the day the agreement changes and the new threshold applies from that date forward. On a platform where the rule is code, the change is a request to the vendor and a wait, and during the wait schedulers work around a rule the system still enforces the old way, which leaves the workaround undocumented.

What should you ask a workforce management vendor at a trade show?

Four questions separate a system that runs the operation from one that records it, and they are quick enough to ask standing in a booth. An officer changes post mid-shift, does the pay follow the minutes? It is four in the morning, does it show who is cleared, or only who is free? The agreement changes, do you edit the rule, or open a ticket? A decision crosses a rule, does it name the rule, and record who decided? Ask for a live screen rather than a slide on each one.

What software handles workforce scheduling and dispatch for a security operation?

WorkAxle is an enterprise workforce management platform built for organisations running multi-jurisdiction, multi-union workforces, including contract security and aviation screening. It sits between the HR system and the payroll run, so scheduling, time capture and the compliance rules are in one engine. Collective agreements, jurisdictional rules and client-specific post requirements run as configuration rather than as exceptions somebody has to remember to apply, and rules are effective-dated so a change takes effect on the date the contract changes. Assignment eligibility is filtered on role, skills and certifications. Moving an officer between posts writes the time segment with the new location, role and pay conditions. When an assignment crosses a rule the engine names the rule and the threshold it crossed, a scheduler decides, and the override is logged with the account that made it and the time.

WX
WorkAxle Security operations

WorkAxle builds workforce management software for organisations running multi-jurisdiction, multi-union workforces, including contract security and aviation screening. Scheduling, time capture and the compliance rules run on one engine that the customer's own team maintains.

Security & guarding on WorkAxle

Get workforce management insights delivered.

One post every two weeks. Long-form analysis from the team that runs the platform. Written for operators, not for the marketing pipeline.

The Compliance Rule Engine page.

How labour rules, collective agreements and client-specific post requirements run as effective-dated configuration that your own team maintains.

Score your own operation.

Ten questions on the four principles above. You get your band and the gap to close first. Nobody likes their number the first time.

Bring us the shift that went wrong.

The post that went uncovered last week, the agreement conflict that keeps surfacing, the mid-shift swap that broke a timecard. We will run it on screen.