Author: Jim Townzen, PSP, CPP, CSC

It is a familiar situation for many security consultants. The project is already well into Construction Documents. The floor plans are established, Mechanical, Electrical, Plumbing (MEP) coordination is underway, and door hardware is being finalized. Then someone asks a simple question: “Has security reviewed this?”
The owner’s security or risk management team brings in a security consultant, and suddenly the design team is working through requirements that should have influenced the building design months earlier. A card reader needs to be added to a door that was never intended to be controlled. The lobby needs visitor screening, but there is no space for queuing or equipment. A sallyport needs to function differently. Security equipment needs dedicated space, or public and secure circulation paths overlap.
The team usually finds a solution, but the solution often costs more, requires redesign, affects other disciplines, and compromises some of the original design intent. The problem is rarely the security design itself. The problem is when security entered the project. Security consultants should be part of Programming, alongside civil, structural, MEP, and other core disciplines.
Security Starts with the Program
Programming establishes what the building needs to do before the team determines exactly what the building will look like. This is where one establishes space requirements, adjacencies, circulation, occupancy, operational relationships, and net-to-gross ratios, all important planning considerations for architects as they determine how much space the building needs and how those spaces should function together.
Security requirements belong in the same conversation. During Programming, the team should already understand how employees, visitors, vendors, and deliveries will enter and move through the facility. The team should identify where public access ends, which areas require controlled access, whether the lobby requires reception or security screening, and whether the facility needs a security operations center, secure vestibule, sallyport, or other controlled transition area.
These decisions affect space, circulation, adjacencies, infrastructure, and operations. They are programming decisions long before they become security drawings. This is where the Basis of Design (BOD) is typically developed. The BOD becomes the bridge between programming and design. It documents the rationale, assumptions, operational concepts, and performance requirements that architects, engineers, and security consultants use to develop the actual design.
Leaving security out of the Program of Requirements does not eliminate those requirements. More often, they return later as RFIs, bulletins, redesign, change orders, or compromises.
Space Planning Locks Up Earlier Than Many People Think
By the end of Schematic Design, many major decisions are already taking shape. The floor plate is established, structural grids are developing, vertical circulation is located, major mechanical and electrical spaces are identified, and public and private circulation patterns are becoming defined.
Many security requirements depend on those same decisions. A security operations center requires dedicated space and appropriate adjacencies. A screening operation needs enough room for equipment, personnel, and queuing without interfering with normal circulation. Access control systems need infrastructure and equipment locations. Public and secure zones need logical separation, and visitor processing needs to occur somewhere that supports both security and the normal operation of the building.
These are architectural planning issues, not simply decisions about where to place security devices. When security enters during Schematic Design, the architect may already be trying to find space that was never included in the program. By Design Development, the available options become more limited. By Construction Documents, much of the plan is effectively fixed, and security becomes a negotiation over what will fit rather than an opportunity to help shape the building.
The Cost of Change Increases With Every Phase
A security requirement identified during Programming might require little more than adjusting an adjacency or allocating space before the first floor plan is developed.
Find the same requirement during Design Development, and the team might need to relocate walls, resize electrical rooms, revise door hardware, or reroute pathways. Find it during Construction Documents, and the result might include revised drawings, consultant fee amendments, bulletins, additional coordination, and schedule impacts. Find it during construction, and the project might face rework, change orders, and delays.
Security also intersects with nearly every major design discipline. Access control affects electrical systems, door hardware, life safety, fire alarm interfaces, and egress. Ballistic or forced-entry protection affects architecture and in most cases structural design. Vehicle mitigation affects civil design, site circulation, landscape architecture, and utilities. Video surveillance affects lighting, ceilings, pathways, network infrastructure, and architectural sightlines. The later these requirements enter the project, the more difficult and expensive coordination becomes.
Good Security Should Look Like Part of the Architecture
Some of the strongest security measures do not immediately look like security systems. They appear as good site planning, clear sightlines, logical circulation, appropriate separation between public and restricted areas, controlled approaches to entrances, thoughtful landscape design, and well-designed transitions between security zones. Crime Prevention through Environmental Design (CPTED) principles work best when they influence the concept from the beginning rather than being applied after the concept is complete.
When the security consultant participates during Programming, security becomes one of the inputs shaping the building. When the consultant joins during Design Development or Construction Documents, the available options often shrink to cameras, card readers, electronic locks, bollards, signage, and other measures placed onto an already developed design. Those components serve important purposes, but a collection of security devices does not replace an integrated security strategy.
Early Security Coordination Also Reduces Code Conflicts
Security requirements frequently intersect with life safety and accessibility. A controlled door still has to meet egress requirements. A secure vestibule must maintain required clearances. Certain locking arrangements require coordination with fire alarm and life-safety systems. Security barriers must maintain accessible routes, and screening operations must account for required exit capacity. None of these issues are unusual or particularly difficult when the team identifies them early and coordinates them with the other disciplines. They become much harder when they surface after the architecture, door hardware, life-safety strategy, and MEP systems have already been developed or reviewed.
Early involvement gives the team time to resolve security, accessibility, and life-safety requirements together instead of forcing one discipline to work around decisions already made by another.
Security Is a Performance Requirement
One would not wait until Construction Documents to determine structural loading, complete the floor plan before deciding whether the building needs major mechanical spaces, or treat accessibility as something to add after the architecture is finished.
Security deserves the same planning discipline.
This does not mean the security consultant needs to design every camera, card reader, or intrusion detection point during Programming. The purpose at this stage is to establish the security requirements that affect the architecture, site, circulation, infrastructure, and operations. These requirements then follow the project through each design phase with increasing levels of detail.
Programming establishes the security strategy and major requirements. Schematic Design incorporates those requirements into the concept. Design Development develops and coordinates the systems with the other disciplines. Construction Documents provide the detailed requirements needed for bidding and construction.
That sequence produces a much different result than introducing security after the major architectural decisions have already been made. If the goal is to have security integrated into the architecture rather than applied to a finished design, security consultant selection should begin before Programming.
By the time a project reaches Design Development or Construction Documents, many of its most important security decisions have already been made, whether a security professional participated in those decisions or not.
Conclusion
Bringing a security consultant into Programming does not mean designing the security system earlier. It means identifying security requirements early enough for the entire design team to respond to them while critical decisions are still flexible.
The process should begin with a security programming discussion involving the owner, architect, security consultant, and key operational stakeholders to define security objectives, operational needs, risks, and regulatory considerations. From that effort, the security consultant develops programming requirements that address items such as access control strategies, security zoning, operational spaces, perimeter considerations, infrastructure needs, and future system requirements. The goal is not to select security technology, but to provide the design team with the information needed to allocate space, establish adjacencies, plan circulation, and budget appropriately.
When security requirements are established during Programming, integrated during Schematic Design, coordinated during Design Development, and documented during Construction Documents, the project experiences fewer late-stage changes, better coordination across disciplines, and a more effective balance between security, operations, and design. Security will influence the project at some point; the advantage of engaging a security consultant early is that those influences shape the design rather than forcing costly modifications after key decisions have already been made.