Engineering overview

How Genetec’s Unified Architecture Changes Post-Incident Video Investigations

The most common request to a video surveillance team sounds something like this: “Give me the footage from camera 17 between 2:32 and 2:37 p.m.”

The problem with this request is that, by the time it is made, neither the camera number nor the exact time is usually known.

First, you need to establish what happened, where it happened, and when. A traditional VMS does not do that part of the work: it is good at storing and retrieving video, but reconstructing the event is still up to the investigator.

The previous article in this series looked at how a unified architecture eliminates the need for operators to piece together context manually during an event. The logical next question is a far more interesting one:

What happens to that context after the event is over?

What an Event Actually Leaves Behind

Consider a routine scenario: a vehicle enters the site, and twenty minutes later, someone needs to know who it was.

An event always leaves multiple traces: a recognized license plate, an access point event, the owner’s identifier, the barrier status, a location on the map, and video from the associated camera. The question is not whether these traces exist—they do in any properly designed system. The question is where they reside and how they are connected.

When subsystems operate independently, these traces end up in different databases, with different timestamps and different interfaces. It is up to the investigator to correlate them.

In Security Center, these data are part of a shared model of entities and events and can be linked by time, location, and entity. The impact on an investigation is direct: instead of asking, “Find the video from camera X,” the request becomes, “Show me what was happening around this event.”

Security Center hybrid report view: an event list displayed alongside the relevant video
Figure 1. Dynamic reporting: cross-referencing alarms, events, and archived video – a hybrid report view where the event list is displayed alongside the relevant video.

The clearest example is the one that opened this series. When a license plate is used as an access credential, a vehicle entry is no longer just an ALPR event. It becomes an access control record, with the associated reporting for both the user and the access point.

The ability to open a barrier using a license plate is not unusual in itself—many systems can do that. The more interesting question is what that event will look like in the system two weeks later, when someone needs to retrieve it. Will it be a line in an ALPR log, or a complete access record that can be found by searching for the person?

License Plate as Credential diagram: the SharpV camera as a reader with credentials stored in the Synergis Cloud Link controller
Figure 2. License Plate as Credential: the SharpV camera acts as a reader, while the credential and access rights are stored in the Synergis Cloud Link controller, allowing access rules to remain in effect even if the connection to the server is lost.

The Archive Has to Survive That Long

Everything above depends on one condition: the recording you need still exists and is accessible.

That makes the infrastructure layer just as important. In Genetec, recording is handled by the Archiver role, and it is the role itself that is made redundant. This is not the same as RAID: a disk array protects against disk failure, not the failure of the server hosting the role.

The archive can be maintained as a second independent copy with different video quality and retention, moved between storage tiers, retrieved directly from cameras where deploying a server is impractical, and extended to the cloud as another tier of the same archive.

Flexible recording options diagram: redundant Archivers recording at lower resolution or shorter retention
Figure 3. Flexible recording options: redundant Archivers do not have to mirror the primary Archiver—they can record at a lower resolution, retain a shorter archive, or provide live video only.

Recording redundancy, edge recording, and tiered storage address the problem of preserving the archive. But for an investigation, what matters is not only whether the required footage has survived, but also what has been preserved along with it.

In Security Center, the archive is linked to the same entities that represent doors, zones, users, and license plates. So two weeks later, the system can provide not only the video, but also the context of the event it belongs to.

From Search to Reconstruction

Thirty days of archive retention is a storage specification. The practical question is different: how long does it take to find the thirty seconds that matter?

Two different tools come into play here. One helps maintain continuity as an object moves between cameras. The other narrows down the accumulated footage based on specific attributes.

The second is worth a closer look because it immediately raises a question: where do those attributes come from? Analytics enters Security Center from two sources.

  • The first is the cameras themselves: onboard analytics from supported models, whose results are ingested by the platform as standard system events, alongside access control and license plate recognition events.
  • The second is technology partner solutions, including those for object and face recognition and more advanced searches across archived video.

The platform’s role here is not to recognize objects in the video itself. Its role is to bring the analytics results into the same model of events and entities that already represents doors, zones, users, and license plates. That is what makes those results searchable in the same way as an access event—and what makes analytics not a separate system sitting alongside the platform, but another source of context.

The analytics capabilities are defined during system specification, and they determine how specific an archive query can be six months after deployment.

That is why, in a system with a unified architecture, an investigation often does not start with video at all. It starts with a selected entity—a person, a vehicle, an access point, or a zone—and video is then brought in as evidence supporting what has already been found through other means. This reverses the usual direction of archive investigation.

There is one more layer: trust in the evidence. Digital signing is enabled at the Archiver role level: any modification to the video causes the signature to no longer match the original.

The Evidence Has to Leave the System

This is where the VMS ends.

A serious investigation involves more than just operators: security teams, legal, management, and sometimes authorized external parties. And the evidence rarely consists of a single video file.

Genetec Clearance is a separate digital evidence management system for managing cases, controlled access, retention periods, and audit trails.

Importantly, Clearance does not simply extend the video archive. It extends an archive in which video is already linked to access events, identities, and recognized license plates. What goes into a case is not an isolated file, but a video segment together with the context that had already been built around it before anyone decided to export it.

Genetec Clearance interface: working with digital evidence and case materials
Figure 4. Genetec Clearance interface: working with digital evidence and case materials.

Evidence is transferred to Clearance by exporting it from Security Center—either at the operator’s discretion or automatically in response to an external request. A case can be created directly from that export, without having to assemble it manually from individual files afterward.

This creates three distinct layers that are easy to conflate.

01

Shared context — different subsystems contribute data about the event.

02

Investigation — that data is used to reconstruct what happened.

03

Evidence lifecycle — what has been found becomes managed evidence that can be shared with others without losing control over who has access to it.

The distinction between these layers is fundamental: finding the right evidence is not the same as managing what happens to it once the search is over. This is where the focus shifts from the video archive to managing evidence, access, and accountability.

The practical question at this level is not measured in terabytes:

How much time passes between “the incident happened” and “the right people are already working with the right evidence”?

As System Complexity Grows, Individual Features Matter Less

If there is one takeaway from all of this, it is this.

In a small video system, architecture matters relatively little. There are only a few cameras, a single operator, and an investigation may amount to little more than reviewing recorded video. But as the system becomes more complex—with multiple sites, multiple security disciplines, heterogeneous equipment, and requirements for autonomous operation—the number of features in individual subsystems matters less, while the architecture of the relationships between them matters more.

This is precisely where Genetec becomes interesting.

More open platforms often leave access control as an external integrated system.

More deeply unified alternatives achieve that integration at the cost of tighter dependence on their own hardware.

Security Center brings video, access control, and license plate recognition together as native disciplines within a single platform, while retaining support for heterogeneous hardware.

Takeaway

So the question is no longer whether the system can record, retain, and retrieve video. That is the baseline.

The real question is how much of the work the system takes on after the event has already happened.