Daily Occurrence Log vs Incident Management System: when does a hotel occurrence become an incident?

At 10:14pm, a guest complains about somebody making noise in the corridor.

At 10:22pm, security attends.

At 10:27pm, everything is quiet again.

Occurrence logged.

At 11:46pm, the same guest reports shouting.

Security returns. This time, two guests are arguing. Still an occurrence?

At 11:51pm, one pushes the other. Now we probably have an incident.

Which raises a deceptively simple question: At what precise moment did it become one?

Hotels generate hundreds of things worth knowing about every day. Most are completely ordinary. Some are unusual. A much smaller number require investigation, escalation or a formal response.

The difficult part isn't recording what happens.

It's deciding what happens next.

 

What is a Daily Occurrence Book in a hotel?

A Daily Occurrence Log, often still called a Daily Occurrence Book or DOB, is essentially the hotel's operational memory.

It records the things that happen during a shift which somebody else may need to know about later.

A fire door was found open, a guest reported suspicious behaviour, a lift temporarily stopped working, so on and so forth...

None of these events necessarily requires a major response. But forgetting them isn't particularly helpful either.

This is why occurrence logs have survived remarkably well despite decades of technological change.

Hotels are 24-hour operations staffed by people who aren't there for 24 hours.

Somewhere, information has to survive the handover.

 

A hotel incident management system has a different job

An Incident Management System begins from a different premise.

Something has happened that requires more than simply remembering it.

Perhaps somebody has been assaulted, there has been a serious theft, or a guest or employee has been injured.

Or an event creates regulatory, reputational or legal consequences that need to be managed.

Now the organisation needs structure.

Who has been informed? Who owns the response? Does somebody need to investigate? What evidence has been collected? Does the incident need escalating?

The Daily Occurrence Log asks: “What happened?”

Incident management adds: “What are we going to do about it?”

That small difference is really the dividing line between the two.

 

Daily Occurrence Log vs Incident Management isn't really a technology question

It is tempting to see DOL and IMS as two pieces of software competing for the same job. They aren't.

The distinction exists even if the hotel uses nothing more sophisticated than two notebooks.

One is concerned with operational awareness. The other is concerned with structured response.

Imagine a security officer notices the same external door has been found unsecured three nights in one week. Each occurrence belongs in the Daily Occurrence Log.

Monday: door found unsecured. Wednesday: same thing. Friday: again.

Individually, each may be fairly mundane.

Collectively, they suggest something else is happening.

Perhaps there is a faulty lock, or somebody isn't following procedure. Perhaps there is a vulnerability nobody has investigated.

The individual occurrences haven't changed. Their meaning has.

And that is where the boundary between logging activity and managing an incident can become surprisingly interesting.

 

When does a daily occurrence become a security incident?

This matters because over-reporting can be almost as unhelpful as under-reporting.

Imagine if every operational problem triggered a full incident workflow.

A contractor arriving ten minutes late. Incident.

A light failing in the stairwell. Incident.

A guest leaving an umbrella behind. Incident.

Before long, the incident management system becomes the digital equivalent of the boy who cried wolf. Everything is important. Therefore nothing is.

A useful Daily Occurrence Log protects against this by giving teams somewhere appropriate to record the vast amount of operational activity that matters enough to remember, but not enough to investigate.

The mundane deserves a record.

It does not always deserve a committee.

 

A Daily Occurrence Book records the shift. Incident management manages the exception.

Perhaps the easiest distinction is also the least technical.

A Daily Occurrence Book tells the story of the hotel.

Most of that story will be gloriously uneventful; contractors arrive, patrols happen, guests complain.

The log preserves that operational history so the next person isn't starting the shift with amnesia.

An Incident Management System exists for the moments within that story that demand something more.

Something needs investigating. Somebody needs informing. An action needs completing. A risk needs managing.

One creates continuity and the other creates control.

 

Security operations require incident management and a daily occurrence log

It is easy to ask whether an event belongs in a Daily Occurrence Log or an Incident Management System.

In practice, the answer can be both. Something happens, it is recorded. Its significance becomes clear, it is escalated.

The original information provides the context for whatever happens next.

That feels much closer to how hotels actually operate than trying to divide the world neatly into “occurrences” and “incidents”.

Because real life rarely respects the categories we create for it.

The noise complaint at 10:14pm was an occurrence. The argument at 11:46pm was becoming something more.

The important thing isn't arguing about exactly which minute the incident began.

It's making sure the hotel can recognise when the story has changed and respond accordingly.

 

Leave a Comment