top of page

From Alarm to Action: Rethinking Incident Management for Smart Buildings

Chakrapan Pawangkarat

Head of Property Management, JLL Thailand

Secretary-General, Property Management Association of Thailand

16 August 2026



Incident Management is one of the most important disciplines in building operations. A lift stops, water leaks into a plant room, a fire protection system reports a fault, an access-control door fails, or a tenant complains that an area is too warm. The traditional response is familiar: someone notices the problem, informs the control room, a technician or contractor is called, the issue is investigated, progress is followed up, and the incident is eventually closed.


That process still works, but it was designed for a world in which buildings waited for people to notice problems. Smart Incident Management changes the model. It moves incident handling from a largely reactive workflow into a connected operating system that can detect abnormalities, assess severity, coordinate response, track recovery, and learn from every event.


The goal is therefore much bigger than replacing a logbook with an application or a phone call with a digital ticket. The real opportunity is to redesign how incidents are detected, prioritised, resolved, and prevented.


1. Detect the Incident Earlier


Traditional Incident Management often begins with human observation. A tenant feels warm and calls the building team. A technician notices water on the floor. A security officer discovers that a door has been forced open. In each case, the incident already exists before the organisation becomes aware of it.


Smart Incident Management moves detection closer to the source. Building management systems, IoT sensors, lift monitoring, water-leak detection, CCTV analytics, access control, fire systems, and other digital platforms can continuously monitor building conditions and generate alerts when something moves outside normal parameters.


This changes the first question from “What has gone wrong?” to “What is becoming abnormal?”


That distinction matters. If a lift system begins to show unusual behaviour, a pump starts drawing abnormal current, or a water sensor detects leakage in a plant room, the building team may be able to intervene before the problem becomes a major service interruption.


The earlier the incident is detected, the more options the team has. Early detection can reduce downtime, limit damage, improve safety, and protect tenant experience.


2. Turn Alarms into Incident Intelligence


More sensors, however, do not automatically produce better Incident Management. They can simply produce more alarms.


Modern buildings may receive alerts from BMS, fire systems, lifts, electrical systems, CCTV analytics, access control, water systems, and multiple vendor platforms. If every alarm is treated equally, the control room quickly becomes overwhelmed.


The next step is therefore incident intelligence: converting raw alerts into events that can be understood operationally.


A smart incident platform should help answer five questions immediately: What happened? Where did it happen? How serious is it? Who or what is affected? What should happen next?


That requires structured incident data. Every incident should have a clear time of occurrence, location, affected asset, classification, severity, acknowledgement time, response time, restoration time, resolution, and ownership.


Severity should also reflect consequence, not simply the type of fault. A small water leak in a pantry may be moderate; the same leak beside an electrical switchboard could be critical. A normal lift fault may be a routine work order, while a lift entrapment requires an immediate emergency response.


The purpose is not to send more notifications. It is to ensure that the most important event reaches the right people first.


3. Automate the Response Workflow


Detection is useful only when it leads to action.


In a traditional workflow, an alarm reaches the control room, someone calls an engineer, the engineer calls a technician, the technician visits the location, and the supervisor decides whether a vendor is needed. Much of the response time is not technical work; it is coordination.


A smarter workflow can automatically create the incident, assign severity, identify the affected asset, dispatch the appropriate technician, start the SLA clock, and escalate the incident if no acknowledgement is received. The technician can receive asset history, location information, fault details, and previous repair records before arriving at the scene.


If the incident affects tenants, the system can also trigger a communication workflow. If the situation becomes critical, it can escalate simultaneously to engineering, security, property management, and senior management according to a predefined protocol.


This reduces what might be called coordination latency — the time lost while people call, message, wait, repeat information, and search for the right person.


Smart Incident Management is therefore not simply a faster ticketing system. It is a better response architecture.


4. See One Incident, Not Ten Separate Alarms


One of the biggest weaknesses in many smart buildings is fragmentation. The BMS has one dashboard, the lift vendor another, the fire system another, the CCTV system another, and the CMMS another. The person in the control room becomes a human API, manually connecting information from different systems.


Consider a main power failure. The BMS reports power loss. The generator starts. Several lifts generate faults. Access-control devices go offline. Temperatures begin to rise. Tenant complaints start arriving.


Technically, the systems may generate six or seven separate alarms. Operationally, they are consequences of one incident.


This is why event correlation matters. Smart Incident Management should help identify relationships between alarms, group related events, and highlight the likely root cause. When this works well, the command centre stops being a room full of screens and becomes a place where the team can see one coherent operational picture.


That ability is especially important during critical incidents, when too much information can be as dangerous as too little.


5. Dispatch the Right Response, Not Just the Nearest Person


Traditional Incident Management often begins with a simple instruction: “Send someone to take a look.” Smart Incident Management asks a more useful question: Who is the right person for this incident?


The best technician may depend on competency, certification, location, workload, SLA risk, previous experience with the asset, and spare-parts availability. A lift entrapment may require engineering and security at the same time. A major fire-system fault may require multiple teams. A chiller problem may need a technician who already knows that specific machine.


This changes incident response from basic work assignment into resource orchestration.


The objective is not simply to send someone faster. It is to send the right person, with the right information, to the right problem, at the right time.


6. Manage Incidents Before They Become Failures


The most advanced form of Incident Management begins before a breakdown occurs.


Fault Detection and Diagnostics can identify deviations from normal operation while equipment is still running. A chiller may still be operating, but its efficiency is deteriorating. A pump may not have failed, but its vibration pattern is changing. A lift may still be in service, but remote monitoring shows abnormal behaviour.


In a traditional system, there may still be “no incident.” In a smarter system, this becomes an early incident that deserves investigation.


The system can generate a predictive work order before the condition develops into a breakdown. This changes the management question from “How quickly did we repair the failure?” to “How many failures did we prevent?”


Mean Time to Repair will remain important, but it should sit alongside other measures such as repeat incident rate, first-time fix rate, time to detect, time to acknowledge, time to restore service, and prevented failures.


The best incident is often the one that never reaches the tenant.


7. Every Incident Should Make the Building Smarter


Too many incidents are closed and forgotten. Yet every incident contains information about asset health, service quality, vendor performance, and operational risk.


If the same lift fails repeatedly, the same AHU generates recurring alarms, or the same zone receives temperature complaints every month, those events should not be treated as isolated tickets. Together, they form a pattern.


The incident database should therefore become the organisational memory of the building. Management should be able to identify recurring failure modes, assets with unusually high incident rates, vendors with stronger first-time fix performance, and incident categories that are trending upward.


That information can influence preventive maintenance, vendor contracts, asset replacement, capital planning, and even property value. Incident data is no longer just an operational record; it becomes management intelligence.


AI can take this further by moving the system through four stages: What happened? Why did it happen? What is likely to happen next? What should we do now?


This is where Incident Management starts to evolve from a record-keeping process into a learning system.


8. Adoption Determines Whether the System Works


Technology can be installed successfully and still fail operationally. A new platform may go live, but teams continue to use phone calls, messaging apps, spreadsheets, and verbal instructions. Tickets are created afterwards only to complete the report.


In that situation, the technology went live, but the operating model did not.


Smart Incident Management therefore requires adoption and change management from the beginning. The new workflow must be easier than the old one. Technicians should receive useful information rather than extra data-entry work. Supervisors should use the platform to prioritise incidents. Vendors should work within the same process. Managers should stop creating parallel reporting channels that encourage people to maintain shadow systems.


Adoption should also be measured. Useful indicators include the percentage of incidents created automatically, the percentage dispatched through digital workflows, data completeness, mobile usage, first-time fix rate, repeat incident rate, and the percentage of incidents managed without parallel manual processes.


The goal is reached when teams stop saying “We have to use the system” and start saying “This is how we manage incidents.”


Incident Management Is Becoming a Core Operating Capability


The future of Incident Management will not be defined by who has the most sensors, the biggest command centre, or the most sophisticated dashboard. It will be defined by how effectively an organisation can turn signals into decisions and decisions into action.


The maturity path is clear: Reactive → Digital → Connected → Intelligent → Predictive.


At the reactive level, people discover problems and report them. At the digital level, incidents are recorded and tracked. At the connected level, systems detect and create incidents automatically. At the intelligent level, the platform prioritises, correlates, and supports diagnosis. At the predictive level, the organisation begins to intervene before failures occur.


The best-managed building of the future may therefore not be the one that responds fastest to incidents. It may be the one that detects them earlier, resolves them more intelligently, learns from them systematically, and prevents more of them from happening again.


That is the real promise of Smart Incident Management: not better ticketing, but better operational control.

Chakrapan Pawangkarat

  • TikTok
  • Facebook
  • LinkedIn
  • Instagram
  • Youtube
bottom of page