Brief: campus security, for the people who work there instead of the students. Turn: students have a roster and can be watched; staff have neither — so the product is one constraint, do more for a lone worker than a camera wall does while looking at them less. Demo: raniafsl.github.io/Safe-shift
A night-desk console for the people who work on a campus
Built for the Verkada hackathon brief, which asks for campus safety aimed at students. We pointed it at the other population in the same buildings: the roughly four thousand staff at the University of Waterloo — custodians, plant operators, millwrights, lab technicians, Turnkey staff — who are in those buildings at two in the morning, alone, and who almost no safety system is actually built for.
Live demo: open demo.html in any browser. No install, no server, works offline.
You're a lab technician. It's 10pm. You tap your WatCard into the cryogenics bay, and nobody else is in there.
- Safe Shift starts a twenty-minute timer. That's all. No camera turns on, nobody is told, and nothing is recorded that the door wasn't already recording.
- Tap any door, answer the intercom, or tap your phone, and the timer clears. That is what happens almost every night, and nothing else ever occurs.
- If it runs out, the gentlest thing happens first: your phone buzzes. Two minutes to tap it.
- Still nothing → the buddy you nominated gets called, and the intercom in the room opens so someone can talk to you.
- Still nothing → the on-call Safety Office advisor takes it over. Only now can the dispatcher ask for a camera — and that costs them a typed reason, lasts ten minutes, covers one camera, seals itself, and sends you a notice saying they looked.
- Still nothing → a handover goes to Special Constables and paramedics: which room, what's in it, how to get in, which doors unlock when they arrive.
That's the product. Each step is deliberately more intrusive than the one before it, and each one only happens because the cheaper one was ignored — so someone who feels the buzz and taps it never has a single frame of video taken of them.
The second thing it does is roll-call. When a fire alarm sounds, it works out who is inside from the last four hours of door taps — because no employer has a list of who's in a building at 10pm — clears people as they reach the assembly point, and deletes the list a day after the all-clear so it can never become an attendance record.
What's underneath: eight hazardous spaces on campus, ~4,000 staff, six rules, and a page recording every single time anyone was looked at. Everything else in this repo is the reasoning behind those steps, and the reasons it refuses to do more.
A student and a staff member can be standing in the same corridor at the same hour and be two completely different safety problems.
| Students | Staff | |
|---|---|---|
| Is there a roster? | Yes — enrolment, residence, timetable | No. Shift swaps, call-ins, contractors |
| Where's the risk? | Assault, wellness, mental health | Lone work. Cryogens, steam, roofs, machine shops, the walk to the car |
| Who's around? | Crowds, roommates, RAs | Nobody. That's the whole problem |
| Can you just watch them? | Broadly tolerated | No. It's their employer, and there's a staff association |
That last row is the one that kills most products in this space. A university can put a camera almost anywhere a student goes. The moment the person in frame is an employee, continuous monitoring stops being a safety feature and becomes a labour-relations problem — and the deployment dies in committee, no matter how good the technology is.
So Safe Shift is built around a single constraint:
It must do more for a lone worker than a camera wall does, while looking at them less.
A check-in, not a recording. Tap into a room that could hurt you, with nobody else in it, and a twenty-minute check-in opens. Any door tap, intercom answer, or tap on your own phone closes it. Nothing is watched. Nothing is stored beyond the door event that was already there.
A ladder that starts gentle. Miss the check-in and the cheapest thing happens first — a buzz on your own phone. Then the buddy you nominated. Then the Safety Office. Only at the third rung can anyone ask for a camera, and only at the fourth does it become a call to Special Constables and paramedics. Someone who feels the buzz and taps it never has a single frame of video taken of them.
Movement is not the same as being alright. A camera reporting motion buys five more minutes and nothing else. It never closes a check-in — someone collapsed on the floor still registers as movement. This is a small rule that a lot of real systems get wrong.
Breaking the glass costs something. Opening a camera takes a stated reason, lasts ten minutes, covers one camera, seals itself, and the person inside is told it happened. Every one of those is a row on the "Who looked" page, which is the same page the staff association gets a monthly summary of.
In a fire, the doors are the only honest roster. No employer knows who is inside a building at 22:00. Safe Shift rebuilds the roll-call from four hours of card taps, clears people as they reach the assembly point, and deletes the list a day after the all-clear so it can never become an attendance record.
A cancelled card is a door problem, not a face problem. Revoked credential at a reader: door holds, Turnkey and dispatch are told, intercom opens so somebody can just ask who's out there. No face recognition, no watchlist, anywhere in the system. We think refusing that is a feature, and we say so on the screen.
- Open
demo.html. - Right-hand panel → "Nadia goes into the cryo bay alone."
- Put the clock on 30×. Watch the check-in run down on the board.
- At zero, it climbs: nudge → buddy → Safety Office → send help. Along the way a camera reports movement and buys five minutes, without closing anything.
- Open the call, press Break the glass, pick a reason. Watch the ten-minute timer start and the camera shut itself.
- Go to Who looked. Your reason is sitting there with your name on it, and so is the note Nadia receives.
The other four scenarios — oxygen falling in the Davis Centre machine room, a cancelled card at the chem stores door, the Lot B call post, and a fire alarm in QNC — each exist to show one rule doing something a camera wall cannot.
The brief asks for safety on a campus. For staff, safety and privacy are the same requirement — a system the workforce won't accept never gets installed, so it protects nobody. So privacy here isn't a settings page. It's the shape of the escalation ladder.
Six promises, each with the mechanism that makes it true. A promise without a mechanism is a policy nobody can check.
| What we promise | Why it's true, not just stated |
|---|---|
| Most nights, nobody looks at you | Video only exists inside a ten-minute grant. There is exactly one function in the codebase that can open a camera, and it can't run without writing a ledger row. |
| If someone does look, you're told | The notice names who looked and quotes the reason they typed. It replies to the Safety Office and the Staff Association — not to the people who run the cameras. |
| Nobody can scroll back through your shift | There is no rewind. One camera, live, ten minutes, then it seals itself. Not a rule someone follows — the button doesn't exist. |
| The system doesn't know your face | No facial recognition, no watchlist. When a cancelled card is tapped it knows the card was cancelled. It doesn't know who's holding it. |
| It isn't on your desk | Eight spaces on the whole campus, every one a physical hazard. No reader, no rule, no camera on an office or corridor. |
| The fire roll-call isn't an attendance record | Built from four hours of door taps, deleted a day after the all-clear, never reaches a supervisor. |
The strongest single fact: someone who feels the buzz and taps it never has a single frame of video taken of them. Answering your phone is how you stay invisible.
You can check all six on one screen — open Who looked. On a normal night the table is empty, and that's the product working.
The first question anyone asks. Four answers:
A camera is a record, not a tripwire. Footage tells you what happened, afterwards. The way lone workers actually get hurt is that nobody realised they were gone until the next shift came in. Nothing on a camera wall notices an absence.
Somebody has to be looking. At 2am there is one dispatcher and dozens of feeds. A camera nobody happens to be watching saves the footage, not the person.
The rooms that matter have terrible sightlines. A cryo bay is dewars and racking. A boiler hall is pipework. A roof is plant. In exactly the places where someone alone gets hurt, there is no angle that reliably sees the floor.
And you can't point them at staff all night anyway. A camera wall is a monitoring posture; a check-in is a safety posture. Same hardware, opposite relationship with the workforce — and only one of the two ever gets installed.
The cameras are already on the wall. What's missing is something that notices.
No new hardware. Every part of this is something Verkada ships today:
| What Safe Shift needs | The Verkada part | Doing what |
|---|---|---|
| Who went where, and when | Access control — door controllers, readers, Verkada Pass credentials | Every check-in opens and closes on a card tap. This is the entire sensing layer, and it's already on the doors. |
| Something moved in there | Cameras, with on-camera motion and person analytics | Buys five more minutes. Deliberately cannot clear a check-in. |
| Talk to the room | Intercoms | Rung two opens the room intercom. At the chem stores door it lets you simply ask who's outside. |
| The call post in Lot B | Alarms — panic button / call point | Jumps straight to the top of the ladder. |
| The room is turning dangerous | Environmental sensors | Air quality, gas, temperature, humidity. |
| The one camera you broke the glass for | Camera live stream, scoped to a single session | One camera, ten minutes, then it closes itself. |
| All of it talking to each other | Command, its API and webhooks | Events out, credential state in, and an HR sync so a cancelled contract cancels a card the same hour. |
One honest gap: oxygen depletion in a cryo bay isn't a stock Verkada part. That's a third-party O₂ monitor on an alarm input or pushed through the API. We'd rather say so than draw a slide that implies otherwise.
The one thing Verkada would have to build: video access that is scoped to a session, tagged with a reason, expires on its own, and tells the person it happened. Everything else on that list ships today — this is a Command-layer product, not a hardware pitch.
That's also the commercial argument. It doesn't ask a university to buy anything new. It makes the access control they already own into a safety system for staff, and gives the staff association a reason to accept it.
Real: the rules engine, the clock, the check-in state machine, the escalation ladder, the break-glass grant with its self-expiry, the ledger, and the roll-call reconstruction. Press a button and the event goes into the same engine the rest of the screen reads. Nothing is on rails after you press it.
Stand-ins: camera video, card-reader hardware, phone push, and the call to dispatch.
docs/ARCHITECTURE.md maps each one to the Verkada Command capability it would become.
Before any more code: sit a full shift with a night custodian, and take the notice wording to the Staff Association. Every assumption about the job is ours rather than theirs, and if the thing a watched person receives reads wrong, nothing downstream matters.
Gaps we already know about: a buddy is currently just a name on a record and needs to know who's actually on shift; free-egress doors mean the system can think you're still in a room you left; and the metric we'd hold ourselves to is how often rung one fires and gets tapped — if that's high, the window is wrong and people start resenting the buzz, which is how these systems die.
Honest debt: nothing persists, so a refresh resets the night — which means the ledger,
the one thing we promise is permanent, is currently the least permanent part of the system.
There's no per-operator login yet either, and break-glass attribution is only worth as much
as knowing who was sitting at the desk. Full list in
docs/ARCHITECTURE.md.
index.html the console (multi-file version)
demo.html the same thing bundled into one file — use this on demo day
build.js makes demo.html from the sources
assets/safeshift.css the visual system
src/data.js the world: spaces, people, rules, scenarios
src/engine.js clock, check-ins, ladder, break-glass, ledger, roll-call
src/ui.js rendering
docs/PITCH.md five-minute pitch and the run sheet for the demo
docs/ARCHITECTURE.md how it maps onto real Verkada hardware
Nothing to install. node build.js after editing anything in src/.