A supervisor receives a troubling message from an employee: “You will regret what you did.” Another employee reports that the sender has been angry for weeks, discussing weapons, and blaming specific people for losing a promotion. This is not a moment for guesswork, rumor, or a rushed termination meeting. A guide to workplace threat assessment starts with one objective: identify whether a person’s behavior is moving toward violence, then take proportionate action to protect people.
Workplace violence is rarely solved by a single policy or an annual training video. Effective assessment requires disciplined reporting, timely fact-finding, documented decisions, and a response plan that treats safety and evidence as connected priorities. For employers, HR leaders, security teams, and legal counsel, the question is not whether someone “looks dangerous.” The question is what the available facts say about intent, capability, stressors, targets, escalation, and access.
Why Workplace Threat Assessment Cannot Wait
A threat may be explicit, such as a statement to harm a manager. It may also be indirect: fixation on a grievance, repeated unwanted contact, intimidation, stalking, sudden interest in a target’s schedule, or online posts that signal planning or revenge. None of these facts alone proves that violence will occur. Together, however, they can establish a pattern that demands immediate attention.
The cost of delay is not limited to physical injury. A poorly handled complaint can expose employees to continued harassment, compromise digital evidence, damage morale, and create legal risk for the organization. On the other hand, overreacting without facts can wrongly stigmatize an employee, inflame a conflict, and undermine trust. Threat assessment is designed to manage that tension through evidence-based decisions rather than instinct.
If there is an immediate risk of harm, call 911 and follow your emergency procedures. Do not attempt to conduct an internal interview while a person is making credible threats, is armed, is actively pursuing someone, or cannot be safely contained.
Build a Threat Assessment Process Before a Crisis
A workplace needs a clear reporting path that employees can use without fear of retaliation. Reports should reach a designated threat assessment team, not disappear into an individual manager’s inbox. The team commonly includes HR, security, operations leadership, legal counsel, and, when needed, outside investigative and digital forensic specialists.
The team’s role is not to diagnose mental health conditions or predict the future with certainty. Its role is to collect credible information, evaluate the level of concern, identify protective actions, and revisit the assessment as facts change. A case can move quickly from a low-level conduct issue to an urgent safety concern when a new message, weapon reference, or attempted contact appears.
Establish the basics in advance: who receives reports after hours, who can approve access restrictions, who contacts law enforcement, and who preserves company devices, badges, emails, surveillance footage, and chat records. A written process reduces hesitation when seconds and evidence matter.
Evaluate Behavior, Not a Person’s Identity
A defensible assessment focuses on observable conduct and corroborated facts. Avoid assumptions based on appearance, disability, religion, race, political views, or personality. The point is not to label a person as dangerous. It is to determine whether specific behavior creates a credible risk to identifiable people or the workplace.
Start by documenting the triggering event in the reporting party’s own words. Record dates, times, locations, witnesses, screenshots, voicemail files, social media posts, vehicle details, and prior incidents. Ask what was said or done, who saw it, whether the subject named a target, and whether there was any mention of weapons, surveillance, retaliation, or a deadline.
Then examine context. Has the individual experienced a recent discipline action, termination, relationship conflict, financial pressure, legal dispute, or perceived humiliation? Are they escalating from complaints to threats, from threats to surveillance, or from online posts to physical approach behavior? Have they shown an unusual fixation on a coworker, executive, former partner, or facility?
Capability matters as well. Relevant facts may include access to the workplace, knowledge of routines, possession or attempted acquisition of weapons, technical ability to monitor someone, prior violent conduct, or associates who may be involved. These details must be verified carefully. Rumor is not evidence, and an investigator should distinguish a confirmed fact from an uncorroborated claim.
A Practical Guide to Workplace Threat Assessment Actions
Once the initial facts are collected, the team should select controls that match the risk. The right response depends on the circumstances. A concerning email from a current employee may call for a structured interview and enhanced monitoring. A former employee who has made targeted threats and is appearing near the property may require law enforcement coordination, access restrictions, surveillance review, and immediate executive protection measures.
A strong action plan typically addresses five areas:
- Safety: Protect likely targets, adjust schedules or entry procedures when justified, alert appropriate security personnel, and define what employees should do if the subject appears.
- Access: Disable credentials, review keys and remote access, preserve rather than erase relevant accounts, and consider whether a termination or leave decision changes the risk level.
- Communication: Give affected personnel the information they need to stay safe without broadcasting unsupported allegations or confidential personnel details.
- Investigation: Interview witnesses, review prior reports, preserve physical and digital evidence, and establish a timeline of conduct.
- Follow-up: Set review dates, assign ownership, and reassess when new information emerges.
Do not confuse removal from the workplace with resolution. A subject may retain remote access, personal knowledge of the facility, contact with coworkers, or motivation to retaliate. Any separation meeting should be planned with security in mind, especially when the employee has displayed threatening behavior or may react badly to bad news.
Preserve Digital Evidence Before It Disappears
Threat cases increasingly involve phones, messaging platforms, email, cloud accounts, social media, access-control records, GPS data, and deleted communications. A screenshot may show the words of a threat, but it may not preserve the source, full context, timestamps, metadata, or proof that the item was not altered. That distinction can matter in court, in an employment action, and in a law enforcement investigation.
Preserve original records whenever possible. Issue appropriate retention instructions, secure company-issued devices, export audit logs, and document who collected each item, when it was collected, and where it is stored. Avoid having multiple people forward, crop, edit, or annotate evidence files. Small changes can create unnecessary questions about authenticity.
For serious matters, trained forensic handling can recover relevant data, document acquisition methods, and maintain a clear chain of custody. Advanced Technology Investigations, LLC combines field investigation with digital forensic preservation when organizations need facts that can withstand legal and internal scrutiny. This is particularly valuable when threats involve deleted messages, suspected spyware, anonymous accounts, impersonation, or unauthorized access to company systems.
Conduct Interviews Without Creating More Risk
Interviews should be planned, not improvised. Speak first with reporting parties and witnesses who can provide direct information. Use open questions, then clarify specific details. Ask what they saw, heard, received, or experienced rather than asking them to interpret motive.
When interviewing the subject of concern, consider timing, location, staffing, and exit routes. The interviewer should know the key facts but avoid revealing every source or piece of evidence. Keep the conversation professional and direct. A confrontational approach can push a volatile person into further escalation, while a vague approach may fail to establish accountability.
Document statements accurately. If the subject denies conduct, preserve that denial alongside the evidence. If they make new threats, admit a grievance, disclose weapon access, or identify a target, update the safety plan immediately. Consult legal counsel on employment decisions, privacy boundaries, reporting duties, and any protective-order issues that may apply.
Keep the Assessment Active
Threat assessment is a process, not a one-time score. A case that appears manageable can change after disciplinary action, a court hearing, a breakup, an eviction, a public post, or a failed attempt to contact a target. Review active cases at defined intervals and whenever a material new fact appears.
Employees also need permission to report changes. They may notice a vehicle parked outside, repeated calls to a coworker, concerning online language, missing equipment, or a person attempting to gain access through another employee. Encourage reporting based on behavior and facts, then respond consistently. Silence often grows when people believe prior reports were dismissed.
The best time to establish reporting channels, evidence procedures, and decision authority is before an alarming message lands on a manager’s phone. When warning signs surface, act calmly, preserve what matters, and bring in qualified help before a manageable concern becomes a preventable emergency.








