Smart Building Access Incident Logs

This dataset provides a detailed log of remote access incidents across commercial properties, capturing user, location, device, and event attributes to support advanced security analytics, compliance auditing, and operational optimization. It enables property managers and IT administrators to monitor access patterns, detect anomalies, and streamline incident response for hybrid and remote workforce environments.

  • last updated 3 Feb 2026
  • by GoMask
The brief that made it

Security anomaly detection and incident investigation

Sample rows

preview · 8 of 65 rows · all 28 columns
incident_idstringincident_severitystringcompliance_flagbooleanuser_departmentstringtimestampdatetimeuser_idstringuser_namestringuser_rolestringproperty_idstringproperty_namestringproperty_street_addressstringproperty_citystringproperty_statestringproperty_postal_codestringproperty_countrystringaccess_point_idstringaccess_point_namestringaccess_methodstringincident_typestringincident_statusstringreviewed_bystringreviewed_atdatetimenotesstringdevice_idstringdevice_typestringip_addressstringgeo_location_latfloatgeo_location_longfloat
INC-9A4B7C12infofalseIT2024-05-20T08:21:05ZUSR-3572Dwayne CarteremployeePROP-101Greenhill Business Center101 Greenhill RdSan DiegoCA92121USAAP-001Main Entrance Lobbykeycardaccess_grantedresolvedSEC-1022024-05-20T09:00:12ZRoutine access.DEV-01Acontroller192.168.1.1532.899-117.237
INC-1FD73E84warningtrueFacilities2024-05-20T09:14:45ZUSR-2214Emily ZhangcontractorPROP-102Harbor View Tower212 Harbor StSan FranciscoCA94111USAAP-008Loading Dockpinaccess_deniednewblankblankIncorrect PIN entered.DEV-02Fpanel10.0.0.22337.795-122.397
INC-7E6F4B09infofalseOperations2024-05-20T10:07:32ZUSR-4521Juan MartinezemployeePROP-103Sunset Plaza328 Sunset AveLos AngelesCA90026USAAP-012West Gatekeycardaccess_grantednewblankblankNo issues reported.DEV-05Bcontroller172.16.0.10534.078-118.26
INC-5B2D1C63infofalseFinance2024-05-20T11:33:11ZUSR-9876Priya SinghemployeePROP-104Corporate Hub1500 Market StDallasTX75201USAAP-019Parking Garage Entrymobile_appaccess_grantedresolvedSEC-2012024-05-20T12:10:55ZMobile access normal.DEV-10Csensor192.168.2.4732.783-96.8
INC-4A8E9B77infofalseblank2024-05-20T13:42:18ZUSR-3145Sharon LeevisitorPROP-105TechWorks Campus221 Innovation BlvdAustinTX78758USAAP-025Receptionbiometricaccess_grantednewblankblankVisitor fingerprint match.DEV-16Dcamera10.10.20.1830.391-97.722
INC-A5C1D2B0infofalseSecurity2024-05-20T14:15:02ZUSR-6543Robert AndersonadminPROP-101Greenhill Business Center101 Greenhill RdSan DiegoCA92121USAAP-003Server Roombiometricaccess_grantedresolvedSEC-1022024-05-20T14:45:00ZAdmin access approved.DEV-01Acontroller172.16.0.8832.899-117.237
INC-CCF35D1EwarningtrueMarketing2024-05-20T14:37:44ZUSR-7685Lisa YoungemployeePROP-104Corporate Hub1500 Market StDallasTX75201USAAP-020Side Entrancekeycardaccess_deniedin_reviewSEC-3012024-05-20T15:05:12ZKeycard expired.DEV-10Ccontroller192.168.2.4932.783-96.8
INC-8D51A2C4criticaltrueMaintenance2024-05-20T15:22:08ZUSR-1123Tommy EvanscontractorPROP-102Harbor View Tower212 Harbor StSan FranciscoCA94111USAAP-010Rooftop Accesskeycardforced_entryescalatedSEC-1022024-05-20T15:45:33ZCard reader damaged.DEV-02Fpanel10.0.0.22937.795-122.397

What the 65 rows show

from the 65-row sample

Warning (incident severity) stands out: 18 of its 18 rows have compliance_flag = true, against 8 of 47 for the rest.

  • 40%compliance_flag = true
  • 4incident statuses
  • 4device types
  • 5user roles
  • 5property states
  • 5access methods
Compliance flag rate by incident_severitycompliance_flag = true
0%50%100%0%info0 of 39100%warning18 of 18100%critical8 of 8
user_department60 rows with a value · 5 left blank
  1. Finance9
  2. IT8
  3. Operations8
  4. HR6
  5. Security5
  6. Marketing5
  7. Sales5
  8. Facilities4
  9. Maintenance4
  10. Legal3
28 columns by typefrom the column list below
  • string 23
  • float 2
  • datetime 2
  • boolean 1

Columns

28 columns in four groups
blueprint · 28 columns
columntypedescriptionexample
Text 23 columns
incident_idstringUnique identifier for each access incident log entry.uniqueINC-9A4B7C12
user_idstringUnique identifier for the user involved in the incident.USR-3572
user_namestringFull name of the user involved in the incident.optionalDwayne Carter
user_rolestringRole of the user (e.g., employee, contractor, visitor, admin).employee · contractor · visitor · admin · other · optionalemployee
user_departmentstringDepartment or team of the user, if applicable.optionalIT
property_idstringUnique identifier for the property/building where the incident occurred.PROP-101
property_namestringName of the property/building.optionalHarbor View Tower
property_street_addressstringStreet address of the property.optional101 Greenhill Rd
property_citystringCity where the property is located.11 cities · optionalSan Diego
property_statestringState or region where the property is located.5 states · optionalCA
property_postal_codestringPostal code of the property.optional92121
property_countrystringCountry where the property is located.optionalUSA
access_point_idstringUnique identifier for the access point (e.g., door, gate, turnstile).AP-001
access_point_namestringDescriptive name or location of the access point.optionalMain Entrance Lobby
access_methodstringMethod used for access (e.g., mobile app, keycard, biometric, PIN, remote override).6 valueskeycard
incident_typestringType of incident (e.g., access_granted, access_denied, forced_entry, tailgating, system_error, anomaly_detected).7 valuesaccess_granted
incident_severitystringSeverity level of the incident (e.g., info, warning, critical).info · warning · critical · optionalinfo
incident_statusstringCurrent status of the incident (e.g., new, in_review, resolved, escalated).new · in_review · resolved · escalated · optionalresolved
reviewed_bystringUser ID or name of the person who reviewed the incident, if applicable.optionalSEC-102
notesstringAdditional notes or comments regarding the incident.optionalRoutine access.
device_idstringUnique identifier for the device or controller that logged the incident.optionalDEV-01A
device_typestringType of device (e.g., controller, sensor, camera, panel).controller · sensor · camera · panel · other · optionalcontroller
ip_addressstringIP address from which remote access was attempted, if applicable.optional192.168.1.15
Numbers 2 columns
geo_location_latfloatLatitude of the access attempt (if available).-90 to 90 · optional32.899
geo_location_longfloatLongitude of the access attempt (if available).-180 to 180 · optional-117.237
Dates and times 2 columns
timestampdatetimeDate and time when the access incident occurred.2024-05-20T08:21:05Z
reviewed_atdatetimeTimestamp when the incident was reviewed.optional2024-05-20T09:00:12Z
True or false 1 column
compliance_flagbooleanIndicates if the incident is a compliance concern (true/false).optionalfalse

Use it for

  • compliance flag40%26 of 65 rowscompliance flag by in…0%info100%warning100%critic…

    A real estate dashboard

    The compliance_flag rate, compliance_flag by incident_severity and a breakdown of user_department. Excel, Power BI or Tableau.

  • Why do 26 of 65 rows have compliance_flag = true?

    A root-cause class exercise

    Hand out the rows and one question. The answer is in the data, not in the brief.

  • A software demo

    Believable incidents with timestamp, user_id and user_name to fill a screen in front of a buyer.

Not quite right?

Make it yours.

Same 28 columns, your size and your rules. See 20 rows before you pay.

Preview 20 rows free

10,000 rows of yours: $12.99One-time. No subscription. All prices

This dataset65 rows28 columns
Yours10,000 rows28 columnsproperty_street_address: UK only

blueprint · smart-building-access-incident-logs

Behind this dataset

Same schema. As many rows as you need.

These 65 rows came out of a blueprint — 28 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.

Rules it was built with
  • Each incident log must include timestamp, access point ID, user role, and access method (e.g., mobile app, badge, PIN).
  • Flag incidents as normal, suspicious, or unauthorized based on predefined security policies.
  • Record incident resolution status and response time in minutes.
  • Tag each entry with building occupancy level at time of incident.
  • Include optional note for manual overrides or escalations.
Rows
Open the blueprint in Data Factory

1 credit per row. New accounts start with 25 free credits.

Exports
CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
Licence
yours to use, including commercially
API slug
smart-building-access-incident-logs

What should your data show?

Preview 20 rows free
No signup. No card.