Workplace Threat Assessment Guide for HR and Safety Leaders
- William DeMuth

- 2 days ago
- 10 min read

A workplace threat assessment is led by a multidisciplinary Threat Assessment Team (TAT) and follows a six-step workflow: intake, information gathering, analysis using a pathway-to-violence framework, risk scoring, mitigation planning, and monitored closure. When a report comes in, your first 24 hours determine whether someone gets hurt or gets help.
Immediate next steps when a report arrives:
Intake within 2 hours: Log the report, assign a case number, and notify the TAT coordinator.
Safety first: Determine whether the situation requires calling 911 before any investigation begins.
Assemble the TAT: Notify HR, security, legal, and behavioral health within the same business day.
Place an information hold: Preserve all relevant communications, records, and digital evidence immediately.
Initial triage decision: Classify the report as imminent, elevated, or low concern using the criteria in Section 4.
Secure documentation: Open a locked case file and restrict access to TAT members only.
Three authoritative references anchor this guide: FBI Law Enforcement Bulletin guidance on TATs, Texas Department of Insurance (DWC) Workplace Violence Prevention Program standards, and Dr. Marisa Randazzo’s pathway-to-violence framework as described in practitioner threat management literature.
Table of Contents
Who belongs on your Threat Assessment Team?
FBI guidance is clear: effective TATs shift thinking from “What do I do?” to “What do we do?” That shift requires the right people in the room with defined authority.

Role | Core Responsibilities | Escalation Authority | Recommended Backup |
HR Representative | Case intake, employment records, discipline coordination | Refer to EAP or legal | Deputy HR Director |
Security Officer | Physical safety controls, access management, law enforcement liaison | Initiate emergency response | Facilities Manager |
Legal/Compliance | ADA review, privacy compliance, documentation oversight | Halt investigation pending counsel | Outside employment attorney |
Senior Leader | Final mitigation decisions, resource allocation | Authorize temporary workplace changes | COO or designee |
EAP/Behavioral Health | Clinical risk consultation, referral coordination | Recommend psychiatric evaluation | External clinician |
Case Manager | Coordinates TAT meetings, maintains case file, tracks timelines | None (coordination role) | HR Generalist |
Document each member’s role and decision authority in a written TAT charter or delegation memo. That document becomes part of the program record and supports any future audit.

Pro Tip: Include local law enforcement as an advisory member, not a voting one. Document that arrangement explicitly in the charter so the TAT retains operational control while benefiting from law enforcement perspective.
How to conduct a workplace threat assessment: the step-by-step workflow
A reproducible, auditable sequence protects both employees and the organization. Structured threat management processes consistently follow six stages, each with defined outputs and owners.
Intake and screening (within 2 hours for potential imminent threats): Log the report, assign a case manager, and make the initial triage call.
Investigation and information gathering (24–48 hours): Collect multi-source evidence: HR records, incident reports, witness accounts, digital communications, and public records.
Pathway-to-violence analysis (within 72 hours where safely possible): Apply Dr. Marisa Randazzo’s framework, assessing whether the subject is on a behavioral pathway toward violence, not simply whether they fit a profile.
Risk scoring: Use a 5x5 semi-quantitative risk matrix to rate likelihood and impact, then assign a treatment zone: Accept, Monitor, Mitigate, or Escalate.
Mitigation planning: Assign controls, owners, and deadlines. Record residual risk and re-evaluation dates.
Monitoring and closure: Follow up at intervals matched to the risk zone until residual risk is acceptable, then document closure.
Artifact | Owner | Timing |
Incident report | Case Manager | Within 2 hours of intake |
Interview notes | HR + Security | During investigation phase |
Risk register entry | Case Manager | After scoring |
Mitigation plan | TAT (all members) | Within 72 hours |
Monitoring notes | Case Manager | Per monitoring schedule |
Closure memo | Senior Leader | Upon case resolution |
Pro Tip: Before scoring, deduplicate your incident data. Duplicate reports in historical records inflate perceived threat levels and can send resources to the wrong place.
How do you triage imminent danger from a performance issue?
The primary triage criteria for imminent danger are specificity, plan, means, timeline, and capability. A subject who has named a target, described a method, and has access to weapons requires law enforcement contact before any HR process begins.
Red Flag (Imminent/Elevated) | Lower Concern Indicator |
Specific threat naming a person or location | Vague frustration or general complaints |
Evidence of planning (maps, schedules, research) | Isolated outburst with no follow-up behavior |
Weapons access or recent acquisition | No known access to weapons |
Stated timeline (“by Friday”) | No timeline mentioned |
History of targeted violence | First-time behavioral concern |
Sudden withdrawal after escalating grievance | Ongoing but stable performance issues |
Scenario A: An employee tells a coworker, “I know where [manager] parks and I’m done being ignored.” Call 911 and notify security before opening an HR file.
Scenario B: An employee raises their voice during a performance review and says, “This place is a joke.” Open a TAT review, notify EAP, and schedule a supervisor debrief. No law enforcement contact needed at this stage.
Supervisors need scripted initial actions and clear notification paths so they do not have to make these judgment calls alone under pressure.
What to collect and how to document it
Gather multi-source evidence quickly and preserve chain-of-custody for all physical and digital artifacts. Structured methods including checklists, interviews, and participatory review produce more reliable hazard identification than single-source reporting.
Evidence collection checklist:
Employment records: performance reviews, prior incidents, disciplinary history
Communications: emails, texts, voicemails (screenshots with metadata preserved)
Witness statements: written, dated, and signed
Physical evidence: notes, objects, photographs (logged with chain-of-custody form)
Public records: social media, court records, news items
Mitigating factors: family ties, community supports, treatment history (record these alongside warning signs to avoid overreaction)
Interview guidance: Ask supervisors, “Have you observed any changes in behavior, statements, or social withdrawal in the past 30 days?” Ask witnesses, “Can you describe exactly what you heard or saw, and who else was present?” For the person of concern, keep questions behavioral and factual: “Can you help me understand what happened during that conversation?”
Retain all case records for a minimum period aligned with your program audit cycle. The Texas DWC program standard includes recordkeeping as a core program element, and audit reviewers will expect complete files.
How to design a mitigation plan that fits the risk
Pick proportional, evidence-based controls and assign ownership and timelines before the TAT meeting ends.
Mitigation Category | Examples | Best Used When | Consideration |
Administrative controls | Policy updates, reporting procedures, no-contact orders | All risk levels | Low cost; requires compliance monitoring |
Behavioral/EAP referral | Counseling, threat management counseling, fitness-for-duty evaluation | Elevated behavioral concern | Requires employee consent in most cases |
Physical controls | Access badge changes, escort protocols, camera review | Elevated or imminent risk | Visible; may signal to subject |
Temporary workplace changes | Remote work, schedule modification, relocation | Active investigation period | Temporary; document rationale |
Law enforcement coordination | Welfare checks, criminal history review, protective orders | Imminent or credible threats | Requires legal review before contact |
Record residual risk, the rationale for accepting it, and the re-evaluation date in the risk register for every case. EAP referrals work best when the behavioral health clinician is briefed on the TAT’s concerns before the first appointment.
Pro Tip: Link your workplace violence prevention plan directly to the mitigation plan template so every control maps back to a written policy.
US legal and compliance considerations you cannot skip
Safety obligations do not negate ADA or privacy protections. Balance is required, and the legal rationale must be documented on every case.
ADA: Mental health conditions may qualify as disabilities. Consult legal counsel before taking adverse action based on behavioral concerns. Reasonable accommodation requests must be evaluated separately from threat assessment findings.
Medical information: Keep all medical and EAP records in a separate, restricted file. Do not include clinical information in the general HR file.
Privacy: Limit case file access strictly to TAT members. Document who accessed the file and when.
Union contracts: Review collective bargaining agreements before conducting interviews or imposing workplace changes. Some contracts require union representation during investigative meetings.
Mandated reporting: Healthcare, education, and behavioral health sectors carry sector-specific mandatory reporting obligations. Verify your obligations with legal counsel before closing a case.
External agency coordination: Engage local law enforcement, behavioral health crisis teams, or the FBI’s Interagency Security Committee framework when the threat involves federal facilities or crosses jurisdictional lines.
This guide provides general information, not legal advice. Confirm current obligations with qualified employment counsel and your jurisdiction’s primary regulatory sources.
How to monitor cases and audit your program
Set monitoring cadence by risk zone and record every follow-up action until residual risk reaches an acceptable level.
Risk Zone | Check-In Frequency | Who Checks | What to Record |
Imminent (resolved) | Weekly for 90 days | Case Manager + Security | Behavioral observations, any new incidents |
Elevated | Bi-weekly for 60 days | Case Manager + HR | Mitigation progress, EAP attendance |
Low/Monitor | Monthly for 30 days | Case Manager | No new concerns noted, or escalation trigger |
Closed | Annual review | HR | No recurrence; file archived |
The Texas DWC program standard recommends auditing the overall Workplace Violence Prevention Program at least every two years. Track these program-level metrics: case volume by outcome, median time-to-triage, mitigation-closure rate, and audit findings resolved within 90 days.
Training supervisors and building internal capacity
Train supervisors to spot red flags and follow triage rules. Train TAT members to run structured assessments. These are different skill sets requiring different curricula.
Recommended training by audience:
Frontline supervisors: Annual training covering red flag recognition, triage criteria, initial notification steps, and how to document a concern without conducting an investigation themselves. Frontline safety training should include scripted language for initial conversations.
TAT members: Semi-annual training on pathway-to-violence analysis, interview techniques, risk scoring, and legal compliance. Annual tabletop exercises simulating a realistic case scenario.
All staff: Awareness-level training on reporting procedures and available support resources.
Bring in external specialists when a case involves active planning, weapons acquisition, clinical risk beyond the EAP’s scope, or when legal counsel recommends an independent review. After any critical incident, schedule a supervisor refresher within 30 days.
Practical templates you can adapt today
Template | Key Fields | When to Use |
Triage checklist | Threat specificity, plan, means, timeline, capability, mitigating factors | First 2 hours after intake |
Incident report | Date/time, reporter, subject, description, witnesses, initial classification | Every new report |
Interview note template | Interviewee, date, questions asked, verbatim responses, interviewer signature | All investigative interviews |
Risk register row | Case ID, likelihood score, impact score, treatment zone, owner, re-evaluation date | After risk scoring |
Mitigation plan | Control type, description, owner, deadline, residual risk, acceptance rationale | After TAT analysis |
Store templates in a version-controlled, access-restricted system. Link each template to the corresponding case file so auditors can trace every decision. Prepare templates in both PDF (for signed records) and editable DOCX or CSV formats for active case management.
Key Takeaways
A team-based, documented, and periodically audited workplace threat assessment process is the most defensible and effective approach for US organizations.
Point | Details |
Assemble a multidisciplinary TAT | Include HR, security, legal, behavioral health, and a senior decision-maker with a written charter. |
Follow the six-step workflow | Move from intake through closure with defined timing, owners, and documentation artifacts at each stage. |
Triage by specificity and capability | Imminent threats go to law enforcement first; behavioral concerns go to the TAT and EAP. |
Document everything | Maintain locked case files, decision logs, and a risk register; audit the program every two years per Texas DWC guidance. |
CVPSD training builds capacity | CVPSD offers TAT setup consulting, supervisor training, and tabletop exercises to help organizations implement this process. |
Why the team-based approach is the only approach that holds up
Most organizations treat threat assessment as a reactive HR task. A manager gets a complaint, HR opens a file, and someone decides alone whether to act. That model fails for two reasons: no single discipline has the full picture, and undocumented solo decisions create serious legal exposure.
The FBI’s guidance on TATs exists precisely because behavioral threat assessment requires clinical, legal, operational, and human judgment working together. Dr. Marisa Randazzo’s pathway-to-violence framework reinforces this: violence is rarely spontaneous. There is almost always a behavioral arc, and catching it requires people who know what to look for and a process that keeps them looking.
What gets overlooked in most guides is the mitigating factors side of the equation. Recording what is stabilizing a person, not just what is alarming, produces proportionate responses. An overreaction can itself become a precipitating event.
CVPSD’s evidence-based approach, grounded in the same FBI and Texas DWC frameworks cited here, is built on this principle: calm, structured, multidisciplinary assessment protects everyone, including the person of concern.
CVPSD can help you put this into practice
Building a threat assessment program from scratch takes time, and most organizations need outside expertise to get it right the first time. CVPSD offers in-person and online training for TAT members and supervisors, TAT charter development, tabletop exercise facilitation, and program audit support, all grounded in evidence-based, violence prevention training methods aligned with FBI and Texas DWC guidance.

A typical engagement begins with a program gap assessment, followed by customized training delivery and documentation review. CVPSD works with healthcare, corporate, education, behavioral health, and government organizations across the United States. To schedule a consultation or learn more about available programs, visit cvpsd.org.
Useful sources
Save these links in your program case file for future audits and reference:
FBI Law Enforcement Bulletin: Threat Assessment Teams — Core guidance on TAT composition, functions, and the team-based assessment model.
Texas DWC Workplace Violence Prevention Program — Policy checklist covering program elements, training, recordkeeping, and the two-year audit recommendation.
CISA Risk Management Process Standard (2024 Edition) — Five-step federal risk management methodology for facility security and resource prioritization.
CISA Security Planning Workbook — Practical workbook for threat and hazard identification, on-site inspection, and risk interpretation.
PMC: Assessing Workplace Violence — Methodological Considerations — Peer-reviewed review of structured hazard identification methods and continuous detection systems.
Colorado SEAP Threat Assessment Toolkit — Supervisor training guidance with scripted initial actions and referral pathways.
FAQ
What is a Threat Assessment Team and who should be on it?
A TAT is a multidisciplinary group that evaluates behavioral concerns before they escalate to violence. Core members include HR, security, legal, a senior leader, and a behavioral health or EAP representative, as recommended by FBI guidance.
How long does a workplace threat assessment take?
Initial triage should happen within 2 hours for potential imminent threats. Full analysis and a mitigation plan should be completed within 72 hours where it is safe to do so.
When should you call law enforcement instead of opening an HR case?
Call 911 when a threat is specific, the subject has a plan and means, or there is a stated timeline. Behavioral concerns without those elements go to the TAT and EAP first.
How often should you audit your threat assessment program?
The Texas DWC recommends auditing the Workplace Violence Prevention Program at least every two years. Track case volume, time-to-triage, and mitigation-closure rates between audits.
How can CVPSD help organizations implement a threat assessment program?
CVPSD provides TAT setup consulting, supervisor training, tabletop exercises, and program audit support for healthcare, corporate, education, and government organizations across the United States. Visit cvpsd.org to schedule a consultation.
Recommended






