How Do You Stop Security Overtime Creep Before It Eats Your Margin?
How security overtime creep eats contract margin, the math behind it, and how to catch unplanned OT before payroll closes. Fixes that actually hold.
Overtime creep is unplanned OT that accumulates in small, invisible increments — the same reliable guards volunteering for open shifts, schedules drifting from what was bid, and nobody seeing actual hours until payroll closes. On a fixed-bill contract, time-and-a-half comes straight out of margin, and a handful of chronic OT hours can erase most of a site's profit. The fix is detection before payroll (scheduled-vs-actual variance alerts, weekly OT pacing) plus structural changes: a real float pool, current availability data, and fair distribution of open shifts.
Nobody decides to blow the overtime budget. It happens eight hours at a time, filled by whoever answered the phone, discovered three weeks later when payroll runs and the site P&L quietly gets worse. That's overtime creep — and in an industry where contracts are bid at fixed rates, it's one of the most common ways a profitable contract turns into a break-even one without anyone making a single bad decision.
How Does Unplanned Overtime Happen in a Security Company?
Three mechanisms:
1. Open shifts filled by the same volunteers. A guard calls off. The scheduler needs the post covered in four hours. Who gets called? The reliable ones — the guards who always say yes. But your most reliable people are usually already at or near 40 hours, so every emergency fill lands as time-and-a-half. With industry turnover commonly cited at 100%+ annually, there's a constant supply of call-offs and a thin bench of people you trust to cover them. So OT concentrates on five or six names, month after month.
2. Schedule drift. The contract was bid on a coverage model — say, 168 hours a week across four guards. Then reality arrives: a guard quits, a client adds a temporary post that becomes permanent, shift boundaries stretch ("stay until the relief shows up"). Twelve weeks later, the live schedule no longer resembles the one the price was built on, and nobody has compared them since the contract started. Drift is a scheduling-discipline problem before it's an overtime problem — our security guard scheduling guide covers the upstream half.
3. No real-time visibility. This is the enabler for the first two. If actual worked hours only become visible when timesheets are processed, every OT decision is made blind and every OT discovery is retroactive. By the time payroll closes, the money is spent, the guard is owed it (correctly — federal law under the FLSA requires the premium for hours over 40), and the only available response is a stern email about next month.
What Does Overtime Creep Actually Cost? The Margin Math
Walk one week at one post with typical US commercial numbers — guard billed at $28/hour, paid $18/hour:
| Straight time | With 8 OT hours | |
|---|---|---|
| Hours billed to client | 40 @ $28 = $1,120 | 40 @ $28 = $1,120 |
| Wage cost | 40 @ $18 = $720 | 32 @ $18 + 8 @ $27 = $792 |
| Gross margin before burden | $400 (35.7%) | $328 (29.3%) |
Eight OT hours — one covered shift — cut this post's gross margin by $72, about 18% of the week's profit, and the client's bill didn't move a dollar. Layer on payroll taxes and workers' comp (which scale with wages) and the real hit is worse. Now run it at company scale: if chronic creep averages even 4 OT hours per guard per week across 50 guards, that's roughly $1,800 a week in pure premium cost — north of $90,000 a year — coming entirely out of margin on fixed-bill contracts — the difference between a healthy year and a flat one, hiding inside individually reasonable staffing decisions. It's the payroll-side sibling of the billing leaks covered in security company revenue leakage.
The insidious part: bill rates in the $25–35/hour range typically price in single-digit percentage OT. Creep doesn't announce itself when it crosses that line. Detection has to be built, not assumed.
How Do You Catch Overtime Before Payroll Closes?
The entire game is moving detection from after payroll to during the week. Two mechanisms:
Scheduled-vs-actual variance alerts. Every shift has a scheduled length; every guard has a scheduled week. When actual punches diverge — a shift running long, a guard picking up hours that push their weekly total past a threshold — someone should know that day, not at payroll close. GPS-verified clock-in and clock-out makes the "actual" side trustworthy; if punch data is guesswork, so is everything downstream (this is the same data foundation as GPS-verified clock-in with geofencing).
Weekly OT pacing views. A dashboard answering, every day: who is on pace to cross 40 this week? A guard at 34 hours by Wednesday night is a flag — while there's still time to give Thursday's open shift to someone at 22 hours instead. Pacing turns OT from a payroll-report line item into a live dispatch input.
At Ranger Guard — 400+ employees across Houston, Corpus Christi, Las Vegas, and Florida — moving hours visibility into the live week changed the scheduler's default question from "who will say yes?" to "who can take this without going over?" The overtime that survives is the OT we chose — coverage emergencies worth paying a premium for — instead of OT we discovered — which is the practical definition of solving creep.
The pre-payroll review itself is short once the data exists: a standing 15-minute weekly look at variance by site and OT by guard, before the period locks. Fixing a miscoded shift or catching a drifting site costs minutes on Wednesday and real money on the following Friday.
What Structural Fixes Prevent Overtime Creep Long-Term?
Alerts catch creep; structure prevents it.
- Build a real float pool. The volunteer-concentration problem is a bench problem. Designate and train floaters — part-timers and guards who want more hours — cleared for your major sites (post orders acknowledged in advance, so an unfamiliar site isn't a barrier). A floater at 25 hours covering a call-off costs straight time; your star at 42 hours costs time-and-a-half and burnout.
- Keep availability data current. Most schedulers call the same names because they don't actually know who else could work. Collected-once-at-hire availability is fiction within months. Make updating availability a live, guard-driven process, and the pool of straight-time options gets visible.
- Distribute open shifts fairly. Broadcast open shifts to everyone qualified and under-hours rather than phone-tree-ing the usual five. This spreads hours (cutting OT), spreads income (guards who want hours get them), and reduces the burnout-quit cycle on your most reliable people — who are exactly the ones you can least afford to lose at 100%+ industry turnover.
- Re-baseline drifted sites quarterly. Compare each site's live schedule to its bid model. Where drift is client-driven — added posts, stretched shifts — that's not an OT problem, it's an unbilled scope change: a pricing conversation backed by your coverage records.
One caution: never manage OT by shaving worked time or discouraging accurate punches. Besides being an FLSA violation with real exposure, it destroys the trustworthy punch data the whole detection system depends on. This is general information, not legal or financial advice — verify wage-and-hour requirements with your attorney, including state rules (some states, like Nevada, have daily overtime provisions).
If you're finding out about overtime at payroll close, book a demo and we'll show you the pacing and variance views Ranger Guard's schedulers use during the live week — priced per scheduled hour, so watching your hours doesn't cost extra per user.
Keep reading
How Many Guards per Supervisor Is the Right Ratio?
How many guards per supervisor is right? Common field ratios, the windshield-time problem, and how remote visi…
How Do You Get Real Night Shift Security Guard Accountability?
Night shift security guard accountability without burning out your team: randomized checkpoints, missed-scan a…
What Does Security Payroll Integration Actually Mean?
What security payroll integration actually means — exports vs. API sync, ADP mapping, and what to verify befor…