Honeybadger Solutions LLC

Preventing the Unthinkable: A Guide to Workplace Violence Prevention

Multidisciplinary threat assessment team reviewing a workplace violence case

A workplace violence prevention program is a documented system — a multidisciplinary threat assessment team, defined reporting channels, behavioral threat criteria, and physical and policy controls — that identifies escalating risk before it becomes an incident and gives an organization a lawful, coordinated way to intervene. Under the OSHA General Duty Clause, employers already carry a legal obligation to address recognized workplace violence hazards; the organizations that do this well treat it as an operational discipline, not a one-time policy memo.

Most workplace violence events are not sudden. Behavioral threat assessment research — the body of work behind the FBI’s and U.S. Secret Service’s approach to targeted violence — has consistently found that attackers typically move through an observable progression of grievance, ideation, planning, and preparation before an attack occurs. That progression is exactly what a well-run prevention program is built to interrupt. This guide is written for the executives, general counsel, HR leaders, and security directors who own that responsibility: how to structure a threat assessment team, what the OSHA General Duty Clause actually requires, how to read warning behaviors without diagnosing anyone, how to build a reporting culture people actually use, and how to plan the investigation and response before you ever need it.

Why does workplace violence prevention belong on the executive agenda?

Workplace violence sits at the intersection of employee safety, legal exposure, and business continuity — which is precisely why it can no longer live solely inside HR’s employee-handbook binder. A serious incident carries the direct human cost, then a second wave of consequence: OSHA scrutiny, wrongful-death and negligent-retention litigation, D&O and general-liability exposure, regulatory reporting obligations, and reputational damage that outlasts the news cycle. Boards and general counsel increasingly ask a direct question after any high-profile industry incident: could we show, in writing, that we had a functioning threat assessment process before this happened? Organizations that can answer yes are in a fundamentally different legal and operational position than those relying on an informal “someone would have said something” assumption.

A mature program also pays a quieter dividend: it catches the far more common lower-severity events — domestic-violence spillover into the workplace, a terminated employee’s escalating contact, a customer or client fixation, an intimate-partner stalking situation — long before they reach the threshold that makes headlines. The infrastructure is the same whether the outcome you’re preventing is catastrophic or merely disruptive.

What does the OSHA General Duty Clause actually require?

With the exception of specific standards for healthcare and social-service settings, OSHA has no single dedicated workplace-violence regulation. What it has instead is broader and, in practice, harder to argue around: Section 5(a)(1) of the Occupational Safety and Health Act — the General Duty Clause — requires every covered employer to furnish a workplace “free from recognized hazards that are causing or likely to cause death or serious physical harm.” Workplace violence is explicitly treated by OSHA as a recognized hazard in industries with elevated risk indicators, and General Duty Clause citations have been issued against employers who knew of a violence risk (prior incidents, threats, documented complaints) and failed to take feasible abatement steps.

The practical implication for counsel and risk leadership: “recognized hazard” is established through what the employer knew or should have known — prior incidents, employee complaints, industry data, insurer bulletins. That means the legal exposure question is not “did we have a policy,” it’s “did we have a functioning system that would have surfaced and acted on the warning signs available to us.” A written policy nobody follows is not a defense; a documented, exercised threat assessment process is.

How do you structure a multidisciplinary threat assessment team?

The threat assessment team (TAT) is the operational core of the program — the standing body that receives reports, gathers facts, assesses risk, and decides on intervention. A credible TAT is deliberately cross-functional because no single department has the full picture or the full authority to act:

  • Human Resources — employment history, performance context, disciplinary record, and the authority to manage employment actions.
  • Legal / Compliance — privacy, disability, and labor-law constraints; documentation standards; privilege considerations.
  • Security leadership — physical risk assessment, protective measures, and liaison with law enforcement.
  • A qualified behavioral consultant — a licensed threat assessment or forensic psychology professional retained to evaluate risk indicators; never an in-house manager “diagnosing” a colleague.
  • A senior business sponsor — an executive with the authority to approve leave, restricted access, or separation decisions without delay.

The team needs a standing charter, a defined case-intake process, documented meeting cadence (regular case review plus an emergency-convening protocol), and a case-management log that is treated as attorney-work-product where appropriate. Ad hoc committees assembled only after something happens are, by definition, too late — and they tend to produce exactly the kind of inconsistent, undocumented decision-making that becomes a liability exhibit later.

What is the “pathway to violence,” and how should warning behaviors be read?

Modern behavioral threat assessment does not rely on personality profiling or predicting who is “capable” of violence — that approach has been repeatedly discredited. Instead it tracks behavior over time against a generic progression widely used in threat assessment training: grievance, ideation, research and planning, preparation, and — in a small fraction of cases that escalate all the way — approach and attack. The value of the framework is not diagnostic; it’s a shared vocabulary that lets a threat assessment team ask, “where does this specific, observed behavior sit on this progression, and what does that call for?” instead of relying on gut instinct.

Consistent with that discipline, this guide describes categories of observable behavior, never a checklist for labeling a person. The same behavior can mean very different things depending on context, and a team’s job is to gather facts, not assign a diagnosis.

Pathway stageIllustrative observable behaviorOrganizational response
GrievancePersistent, escalating fixation on a perceived injustice (termination, denied promotion, a dispute)Document the report; open a low-level case file; monitor for escalation
IdeationVerbalized or written references to violence as a solution, even framed as a “joke”Immediate TAT review; behavioral-consultant consult; no unilateral dismissal of the report
Research & planningInquiries about a target’s schedule, access, or security; researching weapons or tacticsEscalate to security leadership and, where warranted, law-enforcement liaison
PreparationAcquiring means (weapons, tools), rehearsing, or making final arrangements (financial, communications)Immediate protective action: access restriction, law-enforcement notification, protective order support
Breach / attackApproaching a target or the facility with intent to actEmergency response, lockdown/evacuation protocol, law enforcement

Two disciplines matter more than the framework itself. First, base rates: most people who make a threatening or troubling statement never act on it, and treating every statement as an emergency erodes trust and chills reporting. Second, escalation and specificity matter far more than a single data point — a specific plan, a named target, and access to means is a fundamentally different case than a vague, unspecific complaint. The team’s job is to weigh the whole picture, not react to any one behavior in isolation.

How do you build a reporting culture that people actually use?

A threat assessment team is only as good as what reaches it. Employees consistently under-report concerning behavior for three predictable reasons: they doubt anything will happen, they fear retaliation against the person they’re reporting, or they fear retaliation against themselves. A functioning reporting culture is designed against all three:

  1. Multiple, redundant channels. A direct line to the TAT, an anonymous tip line, HR, and direct-manager escalation — never a single point of failure.
  2. A published “see something, say something” standard that is behavior-based (“threats, weapons, stalking, escalating conflict”) rather than vague, so employees know exactly what qualifies.
  3. Visible closure of the loop. Reporters who never hear anything back stop reporting; a documented (and appropriately confidential) acknowledgment matters even when details can’t be shared.
  4. A hard non-retaliation commitment, enforced and communicated, because fear of retaliation is the single largest suppressor of reporting in every workplace-violence survey and case study on record.
  5. Manager training so first-line supervisors — who see the earliest behavioral changes — know they are a conduit to the TAT, not the decision point.

Training is the multiplier here. A policy nobody has heard of protects no one; annual, scenario-based training that walks employees through realistic (never real-client) examples of what to report and how is what actually changes behavior.

Corporate access control and visitor management checkpoint operations

Which policy and physical controls actually reduce risk?

Behavioral threat assessment and physical security are two halves of the same program — a perfect reporting culture with an unlocked lobby, or a hardened facility with no one watching for behavioral escalation, both fail. The controls that consistently matter:

  • Access control and credentialing — badge-restricted entry, controlled after-hours access, and immediate credential deactivation on termination (a step that fails more often than any other control on this list).
  • Visitor management — sign-in with ID verification, pre-registered guest lists, escort requirements, and a documented process for denying entry to a specific individual once a protective order or internal restriction is issued.
  • De-escalation and conflict-management training for front-line staff, security officers, and managers — practical skills for reading escalating agitation and slowing a situation down before it becomes physical.
  • Duress and panic-alert systems — silent alarms at reception, HR, and high-risk points of customer contact, tied to a documented response protocol.
  • Termination and separation protocol — a coordinated sequence (security awareness, access removal timed to the meeting, a safe location, an escort plan) for any separation flagged as elevated risk by the TAT.
  • Protective-order support — a defined process for employees who obtain a civil protective order against a person who could appear at the workplace, including facility-level notification and photo/description sharing with front-line staff where legally appropriate.

None of these controls work in isolation, and none of them substitute for the behavioral threat assessment discipline above — a badge reader does not evaluate a grievance. What separates a mature program is that these physical and policy controls are calibrated to the TAT’s risk findings, not applied uniformly and hoped for the best.

How should you plan investigation and response before you need it?

The worst time to design an investigation and response protocol is during an active case. A response plan drafted under pressure, with no rehearsal and no pre-cleared decision authority, produces slow, inconsistent, and legally exposed decisions. A response plan built in advance does the opposite:

  1. Pre-designate decision authority. Name, in writing, who can approve administrative leave, access suspension, an emergency separation, or a law-enforcement referral without waiting for a full committee to convene.
  2. Define the fact-finding standard. Interviews, document review, and — where appropriate — a retained behavioral consultant’s assessment, all documented contemporaneously and consistently.
  3. Map the legal overlay before a case exists. ADA, FMLA, workers’ compensation, and state-specific leave and privacy laws all intersect with threat assessment; legal review at case intake, not after a decision is made, prevents the single most common process failure.
  4. Build the law-enforcement liaison relationship in advance. Know which agency, which unit, and which contact handles workplace threat referrals in each jurisdiction you operate in — not during the call itself.
  5. Rehearse the emergency protocol. Lockdown, evacuation, and notification procedures should be exercised on a real cadence, not filed away after a single tabletop.
  6. Plan the post-incident sequence. Employee support (EAP activation), stakeholder and, if required, regulatory notification, a documented after-action review, and program adjustments based on what the case revealed.
  7. Preserve the record. Every case — closed, escalated, or ongoing — is documented to a standard that would hold up if the file were ever produced in litigation or to a regulator.

This is also where outside expertise earns its keep. An internal HR or security team, however capable, rarely runs enough of these cases to have deep pattern recognition across grievance dynamics, targeted-violence indicators, and legal exposure simultaneously — which is exactly why organizations retain outside threat assessment and investigative specialists to either run the case directly or advise the internal team in real time.

What separates a world-class program from a checkbox policy?

Mediocre programs have a policy document. World-class programs have a tested system: a chartered, cross-functional threat assessment team that actually meets; a reporting culture employees trust enough to use before a situation is severe; physical and access controls calibrated to real risk findings rather than generic templates; a pre-built, legally reviewed investigation and response protocol; and a documented record that demonstrates, credibly, that the organization recognized the hazard and acted on it — the exact standard the OSHA General Duty Clause and negligent-retention case law both test for. The difference shows up long before any incident: in faster, more consistent case handling, in employees who actually report early-stage concerns, and in a legal posture that can withstand scrutiny rather than merely assert good intentions.

Honeybadger Solutions supports this work nationwide as an in-house consulting and investigative capability: threat assessment team design and training, workplace violence policy development, behavioral-threat case consultation, and investigation support for HR and legal teams managing an active concern. Organizations building or auditing a program should also review CISA’s guidance on active-shooter and workplace security preparedness as a companion resource to internal policy work. For organizations that also need the physical layer — access-control assessments, executive protection, or licensed on-site security personnel — our security services and security consulting teams design and, in Arizona, directly staff those protective measures with our own in-house, state-licensed personnel; where a matter requires licensed field investigation — background verification, threat-subject due diligence, or incident investigation — our investigations team handles that work in-house as well.

Frequently asked questions

Does OSHA require a written workplace violence prevention program?

Outside of specific healthcare and social-service-setting standards, OSHA does not mandate a single dedicated workplace-violence rule for most employers. It applies the General Duty Clause instead, which requires employers to address workplace violence as a “recognized hazard” once they know or should know about the risk. In practice, a documented, functioning prevention program is the strongest evidence an employer can produce that it met that duty.

Who should sit on a workplace threat assessment team?

A credible team is multidisciplinary: Human Resources, Legal/Compliance, security leadership, a retained behavioral or forensic threat assessment consultant, and a senior business sponsor with authority to approve leave, access restrictions, or separation without delay. No single department should own threat assessment alone, and no manager should attempt to evaluate risk without a qualified consultant involved.

What is the “pathway to violence,” and is it used to label employees?

It’s a generic behavioral-progression framework — grievance, ideation, research and planning, preparation, and, rarely, attack — used by threat assessment professionals to evaluate specific, observed behavior over time. It is not a personality profile and is never used to diagnose or label an individual; its only purpose is to help a team calibrate response to the severity and specificity of documented conduct.

How do we get employees to actually report concerning behavior?

Provide multiple reporting channels including an anonymous option, publish a clear behavior-based reporting standard, close the loop with reporters wherever possible, and enforce a strict non-retaliation policy. Fear of retaliation and doubt that anything will happen are the two most common reasons employees stay silent — both are addressable through policy, training, and visible follow-through.

About Honeybadger Solutions

Honeybadger Solutions is an Arizona-licensed security and investigations firm providing workplace violence prevention consulting, threat assessment, and licensed investigative support nationwide, alongside in-house security operations. In Arizona, protective measures — armed and unarmed guards, executive protection, and on-site security — are staffed directly by our own state-licensed personnel; outside Arizona, we command a vetted field-partner network to extend that same standard of coverage nationally.

Three offices: Casa Grande (headquarters), Phoenix, and Oro Valley.
Call: 602-725-2818

This article is educational and not legal advice. Workplace violence prevention obligations, including OSHA General Duty Clause application and state-specific requirements, vary by jurisdiction and industry; consult qualified legal counsel and a licensed threat assessment professional for your specific program.