Research · 5 min read
Raw Alert Volume Is a Sensor Metric. The Real Number Is 11.72%.
A useful monitoring scorecard distinguishes raw alerts, reviewed alerts, incident-linked alerts, and distinct incidents.
64,800 alerts in six months sounds like a flood of crime. It isn’t — and any monitoring provider quoting raw alert volume is counting on you not asking what happened next. Follow 100 alerts through our pipeline: 78 never need a human, 20 get dismissed by one, and fewer than 3 become incidents. Change the denominator and the same data tells a four-times-different story.
Our analysis of 64,800 alerts, January 1 through June 30, 2026.
Key takeaways
- Every 100 raw alerts produced 77.75 automatic filters, 19.64 human dismissals, and only 2.61 incident records.
- Raw conversion is 2.61%, but among alerts that reached human review it was 11.72% — the denominator changes the story by more than four times.
- 1,690 incident-linked alerts consolidated into 1,076 distinct incidents: 1.57 alerts per incident and 60.22 raw alerts per distinct incident.
- Raw alert volume measures sensor sensitivity, not operational workload. Four separate units belong on every monitoring dashboard.
Why is raw alert volume a misleading measure of monitoring workload?
Across 64,800 alerts recorded from January through June 2026, every 100 alerts produced 77.75 automatic filters, 19.64 human dismissals, and only 2.61 incident records. Raw conversion is 2.61%, but among alerts that actually reached human review it was 11.72% — and 1,690 incident-linked alerts consolidated into 1,076 distinct incidents. The denominator decides the story.
The numbers behind the answer
Selected measures only. Denominators and interpretation stay attached so the headline cannot stand alone.
77.75
Automatically filtered per 100 alerts
50,382 of 64,800 raw alerts ended at the automatic-filter stage.
11.72%
Reviewed alerts creating an incident
1,690 of 14,418 alerts in the human-review cohort created an incident record.
1.57
Incident-linked alerts per distinct incident
1,690 incident-linked alerts consolidated into 1,076 distinct incidents.
What happens to 100 raw security alerts
Take 100 raw alerts. 77.75 die at the automatic filter — duplicates, noise, obvious nothing. Of the 22.25 that reach review, 19.64 get dismissed by a person. 2.61 create an incident record. Raw volume, it turns out, mostly measures how twitchy the sensors are.
The second denominator is where the workload lives. Among alerts that actually reach review, 11.72% create an incident — a very different picture from the 2.61% raw conversion. A dashboard quoting only the raw number is describing the sensors, not the review team.
In absolute terms, the six months contained 64,800 raw alerts. The automatic filter absorbed 50,382; 14,418 reached a person; and 1,690 of those created an incident record. So roughly a fifth of all alerts consumed human attention, and about 2.6% survived the entire pipeline to become a case. Those are the numbers a staffing conversation should start from.
Evidence visual
Disposition of every 100 raw alerts
The three stages are mutually exclusive final alert outcomes. “Human dismissed” is not labeled a false alarm because the outcome alone does not establish ground truth.
1,690 incident-linked alerts became 1,076 distinct incidents
One more unit change before the counts mean anything. An alert is a sensor event; an incident is the operational record a reviewer creates. One unfolding situation — somebody working a gate for two minutes — can fire several alerts. In this cohort, 1,690 incident-linked alerts consolidated into 1,076 distinct incidents: 1.57 alerts per incident, and 60.22 raw alerts per distinct incident.
Count linked alerts as separate incidents and you’d overstate case volume by half. These ratios describe the pipeline’s shape. They don’t establish detection accuracy, and they don’t say whether staffing is right.
The per-distinct-incident figure is the one to hold onto: 60.22 raw alerts for every case. That is the true noise-to-signal ratio of the detection layer, and it is also the honest way to describe volume. Saying “we processed 64,800 alerts” and saying “we opened 1,076 cases” are both true and describe a pipeline whose endpoints differ by a factor of sixty.
Dashboard rule
Keep raw alerts, reviewed alerts, incident-linked alerts, and distinct incidents as separate units.
Four units that should stay separate
The pipeline only makes sense if four units stay distinct. A raw alert is a sensor event. A reviewed alert is one a person looked at. An incident-linked alert is one a reviewer judged worth attaching to a new incident. A distinct incident is the operational case record itself — and several alerts can attach to one. Collapsing any pair inflates or deflates the apparent workload, usually in a direction that flatters the vendor.
Here is why it matters in one comparison. Raw conversion — incidents per 100 raw alerts — is 2.61%. Review conversion — incidents per 100 alerts that reached a human — is 11.72%. Neither number is wrong; they answer different questions. The first describes the detection layer’s relationship to action. The second describes what a reviewer’s time actually yields. A provider that quotes only the first is answering the question that makes the sensor look clean.
A useful monitoring scorecard reports the work between detection and action
Each stage answers a different question. Raw alerts: how noisy is the detection layer? Reviewed alerts: how much human work did it take? Review-to-incident yield: what survived scrutiny? Distinct incidents: how many actual cases were there? Alerts per incident: how well does consolidation work?
Two things this aggregate can’t tell you: which sensor source converts best — that needs source-by-stage denominators, not raw source totals — and whether reviewer staffing is adequate, which needs review duration, arrival patterns, and concurrency. The checklist below is the buyer’s version.
The staffing gap is the one buyers most often skip. This cohort shows how many alerts reached a human, but not how long a review took, whether reviews arrived in bursts, or how many ran at once. A pipeline can look healthy at the stage level and still fail on a Monday morning when a third of the day’s alerts land in twenty minutes. Ask for the arrival and duration distributions, not just the totals.
- How many raw alerts entered the system?
- How many required human review?
- How long did review take?
- How many alerts linked to distinct incidents?
- How do stage rates vary by source and month?
22.25 of every 100 alerts land on a person, and that stage decides the outcome
The funnel’s middle stage is where the counts concentrate. Of 64,800 raw alerts, 50,382 died at the automatic filter — 77.75 per 100 — and 14,418 reached a human, 22.25 per 100. Review then dismissed 19.64 per 100 and created an incident for 2.61. Put differently, the review cohort carried all 1,690 incident-linked alerts out of 14,418: an 11.72% yield that no raw-alert percentage reveals.
That middle stage is not waste; it is where the system decides what the sensors got right. Research on semi-automated surveillance shows why the work is hard — operator vigilance, reliance, and workload shift with system confidence and task complexity, and reviewers can over-trust an imperfect detector exactly when it is wrong.
Alert systems also have a documented history of drowning reviewers. Government analysis of false burglar alarms found false activations consumed a large share of police capacity, the same failure mode a monitoring pipeline faces when its filter is too loose. So put review volume, not raw volume, on the scorecard — a pipeline can look healthy in totals while failing the morning a third of the day’s alerts land at once and threaten the coverage a property depends on.
Design point
Filtering is a sensor setting; review capacity is an operational one. Report both.
Questions property teams ask
Does human dismissed mean a false alarm?
No. It means review did not create an incident record; the stage alone does not establish ground truth.
Does 2.61 per 100 mean only 2.61% of alerts were real?
No. It is the share that created incident records. Reality, relevance, and the operational incident threshold are different concepts.
Why do 2.61% and 11.72% both appear?
They use different denominators. 2.61% is incidents per 100 raw alerts; 11.72% is incidents per 100 alerts that reached human review. The review cohort is the workload that matters.
What does 60.22 raw alerts per incident mean?
For every distinct incident record, 60.22 raw sensor events entered the pipeline. It is the honest noise-to-signal ratio of the detection layer.
Can these totals determine reviewer staffing?
Not by themselves. Staffing requires arrival patterns, review duration, concurrency, service levels, and escalation workload.
Which alert source converts best?
The source-by-stage calculation is required for that comparison. Raw source totals alone are not conversion rates.
Why does review workload matter more than alert volume?
Because a person has to act on reviewed alerts, and research on surveillance operators shows vigilance and reliance degrade under load. A high-volume, low-filter pipeline can overwhelm review exactly when it matters.
Our methods, limits, and sources
How we calculated this
This is original 911 Sentinel research — we gathered the records, ran every calculation below, and published the aggregate dataset.
We exported our own alert records, assigned each alert to one final stage, calculated a per-100-alert funnel, isolated the human-review cohort, and deduplicated linked incident IDs.
- We validated alert timestamps, source, stage, and any incident link.
- We counted automatic-filter, human-dismissed, and incident-created outcomes across 64,800 alerts.
- We calculated raw-alert and reviewed-alert conversion rates with explicit denominators.
- We counted 1,076 distinct linked incidents and derived alerts per incident and raw alerts per incident.
- We summarized source-stage and monthly patterns.
What this analysis cannot establish
- Reached human review is inferred from final stage rather than a dedicated review-start event.
- Review timing is not captured as a distinct event; review volume is inferred from final stage outcomes.
- A human-dismissed alert is not automatically a confirmed false alarm.
- Source volume alone cannot establish source-specific effectiveness.
- Several alerts can link to one incident.
- The aggregate cannot determine whether reviewer staffing is adequate without duration and arrival distributions.
Sources
The raw records come from the sources below; the study design, analysis, charts, and conclusions are our own.
- Noushin Dadashi, Alex W. Stedmon & Tom P. Pridmore (Applied Ergonomics) — Semi-automated CCTV surveillance: The effects of system confidence, system accuracy and task complexity on operator vigilance, reliance and workload
- U.S. Department of Justice, Office of Justice Programs (Problem-Oriented Guides for Police) — False Burglar Alarms, 2nd Edition (Problem-Specific Guide Series)
Related questions and practical guides
No obligation · free property walk
Define the alert-to-action scorecard before comparing systems
The operating model should make filtering, verification, incident creation, response, and reporting separate and inspectable stages.