When the FBI's Behavioral Analysis Unit studied 63 active shooter cases from 2000 to 2013, it found that each attacker had displayed an average of 4.7 concerning behaviors that were observable to the people around them. Someone noticed something in nearly every case. The same study found that in cases where leakage occurred, meaning the attacker communicated intent to a third party, none of the observed instances were reported to law enforcement.
Noticing is rarely where corporate security programs break down. Somebody usually notices. The difficulty comes after that, in whether the observation gets reported at all, who receives it, and whether that person can see it alongside other concerns raised about the same individual over the past two years.
This post covers the behavioral indicators that matter, the ones that get overlooked because they sit outside the employee population, and how open-source intelligence fits into a threat assessment process that can do something useful with them.
The typology developed by NIOSH and used widely across corporate security divides workplace violence into four categories. Each one produces a different set of indicators, which is why programs built around only one category tend to miss the others.
Essentially then, a program that only watches its own workforce is covering one of these four. Type II and Type IV threats arrive from outside the badge system entirely.
There is no profile of a violent employee, and the FBI study is explicit on this point. What exists instead is a set of behaviors that warrant assessment when they cluster and escalate. Any single item on the list below appears in plenty of people who will never harm anyone. The pattern is what carries the signal.
In the FBI sample, 79% of attackers appeared to be acting on some grievance. For 16%, that grievance stemmed from an adverse employment action. A grievance becomes a security concern when it stops being general frustration and acquires a name, a title, or a location.
Leakage was observed in 56% of cases. It includes direct threats, but more often it looks like something else: a comment that a specific manager will 'get what is coming,' a social post about how a former employer will regret a decision, or a joke about an unusually detailed scenario. Leakage is the single most actionable indicator because it is intentional communication.
Problematic interpersonal interactions appeared in 57% of cases. Look for a change in trajectory rather than a snapshot. Conflicts that used to be resolved now recur, involve more people, and shift from disagreement to a grievance narrative.
Declining work performance showed up in 46% of cases. Performance decline on its own is a management issue. Performance decline combined with a belief that the decline was caused by a hostile colleague or unfair supervisor is a different signal.
A person who begins gathering information about a specific individual, learning their schedule, their vehicle, or their home area, has moved from grievance to planning. In the FBI sample, 77% of attackers spent a week or longer planning.
Lawful ownership is not an indicator. New acquisition, a shift in how weapons are discussed, or the appearance of weapons in content directed at a grievance target is a change worth documenting.
Repeated policy violations, refusal to accept supervision, and probing of access controls or after-hours entry all indicate someone testing what the organization will tolerate.
Most indicator lists are written for HR, which means they cover current employees and stop there. Security teams also have to account for people who never appeared on the payroll, or who left it years ago.
A grievance can outlast the job by years. Someone who felt their termination was unfair may still be carrying it long after the exit interview, and the day their badge gets deactivated is the day the company stops hearing about them. Managers no longer see them, and HR no longer takes reports. From that point, the only thing anyone can observe is what the person chooses to post publicly.
Customers, patients, tenants, litigants, and unsuccessful job candidates all generate grievances against organizations. These signals tend to sit in customer service logs, legal correspondence, and public review platforms, where security teams rarely look.
The observable indicators usually come from the victim. You may see: an employee requesting a parking reassignment, unexpected visits to the lobby, a protective order that names the worksite. Cal/OSHA's plan requirements and most duty of care frameworks treat this as within scope.
Increased absenteeism on a specific team, requests to transfer away from one individual, or reluctance to be scheduled alone with someone often precede any formal complaint. People adjust their behavior around a perceived threat before they report it.
A concern that was investigated, deemed unsubstantiated, and closed is not the same as a concern that resolved. Without a scheduled review, the file becomes invisible while the underlying grievance continues.
The performance write-up sits with HR. The demand letter from the terminated employee sits with legal, the odd after-hours badge activity with IT, and the parking lot argument with facilities. Nobody holding one of those pieces has much reason to call security about it on its own. They only mean something next to each other, and that is hard to arrange when they live in four separate systems.
Open-source intelligence contributes to workplace violence prevention by covering observation gaps that internal systems cannot reach, including, but not limited to, former employees, non-employee actors, and public expressions of grievance that have not yet been reported internally.
Effective collection begins with defined requirements rather than broad monitoring. A workable set of collection requirements for a workplace violence program includes:
Requirements like these work best when written down and reviewed quarterly with HR, legal, and privacy teams. Documented scope is also what allows a program to answer the inevitable question about what it collects and why.
Most of the difficulty comes after the alert lands, in the days between finding something and deciding what to do about it.
An anonymous post that names one of your buildings is a lead and not much else. Somebody has to establish that the account belongs to a real person with a real connection to the organization before it goes any further. Identity resolution matters at this stage because escalating on a misidentified account can cost the wrong person their job.
Validated instruments such as WAVR-21 give a threat management team a common language and a defensible record. Structured assessment also protects against the two failure modes analysts know well, which are dismissing a credible concern because the person seems unremarkable, and overreacting to crude language from someone with no capability or intent.
A single analyst should not carry an assessment decision. Multidisciplinary threat management teams that include security, HR, legal, and counsel are the accepted model precisely because these cases require judgment from several disciplines at once.
Everything gathered on a case belongs in one file with a documented rationale, a decision log, and a scheduled review date. A case manager who holds the full timeline is what allows the next analyst to pick up a two-year-old concern and understand where it sat when it was last reviewed.
A closed case usually reveals which sources produced value and which produced noise. That knowledge should update the collection requirements.
The runway is longer than most people assume. In the FBI study, the first observable concerning behavior occurred at least three months before the attack in roughly 90% of cases, and at least two years before in more than half. Attackers move through a process of grievance, ideation, planning, preparation, and action, and that process leaves observable traces at multiple points.
Intervention early in that sequence also has more options available to it. A grievance that surfaces at the ideation stage can sometimes be addressed through mediation, an EAP referral, a schedule change, or a documented conversation. Once someone has begun preparation, the available responses narrow to protective measures and law enforcement referral. BLS Census of Fatal Occupational Injuries data recorded 470 workplace homicides in 2024, with the majority involving a firearm, which is a reminder of how little margin the late stages leave.
Early intervention also produces better outcomes for the person of concern. The majority of these cases resolve without termination or arrest when someone notices and engages while the situation is still workable.
Indicators are only useful inside a program that can receive, assess, and act on them. The components that consistently distinguish mature programs:
The behaviors described throughout this post were visible in nearly every case the FBI examined. Building the connective tissue that lets an organization see them together, assess them consistently, and act on them early is the work that prevention actually consists of.
Liferaft gives security intelligence teams visibility into publicly available information that relates to a defined security concern. Teams use it to listen for grievance and threat language tied to their facilities, brands, and named personnel, to search deep and dark web sources where grievance content often surfaces first, to resolve online personas to real-world individuals during an investigation, and to keep the full timeline of a case in one record that a threat management team can work from. It supplements internal behavioral observation rather than replacing it, and it provides no covert access to private accounts, messages, devices, or location data.
Open-source intelligence is information collected from publicly available sources and then analyzed to answer a specific question. In a corporate security context that includes social media, forums, news, public records, court filings, review platforms, and deep and dark web sources. The intelligence part is the analysis: raw public data becomes OSINT once it has been corroborated, assessed, and connected to a security requirement.
Corporate security teams apply the same collection and analysis discipline to executive protection, travel risk and duty of care, event and site security, brand and impersonation monitoring, insider risk, exposed credential detection, and geopolitical situational awareness. Most programs find that requirements built for one use case support several others.
Individual acts of violence cannot be predicted, and no reputable practitioner claims otherwise. Prevention is nonetheless achievable at the program level, because the pathway to violence unfolds over time and produces observable behavior along the way. Organizations that can collect those observations, assess them consistently, and intervene early do interrupt cases. The evidence base for threat assessment as a discipline rests on exactly that.