A single HyperQ AI Safety deployment connecting to an existing estate-managed CCTV backbone can partition evidence by tenant zone, generating per-tenant safety records from the same camera feed without giving any tenant visibility into another's zone. That architecture exists because most shared industrial estates in Singapore and Malaysia run a pooled, ungoverned camera estate with no prior governance assigned to it.
The governance gap is not primarily a technology problem. It is a contract problem that technology can solve once the contract terms are agreed. On a shared estate hosting three to six tenants with overlapping subcontractor populations, the same camera captures incidents that multiple safety managers will each be asked to account for. Without prior agreement on who owns which footage, who can request exports, and what triggers evidence preservation, the post-incident conversation starts adversarially and stays that way.
The accountability split in practice
A shared industrial estate in Johor or at Singapore's Jurong Island typically hosts three to seven active operators. Each runs its own subcontractor population: maintenance firms, equipment vendors, cleaning crews, and periodic turnaround teams. Those subcontractors cycle across tenants within the same week. A hot-works crew finishing a scope for tenant A on Tuesday may be working under tenant B's permit by Thursday.
When an incident occurs near a zone boundary or in a shared corridor, the accountability sequence follows a predictable pattern:
- The incident involves a worker who entered through the estate's shared gate, registered with one tenant's contractor roster, and was performing work scoped under another party's permit.
- The estate manager and the relevant tenants each produce contractor logs. The injured worker does not appear on either list as currently authorized for the location where the incident occurred.
- CCTV footage covering the location exists. The estate manager claims the tenant must authorize release for zone footage. The tenant says the corridor was a common area. The sub-tier employer who provided the worker is not on-site and cannot authorize anything.
- The investigation stalls for weeks on the evidence question, not the incident question.
Singapore's Workplace Safety and Health Act places occupier duties on the party controlling the premises under Section 11. Malaysia's Occupational Safety and Health Act 1994 creates parallel coordination obligations on principal parties at multi-employer sites. Neither framework resolves who owns footage on a shared estate — which is exactly the question investigators and enforcement officers will ask.
What "shared eyes, private walls" means operationally
The workable architecture for shared estates is a single physical camera network with logical evidence partitions that isolate each tenant's zone data while maintaining a coherent common-area record for the estate manager.
"Shared eyes, private walls" means:
- One camera backbone, one storage infrastructure
- Zone boundaries defined in the analytics configuration, not in hardware — adjustable as tenancies change
- Zone footage assigned to a tenant is accessible to that tenant and to the estate manager for incident investigation; no other tenant can access it
- Common-area footage is accessible to all parties for events involving their own authorized personnel; each party sees only the events that relate to them
- Incident evidence packages are generated automatically on alert triggers, not on request — which removes the post-incident dispute over whether footage was preserved
HyperQ AI Safety applies per-zone analytics logic on existing ONVIF-compatible cameras. The analytics layer separates tenant zones at the application level regardless of whether the underlying cameras were installed at different times, by different parties, or on different hardware generations. The estate manager's camera backbone does not need to be replaced or re-segmented. Zone governance is configured, not rewired.
Three evidence outputs each tenant needs from one camera estate
The evidence each tenant requires to satisfy WSH Act or OSHA 1994 audit obligations falls into three categories, all generatable from the same camera network.
Zone access and PPE compliance records
Every person entering a designated zone should produce a timestamped record: entry time, PPE detection result (helmet, high-visibility vest, safety footwear where required), and authorization status against the tenant's contractor registry. These records belong to the tenant, not to the estate manager, because they document the tenant's WSH obligations for workers in their zone.
Contractor authorization and deviation logs
When a contractor is authorized for a specific zone, time window, and scope, the analytics layer creates a log tied to that authorization. Unauthorized zone entry, entry outside authorized hours, and entry without completed induction (if camera-verified induction is configured) all produce deviation records. These logs are per-tenant and form part of the tenant's contractor management audit trail.
Common-area and boundary incident records
Events in shared spaces — loading docks, gate entry corridors, inter-zone transit paths — belong to the estate-level record. Both the estate manager and any affected tenant receive the event record; the tenant's copy is scoped to events that involve their authorized personnel.
This structure allows the estate manager to produce a complete site-level incident reconstruction while each tenant independently demonstrates to MOM or DOSH that their zone was managed to the required standard. No tenant has access to another tenant's contractor data.
Governance table: who owns what on a shared camera estate
This table is a starting governance framework. Actual terms will vary by jurisdiction, site type, and tenancy agreement. The critical point is that this table should be embedded in the shared-services or tenancy agreement before site operations begin — not negotiated during an active investigation.
| Evidence type | Generating party | Primary owner | Estate manager access | Tenant access |
|---|---|---|---|---|
| Zone entry and exit logs | CCTV analytics layer | Tenant (own zone) | Read only, incident investigations | Full read and export |
| PPE compliance records | CCTV analytics layer | Tenant (own zone) | Aggregate metrics only | Full read and export |
| Common-area incident events | CCTV analytics layer | Estate manager | Full | Scoped to own authorized personnel |
| Permit-window continuity records | CCTV + permit system | Tenant (permit holder) | Full | Full |
| Contractor authorization logs | CCTV analytics layer | Tenant (authorizing party) | None without tenant consent | Full |
| Gate and site entry verification | CCTV analytics layer | Estate manager | Full | Read, own authorized personnel only |
| Cross-zone transit records | CCTV analytics layer | Estate manager | Full | Available on incident request only |
The permit-window problem unique to shared estates
Single-operator sites manage one permit book. Shared estates manage several simultaneously. Tenant A may have a confined-space entry permit active for a vessel in section 3 while tenant B is running a hot-works permit 40 metres away in the same building. Neither tenant necessarily knows the other's permit is live. Neither's contractor has authority to challenge the other's workers in a shared transit corridor.
Camera monitoring addresses three specific failure points in concurrent-permit scenarios.
Fire-watch and gas-watch coverage gaps
Presence detection can verify that watch personnel are stationary at their assigned position for the duration of a permit window. Drift — a fire-watch walking to an adjacent work area, leaving the zone temporarily, or being redirected by another supervisor — generates an alert and a continuity gap in the permit record. On a shared estate, watch personnel are frequently provided by a sub-tier firm with limited direct supervision, which makes this continuity check particularly relevant.
Unauthorized approach from shared corridors
During an active permit window, the camera covering the adjacent common-area corridor can alert on personnel approaching without permit authorization. Workers from neighboring tenant zones may not know a permit is active and may approach the zone through a path that bypasses signage.
Permit-window attribution
When multiple permits from different tenants are active concurrently, the incident record needs to capture which permit was active in the relevant zone at each moment. This is primarily a documentation function, but it removes the most common post-incident dispute driver on shared estates: competing claims about which party's work was underway when something went wrong.
For the entry-layer element of contractor safety — verifying authorization before workers pass the site gate — the contractor gate and site-access safety post covers the upstream verification step.
Common failure modes when governance is deferred
Most shared-estate operators recognize the evidence governance gap but address it reactively — after a near-miss produces an improvement notice, or after a fatal incident makes the question non-negotiable.
| Failure mode | How it surfaces | Consequence under SG WSH or MY OSHA |
|---|---|---|
| No pre-agreed footage access protocol | Investigation stalls while parties dispute who authorizes release | MOM issues improvement notice; DOSH can treat obstruction as aggravating factor |
| Contractor registry not integrated with camera system | Unauthorized personnel cannot be identified in real time | Inadequate contractor management records; potential prosecution under Section 11 (SG) or Section 15 (MY) |
| Zone boundaries undefined in analytics configuration | Zone footage is pooled; one tenant's data is technically accessible to others | Potential data privacy breach under SG PDPA or MY PDPA 2010 |
| PPE compliance records held only by estate manager | Tenant cannot independently produce zone-level compliance evidence | Tenant's contractor management records found incomplete at WSH audit |
| Permit-window coverage not logged | Post-incident investigation cannot confirm watch personnel were in position | Incident finding cites "inadequate supervision"; employing party faces prosecution |
| Evidence generated only on request | Footage not preserved at trigger point; may be overwritten by retention cycle | Investigation relies solely on witness accounts; contemporaneous evidence absent |
The SG and MY regulatory backdrop
Singapore's WSH (General Provisions) Regulations require employers and occupiers to take reasonably practicable measures to ensure contractor safety. The MOM's Code of Practice WSH(C) CP 79 on contractor management establishes that the principal contractor or site owner has primary responsibility for coordinating safety across contractors. On a shared estate, this places coordination responsibility with the estate manager, including for incidents that occur in or near tenant zones.
In Malaysia, DOSH enforcement under OSHA 1994 has expanded its focus on principal-party accountability at multi-employer sites. DOSH investigations increasingly examine whether the principal party controlling site access took adequate steps to ensure contractor workers were managed safely — not just whether the employing contractor held valid certification.
Both frameworks are moving toward requiring documented evidence of monitoring, not policy statements alone. Camera-generated records with tamper-evident timestamps, automatically preserved on alert triggers, are the format both MOM and DOSH treat as objective evidence in investigations. The governance structure above is designed to produce that evidence for each responsible party from one system.
A second regulatory consideration specific to shared estates is data residency under Malaysia's Personal Data Protection Act 2010 (PDPA) and Singapore's Personal Data Protection Act. Where a shared CCTV network captures footage of workers employed by multiple tenants, the footage constitutes personal data under both frameworks when individuals are identifiable from it. If the estate management system stores footage on cloud infrastructure with servers outside Malaysia or Singapore, cross-border transfer provisions apply. Footage that straddles tenant zone boundaries — a common area where two tenants' workers are simultaneously present — may require cross-border transfer authorization from both employers whose workers appear in it. The per-tenant evidence partitioning structure above resolves much of this: footage scoped to a single tenant's zone is that tenant's data and subject to that tenant's PDPA compliance obligations. Pooled, unpartitioned common-area footage is the estate manager's data responsibility. Defining these boundaries before the first camera goes live is the correct sequence, not the post-incident one.
What a retrofit looks like
For an estate manager adding AI safety analytics to an existing shared CCTV network, the operational sequence does not require new hardware at the outset.
Zone boundaries for each tenancy are defined in the analytics configuration — a software operation, not a cable change. Boundaries can be updated as tenancy arrangements change without touching cameras. The analytics layer then connects to the estate's existing contractor management or induction system, which establishes the authorized and unauthorized classification that drives real-time alerts and post-event attribution.
Each tenant receives read-only access to their zone's safety metrics: PPE compliance rate, unauthorized entry events, permit-window continuity data. The estate manager receives an aggregate site view. No tenant's contractor data is visible to another tenant's dashboard.
Incident packages are configured to generate automatically on alert triggers: relevant footage clips, the zone access log for the preceding 60 minutes, and active permit records are bundled and assigned to the responsible party at the time of generation. Retrieval does not depend on human action during or after the event.
Whether the estate hosts three tenants or twelve, the per-zone analytics configuration applies at the zone level, not the camera-count level. The governance structure scales with site complexity without proportional cost increase.
Leading indicators for the estate manager
The governance structure above produces incident evidence — the record that matters after something goes wrong. It also produces leading-indicator data that allows the estate manager to manage risk before incidents occur: contractor PPE compliance rate by zone, unauthorized entry event frequency by time of day, permit-window coverage rate across active tenants, and subcontractor concentration patterns that signal overloading of common access routes.
For multi-employer estates where contractor populations rotate frequently, the most operationally useful leading indicator is often zone-level unauthorized entry rate. On a well-managed shared estate, this metric should trend toward zero across an operating quarter as contractor orientation improves and zone configuration stabilizes. A persistent unauthorized entry rate in a specific zone — particularly during shift-change windows or permit-work periods — signals that zone boundary communication, contractor briefing, or authorization workflow has a gap that will eventually produce a recordable incident.
The estate manager can present this trend data to tenants at regular safety coordination meetings without revealing any individual tenant's contractor data to others: the aggregate zone-level rate is estate-level information, not per-tenant contractor information. This gives tenants a shared view of site-level risk without breaching the evidence wall principle.
For more on how to turn camera-generated data into metrics that hold up under WSH audit, see the safety metrics and leading indicators post.
Send us your estate layout — zone count, camera count, tenant count, and the current gap in your contractor monitoring documentation. We will return a per-zone evidence architecture outline within two weeks, showing how your existing camera estate can be configured for per-tenant evidence partitions with no hardware changes required and no contract commitment until the architecture meets your WSH documentation standard.
