Continuous Operation: Define Minimum Manning First, Derive Headcount, Then Add the Buffer
Round-the-clock manning is not computed as "three shifts of so many people". The correct order is to define the minimum number and combination of capabilities that must be present at any moment, derive total headcount from continuous annual coverage, and then add buffer for leave, training, sickness and attrition. Skipping that last step is the single reason a new site's roster fails within the first month.
Start by defining minimum manning by capability rather than by headcount. Whoever is on shift at any moment has to cover: electrical and distribution (able to handle transfers and alarms), mechanical and cooling, network and monitoring, security, and fire and emergency response. Some of those can sit with one person, others cannot. The governing test is whether, on a single point failure, the people already on shift can contain the loss without waiting for someone to travel in. Write that definition down, because it is simultaneously the first question in a customer audit and the foundation of your roster.
Then derive the headcount; three variables drive the answer. One, coverage scope: continuous means weekends and public holidays, and Philippine public holidays are numerous and come in two classes with different pay treatment, see special versus regular holiday pay. Two, shift structure: two shifts or three, rotation length, whether any post is permanent nights — all of which drive attrition and overtime, with the general rules in lawful shift scheduling. Three, the buffer factor: annual leave, sick leave, statutory leaves, training and certification time and the gap between a resignation and a replacement — estimated from your actuals rather than an ideal, with statutory leaves in statutory leave entitlements. Under-buffering has a signature: overtime approved every month, repeated resignations from night posts, and the shortage feeding itself.
Three rostering constraints specific to this industry. One, handover leaves no gap: the outgoing shift does not leave until the incoming shift has arrived and taken handover, which means overlap between shifts, and that overlap is compensable time that belongs in the roster rather than in people's goodwill. Two, change windows fall at night: customer and operator changes, migrations and maintenance are scheduled in the quiet hours, so the night shift's real workload is not necessarily lighter — treating nights as a watching brief is a design error. Three, people must be able to reach and remain on site during typhoons and flooding: duty arrangements, transport and accommodation in severe weather belong in the emergency plan with their pay treatment stated, because negotiating that on the night is where disputes start. To compute minimum manning, shift structure and buffer and turn them into policy in one pass, Yixing's compliance management service can do it. Whether a candidate site can recruit night shift at all is a site question, see choosing a data centre site; retention levers are in turnover and retention.
Access Tiering and Background Screening: Here, People Are the Security Boundary
However complete the physical security, it ultimately rests on who is authorised to walk in — which makes access tiering and background screening operating controls in a data centre rather than HR administration, and auditors ask to see the authorisation list, the basis for each grant and the revocation records. Access hardware, zoning and surveillance design belong to the site side, see choosing a data centre site. This section is the people side: who may enter which tier, on what basis, approved by whom, and withdrawn when.
Design tiers on least privilege; four is typical. Tier one is the campus and office area, the widest population. Tier two is the support envelope — switchrooms, plant areas, loading bay. Tier three is the data hall. Tier four is a customer cage or designated rack area, usually layered with the customer's own authorisation. Each tier has to answer four questions: who is on the list, why this person needs this tier, who approved it, and when it expires. Temporary grants — contractors, customer visitors, vendor engineers — must carry start and end times and expire automatically. A temporary grant that never expires is the most common audit finding in this industry.
Screen candidates, but screen them lawfully. Background checking in the Philippines is governed by data privacy rules covering what may be checked, how, and whether written consent is required; that boundary is in running background checks lawfully, and the standard official clearance is explained in what the NBI clearance is. Three additional points apply to data centres. One, match screening depth to access tier: someone applying for hall or cage access is screened more deeply than someone who only enters the office, and a graded design defends better than a blanket one. Two, screening is not a one-off: re-confirm on privilege escalation, transfer and return from extended leave, and state in the contract who performs and how they evidence screening for contractor personnel. Three, have a procedure for adverse findings: an opportunity to explain, assessed against a stated standard, rather than a quiet blacklisting; handling of personal data is in complying with the Data Privacy Act.
The overlooked end of this is revocation. Resignation, transfer, a contractor substituting personnel, a customer contract ending — on each of those, access comes back the same day: badge, biometric enrolment, system accounts, keys and passwords. Build revocation into the exit and handover checklist with security and IT both signing it off, rather than leaving it to a line manager's verbal notice. The general exit and clearance process is in resignation, handover and clearance; internal misconduct and theft sequencing is in handling employee theft and building a disciplinary system. The same "authorisation must stay current and changes are actioned immediately" logic governs the explosives roster at a mine, see mining workforce compliance, and who may energise at a power plant, see renewable energy project staffing. Take advice on your own facts; this is not legal advice.
Resident Contractors: Security, M&E and Cleaning — Fix the Boundary in the Contract
More than half of the people resident in a data centre are usually not your employees: security, mechanical and electrical maintenance, cleaning, grounds and catering typically arrive through contractors. What makes this industry different is that those people are in your hall every day, carrying your access badge, working to your site rules — which makes the employer question far easier to answer wrongly than in other industries. The principal is solidarily liable for contractor personnel's wages and statutory contributions and cannot contract out of it, and if control sits with you the characterisation goes further. The full test is in legitimate contracting versus labour-only contracting.
The correct interface is deliverables and standards, not people. You may set service levels and response times, require resident personnel to meet competency and training requirements, impose a single site safety and access regime (a safety and security duty, not employment control), and accept or reject service quality. You should not roster them directly, keep their time, decide who is assigned or removed, or discipline and bonus them. Do all four and the contract stops mattering. The boundary is crossed most often with security, because guards and the duty team work side by side every day and the reporting lines blur naturally. Put it in the site rules explicitly: operational instructions to guards come from their own supervisor, and what your duty manager issues is an incident response request — logged.
The three resident teams each need a different emphasis. Security: personnel licensing requirements follow the regulator's current rules, and the operational core is roster management and rotation — a stable team knows the site, but a permanently static team accumulates insider risk, so critical posts need rotation and review. M&E maintenance: this team touches distribution, UPS, cooling and fire systems and is genuinely capable of taking the whole site down, so their work runs under permit to work and lock-out tag-out with a per-person authorisation matrix — the same logic as a power plant, see renewable energy project staffing. Cleaning: apparently the lowest risk, actually a group that enters the hall frequently and whose screening is the first to be quietly downgraded. Set screening depth by the access tier they hold, not by the job title.
Five actions the principal must perform and evidence. Accreditation (registration, sectoral credentials, labour department registration where applicable, employer registration and recent remittance proofs); reconciliation person by person (monthly resident roster against remittance proofs — totals without names is the standard failure); payment gating; retention and direct-payment set-off; and cooperation duties (audit access, records and immediate notification of personnel changes — which in a data centre is also the trigger for access administration). To map the resident contracting chain together with the access authorisation workflow, Yixing's compliance management service handles this. The same question under an EPC wrap is in renewable energy project staffing, and at the contractor tier of a mine in mining workforce compliance. Take advice on your own facts; this is not legal advice.
Is Standby in the Control Room Compensable? The Most Expensive Grey Area Here
The test is not whether hands were on equipment; it is whether the period was substantially controlled by the employer. Being required to remain in the control room, respond to alarms and stay on site normally sits close to working time. Being at home with a phone switched on in case of a call is a different thing. The difficulty in a data centre is that its normal operating state lives between those two poles.
Split standby into three states, characterise each, and write each into policy. First, on-site duty: present, within a defined area, able to respond at any time — normally compensable, even if no alarm sounds all night. Second, on-site rest: meals and rest periods in the duty room. If the person is still required to interrupt that rest to respond, its character sits closer to working time; only where the period is genuinely uninterrupted and freely disposable might it be treated as rest. Everything turns on whether it can really go uninterrupted, and that has to be demonstrated by policy and records, not asserted. Third, off-site call-out: at home under an agreement to attend within a set time. That is treated differently again — and once called, the time from departure to return normally counts.
Four actions make it operational. One, define the three states in the contract and duty policy, with the record-keeping and pay treatment for each. Two, allow the site to issue only one of those three instructions, and only through the system or in writing — a verbal "just stay here for now" can neither be computed nor defended afterwards. Three, generate call-out records automatically: time called, time on site, time released, ideally reconcilable to access control. Four, pre-configure the corresponding computation in payroll instead of adjudicating monthly; general rules are in lawful shift scheduling, computing overtime and payroll compliance mistakes.
Three closing notes. One, "on shift with nothing happening" is not the same as "not working" — this is the most common managerial instinct to get wrong, and in a data centre the waiting is precisely the service being bought. Two, cap continuous duty and mandate rest: fatigue in a live electrical environment is simultaneously a working-time issue and an incident risk, and the second costs more. Three, the same question in other industries: camp standby at a mine, see mining workforce compliance; reporting and waiting for a grid window during commissioning, see renewable energy project staffing; waiting on paper or plates at a press, see printing and packaging staffing. Four industries, one analysis: how far the employer controlled the period. Take advice on your own facts; this is not legal advice.
Handover and Single-Point Dependency: In a Team of a Dozen, One Holiday Opens a Hole
A data centre operations team is small but has to cover a wide combination of capabilities, so single-point dependency is close to inevitable — one person who will actually perform a particular transfer, one who has configured a particular monitoring stack, one who knows a particular customer's process. That is not a character problem, it is an arithmetic consequence of the establishment, and it has to be hedged with structure.
Find the single points with one table. Build a capability matrix: critical tasks down the side (power transfer, generator start and load acceptance, cooling fault response, fire system reset, core network change, escorted work in customer cages), people across the top, and three values in each cell — can perform unsupervised, can perform supervised, cannot perform. Any row with a single "unsupervised" is a single point; any row with none of them on a given shift is a coverage hole. Refresh it quarterly. It is also the single most informative page in a customer audit.
There are only three hedges, in order of effectiveness. One, cross-train against targets: at least two people unsupervised and three supervised on every critical task, made a team objective rather than a matter of individual goodwill. Two, document procedures to the standard of "a stranger could follow this": operating manuals, transfer steps, alarm response, customer-specific requirements. The test is simple — with the usual person's phone switched off, can the duty team complete it from the document. Three, put external support in the contract: vendor and maintenance provider response times and attendance conditions are the backstop when the establishment cannot cover the gap.
Handover is a formatted procedure, not a conversation. Each handover covers at least five items: current system state and abnormalities; open alarms and tickets; contractors and visitors on site with their authorisations; changes in progress and their rollback plans; and anything the incoming shift specifically needs to watch. Both parties sign it (or confirm in the system), and the outgoing shift does not leave before it is complete — which is both a safety requirement and a rostering one, hence the compensable overlap between shifts discussed in the manning section above. Duty logs must remain searchable long-term, because both incident reviews and customer audits look back; retention is in record retention.
Two final points. One, manage the departure window deliberately: when someone in a critical post resigns, the handover schedule, the knowledge transfer list and the access revocation timing all start at once — see resignation, handover and clearance; if the separation is employer-initiated, grounds and procedure are in termination and separation pay. Two, an expatriate specialist is not a durable answer to a single point: permits and visas have cycles and conditions, see the alien employment permit, and the local understudy obligation attached to foreign engagement is in foreign worker ratios and understudy requirements. Turning that specialist's knowledge into filled cells on the capability matrix is the only move that satisfies both compliance and operations.
The Personnel Records Customer Audits Ask For: Keep Seven Sets Current
Customers, insurers and compliance auditors all examine people, and what they examine is rarely how well your HR policy reads. It is whether this individual was authorised at the time, whether they were trained, and whether the record exists. So treat personnel records as operating records, retrievable on demand, rather than something you assemble across departments when an audit is announced.
Seven sets worth keeping current. One, the personnel roster with role descriptions, including the nature of engagement (employee, contractor, temporary authorisation). Two, the access authorisation register: who holds which tier, on what basis, approved by whom, effective and expiry dates, and revocation records. Three, screening completion records — evidence that screening was completed and the authorisation basis, with sensitive content held under restricted access per privacy rules, see complying with the Data Privacy Act. Four, training and certification records: safety, fire, first aid, equipment operation, customer-specific procedures and confidentiality training, with refresher due dates. Five, the capability matrix from the previous section. Six, rosters and actual timekeeping, capable of showing that minimum manning was met at every moment. Seven, incident and change records: duty logs, alarm responses, changes and rollbacks, and any personnel misconduct and its handling.
Three principles that make the set hold up. One, cover contractor personnel: an auditor does not skip someone because they work for the guarding company, so rosters, authorisations, training and screening records are collected to the same standard — and contracts that cannot deliver them need changing. Two, timestamps must reconcile: access logs, timekeeping and duty logs should corroborate each other, and you should decide in advance which governs when they disagree; where biometrics are used for attendance, the privacy boundary is in biometric attendance and privacy. Three, tier the sensitivity: an auditor needs to see that screening was completed and that authorisation had a basis, not the full content of a screening report, so design a disclosable layer and a restricted layer.
Two further record sets are statutory rather than customer-driven. The labour compliance set — payroll, timekeeping, statutory contribution proofs, contracts and termination reports — with retention in record retention and what an inspection looks for in handling a labour inspection. And the policy set — employee handbook, disciplinary system, grievance mechanism and workplace conduct standards — which is not decoration for auditors: in a dispute it is the only internal authority you can cite. See writing an employee handbook, building a disciplinary system and handling employee grievances.
One executable landing point: invert the audit checklist into a routine. Rather than assembling material when an audit is announced, make those seven sets seven monthly-updated registers with a named owner and an update date. The return is not only audit readiness — when something goes wrong operationally, those seven registers are the raw material for the review instead of everyone's memory. Power, cooling, network redundancy and site selection criteria are in choosing a data centre site and are not repeated here. To build the templates and assign ownership for all seven record sets in one pass, Yixing's compliance management service can set it up. Take advice on your own facts; this is not legal advice.
Frequently Asked Questions
How should headcount be calculated for a 24/7 data centre?
How should access rights inside the facility be tiered?
How far can background screening go for data centre staff?
The guards, M&E technicians and cleaners are contractor staff. Who is responsible if something happens?
Does standby time in the control room count as working hours?
Our operations team is a dozen people and only one can perform certain tasks. What do we do?
What personnel records do customer audits ask to see?
Let’s talk through your situation — free
Every company is different. Leave your details and a Chinese-speaking advisor will get back within 1 business day with practical, industry-specific guidance and a transparent quote.
Get help with Compliance → Free consultation
