Open the analytics page of almost any modern camera or recorder and you meet a list of checkboxes. Line crossing. Intrusion. Loitering. Object left behind. Occupancy. Tampering. Each sounds like a capability the system either has or does not, and a quote listing twelve looks cleverer than one listing four.
First, the sentence that matters most: every one of these is a rule applied to what the camera can already see. None improves the image, changes where the camera points, or changes how many pixels land on the thing you care about. A rule is arithmetic sitting on top of a view, and a rule applied to a bad view produces confident nonsense — an event, with a timestamp, that is wrong.
That is why the "where it disappoints" line below keeps returning to the same causes: too high, too far, too oblique, pointed into a light source, or watching a scene that changes for reasons unrelated to people. The fix is almost always upstream of the analytic — where the camera is mounted and how many pixels land on the subject.
These rules run either on raw pixel change or on the output of a classifier that has already decided what is moving — a distinction with its own article. Below, "on classification" means the trigger is a detected person or vehicle; "on motion" means pixel change alone.
Line crossing (tripwire)
What it means. You draw a line across the image, and the rule fires when something crosses it — usually with a selectable direction.
What it is good for. Boundaries with a real geometry: a fence line, a gate throat, a loading-bay threshold. It is the cheapest way to turn "something is moving over there" into "something came in", and direction earns its keep — an object leaving a yard at 4 a.m. is a different event from one arriving.
Where it disappoints. The line is drawn in the two-dimensional image, not in your yard, so a crossing depends entirely on perspective. A line across a driveway at the far end of a wide view is a few pixels tall, and a person walking parallel to it twenty metres beyond can cross it in the image without going near it in reality. The more oblique the view, the worse this gets. It also fires on whatever crosses it — on motion alone, headlights sweeping through, a shadow tracking with the sun, rain lit by the camera's own infrared, a tarp crossing back and forth all night. And every crossing counts: someone pacing the boundary generates a stream of events, not one.
Intrusion (zone entry, area intrusion)
What it means. You draw a shape instead of a line, and the rule fires when something enters it or remains inside it.
What it is good for. Spaces rather than boundaries — a compound, a rooftop, a plant room, an enclosure too irregular for a single line. More forgiving than a tripwire, because an object jittering near the edge does not generate an event every time it wobbles.
Where it disappoints. The same perspective problem, plus one more: the shape is a flat polygon on the image, so it contains everything that appears inside it at any distance. A zone over a parking area also contains the road behind it and the building across the street. Vehicles passing legitimately three hundred metres away sit inside your zone, and no setting tells the polygon how far away the ground is. The fix is not more tuning — it is a camera angle where the area you want is the only thing in that part of the frame.
Loitering (dwell)
What it means. An object is inside a zone for longer than a set period. Thirty seconds, two minutes, ten.
What it is good for. Places where legitimate presence is brief: an ATM vestibule, a rear alcove, a stairwell landing. Set on classification it is one of the more useful events available, because the rule becomes "a person has been here for four minutes" — specific, and rare.
Where it disappoints. It depends on tracking one object continuously for the whole period, and anything that breaks the track resets the timer — the subject passes behind a pillar, sits down and changes shape, or steps into deep shadow. Someone breaking the sightline every twenty seconds may never accumulate a dwell event, while a parked delivery van generates one every morning. A threshold set on a quiet Tuesday afternoon also behaves very differently at a shift change.
Object left behind (abandoned object)
What it means. Something appears in the scene, was not there before, and stays static for a set period. The classic pitch is an unattended bag.
What it is good for. Controlled interiors with a stable background: a lobby, a corridor, a secure area that is supposed to be empty. There it does something no human monitor reliably does — notice that the picture is subtly different from ten minutes ago.
Where it disappoints. One of the most oversold events on any feature list. The rule is fundamentally "part of the background changed and stayed changed", and a great many harmless things do exactly that: a chair moved, a pallet set down, a puddle forming, sunlight arriving and staying an hour, snow accumulating. It also struggles in the environment it is usually pitched for — in a busy scene the object is repeatedly occluded by passing people, so the "static for N seconds" clock never runs cleanly, and outdoors the background is never stable to begin with.
Object removed
What it means. The mirror image — part of the scene that was reliably there is now missing, and stays missing.
What it is good for. Small, high-value, static things in a controlled view: an item on a display plinth, equipment in a rack, an extinguisher on a bracket. With a dedicated camera and constant lighting, it works.
Where it disappoints. Anything that occludes the object reads as removal — a person standing in front of the plinth, a shadow across it, a lighting change at dusk, a camera that shifts a few degrees in the wind. It needs a dedicated view and a stable scene, so it rarely rewards being switched on across a general-purpose system.
Crowd detection and occupancy counting
What it means. Two things worth separating. Crowd detection fires when the density of people in an area exceeds a threshold. Occupancy counting maintains a running number of people inside, usually by counting directional crossings at entrances and exits.
What it is good for. Operational awareness rather than security: queue management, space utilization, capacity awareness in a room with defined doorways. A count that is roughly right and consistently biased still shows a trend.
Where it disappoints. Counting accumulates error. Every miss and double-count stays in the total until someone resets it, so a count that drifts a little each hour is meaningless by evening. Two people through a doorway side by side, one carrying a box, or a group passing together are the standard failures. An overhead camera dedicated to the doorway does far better than a general-purpose view — another way of saying the camera position solved the problem, not the analytic. Crowd density is worse: in a crowded scene people occlude each other, which is exactly when counting them is hardest.
Direction of travel (wrong way)
What it means. An object moves through a zone in a direction you declared unexpected: in through an exit, up a one-way lane the wrong way, against the flow.
What it is good for. Constrained paths where the expected direction is genuinely fixed — a one-way ramp, a turnstile lane, an exit corridor. There it turns an otherwise noisy rule into a rare, meaningful event.
Where it disappoints. It needs a sustained track to establish direction, so anyone who turns around, backs up, or hesitates produces ambiguous data. In open areas there is no meaningful "wrong way" to configure. And direction, like line crossing, is measured in the image plane — a path curving away from the camera can register as travel opposite to what a person on site would describe.
Tailgating (piggybacking)
What it means. A rule that fires when two objects pass a point in close succession — two people entering on one badge presentation, or two vehicles through one gate cycle.
What it is good for. One of the few analytics whose value comes from pairing. On its own a video tailgating count is soft. Correlated with an access-control event — one credential presented, two people through — it becomes a specific, investigable finding, and the standard way to discover that a door everyone assumes is controlled is not.
Where it disappoints. Two people walking through a doorway together are, to a camera looking along the direction of travel, one blob. Separating them needs a camera mounted overhead at the door. A corridor camera that happens to see the door reports far fewer tailgating events than occur, and a reassuring low number is worse than no number at all.
Camera tamper and scene change
What it means. The camera detects that its own view has been interfered with: covered, sprayed, defocused, turned to face a wall, or suddenly changed wholesale.
What it is good for. The quiet workhorse of the list, and the one most worth enabling everywhere. It is the only event that tells you a camera has stopped doing its job while still looking online in the software — nudged by a ladder in March, recording a wall in November.
Where it disappoints. It cannot distinguish malice from weather and maintenance. Fog, a spider web across the housing, condensation inside the dome, headlights washing out the frame, and a legitimate cleaning all produce tamper events. It also has a blind spot: a camera that fails gradually — a dome hazing, an illuminator dimming over years, focus drifting each season — degrades too slowly to trip a change detector. Tamper catches the sudden failure. Only somebody looking at the images catches the slow one.
People and vehicle classification
What it means. Not an event in itself, but the layer the good versions of everything above are built on: the system decides a detected object is a person or a vehicle, and the rule applies only to that class.
What it is good for. Everything in this glossary, made dramatically quieter. "A person crossed this line" is a usable alert. "Something crossed this line" is not, in any outdoor scene in a wet winter.
Where it disappoints. It tells you what, not who — your own night cleaner and an intruder classify identically. It does not produce an image good enough to identify anyone; Axis, describing thermal cameras, puts the distinction plainly: "Unlike conventional cameras, this technology only allows for detection." That split applies to every detector, and identification stays a question of pixels on the subject, or of a detector chosen for the dark. Classification also degrades with distance, occlusion, unusual posture, and angles unlike the model's training images — a person crouched behind a vehicle or at the far edge of a wide view is where it is least reliable, and often where the interesting behaviour happens.
What to do with this list
The use of a glossary like this is to change what you ask for. Three questions do the work.
"Is this rule running on motion or on classification?" The same checkbox label describes two systems with very different lives. One survives a winter of alerts; the other gets muted.
"What view does this event need, and does the quoted camera have it?" Tailgating and occupancy counting both want a dedicated overhead camera at the door; abandoned object wants a stable indoor scene. If all twelve events run on one general-purpose camera in the corner, you were sold a checkbox list, not a design.
"What will this fire on that I do not want, and where does that alert go?" Whoever is quoting you should be able to name the expected noise — deliveries, staff at shift change, vehicles in the lane, weather. "Nothing, it's AI" is the answer to worry about.
None of these events makes a camera see better; they only decide what to do about what it already sees. Get the view right and the list becomes a set of useful tools. Get it wrong and it becomes twelve ways of being told something untrue, on a schedule.
Sources
- Axis Communications, Thermal imaging (the detection-versus-identification quotation) — https://www.axis.com/solutions/thermal-imaging
