Threat Assessment Before a Termination: The Questions That Matter
This article provides an intake framework, not a scoring tool, diagnosis, or substitute for legal, HR, law-enforcement, mental-health, or threat-assessment expertise.
The short version
The short version
A pre-termination threat assessment is a structured way to examine concerning behavior, current circumstances, access, escalation, and available support before an employment separation. It helps HR, legal counsel, leadership, security, and qualified threat-assessment professionals choose reasonable management actions without pretending that violence can be predicted with certainty.
Threat Assessment Is a Process, Not a Prediction
The purpose of threat assessment is not to label a person as safe or dangerous. It is to gather information, test what is known, identify changes that may affect risk, and decide what the organization should do next.
That distinction matters because shortcuts fail in both directions.
One team may hear an angry statement and assume violence is certain. Another may say, “He never made a direct threat,” and dismiss a larger pattern of fixation, escalation, and boundary crossing. Neither conclusion reflects a complete assessment.
The U.S. Secret Service National Threat Assessment Center teaches a behavioral approach to preventing targeted violence. The focus is on observable behavior, circumstances, and a pathway of concern, not a profile of what a dangerous person is supposed to look like.
A useful process remains open to new information. It asks:
0 of 6 checked. Anything left unchecked is where to start.
The assessment should continue as conditions change. The termination may be one important event, but it is not the only point in time that matters.
Start With Behavior, Not Labels
Ask people to describe what the person said or did.
Weak descriptions include:
Those statements may reflect a real concern, bias, loyalty, fear, rumor, or incomplete information. They are not enough to guide a safety plan.
Stronger information is specific:
Record the source. Separate what someone directly observed from what another person repeated. Preserve relevant records through the approved legal and HR process. Do not conduct an informal workplace investigation through gossip.
Ask What Changed and What Is Escalating
Change is often more informative than a single unpleasant interaction.
Ask:
0 of 8 checked. Anything left unchecked is where to start.
Do not confuse volume with seriousness. One highly specific act may matter more than twenty vague complaints. A pattern of small boundary tests may also matter even when no single event seems severe by itself.
Build a timeline. A simple chronology can reveal whether the concern is isolated, stable, increasing, or tied to particular events. It can also expose contradictions that need to be resolved before the team acts.
Test Specificity, Access, and Opportunity
When a threat or concerning communication exists, examine its content without treating any one factor as a verdict.
Specificity
0 of 4 checked. Anything left unchecked is where to start.
Access
0 of 4 checked. Anything left unchecked is where to start.
Opportunity
0 of 4 checked. Anything left unchecked is where to start.
This information is sensitive. Limit detailed findings to the people responsible for assessment and management. Employees who need a specific instruction can receive it without receiving a roadmap of the organization's vulnerabilities.
Examine Grievance, Fixation, and Meaning
Many people experience disappointment, discipline, or termination without becoming violent. The existence of a grievance is not proof of danger.
The assessment should examine how the person is interpreting and acting on the grievance.
Ask:
0 of 8 checked. Anything left unchecked is where to start.
Listen for meaning, not only emotion. Anger can be temporary and understandable. Fixation, increasing personalization, repeated boundary crossing, and movement toward action may require a different response.
Do not debate the fairness of the grievance inside the security assessment. HR and legal teams handle the employment issues. The threat-assessment team examines whether the person's behavior and circumstances create a safety concern and what management actions may reduce it.
Include History and Current Context
Past behavior can add context, but it should be verified and interpreted carefully.
Relevant questions may include:
0 of 7 checked. Anything left unchecked is where to start.
Do not collect private information simply because it might be interesting. Use HR, legal, privacy, and threat-assessment guidance to define what is relevant, lawful, and appropriate to gather.
Mental illness alone should not be treated as a predictor of violence. If a qualified professional's involvement is appropriate, that person should work within the multidisciplinary process. The workplace team's job is to report behavior and manage safety, not diagnose a coworker.
Look for Protective Factors and Openings
An assessment should not collect only reasons to worry. It should also identify factors that may reduce concern or create a path for management.
Ask:
0 of 7 checked. Anything left unchecked is where to start.
Protective factors do not cancel a serious concern. They help the team understand the whole situation and choose interventions that may be more effective than security presence alone.
The goal is not to be soft or hard. It is to manage the concern intelligently.
Build the Picture With More Than One Department
No single department sees the full picture.
HR may know the employment history. A supervisor may know recent behavior. Security may know access, incidents, and physical conditions. IT may know approved system access. Legal counsel may identify rights, duties, and limits. Law enforcement or a qualified threat-assessment professional may bring additional expertise.
Create one coordinated process with a designated lead.
The team should:
Gather verified information from relevant sources.
Build a timeline of behavior and key events.
Separate facts, reports, assumptions, and unknowns.
Identify immediate safety needs.
Select proportionate management actions.
Assign owners and communication limits.
Set a review time and triggers for reassessment.
CISA's insider-threat mitigation guidance also emphasizes a multidisciplinary approach and the importance of detecting, assessing, and managing concerning behavior through coordinated action.
The team should not wait for perfect information when an immediate safety issue exists. It also should not turn an uncertain report into a permanent conclusion without review.
Turn Assessment Into Management Actions
An assessment that ends with “medium risk” is incomplete. The useful output is a set of actions tied to the concern.
Depending on the facts and professional guidance, actions may include:
The action should match the identified problem. If the main concern is repeated unwanted contact with one manager, a general message to the entire workforce may spread fear without protecting the target. If the concern involves access, the plan should address access through the departments that control it.
Use the Pre-Termination Question Set
Bring these questions to the assessment meeting:
Behavior
0 of 3 checked. Anything left unchecked is where to start.
Target and Grievance
0 of 3 checked. Anything left unchecked is where to start.
Specificity and Access
0 of 3 checked. Anything left unchecked is where to start.
History and Context
0 of 3 checked. Anything left unchecked is where to start.
Protective Factors
Management
0 of 5 checked. Anything left unchecked is where to start.
Document the answers, the source of each important fact, and the unknowns that remain. Then build the termination and follow-up plan from that picture.
Threat assessment is not certainty. It is disciplined attention. When a team asks better questions, shares relevant information, and turns findings into owned actions, a difficult employment decision is less likely to be managed by rumor, bias, panic, or the first officer who hears about it at the door.
Written by the People
Who Do the Work.
ARDENT Protection
ARDENT Protection. A Florida security and protection company, licensed since 2020, Florida Security Agency License #B1900411. Guard Services, Fire Watch, Event Security, Executive Protection and Workplace Violence Prevention, statewide.
Who Owns the Concern at Your Workplace Right Now?
A multidisciplinary review needs HR, counsel, security and often an outside professional in the same conversation. Our part is the security seat, helping the group turn what it knows into actions with owners and review dates.