“More and more, the job of being a security professional is being proactive, pulling those alerts and planning ahead instead of waiting for something to happen. Doing that in one place, instead of all these other apps, that’s a real plus.”
Kristine Banda
Senior Physical Security Manager

How CZI keeps its people safe across a growing, always-on security operation
The Chan Zuckerberg Initiative supports the people advancing world-changing science. Behind that work is a physical security team that runs around the clock, protecting employees, visitors, and high-profile leaders across a growing set of offices and lab environments. It is a demanding, high-threat-profile operation, and it never really switches off.
Kristine Banda leads that operation. She spent nine years building security at Meta before coming to CZI to build a scalable, integrated program from the ground up. When she arrived, the team was using Envoy mostly to check people in. She has since expanded its use to emergency response, using it to send alerts, coordinate during an incident, and account for everyone on site, employees and visitors alike.
The challenge: when response stops at employees, people fall through the gap
Most emergency systems start and stop with employees. That is where Kristine sees them fail. When an incident hits, teams reach for a stale HR directory and forget everyone else in the building. Visitors, vendors, and guests do not badge in the same way, so they can disappear from the picture at the exact moment you need to account for everyone.
“You often think of employees when an incident happens, but you forget you have visitors and guests and people here for different reasons. They basically become invisible.”
The cost of that gap shows up under pressure. If the count is wrong, a team can burn precious minutes hunting for someone who left hours ago, time that should go to first responders and to the people who actually need help.
“It’s always panic time when you see Joe Smith is still unaccounted for, but the truth is that Joe Smith left two hours ago, and that you’ve been looking for a person who is not actually at risk. That’s valuable time, for us and for the responders. We want to know who’s accounted for already, so we’re able to focus on what’s actually happening, and who’s actually in need of support.”
The other challenge was fragmentation. During an incident, Kristine’s team was working across many different apps and feeds at once, monitoring cameras, scanning for area activity, communicating with employees, coordinating with responders. In security, time is the one thing you cannot get back, and every extra tool is one more place to lose it.
The solution: one system of record for emergencies
With Envoy Response, CZI's team manages an incident from start to finish in one place, not just the alert but everything after it: emergency notifications, two-way chat, mustering, response status, and reporting. Because Response draws on the same presence data Envoy captures through visitor management and access control, every incident starts with the team already knowing who is in the building and who is expected on site. That lets Kristine's team launch a response, track it end to end, and account for everyone without stitching systems together mid-crisis.
Presence data: knowing exactly who’s there
For Kristine's team, the first question in any incident is who is actually in the building right now. A static directory can't answer it. It's a moment-in-time list that doesn't know who badged in this morning, who signed in as a visitor, or which vendors are on site for the day. Envoy answers it, because the same system that runs the front desk, from visitor check-in to access control, is the one that shows who's present. Employees, visitors, and contractors all appear in one place.
That presence data drives how the team operates. In one recent 90-day window, nearly 14,000 employee entries flowed through Envoy as the record of who was where. In an incident, it lets the team reach the people who are actually on site and skip the ones who aren't, whether that's someone on leave or a visitor who left hours ago. And when first responders arrive, the team can give them a real-time count instead of a guess.
“People don’t really think that access control, who’s in, who’s out, who’s there, does anything. No, it’s pretty much the basis of what we do, and where we start when it comes to any incident.”
What a full evacuation drill showed
CZI recently planned and ran an evacuation drill entirely through Envoy, with around 250 people taking part. Employees and visitors alike received multi-channel notifications, saw where to go, and could mark themselves safe in real time. An external grader scored the drill 98 out of 100.
“It's a big lift for our security operations center to monitor so many things at once. Having one system is really helpful, so they're not battling between apps and pages. It was a successful drill, and having everything in one place made a real difference.”
One place to act, from anywhere
The drill also became a real stress test. Partway through, an unrelated threat alert came in from another CZI location, and the team suddenly had to manage a simulated crisis and a live incident at the same time. They handled the real incident from their phones in Envoy while the drill continued, keeping both running cleanly in parallel.
“We had the drill going here and police activity in another city at the same time. Being able to send a message and communicate with just that group, that was really important, so we could get through what we needed to do.”
Kristine runs responses from her phone, not just a command center. That mobility, combined with a single source of truth, is what lets a lean team keep up when two things happen in two cities at once.
“With security, time is of the essence. You may be on ten different apps at once, shuffling between them. If you can do a one-stop shop where everything is in one place, that saves time, and it could save lives depending on the emergency.”
Duty of care that includes everyone, not just executives
CZI’s leaders are constantly in the public eye, and protecting them is a full-cycle effort, before, during, and after they move through a space. It runs across several teams that all have to work from the same picture. When an incident unfolds with a principal on site, Kristine’s attention goes straight to their safety. What lets her do that is trust in the rest of the system to carry the broader response.
“If our founders are on site and something happens, I know the SOC and the on-site team are going to handle the evacuation. That lets my main focus be executive protection, making sure our founders are safe and out of the building.”
That division of labor only works when everyone is looking at the same real-time information. Because presence, response, and communication live in one place, the teams protecting principals and the teams clearing the building aren’t guessing or working from different data. They’re coordinating from one source of truth, which is exactly what a high-stakes moment demands.
CZI frames security as a support system, not a gatekeeper. The team’s job is to clear obstacles so people can do their work, and to look after everyone on site, employees, visitors, and vendors alike, along with anyone heading toward or away from a situation. CZI backs that philosophy by treating visitors and vendors with the same care as executives and employees, so no one on site is an afterthought.
“We're a support system. We're here to move obstacles out of the way so people can do the job they need to do. Our message isn’t only: “There’s an emergency, evacuate.’ It’s "Are you okay, do you need help, if not, then mark yourself safe. That way we know every person affected is okay and we can stop manual checks and focus on who’s in need of support right now.”
Audit-ready by default
For a team that runs an after-action review on every incident, the record matters as much as the response. CZI pulls timestamps, logs, and message history straight from Envoy to critique its own performance, tighten workflows, and make the case for what security needs at budget time.
“After every incident we do an after-action report and go through it with a fine-tooth comb. We pull the logs and timestamps straight from Envoy to build it."
The results: time saved when it matters as CZI grows
In the year since Kristine’s team has been using Envoy to support CZI’s emergency response and security needs, she has seen roughly a 10% efficiency gain. For an operation where timing decides everything, that is meaningful time returned to the people doing the work.
“I’ve seen about a 10% improvement in just the year I’ve been here. That’s huge for what we do. It’s a lot of time we save that we can put toward other things.”
Kristine Banda
The reach is immediate. Across a cadence of 50 to 60 drills a year, CZI has run a live all-org drill that reached more than 400 people across SMS, email, and push in 60 to 90 seconds. Presence data is what makes that speed count, because the message lands with the right people, not a blast to a directory.
It also changes how the work feels. During an incident, a security operations center is juggling employees, leadership, and responders all at once. One system takes weight off a team that carries a lot of it.
“So many things come at you during an event. Having a system that helps means you’re not feeling that anxiety of juggling everything at once. For a security team, that’s huge.”
And it scales. CZI is no longer a single campus. As the footprint grows across regions, with the real possibility of incidents at two sites at the same time, one platform keeps the whole operation on the same page.
“We’re not just local anymore, we’re regional. You could have something happening at two different sites at once. Having that one system helps balance it out, and it helps with the fatigue.”
What’s next: staying ahead of risk
CZI's team is on heightened alert 24/7, monitoring for anything that could affect its people. Historically that has meant watching a patchwork of separate tools and feeds to understand what is happening nearby.
The CZI team tested Envoy Response for threat intelligence and incident management while in beta and gave feedback on where it should go. They were excited about the presence-aware threat intelligence the Envoy system offers: knowing not just that something is happening near a site, but whether it actually affects the specific people who are there, on a single map that connects a threat to the people in its path
“In an incident, every minute counts, and the teams that move fastest already know what is happening around them. AI helps us surface signals we would have missed and act before a situation escalates, and it works best when it’s paired with people who validate and decide. What matters most is having one place to see risk, instead of stitching five systems together under pressure.”