Understand the main applications of video analytics in CCTV, including use cases, metadata, AI, precision/recall, VMS, image requirements, sizing, and commissioning criteria.
Check it out!
Video analytics in CCTV are processing mechanisms that transform images into events and metadata usable by operations. The technical value does not lie in “having artificial intelligence,” but in applying the right algorithm to a well-defined use case, with image quality, computing architecture, VMS integration, and performance criteria consistent with the system purpose.
In practice, video-analytics applications can support intrusion detection, dwell detection, line crossing, counting, person and vehicle classification, license plate recognition, forensic search, alert generation, and operational analysis. Each application requires different framing, lighting, resolution, latency, processing, and validation conditions. The design should therefore begin with the operational requirement and only then select the technology.
What Are Video Analytics
Analytics should be specified by verifiable use case, not by a generic list of artificial-intelligence features. The design must define the scenario, target, expected performance, and acceptance evidence.
Video analytics are software functions that process video streams or files to detect objects, track trajectories, classify scene elements, extract attributes, and generate structured metadata. These data can support retrospective searches, dashboards, alarms, rules, automations, or integrations with other systems.
A modern architecture can execute part of the processing in the camera itself, on dedicated servers, appliances, virtualized infrastructure, or in the cloud. Analytics placement affects latency, bandwidth usage, network dependency, processing capacity, scalability, and availability.
BriefCam technical material helps illustrate this pipeline: video is received and processed by computer-vision and deep-learning mechanisms, objects are detected and tracked, attributes are classified, and the resulting metadata is stored in a structured database. Different applications can then use the same data set for REVIEW, RESPOND, or RESEARCH.
This distinction matters because “analytics” is not a single function. The same engine can serve different objectives, from generating an immediate alarm to allowing an operator, hours later, to search for all vehicles that crossed an access point.
Video-Analytics Applications in CCTV
The best way to organize the topic is by use case rather than by commercial algorithm name. The design should determine which event must be detected, how early, in what environment, with what acceptable false-positive rate, and what operational response will be triggered.
Intrusion Detection and Perimeter Protection
In perimeter protection, the objective is to identify people or vehicles entering a defined area, crossing a virtual line, or remaining in a restricted zone. Instead of reacting to every pixel change, current systems can combine motion detection with semantic classification to prioritize relevant objects.
The potential benefit is reducing alarms caused by rain, vegetation, shadows, or small animals. This depends on the scene, calibration, and product; false alarms cannot be eliminated completely.
For outdoor environments, the specification should consider lighting, distance, contrast, backlighting, rain, fog, vegetation, cast shadows, insects near the lens, and camera vibration. Daytime and nighttime tests are essential.
Line Crossing, Direction, and Trajectory
Line and trajectory filters can detect objects that cross a virtual boundary or follow a defined path. They are useful at access points, corridors, circulation areas, perimeters, internal roads, and operational zones.
BriefCam documentation shows that line filters can consider direction, while path filters analyze the route of the lower part of the object — legs or wheels — through the scene. This illustrates why camera position and geometry directly affect results.
Unauthorized Dwell and Dwell Time
Dwell analytics looks for objects that remain in an area longer than a defined threshold. It can be used in restricted areas, technical access points, facades, perimeters, platforms, loading zones, and environments requiring detection of abnormal behavior.
The time parameter should represent the actual process. An arbitrary threshold can generate excessive alarms or ignore relevant situations. The design should define the operational condition that constitutes unauthorized dwell.
Abandoned or Removed Object
Abandoned-object detection seeks to identify items left in an area after separation from a person or associated context. Removed-object detection looks for persistent scene changes related to the removal of an item.
These use cases are sensitive to scene stability, occlusion, and background movement. Field validation becomes even more important in highly dynamic environments.
People, Vehicle, and Occupancy Counting
Counting can support occupancy control, flow analysis, operational sizing, and capacity analysis. For reliable performance, the camera should be positioned according to the counting logic, avoiding occlusion zones and excessive crossings.
In many applications, a dedicated overhead camera provides more consistent results than repurposing a camera installed for identification or general context.
Counting should not be treated as an absolute value without validation. Commissioning should compare automatic counts with a known sample and record error, accuracy, and scene conditions.
Person and Vehicle Classification
Deep-learning systems can classify objects into broad categories such as person, vehicle, or animal and then apply subclasses or additional attributes.
BriefCam documentation describes a two-layer approach: first the main class, then subclasses and attributes. The key technical point is not an isolated catalog percentage but understanding that more detailed classification depends more strongly on object quality in the image.
An image may be sufficient to classify “vehicle” but insufficient to distinguish a more specific category reliably. The same applies to person attributes.
Color, Clothing, and Visual Attributes
Color and clothing filters are especially useful during investigation. An operator can search, for example, for people wearing a given clothing combination or vehicles of a specific color.
These attributes are affected by lighting, white balance, reflections, shadows, and each camera’s color response. BriefCam itself notes that different cameras and viewing angles can produce different tones for the same object.
Color filters should therefore be treated as a mechanism for reducing candidates, not as unequivocal identification.
Appearance Similarity
Appearance similarity searches for objects visually similar to a reference selected by the operator. It can be used to follow a person or vehicle across different areas or cameras.
It should not be confused with biometric identification. Two vehicles of the same class and color may be considered similar even when they are different vehicles. For people, clothing and overall appearance can guide a search without proving identity.
Facial Recognition
Facial Recognition compara representações de faces com identidades ou listas previamente cadastradas. É um caso de uso especializado, com requisitos de imagem muito mais restritivos do que uma câmera de contexto geral.
According to BriefCam documentation, performance depends on facial resolution, camera position, distance, lighting, angle, focus, and image quality. A technical recommendation is to position the camera closer to eye level, reduce vertical angles, and obtain frontal faces with adequate lighting.
This type of application also requires legal and governance assessment. The design should define purpose, applicable legal basis, access profiles, retention, and watchlist controls.
License Plate Recognition (LPR/ANPR)
LPR/ANPR should be treated as a dedicated function, not as a simple extension of “vehicle detection.” Alphanumeric reading requires specific framing, speed, shutter, lighting, angle, contrast, and plate pixel-density requirements.
If the requirement is to identify license plates, the specification should measure capture rate and read rate under known conditions. Filtering a vehicle by color or class does not replace license plate recognition.
Forensic Search
Forensic Search usa metadados e filtros para reduzir o volume de vídeo que precisa ser revisado manualmente. Pode combinar período, câmera, classe, cor, direção, região de interesse, permanência, similaridade, face ou placa, conforme os recursos disponíveis.
O artigo sobre Forensic Search in CCTV explores this architecture and investigation criteria in greater depth.
Video Synopsis
Video Synopsis é uma camada de revisão acelerada. Em vez de reproduzir toda a janela temporal na ordem original, eventos podem ser condensados e apresentados simultaneamente ou em sequência otimizada para reduzir o tempo de triagem.
In the BriefCam model, objects can be displayed out of chronological order within the synopsis. When a relevant occurrence is identified, the operator returns to the original video to verify context and preserve evidence.
O conteúdo Video Synopsis in CCTV examines this mechanism in greater depth.
Intelligent Alerts and Real-Time Response
Real-time analytics can feed rules and alerts. In this case, the system is not only an investigation tool; it participates in the operational chain of detection, qualification, and response.
The architecture must define what happens after the event. An alarm without a procedure, priority, associated camera, map, operator instruction, or integration with another system merely transfers the problem to the monitoring center.
Analytics should reduce cognitive load, not create a new queue of irrelevant events.
Analytics Is Not Synonymous with Artificial Intelligence
Motion detection, background change, geometric rules, and statistical processing are also forms of video analysis. Artificial intelligence expands classification and recognition capability but does not replace the fundamentals of computer vision.
In current systems, classical algorithms and deep-learning models can operate together. BriefCam, for example, documents the use of deep learning combined with classical computer-vision techniques for detection, tracking, object extraction, and metadata enrichment.
This distinction avoids a common mistake: presenting any video rule as “AI” or assuming that a system necessarily learns continuously in the field. Many products use pretrained models and perform inference during operation.
Metadata: The Link Between Analytics, VMS, and Operations
Metadata is the structured representation of what analytics found in the video. It can record class, attributes, trajectory, time, bounding boxes, speed, direction, region, events, and other elements.
These data make video searchable and integrable. Without metadata, operations depend mainly on timelines, bookmarks, and predefined events. With metadata, the system can answer complex queries and correlate video with other systems.
O artigo Metadata and Computer Vision explores this layer in greater depth.
Edge Analytics vs. Server-Side Processing
Running analytics in the camera reduces the need to transport video to a server solely for processing and can reduce latency for certain events. It also distributes computing capacity across the edge.
Centralized processing, on the other hand, facilitates engine standardization, hardware management, model updates, GPU sharing, and analysis across multiple sources.
A hybrid architecture can combine both approaches: basic analytics or events in the camera, advanced processing on servers, and the VMS centralizing operations and evidence.
The decision should consider:
- number of cameras;
- camera capabilities;
- latency requirements;
- processing throughput;
- GPU availability;
- bandwidth consumption;
- metadata retention;
- licensing;
- high availability;
- integration with VMS and PSIM.
Throughput and Computing Capacity
Advanced analytics consumes resources. Video processing should not be sized only by “number of cameras.” Resolution, frame rate, model complexity, object count, real-time or on-demand mode, and the engine used all change the workload.
BriefCam documentation uses the concept of Hs/H — hours of video processed per hour — to express on-demand processing capacity. This helps show that reviewing 24 hours of recordings from one hundred cameras is a different computing problem from processing real-time events.
In enterprise systems, at least the following demands should be separated:
| Demand | Useful metric | Risk of undersizing |
| Real-time analytics | simultaneous channels | delayed or missed events |
| On-demand forensic search | hours of video per hour | slow investigation |
| Video synopsis | time to process the time window | low operational usefulness |
| Historical metadata | volume and retention | loss of search capability |
| Dashboards and queries | concurrent queries | degraded operator experience |
The specification should use data from the selected solution manufacturer and validate sizing against the actual project scenario.
Image Quality and Analytics Performance
Analytics does not correct an inadequate image. Nominal resolution is only one variable.
BriefCam documentation highlights lighting, tilt, motion blur, focus, and compression as performance factors. A lower-resolution image that is sharp and well lit can produce better results than a higher-resolution image degraded by blur or excessive compression.
This directly affects CCTV design. An overly wide field of view reduces pixel density on the target. A slow shutter can create motion trails on fast objects. Backlighting can hide attributes. Aggressive compression can destroy details required by analytics.
Frame rate
Frame rate should also be evaluated according to the engine. BriefCam material shows that different engines can process different numbers of frames per second and that high-speed objects can be affected when engines sample too few frames.
There is no universal FPS value for all analytics. The requirement must be validated by use case.
PTZ
Continuously moving PTZ cameras are problematic for algorithms that depend on a stable background and geometry. BriefCam material documents reduced usefulness during movement and the need for the scene to stabilize before normal processing resumes.
If analytics is a permanent requirement for an area, a dedicated fixed camera is usually more predictable than relying on a patrolling PTZ.
Fisheye
Fisheye lenses introduce geometric distortion. This can reduce the quality of analytics that depend on size, speed, proximity, or scene geometry.
Infrared and Thermal
Thermal and IR video can be useful for detection, but attributes such as color, fine classification, and facial recognition may degrade. The design should clearly distinguish the detection objective from the identification objective.
Precision, Recall, and False Positives
Evaluating analytics only as “right or wrong” is insufficient. Two concepts help structure performance: precision and recall.
Precision measures the proportion of returned results that were actually relevant. High precision means fewer false positives.
Recall measures the proportion of existing relevant events that were found. High recall means a lower chance of missing true events.
These metrics trade off against one another. Making a filter stricter tends to increase precision and reduce recall. Making it more permissive tends to recover more events but also increase false positives.
BriefCam documentation makes this trade-off explicit through Strict, Normal, and Loose tolerances. The concept is generalizable: analytics systems always operate with decision thresholds.
For security applications, the choice should reflect risk. In a critical area, accepting more false positives may be reasonable to reduce the chance of missing an intrusion. In a monitoring center handling thousands of events per hour, excessive false positives can make operations unmanageable.
VMS Integration
Events, metadata, and alarms only create value when they reach the VMS and operations correctly. Integration must be specified and tested end to end.
The VMS typically centralizes cameras, recordings, users, events, alarms, and investigation tools. When analytics is integrated with the VMS, the operator can open event-related video, review context, search metadata, and export evidence within the same workflow.
Integration must be verified by function, not merely by a compatibility statement. It is necessary to confirm:
- which metadata is received;
- which events are searchable;
- whether bounding boxes are preserved;
- whether filters work on historical video;
- how alarms are presented;
- how timestamps are handled;
- how the system behaves during connectivity loss;
- how versions and updates affect integration.
Analytics in Operations Centers
In a Monitoring Center or Operations Center, analytics participates in a broader chain: detect, contextualize, prioritize, present, decide, respond, and record.
An intrusion event can automatically open the correct camera, display a map, present an operating procedure, and correlate access-control or perimeter-alarm information. The operator no longer has to manually navigate hundreds of cameras and can work with prioritized events.
A arquitetura é aprofundada em Monitoring Center: Architecture, Systems, and Design Requirements e em Integration of VMS, PSIM, SCADA, and BMS in Operations Centers.
Analytics for Operational Efficiency
Video analytics does not need to serve exclusively security purposes. The same classification and tracking mechanisms can support occupancy, flow, queues, heat maps, common paths, and dwell analysis.
BriefCam material includes visual layers for activity, dwell, and common paths. These resources illustrate how video metadata can support operational decisions.
This use should be conceptually separated from surveillance. Purpose, governance, data access, and retention may differ.
Privacy, LGPD, and Governance
The richer the analytics, the greater the need for governance. Metadata may represent person attributes, faces, license plates, trajectories, and behavior patterns.
The system should have access profiles, auditing, retention policies, export rules, and data-handling procedures. Features such as facial recognition and watchlists require specific assessment.
BriefCam material includes Data Protection mechanisms for locating, exporting, and deleting data associated with individuals or vehicles. This does not replace organizational governance, but it shows that processing is not limited to the video file: metadata, thumbnails, clips, bookmarks, and internal artifacts may also exist.
How to Specify Video Analytics
A weak specification says “the camera must have artificial intelligence.” A verifiable specification defines the expected behavior.
For each use case, engineering should establish:
- scenario and monitored area;
- object or behavior of interest;
- distance range;
- expected lighting;
- target direction and speed;
- detection rule;
- maximum event-generation time;
- expected action in the VMS;
- acceptable false-positive rate;
- minimum true-detection condition;
- metadata retention;
- authorized profiles;
- failure behavior;
- acceptance evidence.
This approach allows manufacturers to be compared by performance without limiting the solution to a catalog feature list.
How to Test Analytics During Commissioning
Commissioning should reproduce the use cases defined in the design. Merely checking that a configuration screen exists does not validate the analytics.
An acceptance test plan may include:
- generate a known event under controlled conditions;
- confirm timestamp and camera;
- verify that the object was detected;
- verify expected classification and attributes;
- measure latency to the VMS;
- confirm alarm or metadata generation;
- repeat under different times and lighting conditions;
- execute a known false-positive scenario;
- validate user permissions;
- verify historical search;
- export evidence;
- record results and nonconformities.
Tests should include relevant adverse conditions: backlighting, nighttime conditions, rain, partial occlusion, multiple objects, direction changes, and background movement.
Recommended Acceptance Criteria
| Criterion | What to measure | Evidence |
| Detection | true event recognized | video + log |
| False positive | incorrect events per period | test report |
| Latency | time between event and presentation | timestamp |
| Classification | expected class/attribute | analytics result |
| Search | event located through filters | screen + original video |
| Retention | metadata available over the period | historical query |
| Integration | event received in the VMS | log + interface |
| Failover | continuity or recovery | failure test |
| Permissions | function available only to the correct profile | access matrix |
| Export | reproducible and contextualized file | exported file |
Quantitative limits should come from project requirements and the declared and tested capabilities of the solution. There is no single percentage suitable for every environment.
Common Errors in Analytics Projects
A recurring mistake is purchasing analytics before defining the use case. Another is installing a general-context camera and expecting detailed recognition of faces, license plates, or attributes anywhere in the scene.
Other frequent problems include:
- framing incompatible with the task;
- excessive compression;
- poor lighting;
- attempting to use a moving PTZ for continuous analytics;
- lack of GPU sizing;
- metadata retention shorter than video retention;
- incomplete VMS integration;
- too many unprioritized alarms;
- lack of an operating procedure;
- lack of false-positive testing;
- relying on catalog figures without a POC or commissioning;
- confusing similarity with identification;
- confusing vehicle classification with LPR;
- treating analytics as conclusive evidence without human review.
Final Considerations
Video analytics add value when they transform an operational need into an event, metadata, or usable evidence. The benefit does not come from the “AI” label, but from the combination of use case, adequate imagery, algorithm, infrastructure, integration, and process.
Engineering should treat each application as a verifiable function. Intrusion, dwell, counting, forensic search, facial recognition, LPR, and video synopsis require different criteria and should not be grouped generically into a single specification line.
The design must also consider operations. Analytics that generates thousands of irrelevant alerts can worsen security. A well-specified system balances recall, precision, latency, and the team’s response capacity.
Finally, acceptance must demonstrate field performance. Camera, analytics, VMS, server, network, and operating procedure form a single system and must be tested end to end.
Analytics acceptance must measure detection, false positives, latency, historical search, integration, and behavior under adverse conditions — not merely confirm that the feature exists in the interface.
Technical References
[1] IEC. IEC 62676-4:2025 — Video surveillance systems for use in security applications — Part 4: Application guidelines. Available at: https://webstore.iec.ch/en/publication/83425
[2] ONVIF. Profile M — Metadata and events for analytics applications. Available at: https://www.onvif.org/profiles/profile-m/
[3] BRIEFCAM. BriefCam 2024 M1 User Guide. Setembro de 2024. Technical document consulted in the A3A Engenharia knowledge base.
[4] BRIEFCAM. Video Analytics White Paper. Dezembro de 2023. Technical document consulted in the A3A Engenharia knowledge base.
[5] BRIEFCAM. Video Characteristics for Best Video Results. Setembro de 2024. Technical document consulted in the A3A Engenharia knowledge base.
Frequently Asked Questions
They are software functions that process video to detect, track, and classify objects, generate events, and produce metadata usable by the VMS and operations.
Applications include intrusion detection, line crossing, dwell, counting, person and vehicle classification, facial recognition, LPR/ANPR, forensic search, video synopsis, and real-time alerts.
No. AI and deep learning are technologies used in many modern analytics systems, but motion rules, geometry, and classical computer vision are also forms of video analysis.
Precision indicates the proportion of returned results that are actually relevant. Recall indicates the proportion of existing relevant events that the system was able to find.
It depends on the use case. Edge analytics reduces latency and distributes processing; servers centralize capacity, engines, and advanced queries. Hybrid architectures are common.
Yes. Lighting, resolution, pixel density, focus, motion blur, angle, compression, and camera stability directly affect detection, tracking, and classification.
Define verifiable use cases, scenario, target, distance, latency, expected VMS behavior, false-positive tolerance, metadata retention, and acceptance criteria.
Generate known events and verify detection, classification, latency, integration, historical search, false positives, permissions, export, and behavior under adverse conditions.
