However in my experience in a big org, #1 happens frequently enough where it basically would be needed at all times, and would need a security person (or entire team) dedicated solely to that purpose. And sadly in my experience, companies are not willing to spend the money, or able to hire enough security people, to have that level of a dedicated security concierge for every team that needs it.