Video operations
What is a video management system (VMS)?
A video management system (VMS) is the software layer that sits above your cameras and turns them into a usable system — discovering devices, pulling and recording their streams, enforcing how long each recording is kept, and controlling who is allowed to watch, export or delete it. It is not a camera and not a recorder appliance: it is the layer that makes cameras from different manufacturers, on different sites, behave as one estate with one login, one search and one audit trail. Most organisations buy cameras first and meet the VMS question later — usually at the moment somebody asks for footage from a site nobody has logged into in a year.
What a video management system actually does
Strip away the marketing and a VMS performs a small number of jobs, repeatedly, across every camera you own. It has to find devices on the network and keep track of them when addresses or firmware change. It has to receive each stream and write it to disk under a policy that says how long that particular camera's footage lives. It has to give an operator a live view that does not collapse when forty tiles are open, and a playback timeline that can be scrubbed, clipped and exported in a form an investigator will accept. And it has to know who did all of that. The last item is the one most estates fail. Without per-user roles and an export log, footage leaves the building with no record of who took it, when, or why — and the first time that matters is the first time it is contested.
- Device discovery and inventory — cameras found, named, grouped by site and zone
- Live view and video walls across multiple monitors and multiple sites
- Continuous or event-driven recording, with retention set per camera or per zone
- Playback, timeline search, and evidence export in a verifiable format
- Health monitoring — a camera offline or a disk filling is an alert, not a discovery
- User roles, permissions, and an audit trail covering every view, export and deletion
VMS vs an NVR, a DVR, and the camera's own web page
These are sold as alternatives but they are really three points on one line. A DVR is a fixed appliance that digitises and records analogue cameras over coaxial cable. An NVR does the same job for IP cameras over the network, usually with a fixed channel count and a fixed set of disks. Both are recorders with an interface bolted on, and both are bounded by the box: when you need channel thirty-three you buy a second NVR, and now you have two systems and two logins. A camera's own web interface sits below even that — it configures one camera and often records to an SD card, which is adequate until you need to correlate two cameras or prove who watched what. A VMS is software, so it is bounded by the servers and storage you give it rather than by a chassis. The honest counterpoint: for one shop with eight cameras, an NVR is cheaper, simpler and entirely sufficient. The VMS argument begins when sites, brands or accountability multiply.
Video management system software and multi-vendor CCTV
This is where projects succeed or fail, and it is the question buyers underestimate. An Indian estate assembled over a decade will hold Hikvision and Dahua from the early rollouts, CP Plus from the branch expansions, an Axis or Hanwha camera where somebody specified quality, and a run of analogue cameras nobody wants to re-cable. The useful question is not whether a VMS supports cameras. It is which of your cameras it supports, and how deeply. Three mechanisms do the work and they are not equivalent. Generic RTSP will usually get you a picture and very little else. ONVIF gives you a standardised conversation about discovery, streaming, events and PTZ. A vendor SDK gives you the manufacturer's full feature set, and ties that feature set to one integration continuing to be maintained. Most real deployments use all three at once, which is why the supported-device list matters more than the feature grid.
- RTSP — the transport for the stream itself; a fallback that yields video but rarely configuration, events or PTZ
- ONVIF Profile S — the original streaming profile, now being deprecated; new conformance submissions close in March 2027, largely because its username token authentication no longer matches current security guidance
- ONVIF Profile T — the recommended successor, covering H.264 and H.265, imaging settings, motion and tamper events, and metadata streaming
- ONVIF Profile G — recording and playback, including retrieval from a camera's own edge storage
- Vendor SDKs — the deepest integration and the highest maintenance; ask when yours was last updated
- The practical test — find your exact model numbers on the supported list, not just your brand names
Analogue cameras, encoders, and the estate you actually have
Very few Indian sites are purely IP. Coaxial runs installed years ago still carry serviceable cameras, and re-cabling a live factory floor or a bank branch is disruptive, expensive and rarely the priority. A video encoder solves this. It is an appliance that takes analogue inputs on one side and presents standards-compliant IP streams — typically ONVIF and RTSP — on the other, so the VMS sees an ordinary network camera. HD-over-coax formats such as HDCVI, TVI and AHD complicate this slightly, because the encoder has to speak the same variant the camera does. The trade-off is worth stating plainly: an encoder does not add resolution the camera never had, it adds one more device that can fail, and it consumes power and rack space at the edge. What it buys is sequencing. You unify the estate under one system now and replace cameras on their own depreciation schedule instead of all at once, because the software layer is what changes how the estate is operated.
VMS versus video analytics: archive, or live interpretation
A VMS answers questions about the past. Something happened, you know roughly when and where, and the system helps you find the clip and export it. That is genuinely valuable, and it is structurally forensic — the value arrives after the event, as evidence. Video analytics does something different. It interprets the stream as it arrives — a person in a restricted zone, a vehicle stopped where nothing should stop, a queue past a threshold, a fire door propped open — and raises an event while the situation is still live. The distinction is not a feature comparison, it is a change in what the camera is for: an estate running a VMS alone has an excellent record of incidents nobody was told about at the time. The two are complementary. Analytics needs somewhere to record and a retention policy; the archive needs a reason for anyone to be watching. When evaluating, ask where the analysis runs — on the camera, on the recording server, or on a separate platform — because that decides your bandwidth and how many streams you can decode at once.
Storage and bandwidth: the sizing that sets the budget
Retention is a storage question before it is a policy question, and the arithmetic is unforgiving: capacity equals bitrate times time times camera count. Everything else is detail about bitrate. Resolution raises it, frame rate raises it close to linearly, and codec choice moves it most — H.265 is commonly cited as delivering comparable quality at roughly half the bitrate of H.264, which is the largest single lever available, provided both the camera and the VMS support it, which across a mixed estate they often do not. Two things break naive estimates. Modern encoders are variable bitrate, so a still corridor costs almost nothing while a windy night of noise and moving foliage can run at several times the datasheet figure — averages under-predict. And motion-only recording appears to solve the problem when it mostly relocates it: you save disk and accept gaps, false triggers from rain and headlights, and questions about the thirty seconds before the trigger. Size on continuous recording, then treat motion-only as an optimisation. Recording bandwidth is also not viewing bandwidth — a video wall pulling forty main streams over a WAN link is what sub-streams exist to prevent.
Retention, the DPDP Act, and why one global setting will not do
Footage of identifiable people, held digitally, is personal data. India's Digital Personal Data Protection Act was enacted in August 2023, and the Rules notified in November 2025 phase its obligations in — the substantive duties, including notice and consent, data principal rights, reasonable security safeguards and breach notification, arrive in May 2027. Two principles bear on video: collect for a stated purpose, and do not keep the data longer than that purpose requires. Sectoral expectations pull the other way, and they differ. Banking premises, government and critical infrastructure sites, commercial premises under local licensing conditions, and housing societies under state co-operative rules and their bye-laws answer to different instruments. Check the one that binds you, not a day count from a vendor blog, including this one, which is why no number appears here. One estate-wide setting cannot serve both pulls; per-camera or per-zone retention can, with each choice documented against its reason. To be blunt: no product makes an organisation DPDP compliant. Compliance is a legal posture: your purposes, notices, contracts, and accountable people. Software can enforce a policy, log every export and delete on schedule — evidence that the policy is real. Choosing it is not the vendor's job.
What to check before you commit
The differences that decide a video surveillance project show up during a proof of concept on your own cameras, not on a datasheet. Run one — and run it on the worst site rather than the newest. The branch with the decade-old coax, the plant with the flaky link, the building where nobody remembers the camera passwords: that is the site that reveals whether discovery genuinely works, whether the older models stream reliably for a week rather than an afternoon, and whether an operator can be trained to use the system at two in the morning. Take these answers out of the pilot rather than out of the proposal, and put the ones that matter into the contract.
- Are your exact camera models on the supported list, or only your camera brands?
- Which ONVIF profiles are supported, and what happens to a Profile S-only camera you cannot replace yet?
- Can retention be set per camera and per zone, or only globally?
- Is every live view, export and deletion logged against a named user?
- Does export produce something an investigator or a court will accept, with integrity intact?
- Where does analytics run, and what does that do to server, decode and bandwidth sizing?
- What happens when a site link drops — does anything buffer at the edge, and does it backfill?
Have Questions? We've Got Answers.
A video management system, usually shortened to VMS, is software that discovers cameras, records and retains their streams, provides live view and playback, and controls who can see or export footage. It is the system layer above the cameras — the cameras produce video, the VMS makes it findable, governed and auditable.
The same thing, described from the estate's point of view. A VMS for CCTV is the software that unifies the cameras you already own — IP cameras directly, analogue cameras through an encoder — into one console, so a mixed-brand, multi-site deployment is searched, retained and audited as one system rather than as a collection of separate recorders.
An NVR or DVR is a recorder appliance with a fixed channel count and fixed disks; when you outgrow it you add a second one and a second login. A VMS is software bounded by the servers and storage you give it, so it scales across sites and brands. For a single small site, an NVR is often the more sensible purchase.
Usually yes, but the depth varies. Generic RTSP gets a stream; ONVIF adds standardised discovery, events and PTZ; a vendor SDK unlocks the manufacturer's full feature set. Ask for the supported-device list and check your exact model numbers, because brand-level support does not guarantee that a specific model behaves.
No. A VMS is an archive with a search box — it helps you reconstruct what happened after you already know something happened. Video analytics interprets the live stream and raises an event while the situation is still unfolding. They work together, but only one of them changes response from forensic to preventive.
It depends on which instrument binds you, and expectations differ between banking premises, government and critical infrastructure sites, commercial premises under local licensing conditions, and housing societies. Check your own obligation rather than a general figure. Under the DPDP Act the countervailing principle is that footage should not be kept longer than the stated purpose requires — which is why per-camera or per-zone retention, documented against a reason, is the practical way to satisfy both pulls.
Keep reading
Want to see your existing cameras on one console?
Tell us what is on your sites — brands, analogue runs, whatever the last integrator left behind — and we will walk through discovery, retention and live events on your own estate.