VMS, NVR, and VSaaS platforms
VMS, NVR and cloud video platforms manage different combinations of devices, recording, users and events. Identify the supported interface for the workflow you're building.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Platform neutral architecture; licensed features, API behaviour, residency, and service commitments require exact vendor/contract verification.
On this page
Overview#
A video management system (VMS) coordinates devices, live viewing, recording, search, events, users, audit, and integrations. A network video recorder (NVR) packages some or all roles in an appliance. Video Surveillance as a Service (VSaaS) moves management and often storage/processing to cloud services, but doesn't remove edge or network dependencies.
Role decomposition#
| Role | Authority/data |
|---|---|
| Device registry | Logical camera/source IDs, capabilities, credentials, configuration intent |
| Media ingress | Sessions, stream selection, receive health, transcoding/relay |
| Recording service | Recording policy, segment/index creation, retention/deletion |
| Event service | Subscriptions, normalisation, rules, bookmarks/incidents |
| Client/access service | User/workload auth, site/tenant/resource permissions |
| Federation/cloud control | Site registry, remote access, tenancy, regional services |
| Export/evidence | Search selection, native/open export, provenance, audit |
Products combine these roles; design redundancy and privilege around the roles, not one product name.
Deployment patterns#
- Central VMS: cameras stream to site/datacentre recorders and management servers.
- Distributed/federated: sites retain local recording/control; a central service searches/views via federation.
- Edge recording: camera/local device records and VMS retrieves/reconciles gaps, often using ONVIF Profile G or native APIs.
- Hybrid cloud: on site gateway/recording plus cloud management/remote access/analytics.
- Cloud first VSaaS: device or gateway initiates authenticated uplink; recording may use local buffer and cloud object storage.
IEC 62676-2-11:2024 defines public scope interoperability profiles for VMS/cloud VSaaS interfaces, including levels from export to exclusive video control. It is not a blanket authorisation to share video.
ONVIF Profile V is still a Release Candidate on 25 August 2026. The official FAQ says products can't claim conformance until finalization and testing. Treat current Profile V designs as changeable.
Data and control boundaries#
Separate live view, playback/export, event/metadata, device management, PTZ/I/O, platform administration, and support access. A cloud viewer shouldn't inherit camera firmware or relay rights. Federation must preserve site/tenant identity and distinguish local authority from cached central state.
Availability#
Define behaviour under camera, recorder, storage, database, message bus, identity provider, DNS/time, WAN, cloud region, license, and certificate outage. Record recovery point/objective, buffer capacity, gap reconciliation, split brain/fencing, client failover, and whether local operators retain required functions.
Don't assume high availability because multiple nodes exist. Validate shared dependencies, storage quorum, licenses, virtual infrastructure, switches/PoE, and recovery procedures.
Cloud and tenancy#
- Establish customer/vendor controller/processor roles, region, subprocessors, support access, retention/deletion, legal hold, export, and tenant exit.
- Use distinct device/workload/user identities and resource/site/tenant authorisation; test cross tenant denials.
- Limit device egress to named services and verify certificate/token bootstrap and rotation.
- Understand who can decrypt live, recorded, analytic, and exported data and where keys reside.
- Plan service termination: credential revocation, local ownership, bulk evidence/config export, deletion confirmation, and replacement path.
Migration/acceptance#
Build a capability intersection for exact device/client profiles, codecs, events, analytics, PTZ, recording, audio, I/O, certificates, and APIs. Test migration with representative retention, bookmarks, users/roles, audit, time, edge gaps, exports, and rollback. Never equate an imported camera list with a complete evidential migration.
Return to Video surveillance systems.