# Flock Audit Logs and Retention The Flock platform's **search-event recording and data-retention** layer. Conway produced monthly organization audit logs and a separate federal-tagged search export. Their fields include searching officer, agency, reason, search time, queried plate, filters, and network-count or device information, but the federal file does not name the networks searched or returned. The retention layer separately governs how long raw plate-read data remains queryable. ## How it appears in the corpus **Internal-officer audit logs** ([[Conway PD Audit Logs Series]]): 13 monthly CSVs across April 2025 – April 2026, totaling 10,378 Conway-officer search events. Pre-cutover schema 14 cols (`Text Prompt, Moderation` included); post-cutover schema (effective 2025-12-17) drops one column. **Federal-tagged search export** ([[Federal Searches CSV]]): A single file covering March 14–April 13, 2026, with 5,929 lookup rows across 31 calendar dates. Its fields do not name the networks searched or returned, so the file cannot establish that every row touched Conway data. **Van Buren policy requirements:** Policy 2.36 requires every historical search to include a case number or reason, requires a retained search log, and requires all searches to be included in a six-month public report. It also sets a default thirty-day purge for LPR data, related records, and logs absent a specific schedule. The first rolling production contains the policy but no native Flock search/audit export or six-month report ([[Van Buren License Plate Reader Policy]], `Policy 2.36 License Plate Readers.pdf`, pp. 4-5). **Retention rules:** - **Flock platform default (per [[Flock Safety Order Form and Contract]]):** 30-day retention for raw plate reads. - **Saline County order and Policy 5.27:** both state 30 days; the policy directs separate preservation of evidentiary data. - **CPD Policy 800-32:** 150-day retention ceiling, "in accordance with State Law," then automatic purge. Hit data used in investigations may be retained until "no longer needed." - **Audit log retention:** Not specified in the corpus. The 13 monthly files extending back to April 2025 suggest at least 13-month retention, but the corpus does not surface Flock's official audit-log retention policy. - **Conway preservation response:** CPD committed to preserve potentially responsive existing records in its possession or administrative control as required by law, practice, and counsel, but did not promise vendor preservation. It said records already deleted, purged, overwritten, or unavailable could not be recreated ([[Preservation Demand and CPD Response]], `FOIA 760 Preservation Demand - Connor.docx`, pp. 2-3). - **Lonoke County:** Policy 10.16 requires a related CAD or incident-report number for every deputy Search-tool use, frequent routine random browsing audits, 30-day vendor purging, and a 150-day local preservation ceiling. The live public CSV shows 100 blank visible case-number fields among 104 masked-user rows; its scope is unresolved ([[Lonoke County ALPR Policy 10.16]]; [[T035 - Lonoke Required Case Numbers vs Public Search Audit]]). ## Stakeholders - **Flock** — platform operator; sets the retention defaults and generates the audit-log exports. - **Agency administrators** — configure retention within the platform-supported range; per CPD Policy 800-32 are responsible for "automatic purge" verification. - **Auditing/oversight bodies** — Conway PD's "LPR supervisor" (per Policy 800-32) reviews semi-annual statistical reports; the public has access on request. - **FOIA requesters** — depend on audit-log retention to surface evidence of historical activity. ## Key takeaways - **Schema cutover at 2025-12-17.** The Conway audit log series shifts from 14 to 13 columns on this date. The `Important Update to Flock Audit Logs to Protect Officer Safety Active Investigations.msg` is the platform-change announcement; which column was dropped, and the stated rationale, are not established on this page. - **Officer-name redaction is inconsistent.** Some pre-cutover files marked "Redacted" still contain visible officer names. Plates are never redacted. The post-cutover files (March 2026, April 2026 partial) carry no "- Redacted" suffix but still contain identical PII patterns. - **The Reason field is officer-supplied free text.** It is the primary check on policy-compliant use (per CPD Policy 800-32's "evidence of an offense is indicated" sharing standard), but it is not validated at search time. An open analytic question is the distribution of Reason values across all 10,378 internal searches. - **Vendor generation does not decide custody.** Flock generates and can alter platform exports, but the public-record inquiry asks whether an existing record documents official activity and is possessed or administratively controlled by the agency. A storage/data-processing vendor is not independently suable under FOIA; the public body retains the initial record-status and access duties, subject to existence and exemptions. - **Retention, preservation, and FOIA are distinct.** A 30-day platform default may reduce what remains queryable, but it is not the outer boundary of FOIA availability if agency copies, backups, preserved evidence, or other existing records remain. FOIA is not itself a general retention schedule. Act 668 duties, agency schedules, contracts, preservation notices, and pending-request timing must be analyzed separately. ## Current-law record sequence For a vendor-hosted audit record, ask in order: (1) did the record exist when requested; (2) does it document official functions and satisfy the public-record definition; (3) did the agency possess it or have administrative control sufficient to arrange access; (4) does a statutory exemption or confidentiality rule apply; (5) is the requested output an existing or readily convertible record, or a discretionary new compilation; and (6) did a separate retention or preservation duty apply. (primary public record, [current section 25-19-105](../../web%20archive/2026-08-10/media.ark.org/ark-code-ann-25-19-105-2025-2026-annotated-laws.md)); (web research 2026-08-10, [Apprentice Information Systems v. DataScout](../../web%20archive/2026-08-10/app.midpage.ai/apprentice-info-sys-inc-v-datascout-llc-544-s-w-3d-39-ark-2018.md)); (web research 2026-08-10, [Daugherty v. Jacksonville Police Department](../../web%20archive/2026-08-10/app.midpage.ai/daugherty-v-jacksonville-police-department-411-s-w-3d-196-ark-2012.md)) The statewide general retention schedule is a minimum schedule for common state-agency records; it does not automatically classify or govern every local or vendor-specific audit record. (primary public record, [25 CAR Part 60](../../web%20archive/2026-08-10/webftp.blr.arkansas.gov/25-car-part-60-arkansas-general-records-retention-schedule.md)) ### In PDFOI-2026-1874 (LRPD Flock emails) The Little Rock PD production surfaces several 2026 audit and compliance developments visible in the agency's mailbox, documented in [[Flock Audit and Compliance Controls and Gaps]]: - **Mandatory NIBRS Offense Type per search.** Flock made selection of a NIBRS-based "Offense Type" from a dropdown a required field before any LPR search runs, while the older free-text "Search Reason" became optional ([[Flock Audit and Compliance Controls and Gaps]], Emails 1-24.pdf pp. 564, 645). Axon Fusus made a parallel change in its own RTCC stack, requiring an "Offense category" / "Search purpose" before an ALPR search and defaulting a "Case number" field to Required (min 3 chars) in release 2026.14 ([[Flock Audit and Compliance Controls and Gaps]], Emails 1-24.pdf p. 476). - **The "\*\*\*" masking disclaimer.** Flock added audit-record disclaimer text explaining that records shown as "\*\*\*" do exist but are "intentionally only visible to the searching agency" ([[Flock Audit and Compliance Controls and Gaps]], Emails 1-24.pdf p. 564; reprinted in Emails 25-35.pdf p. 275). This describes a vendor visibility rule; it does not establish that LRPD generated or retained a particular export. - **Out-of-state "Network Audit filter."** Flock's April 2026 newsletter announced a new "Network Audit filter" surfacing only out-of-state searches for any date range across the full audit history, pitched to "confirm there's no out-of-state activity, or review the searches that did happen" ([[Flock Audit and Compliance Controls and Gaps]], Emails 1-24.pdf p. 1330). - **A documented audit-log gap.** Axon Fusus release 2026.4 added adjustable confidence levels for ALPR vehicle-attribute searches with a stated caveat that "Adjusting confidence levels does not create audit log entries" ([[Flock Audit and Compliance Controls and Gaps]], Emails 1-24.pdf p. 556) — a parameter that materially shapes search results yet leaves no entry in the trail. These vendor-announced features bear on [[T004 - Ambiguous Audit-Log-Review Response vs Unresolved Item 3]], but they do not prove LRPD's configuration, permissions, retention, or possession of the named exports. The separate Deconfliction Advisories establish particular overlap-triggering events, not a complete officer-level audit log. ### Cabot retention and audit gaps Cabot Policy 305.1 sets a 150-day maximum for captured plate data, with defined case-preservation exceptions, while Cabot's produced Flock order forms specify 30-day platform retention ([[Cabot LPR Policy 305.1]], p. 3; [[Cabot Flock Agreements and Purchase History]], `Quote_Cabot PD Flex.pdf`, pp. 1-3). The shorter contract setting fits within the statutory/policy ceiling, but no tenant configuration or change-history export verifies that setting throughout the deployment. Cabot's six-month reports describe data purging before statistics were collected, an uncollected March-April 2023 interval, camera downtime, and a duplicated 2024 scan total ([[Cabot Semiannual LPR Reports]]; [[T016 - Cabot 2024 Semiannual LPR Report Accuracy]]). The July 2026 user export supplies account status, permissions, and last-login fields but not a search or Network Audit ([[Cabot Flock User Access Export]]). No SharedNetworks, Network Audit/history, retained search-audit, search-reason report, or underlying semiannual statistical spreadsheet was included, leaving both access scope and public-report accuracy unresolved. ### Saline County's policy-required audits versus produced printouts Saline County Policy 5.27 requires the LPR administrator or Sheriff's designee to audit a sample of browsing inquiries at least quarterly, document each audit in writing, forward it for Sheriff review, and file and retain the audit. It also requires a reason to be documented for each search ([[Saline County Camera Policies UAV Log and Audit Printouts]], `Questions #4 & #5.pdf`, pp. 13-14). The same production includes twelve screenshot-style pages of an audit table and twelve pages of recent search/lookup activity. Several columns are clipped, and no written quarterly audit, native export, field dictionary, or complete retained period was supplied (`Questions #4 & #5.pdf`, pp. 24-47). The screens establish record existence at the interface level; they do not establish the completeness or conclusion of a policy-required audit. The supplement did not extend that record set. Its 65-page file recompiled the same 41 sharing pages and the same 24 audit/activity pages, while the transmittal said the "network audit is kept for only 30 days" and concluded, "No more records located" (Gmail thread `19f904f131642359`, message `19fa534ea2d21ce9`; [[Saline County Recompiled Sharing and Thirty-Day Audit Packet]]). The unresolved difference between thirty-day platform activity retention and the policy's separate written-quarterly-audit retention duty is tracked at [[T033 - Saline County Quarterly Audit Requirement vs No-More-Records Disposition]]. ### Jacksonville native event log and local record duties Jacksonville produced a native Flock event log with 84,143 rows spanning 2025-01-13 through 2026-07-24. Its leading entity types are `stream` (79,301), `search` (1,967), `networkShare` (1,569), and `userSearchAudit` (776); these are reproducible groupings of the CSV fields, not a claim that the file is a normalized current configuration export ([[Jacksonville Flock Access Analytics and Event Logs]], `FLOCK - event-logs.csv`, header and data rows 1-84143). Jacksonville Policy 10-28 requires deployment/result records, alert/hit dispositions, reasons for manually entered hot-list plates, and a secondary-dissemination log. The first production did not include those records or a six-month statutory report. The supplement adds a 317-row tenant audit, a 990,877-row scope-ambiguous network audit, and a 10,379-row event log ([[Jacksonville Flock Search Network and Event Audit Exports]]). The supplement also includes an unsigned statutory-report template with entered scan and match figures, but blank reporting-term, compilation, public-availability, supervisor-signature, title, and signed-date fields. It is not treated as a completed report ([[Jacksonville Flock Compliance Analytics and Outcomes]]). The Flock order, Flock retention screenshot, and VehicleManager settings screen each show 30-day retention, within the policy's 150-day ceiling ([[Jacksonville LPR Policy and Retention Settings]], pp. 2-3). ## Independently archived vendor policy and audit context (2026-07-20) Flock's current evidence policy states a **30-day default** from capture, subject to customer agreements and law; says data are hard-deleted after the applicable period; and offers extended LPR retention up to one year when not otherwise required by law only after approval from an elected official or governing body (vendor primary/self-description, [Flock Evidence Policy](../../web%20archive/2026-07-20/flocksafety.com/flock-evidence-policy.md)). This is evidence of Flock's published policy, not proof that a tenant's setting or deletion process conformed. Flock's LPR policy says all queries are stored for auditing and describes customer administrators, privileged vendor access, customer-controlled sharing, legal/security disclosure exceptions, and use of less than one percent of LPR images — described by Flock as stripped of metadata and identifying information — for machine-learning improvement (vendor primary/self-description, [Flock LPR policy](../../web%20archive/2026-07-20/flocksafety.com/lpr-policy.md)). Those are vendor representations. They do not independently establish technical enforcement, completeness of logs, de-identification sufficiency, or the setting used by an Arkansas tenant. The May 26, 2026 price list separately contains extended-retention SKUs, including jurisdiction-specific one-, three-, and five-year entries. Catalog availability is not a tenant setting (official procurement attachment / vendor catalog, [Flock price list](../../web%20archive/2026-07-20/omniapartners.com/r250203-flock-pricing-2026-05-26.md)). The LAPD Inspector General found a special five-year Flock retention term in that mixed-vendor program and documented uncertainty over vendor access and written security agreements (primary public record, [LAPD OIG ALPR audit](../../web%20archive/2026-07-20/lapdpolicecom.lacity.org/lapd-oig-alpr-audit-2026-07.md)). That California configuration cannot be imputed to Arkansas. ## Arkansas compliance tests after Act 668 [[Arkansas Automatic License Plate Reader System Act|Act 668 of 2025]] makes the relevant record set broader than a contract's headline retention number. Compliance testing requires the tenant configuration and change history; preservation linked to each ongoing investigation; destruction at investigation/criminal-action conclusion; 24-hour data-update records when updates are available; public policies; six-month statistics; and dissemination/sharing logs. Vendor policy and a transparency page cannot substitute for those agency records. ## Bryant and Bentonville native audit additions Bryant's ten-sheet workbook contains 2,039 unique search/lookup rows across 27 operators. A case-number value appears on 493 rows, 1,546 are blank, and `Total Networks Searched` ranges from one to 6,353 ([[Bryant Flock Search Audit June 2025 to March 2026]]). Bentonville's June 24-July 24 Network Audit contains 4,241 rows associated with twelve organization labels. The export records activity within the produced report but does not identify that every query returned Bentonville data or that every listed organization had identical access ([[Bentonville Organization Access Sharing and Network Audit]]). ## Current-law authority crosswalk The 2026-08-10 legal audit uses these authorities only for the bounded propositions stated below: - (primary public record, [Arkansas Freedom of Information Act Handbook, 21st ed. (2025)](../../web%20archive/2026-07-20/healthy.arkansas.gov/arkansas-foia-handbook-21st-edition-2025.md)) — Current Arkansas FOIA response, segregation, format, judicial-remedy, and fee rules; the handbook is used as an official current-law guide rather than as evidence of agency conduct. - (web research 2026-08-10, [Fox v. Perroni, 188 S.W.3d 881 (Ark. 2004)](../../web%20archive/2026-08-10/caselaw.findlaw.com/fox-v-perroni-188-s-w-3d-881-ark-2004.md)) — Location and physical possession do not determine public-record status; administrative control and official function can require access arrangements. The Glaze dissent's proposed nexus test is excluded from the relied proposition. - (web research 2026-08-10, [Nabholz Construction Corp. v. Contractors for Public Protection Ass'n, 266 S.W.3d 689 (Ark. 2007)](../../web%20archive/2026-08-10/app.midpage.ai/nabholz-construction-corp-v-contractors-for-public-protection-ass-n-266-s-w-3d-689-ark-2007.md)) — A private contractor cannot be sued alone under FOIA, while a public body may not evade duties by handing records to a private entity. Does not by itself establish that every contractor record is public or under agency control. - (web research 2026-08-10, [Pulaski Cnty. Special Sch. Dist. v. Delaney, 575 S.W.3d 420 (Ark. Ct. App. 2019)](../../web%20archive/2026-08-10/app.midpage.ai/pulaski-cnty-special-sch-dist-v-delaney-575-s-w-3d-420-ark-ct-app-2019.md)) — A readily achievable requested format cannot be refused merely because volume or redaction makes another format preferable. Does not decide that scanning always avoids creation of a new record. - (web research 2026-08-10, [Swaney v. Tilford, 898 S.W.2d 462 (Ark. 1995)](../../web%20archive/2026-08-10/app.midpage.ai/swaney-v-tilford-898-s-w-2d-462-ark-1995.md)) — For existing, public, nonexempt records, the agency must arrange reasonable access even when a contractor physically holds them. Duties attach only after public-record status, existence, and nonexemption are established. ## Benton audit coverage and user export Benton's nine produced audit PDFs contain 4,659 parsed activity rows from November 2025 through July 2026. The March file ends on March 12, and no January-October 2025 audit appears even though the request sought retained records beginning January 1, 2025 (`11_1_2025-11_30_2025-Benton AR PD-Audit (REDACTED).pdf` through `7_1_2026-7_31_2026-Benton AR PD-Audit (REDACTED).pdf`, full tables; [[Benton Flock Audit and User Export 2025-2026]]). [[T060 - Benton Requested Audit Period vs Produced Coverage]] tracks the unexplained coverage gap. The separate August 3 user export contains 84 account rows, including 82 active and two deactivated accounts; 81 rows display Search and Hotlist Tool enabled (`Users_Roles_August_3_2026 (REDACTED).pdf`, full table). Account capability labels do not establish use during the audit period.