# Cabot Flock User Access Export `Users_July_21_2026.pdf` is a ten-page Flock user table produced on 2026-07-21. Pages 1-5 contain the left half of the rows—user identity, email, title, role, and status—while pages 6-10 continue those same rows with identity-provider, user-management, Search, Hotlist Tool, and Last Login fields. The wiki does **not** republish account-holder names, email addresses, user IDs, titles tied to individuals, or login dates. The aggregate findings below were reconstructed by preserving page-pair row order and validating all 140 status rows. ## Account status | Status | Accounts | |---|---:| | Active | 87 | | Deactivated | 53 | | **Total** | **140** | Source: `Users_July_21_2026.pdf`, pp. 1-5, full `Status` column count. ## Active accounts by email-domain category | Domain category | Active accounts | |---|---:| | Cabot municipal domain | 47 | | Lonoke PSAP domain | 20 | | Arkansas State Police domain | 18 | | Lonoke sheriff domain | 1 | | Consumer-email domain | 1 | | **Total active** | **87** | Forty active rows therefore use non-Cabot domains. A domain identifies the address namespace, not necessarily an account-holder's present employer, authority, or access scope. ## Active roles and permissions The active role values are: 23 `Supervisors and Investigators`, 22 `Dispatch`, 19 `Outside Agencies`, 13 `Patrol`, five `Admin`, four `Supervisor`, and one `Lieutenant's` (`Users_July_21_2026.pdf`, pp. 1-5, `Role` column). The paired permission columns show: - Search enabled: **87 of 87 active accounts**. - Hotlist Tool enabled: **87 of 87 active accounts**. - User Management enabled: **5 active accounts**; disabled for 82. - Nine active accounts have no Last Login value. - Eight additional active accounts have a last-login date more than 365 days before the export date. Source: `Users_July_21_2026.pdf`, pp. 6-10, paired to the 87 active rows on pp. 1-5. ## What this establishes—and does not The export establishes that Cabot's Flock tenant retained active accounts under multiple public-agency and one consumer domain, and that Search and Hotlist Tool permissions were enabled at the account-feature level. It does **not** identify: - which Cabot cameras or networks each account could search; - whether the account could see Cabot data, only its own agency's data, or another configured scope; - whether any account actually conducted a search, received an alert, downloaded data, or shared a hot list; - who approved the account or permissions, their effective dates, or whether stale accounts were later disabled; - organization-level SharedNetworks direction, camera-level sharing, or National Lookup scope. Those limits prevent the 40 non-Cabot-domain accounts from being equated with 40 confirmed recipients of Cabot plate data. The unresolved policy and scope question is tracked at [[T017 - Cabot Sharing Rule vs Unresolved External Account Scope]].