# Jacksonville Flock Access, Analytics, and Event Logs
Four artifacts document different slices of Jacksonville's Flock tenant: an outside-agency access printout, a two-page hot-list analytics view, a native event-log CSV, and a dashboard map screenshot. None is a complete bidirectional SharedNetworks export with historical configuration fields.
## Outside-agency participation
`Devices - Jacksonville AR PD - Admin - Flock Safety - OUTSIDE AGENCY PARTICIPATION.pdf` is a 12-page printout generated on 2026-07-14 at 10:23. Machine parsing yields **349 organization rows**, all with the relationship label `Access`:
| Produced setting | Enabled | Disabled |
|---|---:|---:|
| Search | 343 | 6 |
| Hotlist | 287 | 62 |
Fifteen organization names include `(0 cameras)`. The printout's rows establish organizations presented to Jacksonville with the displayed permissions; they do not define whether access is incoming, reciprocal, or matched by outbound access to Jacksonville data, and they do not carry effective dates or change history (`...OUTSIDE AGENCY PARTICIPATION.pdf`, pp. 1-12).
## Alert analytics
The Flock analytics screenshot reports:
- `Total Hotlist Alerts` — **14,912**
- `Official Hotlist Alerts` — **2,021**
- `Your Custom Hotlist Alerts` — **1,758**
- `Other Custom Hotlist Alerts on Your Networks` — **11,133**
The topic table includes 819 sex-offender, 619 warrant, 192 protection-order, 158 stolen-vehicle, and 149 stolen-plate alerts (`Flock - Analytics.pdf`, p. 1). The page was printed on 2026-07-24 at 9:44 AM, but no selected date range is visible. These figures therefore cannot be assigned a defensible reporting period from the produced page.
## Native event log
`FLOCK - event-logs.csv` has the fields `Timestamp`, `User`, `Event Type`, `Entity Type`, `Entity Details`, and `Event Id`. It contains **84,143 data rows** from `2025-01-13T19:35:31.000Z` through `2026-07-24T13:09:08.000Z`, with 70 distinct nonblank user values.
| Event type | Rows |
|---|---:|
| update | 55,949 |
| read | 26,340 |
| create | 1,768 |
| delete | 86 |
| Leading entity type | Rows |
|---|---:|
| stream | 79,301 |
| search | 1,967 |
| networkShare | 1,569 |
| userSearchAudit | 776 |
| Custom Hotlist Entry | 190 |
| user | 111 |
| location | 108 |
| role | 44 |
| customHotlist | 31 |
| export | 28 |
The remaining types total 18 rows: organization, network-share settings, integration, organization audit, transparency report, and organization file. Counts are reproducible groupings of the native CSV's event and entity fields (`FLOCK - event-logs.csv`, header and data rows 1-84143).
The event log is strong evidence of retained tenant activity, but it is not a normalized current configuration export. `networkShare` events do not by themselves supply a complete current topology, and the event-detail field requires event-specific interpretation.
## Dashboard map screenshot
`Screenshot 2026-07-24 093424.png` shows a Jacksonville-centered Flock map with green, gray, and red camera icons. It carries no legend, visible device labels, or coordinates; the location export is the authoritative produced source for exact points.
## Open questions / follow-ups
- Native current and historical SharedNetworks, organization-access, role, permission, user/access, device-group, and network-audit exports with direction and effective dates.
- The selected date range and underlying export for the 14,912-alert analytics view.
- Definitions for the access printout's relationship and permission fields and the event log's entity-detail structures.
- Complete retained search-audit, alert-disposition, manual-hot-list-reason, and secondary-dissemination records required by local policy.