# ACIN Policy and Operations Manual `POL-301_ACIN_Policy_and_Operations_Manual_REDACTED_2026-01.pdf` is an 87-page version 1.0 compilation dated January 2026. Its pages are marked "For Official Use Only — Not for Public Release," and security material is captioned as redacted under Arkansas Code § 25-19-105(b)(11) (pp. 2-3 and throughout). The manual says it governs implementation through activation, while the MOU governs formal operations after go-live (p. 2). Its transmittal calls the manual the official pre-operational reference and says every section and appendix was reviewed and approved by the ACIN Oversight and Governance Board (p. 3). That approval account conflicts with the later kickoff packet's description of an informal, nonvoting initial advisory group; see [[T031 - ACIN Board Approval Claims vs Future Formal Governance]]. ## Architecture and integration The integration policy prescribes technical-readiness review, Peregrine API configuration, NIEM schema mapping, test-ingestion validation, and board approval before access (p. 16). It states: > "Only incident report information (not investigative files) may be shared. 'Case data' refers solely to non-narrative public-record identifiers." It also requires originating-agency tags, automated validation/duplicate detection, and an audit trail for modifications and deletions (p. 16). ## Roles, access, and logging - Access follows least privilege; agency administrators and the ACIN security officer conduct quarterly access reviews (p. 18). - Each agency monitors its users, and audit logs provide traceability for every query and modification (p. 18). - The quality-assurance section says all user activity is logged and reviewed monthly and that the security officer performs quarterly audits (p. 26). - The manual identifies Peregrine as technical coordinator, responsible for integrations, infrastructure, and data security (pp. 16, 18). These are policy requirements. The production contains no completed access review, audit report, or user-activity export. ## FOIA and legal posture The manual says ACIN refers requests to the originating agency, while the Sixth Judicial District Prosecuting Attorney's Office reviews requests for legal sufficiency and record consistency. It separately calls that office the custodian of ACIN records (p. 22). It also repeats ACIN's position that it is a factual data-sharing system rather than a 28 CFR Part 23 intelligence-file system, while voluntarily applying Part 23 privacy and dissemination principles (p. 22). The relationship between originating-agency referral and the Prosecuting Attorney's asserted ACIN-record custody remains unclear for vendor-held logs, cross-agency analytical outputs, and centrally generated audit records. ## Data-scope conflict Later in the same compilation, the Security and Privacy Governance Policy classifies: 1. incident reports, calls for service, and metadata as Tier 1 operational data; 2. **case notes, attachments, and suspect associations** as Tier 2 investigative data; 3. audit logs and system records as Tier 3 administrative data; 4. de-identified statistics as Tier 4 public data. (`POL-301_ACIN_Policy_and_Operations_Manual_REDACTED_2026-01.pdf`, p. 47.) > [!contradiction] Incident-only rule versus investigative-data tier > Page 16 excludes investigative files and limits case data to non-narrative identifiers. Page 47 expressly includes case notes, attachments, and suspect associations. The LeadsOnline contract further provides narrative, phone-extraction, movement, and location analysis. See [[T030 - ACIN Incident-Report-Only Scope vs Investigative Data Services]]. ## Retention hierarchy The manual contains several overlapping schedules: | Record or condition | Rule | |---|---| | Documents and electronic records generally | At least five years (p. 22) | | Procurement records | Five years (p. 24) | | Federal-grant records | Five years after closeout unless audit, litigation, or investigation remains open (p. 36) | | Contributed agency data | Originating agency's schedule and Arkansas records law (p. 44) | | Deactivated or withdrawn agency data | Archived seven years and removed from shared access on written request (p. 44) | | Board minutes | At least seven years (p. 74) | | Security-incident logs, reports, and evidence | Seven years in the ACIN audit repository (p. 83) | | User access and acknowledgments | At least seven years (p. 59) | Those rules may apply to different record classes, but the manual does not supply a field-level schedule resolving which rule controls each central, vendor, originating-agency, or derived record. ## Governance and financial controls The manual describes quarterly board meetings with retained minutes, policy changes by recorded vote, quarterly financial reporting, annual financial statements, procurement controls, and an annual independent audit requirement (pp. 11-12, 23-24, 70-75). Many approval and signature fields in the embedded appendices remain blank. ## Security and incident response The compilation requires CJIS and cybersecurity training, multifactor authentication, role-based access, monitoring, breach reporting, quarterly exercises, and security-incident retention (pp. 13-21, 55-63, 81-84). Substantial configuration detail is captioned as redacted. ## Significance This production resolves the first batch's lack of an underlying policy text. It establishes formal written controls, but also exposes internal conflicts about data scope, governance approval, and retention. Policy text alone does not establish implementation or compliance. ## Open questions / follow-ups - Produce the board action, roster, minutes, and vote approving version 1.0 and each embedded policy. - Produce completed quarterly access reviews, monthly user-activity reviews, security audits, financial audits, and incident reports. - Reconcile the incident-only rule with the investigative-data tier and vendor contracts. - Produce the field-level retention and offboarding schedule identifying the authoritative copy at ACIN, each agency, Peregrine, and LeadsOnline. - Clarify which custodian responds for central audit logs, derived alerts, and vendor-held records.