# Decentralized Acquisition and Centralized Surveillance Interoperability
Arkansas surveillance acquisition is institutionally decentralized while surveillance access is becoming operationally interconnected. Municipal police departments, a county sheriff, county government, and the State Police chose different vendors through different legal and fiscal routes. No single statewide procurement selected the systems, and no single legislative body authorized the resulting network. Yet the records show those separately acquired systems being reconnected through Flock sharing, HIDTA/ELSAG domain administration, fusion-center access, vendor APIs, a proposed trooper-facing statewide query layer, and ACIN's stated federation of agency incident-report systems.
This is not a claim that Arkansas operates one technically unified surveillance database. The corpus documents multiple vendors, domains, contracts, and access paths. The finding is narrower and more consequential: institutional fragmentation at purchase time does not prevent functional integration at use time, while the fragmentation makes it difficult to identify who is responsible for auditing the combined system.
## Evidence
**Acquisition is jurisdiction-specific and procedurally fragmented.** Conway funded Flock through asset forfeiture after the cameras were removed from the ordinary budget, with Council ratification following contract execution ([[Ordinance O-25-09 — LPR Bid Waiver and Asset Forfeiture Appropriation]], *"appropriating asset forfeiture funds"*). Fayetteville activated Axon Fleet 3 ALPR through a no-cost field-trial agreement authorized by the Mayor rather than a Council appropriation ([[Axon Field Trial Agreement and City Authorization]], *"There is no cost for the field trial"*). Pulaski County selected Flock through a scored competitive RFP ([[Pulaski County RFP-23-003 Solicitation and Flock Safety Bid]], *"lease approximately six (6) Automatic License Plate Readers"*). Little Rock renewed Flock and acquired adjacent surveillance systems through cooperative-purchasing and sole-source instruments ([[Flock LPR Renewal (Resolution 16846)]]). ASP bought Leonardo/ELSAG through an NCPA cooperative term contract funded with federal ARPA pass-through money, with a HIDTA network license included at purchase ([[Term Contract 4600055190 and PO 4502235324 — Initial Leonardo ELSAG Buy]], *"One Time HIDTA LPR Network License Included"*). Bald Knob used a DPS equipment grant to buy a smaller Leonardo/ELSAG package from John Wright Associates ([[Bald Knob DPS Equipment Grant Reporting Form]], p. 1, "24PSEG010"; "47693.50"), although the release does not identify that grant's underlying appropriation.
**Interconnection appears after procurement.** Conway's Flock tenant exposed its reads through a 1,384-organization sharing topology ([[SharedNetworks 2025-12-17 Snapshot]]). LRPD's correspondence documents a regional hot-list-sharing network and out-of-state/fusion-center reach ([[Flock Deconfliction Advisories and the LRPD Sharing Network]]), while a separate source documents private Home Depot camera shares ([[Home Depot Camera Sharing into LRPD]]). ASP's ELSAG/HIDTA records show an Arkansas domain with shared hot-list visibility, administrator delegation, and a silent-list domain ([[ASP–Houston HIDTA MOU and ELSAG Domain Architecture]], *"will be seen by all in that domain"* and *"admin rights to manage users within the domain"*).
**The central bridge has formal audit language but unresolved implementation.** The blank HHIDTA MOU/policy package sent to ASP places custody with the origin agency, requires at least twelve months of access-audit logging and monthly member-user/hot-list audits, and requires an incident/report number for each query ([[ASP HIDTA Governance Terms and Administrator Duties]], `HHIDTA LPR MOU 11.15.22 _Secure.pdf`, pp. 6, 8, 11). Yet the executed ASP copy and the resulting audit exports remain absent. The vendor's confirmation that every ASP HIDTA camera used 150-day retention also conflicts in scope or time with ASP's active-investigation-only image-file policy, leaving the governing rule unresolved ([[ASP ALPR Policy Retention and FOIA Exemption Proposal]]; [[T037 - ASP Active-Investigation-Only Image Policy vs 150-Day HIDTA Retention|T037]]).
**The state-level bridge is cross-platform access, not a single-vendor mandate.** The Arkansas State Fusion Center sought analyst access across *"1. ELSAG … 2. Motorola LPR … 3. Flock … 4. AR Advance … 5. ATLAS … 6. ACIC"* ([[Cross-Network Analyst Access and the Arkansas State Fusion Center]]). ASP separately pursued an ELSAG API so a trooper entering a plate in ATLAS could see matching reads from ASP's LPR system *"within Arkansas"* (same source). Lt. [[Dennis Overton]] also answered an interstate survey as the *"ALPR Point of Contact for Arkansas"* ([[ALPR Point of Contact for Arkansas — Statewide Coordination]]). These records establish functional coordination across platforms without establishing that ASP commands local deployments.
**ACIN extends the same interoperability problem beyond plate-reader systems.** ACIN says it connects participating agencies' RMS platforms and lets them "share and analyze incident-report information in near real time" ([[ACIN Executive Overview 2026-05-15]], pp. 1-2). The executed Peregrine package names 45 agency roles and provides a $3 million platform scope covering comprehensive search, dashboards, real-time alerts, and geospatial, link, temporal, and trend analysis ([[Peregrine and Carahsoft Executed Contract]], `CON-002_Peregrine_Carahsoft_Executed_Contract_2026-03-17.pdf`, pp. 2-5). The executed LeadsOnline package adds automated case searching, AI-generated narratives and timelines, phone-extraction material, communications and movement, location references, LPR-hit analysis, and cross-agency collaboration ([[LeadsOnline Executed Contract]], `CON-001_LeadsOnline_Executed_Contract_2026-07-13.pdf`, pp. 15-17, 25, 46-47).
**ACIN's documentary governance does not yet reconcile the interconnected system.** The standard MOU restricts sharing to incident reports and excludes investigative files, while the manual classifies case notes, attachments, and suspect associations as investigative data and LeadsOnline contracts for complete-case and phone/movement analysis ([[ACIN Agreements and Participation Terms]], `AGR-201_El_Dorado_PD_MOU_EXECUTED_2026-05-15.pdf`, p. 1; [[ACIN Policy and Operations Manual]], `POL-301_ACIN_Policy_and_Operations_Manual_REDACTED_2026-01.pdf`, p. 47). The March vendor scope, July status table, and produced agreements also yield different participant snapshots ([[ACIN Participant and Integration Status]], `STS-301_ACIN_Agency_Status_2026-07-15.pdf`, p. 1). Board documents describe competing approval histories and membership models ([[ACIN Governance Board and Controlled Repository]]). Those conflicts are tracked at [[T030 - ACIN Incident-Report-Only Scope vs Investigative Data Services]], [[T031 - ACIN Board Approval Claims vs Future Formal Governance]], and [[T032 - ACIN Participation Rosters and Agreement Status]].
**Accountability remains fragmented.** ASP counsel states that ASP does not conduct *"reviews, audits, or approvals of other agencies or municipalities and their use of ALRPs"* ([[2026-06-05 Roach Route Map and Item-4 Disclaimer]]). [[D003 Synthesis]] resolves the apparent contradiction: formal oversight of local operators is not shown, while ASP's functional state-level coordination role is. LRPD's ambiguous audit-log-review response, partial notification trail, and unproved console custody ([[T004 - Ambiguous Audit-Log-Review Response vs Unresolved Item 3]]) and ASP's no-LPR-system position despite operational ELSAG records ([[T007 - ASP No-LPR-System Position vs Documented ELSAG Operation]]) show why records responsibility cannot be inferred from technical access alone. ACIN's manual likewise routes contributed-data requests to originating agencies while calling the Prosecuting Attorney's Office custodian of ACIN records, leaving centrally generated logs, alerts, and multi-agency outputs without a fully resolved custody map ([[ACIN Policy and Operations Manual]], `POL-301_ACIN_Policy_and_Operations_Manual_REDACTED_2026-01.pdf`, p. 22).
## Strategic finding
The emerging Arkansas model is not centralized procurement followed by centralized governance. It is **decentralized adoption, federated access, and unresolved accountability**. Agencies retain local control over contracts and nominal platform settings; vendor and interagency infrastructure makes the resulting data useful across organizational boundaries; and no produced record assigns one institution responsibility for auditing the whole arrangement.
That structure changes the next investigative question. Asking only *which agency bought which camera* is no longer sufficient. The higher-value questions are: who can query across systems, who can create or share watch lists, who grants access, what audit trail exists at each bridge, and which institution must review misuse that crosses agency or vendor boundaries.
## Caveats
- The corpus does not establish a single statewide database containing all Arkansas plate reads. “Interoperability” here means documented access brokerage, sharing relationships, domain administration, and planned or available query integrations.
- The fusion-center checklist shows desired or initiated access; it does not prove every listed access path was completed or continuously used.
- ASP's ELSAG domain evidence directly establishes ASP/AHP/federal-administrator relationships, not comprehensive municipal and county participation.
- The HHIDTA documents recovered on 2026-07-28 are blank templates sent during onboarding. They establish form terms, not which revision ASP executed or whether ASP performed each audit duty.
- Bald Knob's grant file establishes acquisition and a 2024-03-08 received-but-not-installed status; it contains no later operational, sharing, or interoperability record and therefore is not evidence that Bald Knob joined the state-level bridges described here.
- Vendor portfolios are broader than the products proved in Arkansas. Leonardo's public SignalTrace materials describe electronic-signature/device-group tracking, but ASP's procurement does not name SignalTrace; Flock's public Condor, Raven, Alpha, and advanced-analytics catalog likewise does not establish Arkansas acquisition. See [[SignalTrace Electronic-Signature Tracking]] and the public-technical boundary on [[Flock Safety, Inc.]].
- No produced record establishes that ACIC holds ALPR-specific audit or approval authority. ACIC remains the highest-priority institutional gap, not a presumed answer.
- ACIN's final package establishes executed, funding-contingent vendor terms, participation forms, project-authored status labels, and written policies. It does not establish a federal award, approved final budget, funding-availability notice, payment, accepted integration, live configuration, or actual audit practice ([[ACIN Proposed Federal Grant and Budget]]; [[T014 - ACIN Analytical Reach vs Non-Surveillance Classification]]).
- This page is analytical synthesis. Each factual premise is anchored to a Tier-1 source page; the conclusion describes their cross-jurisdiction relationship.
## Open questions
- Does ACIC audit ALPR-derived NCIC/ACIC access, hot-list use, or cross-system queries, and does it maintain ATLAS policy or access records?
- Which local agencies can be queried through ASP, the Fusion Center, HIDTA, ATLAS, or vendor integrations, and which access paths are reciprocal?
- Was the ELSAG-to-ATLAS API completed, and what logs, retention rules, and user permissions apply to the resulting query surface?
- Who reviews access that crosses vendor boundaries, such as a fusion-center analyst moving among ELSAG, Motorola, Flock, ATLAS, and ACIC?
- Which ACIN agencies and source systems became funded and operational; what fields, historical depth, alerts, relationship graphs, AI tools, retention periods, and access logs were actually configured; and who audits activity across participants?
- Do local procurement records disclose the downstream sharing and integration capabilities that become active after purchase?