# Configured Surveillance Data Sharing as an Operational Model ## Status *Erratum, 2026-07-30: this synthesis formerly said D001 settled that Flock's interface defaults toward sharing and that product design produced Conway's 1,384-row topology. The Tier-1 email used in that dialectic says National Lookup consists of “participating, opt-in agencies” and lists multiple sharing choices, including “Don't share at all” (`Flock Safety Understanding Sharing Search and Audits in the Flock LPR System.msg`, body). The SharedNetworks export shows configured directions, not the initial default, relationship author, or approval path. D001 and the dependent D002 verdict are therefore no longer operative; [[T001 - Default-On Sharing Policy or Product Design]] and [[T002 - Successor-Policy Omission]] are reopened.* Read this page in light of that distinction: - **Established:** Conway's 2025-12-17 export contains 1,384 organization rows with at least one sharing direction; later NLRPD, Rogers, Benton County, and Bentonville exports show similarly broad but differently shaped configurations. - **Established:** Conway's federal activity export records 5,929 federal-tagged searches across 31 calendar dates. A relationship inventory is topology evidence; the federal file is activity evidence, but it does not name the networks searched or returned. - **Not established:** whether an Arkansas tenant begins default-on or default-off, who enabled each relationship, whether a counterparty action alone can create an incoming row, or what approval record accompanied a relationship. - **Not established:** that no MOU, warrant, policy review, or notice exists outside the productions searched. The defensible statement is that none is surfaced for the rows in these productions. The corpus documents a configuration-based operational model: standing organization relationships and permissions can support later searches, alerts, and collaboration without a new relationship decision for each event. That is different from proving a vendor default. The records support scrutiny of the configured reach and its approval/audit trail while leaving the configuration mechanism open. **The topology: 1,384 configured rows.** [[SharedNetworks 2025-12-17 Snapshot]] records **1,384 organization rows** — 486 bilateral, 471 incoming-only, and 427 outgoing-only — in `SharedNetworks_2025_December_17.csv`. Ninety-four percent are outside Arkansas. The production does not surface a relationship-specific agreement or approval history for those rows. That is a production finding, not proof that no such record exists elsewhere. **North Little Rock independently reproduces the scale.** The [[North Little Rock Flock SharedNetworks Snapshot 2026-07-16]] contains 1,616 organization rows, including 1,113 with at least one NLRPD network shared outward, 1,027 with an incoming network, and 524 with both directions populated. Its outward configuration distinguishes a base NLRPD network from `North Little Rock AR PD - Genetec LPR`. The export does not show who enabled each relationship or whether it was exercised, but it establishes that thousand-organization sharing topology is not unique to Conway. **The documented mechanism is configurable, not proved default-on.** Flock's August 2025 email says the administrator has “full control over whether and how” the agency shares, calls National Lookup an opt-in network, and lists state, radius, one-to-one, and no-sharing choices ([[Audit-System Policy Emails (Aug 2025 - Apr 2026)]], `Flock Safety Understanding Sharing Search and Audits in the Flock LPR System.msg`, body). The email establishes configurability. It does not establish the starting selection, number of approvals, or authorship of Conway's rows. **Three record classes.** The [[Federal Searches CSV]] records **5,929 federal-tagged searches** across 31 calendar dates without naming searched networks or results. [[Home Depot Camera Sharing Series]] documents a corporate-coordinated rollout into Conway's available camera networks. [[Escambia County FL SO Hot List Share]] documents an out-of-state custom-hot-list request. Together they show topology, activity, and onboarding; none alone establishes the platform's initial default. **The policy-application question remains open.** CPD Policy 800-32 says captured LPR data may be shared with another law-enforcement agency “if evidence of an offense is indicated” ([[CPD Policy 800-32 — License Plate Reader Vehicle Operations]], `Conway PD LPR Policy.pdf`, § D.4). The record does not show how Conway interpreted that clause for standing configurations, whether another directive governed them, or whether the productions searched every policy repository. Those are the narrower questions at T001 and T002. **“Full control” needs configuration records.** Flock says the customer owns the data and controls whether and how it is shared (same vendor email). Conway's export does not identify the person who exercised that control, the approvals used, or later changes. [[Andrew Burningham]]'s extensive presence in the email set establishes an administrative role, not authorship of every relationship. **Not unique to one vendor category.** Axon markets Fusus with “cross-agency sharing when and where you choose,” and the Fayetteville Fleet 3 trial used managed hot lists ([[Axon Fleet 3 ALPR Trial]]; [[Axon RTCC and Surveillance Ecosystem Pitch]]). That supports a cross-vendor capability comparison, not a claim that every product or tenant starts in the same state. **What this is, and is not.** The page does not characterize a relationship or search as unlawful. It identifies a documented configuration-and-audit question: broad standing relationships exist, selected activity is measurable, and the production lacks the records needed to attribute or evaluate each configuration decision. The record does not establish a product default. ## Jacksonville adds topology and a scope warning Jacksonville's 2026-07-29 SharedNetworks export contains 1,205 organization rows: 276 with an incoming-network field, 1,107 with an outward-sharing field, and 178 with both ([[Jacksonville SharedNetworks Users and Hotlists Exports]], `SharedNetworks_2026_July_29.csv`, header and full-file parse). This is a third large native Arkansas topology after Conway and North Little Rock, but it still does not identify relationship authorship, initial defaults, approvals, or use. The same release contains a 317-row Jacksonville-attributed tenant audit and a separate 990,877-row network-audit export spanning 3,135 organization names. The larger file has no produced data dictionary tying every row to a Jacksonville search, Jacksonville data, or a returned result. Any cross-jurisdiction activity inference therefore remains provisional on [[T041 - Jacksonville Tenant Audit vs Network Audit Scope]]. ## Evidence - **The topology.** [[SharedNetworks 2025-12-17 Snapshot]] enumerates 1,384 organization rows involving Conway (486 bilateral, 471 incoming-only, 427 outgoing-only) in `SharedNetworks_2025_December_17.csv`; 94% are out-of-state. No relationship-specific MOU appears in that production. - **Cross-jurisdiction replication.** [[North Little Rock Flock SharedNetworks Snapshot 2026-07-16]] contains 1,616 organization rows, 1,113 outward, 1,027 inward, and 524 bilateral (`SharedNetworks_2026_July_16.csv`, full-file parse). - **Jacksonville topology.** [[Jacksonville SharedNetworks Users and Hotlists Exports]] contains 1,205 organization rows, with 276 incoming fields, 1,107 outward fields, and 178 both (`SharedNetworks_2026_July_29.csv`, full-file parse). - **Jacksonville activity-scope limit.** [[Jacksonville Flock Search Network and Event Audit Exports]] separates 317 locally attributed audit rows from a 990,877-row multi-organization network-audit export; the data dictionary needed to attribute the larger file is absent ([[T041 - Jacksonville Tenant Audit vs Network Audit Scope]]). - **The vendor's sharing menu.** Flock's August 2025 email describes National Lookup as opt-in and lists state, radius, one-to-one, and no-sharing options ([[Audit-System Policy Emails (Aug 2025 - Apr 2026)]], `Flock Safety Understanding Sharing Search and Audits in the Flock LPR System.msg`, body). - **Federal activity.** [[Federal Searches CSV]] records 5,929 federal-tagged searches across 31 calendar dates. Its columns contain no network-identity, result, per-query Conway approval, or notice field (`Federal Searches March 2026 to April 2026.csv`, header and full-file parse). - **Private-business sharing.** [[Home Depot Camera Sharing Series]] documents six Arkansas Home Depot camera networks made available to Conway in spring 2026. The production does not surface a relationship-specific MOU. - **Out-of-state peer sharing.** [[Escambia County FL SO Hot List Share]] — a January 22, 2026 Flock notification says a Florida sheriff's-office custom hot list was shared to a Conway audience; it does not identify the audience-selection actor or approval path. - **The policy question.** CPD Policy 800-32 permits data sharing “if evidence of an offense is indicated” ([[CPD Policy 800-32 — License Plate Reader Vehicle Operations]], `Conway PD LPR Policy.pdf`, § D.4); the corpus does not show how Conway applied that clause to standing configurations. ## Caveats - [[D001 Synthesis]] and [[D002 Synthesis]] are retained as historical isolated-phase artifacts, but their operative verdicts are superseded by the 2026-07-30 evidence correction described above. - Flock's current public statement describes sharing and National Lookup as agency-controlled and opt-in, limits National Lookup to a full exact plate, and says each search requires a reason and is audited (vendor primary/self-description, [Flock network-sharing statement](../../web%20archive/2026-07-20/flocksafety.com/statement-network-sharing-use-cases-federal-cooperation.md)). Those are vendor-stated controls. They do not contradict the Tier-1 Conway topology and query records; they show why actual tenant settings, delegated identities, and audit exports — not a generic policy page — are needed. - Act 668 of 2025 preserves an evidence-of-an-offense standard for defined law-enforcement sharing and adds public-policy, update, retention, and reporting duties (primary public record, [Act 668 of 2025](../../web%20archive/2026-07-20/arkleg.state.ar.us/act-668-2025.md)). This synthesis does not adjudicate whether any particular Conway relationship complied; it identifies the records needed to test that question. - The [[SharedNetworks 2025-12-17 Snapshot]] is a single point-in-time export; the corpus contains no time series, so the network's growth rate and its earlier or later size are not established. - The corpus does not establish that any specific sharing relationship is improper. The absence of MOUs in the production is not proof that none exist at the Flock-platform level; it is an absence in this agency's records. - The historical “default-on” label should not be used as a finding about tenant initialization or interface friction without configuration or product-default records. - Conway remains the corpus's richest combination of topology, activity, policy, and administrator correspondence. NLRPD supplies a directly comparable and larger SharedNetworks row set, while LRPD, PCSO, and ASP supply other record types that document cross-boundary access or alerting without proving the same configuration mechanism. - This page is the author's analytical synthesis, demarcated as such per the wiki's editorial posture. Every factual claim above is anchored to a source page and, through it, to a raw FOIA document. ## Open questions - **Default and authorship.** What was the initial Arkansas-tenant setting, what action created each direction, and which administrator or counterparty acted? Configuration history and vendor default-state documentation would move [[T001 - Default-On Sharing Policy or Product Design]]. - **Policy scope and search completeness.** Which written directive governed standing relationships, and which policy repositories were searched? Tracked at [[T002 - Successor-Policy Omission]]. - **How does Act 668's evidence-of-an-offense sharing rule apply to a standing platform relationship** as distinct from a per-event transfer? The enacted text supplies the standard; the corpus lacks a judicial or agency interpretation resolving its application to configuration-level access. - Would a refreshed [[SharedNetworks 2025-12-17 Snapshot]] export show the network larger or smaller than the 1,384 organizations recorded on 2025-12-17? - What configuration controls, approval rules, and audit review govern LRPD's regional Flock sharing and ASP's HIDTA/ELSAG domain? Those productions now corroborate cross-boundary access but do not include a directly comparable configuration-history export showing who enabled each relationship and under what policy.