# T017 — Cabot Sharing Rule vs Unresolved External Account Scope Cabot Policy 305.1 permits captured-plate sharing with another law-enforcement agency when the data indicates evidence of an offense and says the data may not otherwise be shared, while Cabot's Flock tenant retained 40 active accounts using non-Cabot domains with Search and Hotlist Tool enabled. The export does not reveal what cameras or networks those accounts could access, so the record raises a compliance question without proving a violation. ## Statement A Policy 305.1 states: "Captured plate data that indicates evidence of an offense may be shared with other law enforcement agencies. Captured plate data may not be otherwise shared, sold, traded, or exchanged" ([[Cabot LPR Policy 305.1]], `305.1 License Plate Readers.pdf`, p. 3). ## Statement B The July 21, 2026 user export contains 87 active accounts, including 40 using non-Cabot domains; all 87 active rows show Search and Hotlist Tool enabled ([[Cabot Flock User Access Export]], `Users_July_21_2026.pdf`, full-file page-pair reconstruction). The domains include state-police and Lonoke-area public-safety namespaces plus one consumer-email domain. ## Why it matters If the accounts can search Cabot reads, Cabot's authorization, purpose, relationship, and audit records are necessary to test the policy's evidence-of-offense boundary and account-management controls. If the accounts are scoped only to their own networks or inactive data domains, the apparent tension narrows substantially. The current user export cannot distinguish those possibilities. ## Resolution status `open` — resolve through per-user network/camera scope, SharedNetworks and Network Audit/history exports, account-approval and role-change records, retained search/audit logs, and a custodian explanation of what Search and Hotlist Tool mean for outside-domain users. **2026-07-23 update:** Sgt. Elliott's supplement transmittal states that beyond the Drive folders "we don't have any responsive documents" (Gmail message `19f8f5d6c0de0fbb`) — a custodian statement that the named exports are not retained as Cabot documents. Resolution therefore likely requires platform-generated exports produced on request, vendor-side records, or account-scope clarification rather than existing Cabot files; see [[cabot-pd/2026-07-23-axon-fleet3-supplement/_overview|Cabot Axon Fleet 3 Supplement]]. **2026-07-28 update:** Lonoke Policy 10.16 says data shared by other agencies remain the originating agency's property and may be accessed only for official law-enforcement purposes ([[Lonoke County ALPR Policy 10.16]], `738.FOIA...pdf`, p. 30). Lonoke's vendor portal separately lists 741 organizations granted access to Lonoke data and 1,984 organizations sharing data with Lonoke (vendor primary/self-description, [Lonoke County AR SO Transparency Portal](../../web%20archive/2026-07-28/transparency.flocksafety.com/lonoke-county-ar-so.md)). Those records confirm a large configured topology, but neither identifies what the `@lonokepsap.gov` and `@lonokeso.com` accounts in Cabot's tenant could search. T017 therefore remains open. ## Discovery Surfaced during the 2026-07-22 Cabot production ingest by comparing Policy 305.1 to the produced user export. ## Notes An enabled feature column is not proof that an account searched Cabot data.