Flock Safety Shares Camera Access Across Agencies

Joshua Michael
Joshua Michael
Published
FlockSurveillance TechnologySecurity ResearchGovernment SurveillanceData Exposure

A town may own the Flock Safety camera that records your car, but ownership does not tell you who can search the result. The captured software supports feature-by-feature access, automatic approval inside a state or radius, and nationwide discoverability so distant agencies can find one another and request sharing. A local road can feed a much larger investigative network, and the driver has no simple way to see which agencies reached the sighting.

A camera can be owned by one organization while access to its capabilities crosses an organizational boundary through software. The captured FlockSafety sharing library does not describe one generic sharing switch. It separates search, hotlists, live video, historical video, recorded-video downloads, imaging settings, pan-tilt-zoom controls, PTZ settings, and analytics into distinct feature scopes.

The development client keeps automatic approval within a state or configured radius separate from nationwide discoverability, and that separation controls how the setting should be read. The nationwide option makes an organization discoverable; it does not automatically approve every nationwide request. The same client also implements revocation actions and CSV downloads describing owned and shared network relationships.

For a person whose vehicle or image is captured, the practical access boundary can depend on recipient organization, feature scope, preference state, and whether a copy leaves the interface.

Owning the camera and reaching the sighting are different powers.

A grant can contain materially different powers

The Garnacha feature library includes SEARCH, HOT_LIST, VMS_GO_LIVE, VMS_HISTORICAL, VMS_DOWNLOAD, VMS_IMAGING_SETTINGS, VMS_PTZ, VMS_PTZ_SETTINGS, and ADVANCED_ANALYTICS. Its display descriptions distinguish viewing live video from viewing recorded video, downloading recorded video, managing imaging settings, issuing live PTZ commands, managing PTZ settings, and accessing traffic analytics

The sharing workflow can translate selected product features into distinct permission sets for another organization, which makes the phrase "share cameras" too imprecise for oversight. A search grant is not a live-view grant, and a live-view grant is not a download grant or PTZ control. Each scope changes what a recipient can do and what could happen to the people the network records.

Nationwide discoverability is not nationwide auto-approval

Being findable is not the same as being auto-approved.

The development sharing client serializes several preference concepts into different fields. shareStatewide is derived from an automatic-acceptance choice within the user's state. shareRadiusMiles is populated from a configured automatic-acceptance radius. Separate fields hold discoverability within 50 miles, within the state, and nationwide. discoverableNationwide is therefore distinct from state and radius auto-approval in the captured logic

One preference can make a network visible to organizations nationwide, while different settings control automatic acceptance within a state or radius. Discoverability can increase the population of organizations able to find and request access without itself granting that access. Auto-approval can reduce the human review of requests that fall within configured boundaries. Those are different risk mechanisms, and collapsing them into a single claim of nationwide automatic access gets the software wrong.

Revocation and export create different lifecycles

The same development client maps two end-access actions, Revoke Access and Stop Accessing. In another path, it can request CSV data for owned networks or shared networks and save a local file after tracking CSV Downloaded (Owned Networks) or CSV Downloaded (Shared Networks)

Revocation changes access through an application request; export writes a file outside the live interface. An in-app revocation can end future access if the backend enforces it correctly. It cannot, by itself, reach backward into a file someone already saved.

The CSV concerns network relationship information, not vehicle detections or video. Recorded-video download appears separately as a shareable feature scope.

Who is affected when access crosses organizations

The privacy cost appears when a person cannot see how many organizations can search, view, download, analyze, or control the network that recorded them. A motorist may pass one locally owned camera while the real software question is which outside organizations hold active feature grants. Recorded by one organization does not mean accessible only to that organization.

Collection and later disclosure remain separate events, and the client makes the chain visible: one organization records, another requests a feature, an administrator approves or automates access, and a recipient may create a copy.

Revocation runs on two clocks. It can end future access inside the service, while a CSV or downloaded recording may keep existing under the recipient's controls. The export path is enough to show why ending an in-app relationship and recovering every copy are not the same event.

The captured software turns an organizational boundary into separate discoverability, approval, feature, export, and revocation decisions, each capable of changing how far an observation travels.

Leave it to us to secure
the seemingly impossible

The world's leading All-Source Intelligence Firm for Cybersecurity and Privacy