

If you want to know how powerful your city's ALPR system is, counting poles is not enough.
Start with paperwork.
The boring documents tell you what the cameras are allowed to become.
1. Get the contract and every incorporated document.
Request the signed master agreement, order forms, amendments, product-specific terms, data-security addenda, implementation documents, and renewal notices.
Those records can answer: How much is the city paying? How many devices or licenses were purchased? What is the contract term? Does it auto-renew? Which retention period is specified? Which product modules are included?
A screenshot of a camera cannot answer any of that.
2. Get the operating policy.
Ask for the agency's ALPR policy, acceptable-use policy, search-justification requirements, hotlist procedures, supervisory rules, prohibited uses, training materials, and discipline policy.
Then compare policy to product capability. A feature existing in the platform does not prove the agency uses it. A policy prohibiting a use does not prove the control is technically enforced.
3. Ask about sharing, not just ownership.
Request the current list of external organizations with access to the agency's ALPR data and any agreements governing that access. Ask whether the agency can search external datasets and whether partners can search its data.
This reveals the effective network boundary without publishing a road map for evading cameras.
4. Request audit information.
Depending on state public-records law and investigative exemptions, useful requests may include aggregate search counts, audit-log exports with legally protected fields redacted, records of internal audits, confirmed misuse findings, user-role counts, administrator activity, and records of access revocation.
If raw logs cannot lawfully be released, ask for aggregate statistics and audit reports.
5. Find the political decision points.
Request council agendas, staff reports, procurement memos, budget approvals, renewal dates, presentations, public comments, and communications about expanding or replacing the system.
Surveillance policy often changes at procurement deadlines because that is when elected officials actually have leverage over the contract.
6. Build a capability sheet, not a paranoia board.
For each deployment, record:
- camera/device count
- retention period
- sharing partners
- search volume
- required search justification
- hotlist sources
- audit frequency
- confirmed misuse findings
- AI or video-search modules
- contract cost and renewal date
That creates a comparable local dataset.
7. Publish uncertainty.
If an agency refuses a record, note the exemption. If a figure comes from Flock rather than the city, label it. If a sharing list is only a snapshot, timestamp it. If audit logs cover six months, do not describe them as the agency's entire history.
The fastest way to ruin civic oversight is to overstate what the records prove.
What not to build.
A governance audit does not require identifying routes that avoid cameras, publishing vulnerable camera positions, interfering with communications, obscuring plates, or damaging equipment.
The point is to make the government's authority observable to the people who fund it.
This is a lawful public-records and governance methodology. It intentionally excludes blind-spot mapping, evasion routing, interference, plate obstruction, and equipment-disabling tactics.