A forensic audit of the Bibb County Sheriff’s Office’s use of Flock Safety automated license plate reader technology has raised significant questions about how deputies and other personnel document their searches — and whether the agency can reliably demonstrate the investigative purpose behind every use of the surveillance system. The audit examined 3,663 Flock Safety search-log entries generated by 63 user accounts between May 1 and June 1, 2026. Its central finding is striking: only 2,063 searches, or 56.3 percent, contained a properly formatted case or incident number in the designated “Case #” field. The other 1,600 searches — 43.7 percent of the total — either placed identifying information in the wrong field or contained no identifiable case reference at all. The report does not conclude that those searches were unauthorized or that any individual employee intentionally misused Flock. In fact, the auditors explicitly caution against drawing that conclusion. What the findings expose instead is a significant accountability problem: when a powerful surveillance tool is used without consistent records tying searches to specific investigations, determining after the fact whether those searches were legitimate becomes considerably more difficult.
204 searches with no identifiable case The most serious category identified by the audit consists of 204 searches — 5.6 percent of the entire dataset — for which investigators could identify no case or incident number anywhere in the record. In those instances, the dedicated case-number field was blank and the reason field contained either no identifying number or only general descriptions such as “suspect,” “stolen,” “shooting” or “investigation.” That distinction matters. A search connected to a documented investigation can potentially be reviewed against an incident report, warrant, dispatch record or other agency documentation. A search recorded simply as “suspect” or “investigation” provides far less information to determine why a person or vehicle was queried. The audit recommends that all 204 searches be individually reconciled against the agency’s records-management system to establish whether each was connected to a legitimate investigative purpose.
More than 1,300 searches documented incorrectly Most of the questionable records do not appear to represent searches completely lacking a case reference. Instead, they reveal what the audit describes as a widespread recordkeeping problem. Of the 3,663 searches examined, 1,396 — 38.1 percent — contained evidence that a case identifier had been entered incorrectly. In 1,022 records, users apparently placed a case number in the free-text “Reason” field while leaving the designated case-number field blank. Another 347 records contained a Flock-generated “FID” identifier in place of an agency case number. Because the same problem appears across numerous user accounts, the report suggests the pattern is more consistent with a systemic workflow or training problem than an isolated employee habit. That explanation may be less alarming than intentional misuse, but it does not eliminate the accountability problem. ALPR audit logs are supposed to make surveillance activity reviewable after it occurs. If investigators must manually reconstruct which case justified thousands of searches because identifying information was entered inconsistently, the usefulness of that audit trail is substantially weakened.
High-volume bursts deserve a closer look The audit also identified 71 “burst sessions” in which the same user performed at least five plate lookups with no more than two minutes between consecutive searches. Some were dramatically larger. One user performed 128 lookups in approximately 14 minutes on May 30. Another performed 101 searches during a roughly 25-minute session. Other sessions included 59, 46 and 41 lookups. Such activity is not inherently suspicious. Investigators could legitimately run dozens of plates while working an organized theft investigation, searching for a wanted person or analyzing vehicles associated with a larger case. The report explicitly recognizes that possibility. But several high-volume sessions lacked an agency case number entirely or relied on a Flock FID rather than an agency case identifier. That combination — unusually concentrated searching coupled with incomplete documentation — is why the auditors recommend supervisory review. Among the sessions identified was a 41-lookup sequence lasting about 26 minutes with no case number entered. Another 33-lookups-in-12-minutes session also contained no case number. Additional sessions of 31, 26 and 25 searches likewise lacked an entered case number. Without additional records, however, the audit cannot determine whether those searches represented legitimate investigative work or something else. And that uncertainty leads to one of the report’s most important limitations.
Redactions prevent the most important verification The data provided for analysis did not include the actual license plates searched. According to the report, both the License and Filters fields were completely redacted from every row of the agency's export. That means the auditors could determine when searches occurred, who conducted them and how closely together they were performed — but they could not determine whether a 40-search burst involved 40 different vehicles, repeated searches of one vehicle or some combination of the two. The report therefore warns that its “repeated plate search” analysis is only a proxy based on temporal clustering rather than a direct comparison of license plates. That limitation is particularly important when evaluating possible misuse. The existing records can identify activity that deserves further examination, but the redacted dataset cannot answer the ultimate question of what vehicles were actually being searched and why. The audit recommends repeating the analysis using unredacted plate-level information if it can be made available through appropriate authorization.
A small group conducted most searches Flock usage was also heavily concentrated among a relatively small number of accounts. The median user performed just 13 searches during the audit period. The highest-volume account performed 553 searches — more than 42 times the median. The top three accounts together generated 35.3 percent of all searches, while the top 10 accounted for roughly 70 percent of the agency’s entire search volume. Again, volume alone is not evidence of misconduct. An investigator assigned specifically to vehicle-related cases or an intelligence analyst could reasonably use the system far more frequently than a patrol deputy. The audit itself stresses that point, saying high-volume users should be viewed as a starting population for supervisory sampling rather than evidence of wrongdoing. The concern becomes more significant when high search volume overlaps with missing case numbers, unusual search bursts or other documentation problems.
Relevant primary-source documents are published in our Open Records Library as they become available.
Browse source documents →