Internal Raleigh Police audits found former employees still listed as active users in the city’s license-plate camera systems, along with hundreds of accounts that saw little or no use. The records show weak access administration. They do not show that a former employee logged in, searched plate data or caused a breach.
Ashley Rowe and Randall Kerr of WRAL reported the findings Aug. 26 after obtaining internal Office of Professional Standards audits for Flock and Vigilant LEARN. Their investigation distinguishes between an account remaining registered and a user being able to authenticate, a distinction that should remain central to any account of the case.
Stale accounts and broad unused access
April and May audit language said several registered active users were no longer Raleigh Police employees. The department told WRAL that former employees could not use the systems because access required city email or phone credentials for multifactor authentication, and those credentials had been disabled when employment ended. Raleigh later removed the stale accounts and ended its practice of retaining them in case employees returned.
Rico Boyce, Raleigh’s police chief, told City Council on Aug. 18 that no former employees were able to access the system. The department’s later clarification is narrower: their registrations remained listed as active, while inactive city credentials and two-factor authentication were supposed to block actual entry. Without login histories, that control remains an explanation from RPD rather than an independently tested fact.
An Aug. 5 audit listed 416 active Flock users. More than half had not logged in during the review period, according to reporting. A large account count does not mean 416 people were actively searching camera data or held identical permissions. It does raise a least-privilege question: why keep access active for users who do not need the tool often enough to use it?
That question matters because automated license-plate readers can reconstruct where vehicles appeared at particular times. Even when stored data is limited, a broad user population increases the number of accounts that must be approved, trained, monitored and removed promptly.
Outcome records are incomplete
A July audit recorded 5,911 queries and 23 reported “successes,” including nine stolen vehicles, 12 arrests or warrants and eight leads. Those categories overlap, so the subcounts cannot be added to produce 29 separate outcomes. The audit also called for better completion of outcome fields, limiting claims about effectiveness.
The City of Raleigh’s Flock policy page says the system costs about $75,000 a year and normally deletes data after 30 days unless records are preserved for an investigation. The city publishes totals for leads, recovered vehicles, arrests and property value. Those are department-reported associations. They do not establish that Flock alone caused a recovery or that the same result would not have occurred through another investigative method.
The city also says every search requires a legitimate purpose and documented reference, that activity is audited, and that Raleigh Police owns the data. The internal audits show that formal policy did produce some review and correction. They also show incomplete justifications, stale registrations and access that had not been narrowed to actual use.
The evidence needed to assess risk
The full audit files and access logs would show how many former employees remained registered, their roles, last login dates and permission levels. An independent test could verify whether deactivated city credentials reliably block Flock and Vigilant authentication. The department should also disclose how quickly access is removed after separation and who approves accounts outside the Raleigh Intelligence Center.
The city’s remediation is relevant. Removing the accounts and ending the retention practice reduces the identified risk. It does not answer why offboarding failed to remove system registrations or why so many active accounts showed no use. A durable correction would connect personnel separation automatically to vendor-account termination and require periodic recertification by supervisors.
A WRAL follow-up compared Raleigh with other North Carolina departments and found substantial variation in the share of officers with Flock access. Those comparisons are directional rather than conclusive because departments assign different roles, operate different camera networks and may count users differently. Raleigh’s strongest benchmark is its own policy: access should reflect job need, receive appropriate approval and leave a complete audit trail.
The unresolved immigration question also shows why precise access records matter. Raleigh says U.S. Immigration and Customs Enforcement has no direct access and that RPD does not use Flock for immigration enforcement. It also says the department can provide information under a legal document tied to criminal activity. An audit should therefore show both direct searches and disclosures to outside agencies, with the legal basis recorded.
The public-record trail should not rely on screenshots or social-media summaries when the underlying audit can be released. The MuckRock request provides a locator for records and correspondence. Publication should use the audit itself for exact dates, counts and wording once available.
The audit supports a governance finding, not a breach allegation. Raleigh had more system access on paper than its usage justified and left former employees registered after departure. The strongest next test is whether the city can prove that its technical controls blocked those accounts and that the remediation lasts.
