A police employee opens Flock and searches a license plate.
No report is written.
No arrest follows.
No supervisor asks about the search.
The employee closes the system and moves on.
But the search did not disappear.
The database recorded it.
User.
Time.
Date.
Search criteria.
Reason entered.
And increasingly, the activity itself starts becoming evidence.
Across the country, law enforcement agencies are dealing with employees accused of using restricted databases for reasons having nothing to do with legitimate police business.
Some have searched relatives.
Some have searched acquaintances.
Some have searched romantic partners or former partners.
Others have searched themselves.
The consequences have included administrative investigations, termination, resignation, criminal investigations, and criminal charges.
This is no longer a technology problem.
This is an Internal Affairs problem.
Why This Matters
On August 7, 2026, the Savannah Police Department announced the termination of four sworn officers and two civilian employees following an internal investigation into misuse of its Flock Safety license plate reader system.
The department reported that a proactive system review identified searches appearing unrelated to legitimate law enforcement activity. All six cases were also referred to the Georgia Bureau of Investigation for independent criminal review.
Days later, a Sarasota, Florida officer was fired and arrested following allegations involving misuse of law-enforcement databases, including Flock and Florida's Driver and Vehicle Information Database, commonly known as DAVID.
These are not isolated incidents.
A Washington Post investigation identified at least 69 police officials accused, charged, or convicted of misusing Flock or other license-plate-reader systems. The investigation also found instances where outside parties identified suspicious activity before the employee's own department did.
That should concern every IA commander.
The question is no longer:
Does your agency have audit logs?
The better question is:
Who is reviewing them?
The Case File
Consider what today's employee might access during an ordinary shift:
Flock or another automated license plate reader system.
State driver's-license databases.
NCIC and state criminal justice systems.
RMS.
CAD.
Jail-management systems.
Body-worn-camera platforms.
Criminal intelligence databases.
Digital evidence systems.
Employee records.
Investigative case-management systems.
Agency email.
Evidence-management software.
Each system serves a legitimate public-safety purpose.
Each system also provides access to information the general public does not possess.
That access creates responsibility.
It also creates temptation.
An employee wants to know where an ex-partner has been.
Someone asks an officer to "run this tag for me."
An employee looks up a neighbor.
A dispatcher searches a family member.
An investigator checks a new romantic partner.
An officer runs his own vehicle to see what the system contains.
The search takes seconds.
The consequences might last years.
What Investigators Should Notice
1. Database Misuse Is Often an Intent Case
The search itself might not be disputed.
The employee's purpose becomes the issue.
An investigator therefore needs to establish:
Why did you search this person, vehicle, address, or record?
That answer needs independent verification.
If the employee says:
"It was related to an investigation."
Find the investigation.
Find the case number.
Find the call.
Find the report.
Find the CAD event.
Find the supplemental report.
Find the intelligence bulletin.
Find the supervisor who assigned the task.
Legitimate law-enforcement activity usually leaves other records behind.
When those records do not exist, the explanation deserves closer examination.
2. Stop Treating the Audit Log as an IT Record
The audit log is investigative evidence.
Preserve it accordingly.
An IA investigation involving database misuse should identify:
User ID.
Login date and time.
Search date and time.
Search criteria.
Plate, person, address, or identifier searched.
Stated purpose.
Case number entered.
Offense category.
Search frequency.
Repeated searches.
Exported information.
Screenshots.
Data sharing.
Related searches.
Access from other systems.
Then compare those records against:
CAD.
RMS.
Dispatch records.
Case assignments.
Arrest reports.
Investigative supplements.
Body-worn-camera activity.
Work schedules.
GPS or vehicle assignment records.
Supervisor instructions.
Build the timeline.
The timeline often tells the story.
3. Repetition Changes the Investigation
One questionable search deserves review.
Fifty questionable searches reveal something different.
Pattern matters.
Investigators should look for:
Repeated searches of the same plate.
Searches occurring while the employee is off duty.
Searches involving relatives.
Searches involving coworkers.
Searches involving current or former romantic partners.
Searches immediately before or after personal communications.
Searches without a corresponding case.
Searches using vague explanations.
Multiple databases queried for the same person.
Activity inconsistent with the employee's assignment.
A single audit entry answers:
What happened?
A pattern starts answering:
Why?
4. Civilian Employees Belong in the Audit Program
This is not an officer-only issue.
Savannah's 2026 investigation resulted in termination of four sworn employees and two civilian employees.
Dispatchers.
Analysts.
Records personnel.
Crime-center employees.
Evidence technicians.
Administrative employees.
Contractors.
Anyone possessing privileged system access belongs inside your auditing structure.
The issue is access.
Not badge status.
5. CJIS Access Carries Its Own Responsibilities
Access to criminal justice information exists for authorized purposes.
The FBI CJIS Security Policy includes controls addressing access, security, accountability, auditing, and sanctions associated with criminal justice information.
IA commanders should therefore avoid writing a database-misuse allegation simply as:
Improper use of equipment.
Depending upon the system and circumstances, potential allegations might involve:
Unauthorized database access.
Misuse of criminal justice information.
Conduct unbecoming.
Truthfulness.
Information security violations.
Confidentiality violations.
Improper dissemination.
Misuse of official position.
Applicable criminal statutes.
State database-specific requirements.
Charge the conduct accurately.
Risk Radar
These statements should trigger additional investigative work.
"I was curious."
Curiosity is not a law-enforcement purpose.
"I know the person."
That makes the purpose more important, not less.
"I didn't do anything with the information."
Unauthorized access might itself violate policy or law.
"Everybody runs themselves."
Custom does not replace policy.
"I entered a case number."
Verify the case.
A case number does not automatically establish a legitimate connection between the search and the investigation.
"My supervisor knew."
Interview the supervisor.
"Nobody ever told me I couldn't."
Review training records, acknowledgments, system warnings, policy, certification requirements, and login screens.
The Audit Question IA Should Be Asking
There is another side to these cases.
Some agencies are finding misconduct because they audit.
Others learn about it because a victim complains.
Or another employee reports it.
Or a journalist requests records.
Or an outside organization identifies suspicious searches.
The Washington Post reported that some departments involved in cases it reviewed did not routinely audit employee Flock activity.
That creates an uncomfortable question.
How much database misuse exists inside agencies that are not looking for it?
You do not know what you do not audit.
Monday Morning Action
IA commanders should meet with IT, intelligence, records, dispatch, and technology administrators and build a complete inventory of systems employees are authorized to search.
Start with five steps.
1. Identify every restricted database.
Do not limit the list to NCIC.
Include commercial and agency platforms.
2. Identify who has access.
Separate access by role.
Officer.
Detective.
Dispatcher.
Analyst.
Supervisor.
Administrator.
Civilian employee.
Contractor.
3. Determine what audit information each system captures.
Ask the vendor.
Do not assume.
4. Establish recurring supervisory audits.
Random audits matter.
Targeted audits matter.
Automated anomaly detection also matters.
5. Establish triggers requiring immediate IA review.
Examples include:
Searches involving employees.
Repeated searches of the same individual.
Searches during off-duty periods.
Searches involving family members.
Missing case numbers.
Unusual search volume.
Searches outside assignment responsibilities.
Vendor-generated abnormal-activity alerts.



