Most public squares in Australia were never designed to count themselves. They were designed to be civic, open, accessible, unobserved. When a festival lands on one, the council's safety obligations don't change, but the surveillance toolkit they're usually offered does. There is a different toolkit available, and the trade it makes is the right one: density, not identity.
We don't have a civic-festival pilot running yet. This post is about how we'd configure one if a council asked us to.
01 · WHAT A CIVIC DEPLOYMENT WOULD COVERWhat a civic deployment would cover
The footprint we'd take to a typical inner-city festival is small: a civic square, the adjacent library forecourt, the town-hall foyer and the two main pedestrian arteries between them. Each is sensed by a single edge device emitting anonymous occupancy counts. Nothing is stored off-device; nothing identifies anyone.
The configuration the council signs off on is two layers deep:
- A threshold matrix, jointly drafted with the safety planner, that maps zone density to a tier of operational response: observe, prepare to redirect, redirect, escalate.
- An alert-routing graph, so threshold crossings push to the right attendant's device with a one-tap acknowledgement, rather than crackling across an ops radio.
02 · WHAT THE COUNCIL WOULD GET POST-EVENTWhat the council would get post-event
The post-event report is one page. We'd build it to answer the questions the council is already accountable to:
- Counts per zone over the event window.
- Threshold crossings with timestamps, durations and an egress-time estimate at peak.
- A narrative for each crossing, where the bottleneck formed and which exits the crowd used.
What would not be in the report: who was there. The platform doesn't see it. Nothing is stored, nothing is inferable, nothing is even captured. The architecture refuses the question.
03 · WHY COUNCILS CARRY A DIFFERENT PRIVACY BUDGETWhy councils carry a different privacy budget
Civic councils have a thinner community-trust budget than a private operator. A festival deployment that quietly photographs every attendee (even for a stated safety purpose) costs that budget more than the safety brief is worth. A privacy-first deployment is structurally different:
- The model runs on-device. The raw frames never leave the sensor.
- No biometric data, no demographics, no PII is ever produced.
- The platform sees the same counts the dashboard does, nothing more.
When the question is asked, "what would happen if this got hacked?", the honest answer is: nothing would leak that isn't already aggregated and public, because the architecture never produces anything else.
04 · WHAT THE ARCHITECTURE ISN'TWhat the architecture isn't
Worth being explicit. A privacy-first occupancy layer is not crowd surveillance. It is not protest monitoring. It is not facial recognition in a civic skin. The platform doesn't have the data to do any of those things, because the architecture never lets it have the data.
A civic square is allowed to count its visitors. It is not allowed to identify them. The platform is built so the first stays possible and the second stays impossible.
05 · WE'RE LOOKING FOR THE FIRST COUNCIL PILOTWe're looking for the first council pilot
If you work in council operations or community safety and your civic events brief is widening, request a demo, and we'd like to scope the first deployment with you.
