Field notes · Cities & councils

Civic festival safety without facial recognition: the architecture

Density thresholds in civic squares don't need to know who anyone is to keep them safe. Here's how a privacy-first occupancy layer would be configured for a civic festival, and why councils can sign off on the architecture without spending the community-trust budget.

A crowd in a public square at dusk under festival lights
Threshold-driven density routing, not identity capture

Most public squares in Australia were never designed to count themselves. They were designed to be civic, open, accessible, unobserved. When a festival lands on one, the council's safety obligations don't change, but the surveillance toolkit they're usually offered does. There is a different toolkit available, and the trade it makes is the right one: density, not identity.

We don't have a civic-festival pilot running yet. This post is about how we'd configure one if a council asked us to.

01 · WHAT A CIVIC DEPLOYMENT WOULD COVERWhat a civic deployment would cover

The footprint we'd take to a typical inner-city festival is small: a civic square, the adjacent library forecourt, the town-hall foyer and the two main pedestrian arteries between them. Each is sensed by a single edge device emitting anonymous occupancy counts. Nothing is stored off-device; nothing identifies anyone.

The configuration the council signs off on is two layers deep:

  1. A threshold matrix, jointly drafted with the safety planner, that maps zone density to a tier of operational response: observe, prepare to redirect, redirect, escalate.
  2. An alert-routing graph, so threshold crossings push to the right attendant's device with a one-tap acknowledgement, rather than crackling across an ops radio.

02 · WHAT THE COUNCIL WOULD GET POST-EVENTWhat the council would get post-event

The post-event report is one page. We'd build it to answer the questions the council is already accountable to:

  • Counts per zone over the event window.
  • Threshold crossings with timestamps, durations and an egress-time estimate at peak.
  • A narrative for each crossing, where the bottleneck formed and which exits the crowd used.

What would not be in the report: who was there. The platform doesn't see it. Nothing is stored, nothing is inferable, nothing is even captured. The architecture refuses the question.

03 · WHY COUNCILS CARRY A DIFFERENT PRIVACY BUDGETWhy councils carry a different privacy budget

Civic councils have a thinner community-trust budget than a private operator. A festival deployment that quietly photographs every attendee (even for a stated safety purpose) costs that budget more than the safety brief is worth. A privacy-first deployment is structurally different:

  • The model runs on-device. The raw frames never leave the sensor.
  • No biometric data, no demographics, no PII is ever produced.
  • The platform sees the same counts the dashboard does, nothing more.

When the question is asked, "what would happen if this got hacked?", the honest answer is: nothing would leak that isn't already aggregated and public, because the architecture never produces anything else.

04 · WHAT THE ARCHITECTURE ISN'TWhat the architecture isn't

Worth being explicit. A privacy-first occupancy layer is not crowd surveillance. It is not protest monitoring. It is not facial recognition in a civic skin. The platform doesn't have the data to do any of those things, because the architecture never lets it have the data.

A civic square is allowed to count its visitors. It is not allowed to identify them. The platform is built so the first stays possible and the second stays impossible.

05 · WE'RE LOOKING FOR THE FIRST COUNCIL PILOTWe're looking for the first council pilot

If you work in council operations or community safety and your civic events brief is widening, request a demo, and we'd like to scope the first deployment with you.

If your building can't answer one of these questions yet, we should talk.