In my last post, I explained why I worry about photographs taken during FBI search warrant operations being made public — in that case, the search of Donald Trump’s Mar-a-Lago home. The standard response is that the FBI has been taking search photos forever. What’s changed?
Everything. And not because the law changed. Because the filing cabinet did.
Film
When I started as an FBI Special Agent in 2002, we photographed search scenes on Nikon film cameras. The film went into an envelope marked with the case information and down to the office photo lab. The prints came back with the exposed film and went into a 1A envelope in the physical case file. Before trial, the AUSA reviewed them for problems with the search or the seizure and produced them in discovery.
After that, they sat in the squad file shelves in the office of origin before being sent to closed file storage and were forgotten. To misuse them, you had to physically find them.
Digital
Digital cameras came first. At the start we still printed everything from the camera’s removable media; later we burned the images to a CD. Either way, the official photos — print, digital, or both — lived in a physical envelope. Plenty of agents also kept a working copy on their hard drive.
That is when meaningful misuse became possible. But it still took something: a bad actor had to find the physical file, or get the copy from the agent whose case it was. Distribution was the bottleneck, and the bottleneck was doing real privacy work that nobody had designed on purpose.
Sentinel
Then came Sentinel, the FBI’s electronic case management system. (I will be writing about Sentinel in exhaustive — and I promise, boring — detail in the posts that follow.) Sentinel was built to approximate existing case management practice in software, and it established that a 1A could be a physical envelope, a digital container, or both.
The value proposition was real. No more trips to the photo lab. No more processing equipment, lab personnel, or floor space to house them.
But Sentinel was also designed to be maximally accessible across the enterprise, and the Bureau said so in writing. The Sentinel Privacy Impact Assessment states that case information is generally available to all FBI users with a need for it in the performance of their duties, subject to restrictions imposed by law or policy. It goes further: the PIA describes maximum access for case-working employees as essential to connecting the dots across seemingly unrelated cases. Every FBI employee receives a Sentinel account automatically with their network account.
The exceptions are narrow and mostly categorical — the access-control rules the Bureau shorthands as prohibited and restricted cases, which the PIA describes as default case-opening rules for sensitive classifications (personnel matters, non-FBI background investigations such as presidential appointments), plus legal caveats for grand jury and similar material, and a case manager’s discretion to limit a specific case. Note that Director Patel has publicly pushed to eliminate the prohibited and restricted case categories — which would widen the aperture further.
A residential search in a run-of-the-mill criminal case is none of those things.
So here is the practical result. Photographs of the inside of a private citizen’s home — bedrooms, medicine cabinets, closets, a child’s room, whatever was in frame — are serialized into a case file that is full-text searchable, indexed, and reachable from any workstation in the Bureau by tens of thousands of people with no connection to the case. Open cases and closed cases alike. And they stay there. The Records Act and the applicable NARA schedule set a floor, not a ceiling: a closed FBI case file is not even eligible for destruction until it has been closed for a long period of years, and the operational reality is that case records are retained indefinitely absent an affirmative reason to dispose of them.
The risk of improper exposure did not increase incrementally. It increased by orders of magnitude.
To its credit, the PIA names the danger — it acknowledges the risk that a trusted authorized user will betray that trust and misuse the data, and it offers supervisory oversight and audit logging as the mitigation. That is a detection control, not a prevention control. It tells you who looked, after they looked. And it only works if someone is looking at the logs for the right reason. Nobody audits a query because a private citizen’s living room got viewed by a squad three field offices away.
In the Trump case, the government released the search photos itself, in the indictment. As I said in my last post: not unlawful, but not necessary either. That case is the visible version of the problem, and the visible version is the easy one.
What comes next
Here is the part that should bother the privacy professionals in the audience. The PIA I have been quoting was approved in May 2014, and it has never been rewritten. Sentinel has not been reassessed in twelve years — same document, same broad categories of Privacy Act data, same mitigations. It was written for a world in which misuse meant a human being clicking through a case file one photograph at a time, and in which the sheer labor of doing so was itself a privacy control. That constraint is gone. In the next post, I will take up what happens when modern analytic tools are pointed at a decade of interior photographs of American homes that the government already lawfully possesses — and why the search that mattered may be the one nobody ever documented.
Leave a comment