Civic · Protocol concept

Open Witness Protocol

A privacy-preserving concept for asking nearby, citizen-owned cameras about a specific public event without opening a general surveillance feed.

Compendium article 043 Revision 0.6 · July 2026

Camera networks usually gain usefulness by centralizing footage, which also centralizes surveillance power. Open Witness Protocol explores whether a community could answer a narrow question about a specific event without creating a general-purpose feed.

The project takes the form of a docs-first protocol idea for signed, time-limited, geography-limited event alerts sent to participating local cameras with rolling local buffers and silence when nothing matches. Its purpose is to explore whether narrowly scoped evidence requests can support public safety while preserving local control and no-match silence.

The question behind Open Witness Protocol

The core idea is an event-scoped request: signed, limited in time and geography, evaluated against a rolling buffer on participating citizen-owned devices. If nothing matches, the network should reveal nothing—not even an inventory of irrelevant footage. Communities, incident investigators, camera owners, and people near an event are affected. Bystanders have the strongest privacy interest and cannot meaningfully opt into every recording.

How Open Witness Protocol took shape

The project currently exists as a docs-first RFC describing request scope, local matching, retention, owner control, no-match silence, and privacy invariants. No operating network, matching model, pilot, or security validation has been built. Josiah developed the citizen-owned, event-scoped architecture and its central rule that nonmatches reveal nothing.

What the evidence supports

The protocol is documented as an idea; no pilot, network, matching model, or security validation exists. The protocol is interesting because minimization is structural rather than promised by policy after collection. It is also incomplete: warrants, coercion, false matches, bystander rights, device compromise, and governance require adversarial review before operational code would be responsible.

Abuse prevention, warrants and legal process, false matches, coercion, device compromise, governance, and bystander rights remain unresolved. The RFC requires adversarial privacy and security critique before any operational implementation would be responsible.