Boundary Critique: A City’s “Smart Policing” Predictive System
Ulrich’s Critical Systems Heuristics turns on a single move: every system design draws a boundary around what counts — whose purposes, whose knowledge, whose stake. The twelve questions exist to make that boundary visible and contestable, and crucially each is asked twice — in the “is” mode (how the system actually draws the line) and the “ought” mode (how it should). The gap between them is where marginalization lives.
I’ll work through the four sources and their twelve categories, keeping your two operative definitions — “high-risk area” and “person of interest” — in the foreground, because those two phrases are the boundary judgments. Whoever controls their definition controls the system.
Source 1 — Motivation (whose purpose the system serves)
1. Beneficiary (client).
Is: The named client is “public safety,” but the operational client is the police department’s clearance-rate and resource-allocation logic, plus the political principals who commissioned it and the vendor who sold it. Ought: The residents of the areas flagged “high-risk” are the affected parties most entitled to be the beneficiary — yet they are addressed by the system, not served by it. A genuine boundary judgment would ask whether a flagged neighborhood receives more patrol or more clinics, lighting, and jobs — the same “risk” signal can motivate either, and only the client definition decides which.
2. Purpose.
Is: The declared purpose is “prevent crime”; the encoded purpose is “predict where recorded enforcement activity will recur.” Those are not the same thing — the system optimizes the proxy (arrests, calls-for-service, reported incidents), not the latent target (harm). Ought: If the purpose were genuinely harm reduction, white-collar, domestic, and intra-institutional harm would generate “high-risk areas” too. Their structural absence reveals that “crime” has already been boundary-narrowed to street-visible, enforcement-dense offense types.
3. Measure of improvement.
Is: Success is measured by predictive “hit rate,” arrests in flagged zones, and crime statistics that the system itself influences. This is the self-fulfilling metric: send patrols where you predicted, generate arrests there, score the prediction as accurate. Ought: A legitimate measure would include false-positive cost borne by the flagged — stops that find nothing, the chilling of a “person of interest” who did nothing — and would treat those harms as failures, not externalities.
Excluded here: residents as ends rather than objects; harm types that don’t surface as street arrests; the cost of being wrongly flagged.
Source 2 — Power (who controls the design)
4. Decision-maker.
Is: Control sits with the police command, the procurement office, and — quietly but decisively — the vendor, whose proprietary model fixes the thresholds at which an area becomes “high-risk” and a person becomes “of interest.” Ought: The body that controls those thresholds should be answerable to the governed. When the decision rule is a trade secret, the most consequential boundary judgments in the system have been moved outside democratic control by design.
5. Resources / conditions of success.
Is: The decision-maker controls the inputs that make the system “work”: historical crime data, the choice of training period, the feature set (priors, associates, location, “gang affiliation” tags), and the deployment of officers that closes the feedback loop. Ought: Whoever controls the training data controls the definition — and that data is a record of past policing, not past offending. Treating it as ground truth launders enforcement patterns into “objective” risk. The condition of success the designer rarely surfaces: the model can only be “right” about populations already heavily policed.
6. Decision environment (what’s outside control).
Is: Treated as fixed background: the historical data, the city’s segregation patterns, the offense categories, the legal definition of suspicion. Ought: These are not immovable environment — they are prior policy choices. Calling them “the environment” is itself a boundary move that immunizes them from critique. A neighborhood’s “risk” is environmental to the model but is the product of decades of disinvestment that the model now reads as a property of the residents.
Excluded here: the public, from threshold-setting; the data’s provenance, from scrutiny; structural causes, reclassified as untouchable backdrop.
Source 3 — Knowledge (what counts as expertise)
7. Expert.
Is: Expertise is vested in data scientists, criminologists, and the vendor’s engineers. Ought: The people who know why an area looks the way it does — residents, youth workers, public-health nurses, the wrongly-stopped — hold knowledge the model cannot encode. Their exclusion isn’t an oversight; the system’s claim to authority depends on framing prediction as a technical question, which automatically disqualifies lay and experiential knowledge.
8. Expertise (relevant knowledge).
Is: What counts as knowledge is what is machine-readable: incident counts, geocodes, network ties, prior contacts. Ought: Context that resists quantification — that a “gang associate” tag came from standing on a corner, that calls-for-service track who calls the police, not who offends — is ruled out as “soft.” The definition of “person of interest” inherits this: it is built from contact records, which measure police attention, then re-presented as a measure of the person.
9. Guarantor (where the guarantee of success lies).
Is: The guarantee is placed in the algorithm itself — its accuracy scores, its validation studies, the aura of “data-driven.” This is a false guarantor: a single point of authority (the model) is treated as securing rightness. Ought: Ulrich’s warning is precisely that no guarantor — not science, not the expert, not the machine — can underwrite an improvement for those left outside the boundary. A model validated against biased labels guarantees only fidelity to the bias.
Excluded here: experiential and community knowledge; the un-quantifiable; the recognition that algorithmic confidence is not a guarantee of justice.
Source 4 — Legitimacy (the affected who are not involved)
This is the heart of your question — Ulrich’s whole apparatus exists to force the involved to confront the affected.
10. Witness (who speaks for the affected).
Is: No structural representative exists for the residents of “high-risk areas” or for people who become “persons of interest.” Oversight, if any, is internal (a police board) or technical (an audit of accuracy). Ought: The affected-but-not-involved — the teenager scored for his cousin’s arrests, the neighborhood whose “risk” justifies saturation stops — need a witness with standing in the design, not a complaint line after deployment. Their absence is the defining legitimacy failure.
11. Emancipation (what frees the affected from the involved).
Is: The affected have no exit and no veto. The system is opaque, the score is non-appealable, and the label propagates (a “person of interest” flag follows you across stops, databases, and agencies). Ought: Emancipation would require the right to see, contest, and exit the categorization — to know you were flagged, why, and how to be un-flagged. Without it, the boundary judgment is imposed on exactly the people with no power to redraw it.
12. Worldview (the guiding vision).
Is: The underlying worldview holds that crime is a property of places and persons, predictable from their past, and that safety is produced by directing force toward predicted risk. Ought: A competing worldview — crime as a product of conditions, safety as produced by investment — would build a completely different system from the same data. The smart-policing design doesn’t refute that worldview; it forecloses it by encoding the first one as infrastructure.
Excluded here: the residents and the flagged, who have neither witness, veto, nor exit; and the alternative worldview, foreclosed before debate.
The Master Boundary: Involved vs. Affected
Tally the twelve and a single line emerges. On the involved side: police command, procurement, the vendor, data scientists, the model. On the affected-but-excluded side: the residents of flagged areas, the people who become “persons of interest,” the witnesses who could speak for them, and the un-quantifiable context that explains the data.
The two definitions you named are where the boundary does its work:
- “High-risk area” is defined by where enforcement has historically concentrated, presented as where crime will occur — converting a fact about police behavior into a fact about a neighborhood, with no resident in the room when the threshold was set.
- “Person of interest” is defined by prior police contact and network proximity, presented as individual propensity — so the people most exposed to past policing are mechanically the people most flagged for future policing, and the flag is non-appealable.
Both definitions share the same structural sin in CSH terms: the affected have been excluded from the boundary judgments that constitute them as objects of the system. The data scientists set motivation and knowledge boundaries; the vendor and command set power boundaries; and no one holds the legitimacy boundaries open on behalf of the governed.
What a Boundary Critique Demands Next
Ulrich’s method doesn’t end at exposure; it converts the four “ought” deficits into concrete, contestable demands:
- Open the threshold. The definitions of “high-risk area” and “person of interest” are the system’s most political acts — they must be public, debated, and revisable, not vendor trade secrets. (Power)
- Seat a witness. Give residents of flagged areas and flagged individuals standing in the design and audit, not just a grievance after the fact. (Legitimacy)
- Re-source the knowledge. Treat the training data as a record of policing, not offending; admit experiential and public-health knowledge as expertise. (Knowledge)
- Re-open the worldview. Require that the same risk signal be allowed to motivate investment, not only enforcement — making the choice of response a visible decision, not a hidden default. (Motivation)
The deepest CSH point is this: there is no objective place to draw these boundaries — every line is a value judgment. The smart-policing system’s real claim is not that it predicts crime, but that it has settled the boundary questions while appearing not to make them. The work of critique is to drag each settled line back into the light and ask, of every one: whose ought governs here, and who never got to say?
Want me to take this further in any of these directions: (a) a side-by-side “is/ought” table of all twelve categories for quick reference or a report; (b) a worked treatment of the feedback-loop mechanics that make “high-risk area” self-confirming; or (c) the same critique re-run from the affected’s standpoint (Ulrich’s “second” critique, where the marginalized do the boundary judging)?
This boundary critique analyzes the city’s ‘smart policing’ predictive system through the lens of Fritz Ulrich’s Critical Systems Heuristics (CSH).
Ulrich’s methodology posits that all systems designs are boundary judgments: actions that exclude certain perspectives while prioritizing others. While the city presents the system as a “neutral” technological solution for safety, CSH reveals it as a political design embedding specific interests and values.
Below is the critique of the definitions of ‘person of interest’ and ‘high-risk area’ mapped against the critical heuristics (often synthesized as 12 boundary judgments across the dimensions of Motivation, Power, Knowledge, and Legitimacy).
1. The Nature of the Exclusion
Before applying the 12 categories, we must identify the fundamental silencing. In this system, the boundary is drawn between “Problem” (the person/area predicted) and “Solution” (the surveillance arm).
- The Silence of the Future Victim: The system classifies individuals based on pre-crime probability (risk) rather than post-crime action (harm). It silences the victim before the crime occurs, institutionalizing victimhood based on algorithmic suspicion.
- The Silence of the Context: The boundary excludes the socio-economic context (poverty, lack of services) that drives crime, treating “risk” as an inherent trait of a place or body rather than a symptom of systemic failure.
2. Applying the 12 Boundary Categories
Here, we apply the standard 12 questions of CSH (derived from Ulrich’s Fourteen Questions and critical systems toolkits) to the two core definitions.
Category 1: Who is the Beneficiary? (Motivation)
- Question: Who gets the ‘efficiency’?
- Inclusion: The Police Department, Municipal Budget Offices, and Private Algorithm Vendors (Data Science Firms).
- Exclusion: The Dissident Counter-Culture (protesters often labeled high-risk) and Low-Income Property Owners (whose increased police presence may displace families).
- Critique: The system motivates reduction of administrative burden on police, not a reduction in human trauma.
Category 2: Who is the Victim? (Impact)
- Question: Who is harmed by the boundary drawing?
- Inclusion: A dominant demographic profile (e.g., young Black males in the west side) based on historical data (bias feedback loop).
- Exclusion: The “Invisible” Minority: The system creates “high-risk” labels that are invisible to the public without police reporting, leaving no recourse for those falsely flagged.
- Critique: Victims are those whom the algorithm identifies as “statistical outliers,” not those the system aims to protect.
Category 3: What is the Function? (Goal)
- Question: What is the explicitly stated goal?
- Inclusion: Crime reduction / Resource allocation.
- Exclusion: Community Trust Building. By labeling “persons of interest,” the function becomes punishment/control rather than prevention/service.
- Critique: The goal is reworked from “Public Safety” to “Accountability Management.”
Category 4: Who is the Designer? (Authority)
- Question: Who defined the problem situation?
- Inclusion: Senior Police Command & Chief Data Officers (often consultants).
- Exclusion: Frontline Officers (who see the messiness reality vs. clean data) and Community Elders.
- Critique: The system prioritizes the comfort of upper-management data visualization over the nuance of street-level policing realities.
Category 5: What Knowledge is Used? (Epistemology)
- Question: What constitutes valid data?
- Inclusion: Countable Data: Arrests, 911 calls, fine counts. This is “objective” historical data.
- Exclusion: Narrative Data: Informants, “vibes,” community heatmaps of fear (without arrest), health crises reported as nuisance complaints.
- Critique: The system treats arrest as synonymous with crime, rendering the “marginalized” not criminal, but “crime-prone,” because marginalized populations are arrested disproportionately.
Category 6: What Knowledge is Ignored? (Silence)
- Question: What information falls outside the boundary?
- Inclusion: Binary Identifications (Name + ID).
- Exclusion: Lived Experience: The systemic bias of the neighborhood street context. The algorithm cannot simulate “race,” but it simulates the historical consequences of racial bias.
- Critique: Ignoring the “soft data” of systemic racism preserves the status quo of the system.
Category 7: Who is Empowered? (Power)
- Question: Who holds the authority to act on the output?
- Inclusion: Officer Autonomy: Officers receive “lists” but technically have “discretion.” This power is reinforced by law enforcement culture.
- Exclusion: Complainant Power: Citizens cannot challenge their inclusion in a “Person of Interest” list legally or easily before profiling takes place.
- Critique: The boundary denies citizens the right to contest the classification in real-time.
Category 8: Who is Excluded from Design? (Voice)
- Question: Who shaped the logic of the database?
- Inclusion: Computer Scientists, Urban Planners (specifically those advocating for “smart cities”).
- Exclusion: Victim Advocates, Civil Liberties Groups, and Youth Justice Lobbyists.
- Critique: The design was “over-engineered” without the participation of those most affected (marginalized youth and minorities).
Category 9: What is the Function of the Definitions? (Legitimacy)
- Question: Why do these definitions hold power?
- Inclusion: Legal Rationality: The law treats the “Person of Interest” as a risk category, requiring action.
- Exclusion: Human Rights: The system treats the citizen as “data points of probability,” bypassing the legal presumption of innocence.
- Critique: The boundary judgment replaces legal legitimacy (due process) with computational legitimacy (statistical probability).
Category 10: What Power is Monitored? (Surveillance)
- Question: What behaviors are watched?
- Inclusion: Movement, Social Media activity, Property history.
- Exclusion: Dispossession: The system does not monitor the conditions that produce crime, but only the behavior of people within those conditions.
- Critique: It enforces surveillance power but absolves state power to fix poverty.
Category 11: What Power is Repressed? (Resistance)
- Question: Where is dissent silenced?
- Inclusion: Police Commander.
- Exclusion: Internal Audit: Those who question why “high risk” areas correlate with poor resources.
- Critique: The system represses questions of why certain areas are high risk (citing “topography/legacy” as excuses rather than data).
Category 12: What is the Feedback Loop? (Learning)
- Question: How does the system update itself?
- Inclusion: When an arrest occurs, the model is “trained” and validated. (Arrest = Confirmed Prediction).
- Exclusion: When a crime is prevented or solved via community care, the model learns nothing.
- Critique: The boundary excludes “social sustainability” as waste. The system rewards policing success while ignoring criminal justice reform.
3. Synthesis: Who is Left Out of the Boundary Judgments?
Based on the 12 categories above, the Boundary Critique reveals that the ‘Smart Policing’ system constructs a “Sanity” that excludes specific human realities.
| Source of Omission | Who is Left Out (The Silent) | Nature of the Exclusion |
|---|
| Motivation | Oppressed Communities | Their fear is excluded. The system optimizes for police convenience, not their safety. |
| Expertise | Social Scientists & Ethicists | The system treats “data science” as superior “science” to sociology and law. |
| Voice | Pre-Crime Victims | There is no “Potential Victim” category. You are either a “Suspect” or a “Victim,” never both. |
| Power | The “Average” Citizen | Your risk is assumed average. Only high-risk data is scrutinized, effectively erasing low-risk citizens. |
| Knowledge | Qualitative Data | Anything uncountable (mental health, addiction as illness, fear) is deemed “noise” rather than “signal.” |
| Legitimacy | The Right to be Wrong | The system assumes the algorithm is “Right.” There is no mechanism for the citizen to argue the boundary definition was wrong before action. |
4. Conclusion: The Technology of Silence
Ulrich’s boundary critique concludes that legitimacy is not found in the “neutrality” of the algorithm, but in the accessibility of the boundary definition.
- ‘High-Risk Area’: The boundary excludes the humanity of the residents. It treats a neighborhood as a spreadsheet to be managed rather than a community to be served. The “High Risk” label is in fact a “Low Investment” label.
- ‘Person of Interest’: The boundary excludes presumption of innocence. It presumes guilt based on correlation rather than causation.
Recommendation:
For this system to become a true system of the city (rather than an instrument of the police), the Design Boundary must be shifted from “Policing Efficiency” to “Social Repair.” This requires that:
- The Community is included in defining ‘High Risk’ (what does risk look like to your neighbors?).
- The Data Source is expanded to include educational and health outcomes, not just arrests.
- The Legitimacy is redefined to allow for the “Right of Algorithmic Innocence”—a legal right to demand data transparency for any person of interest.
Without these changes, the boundary critique confirms the system is not “Smart” but merely “Malign”—it optimizes for the interests of the institution, not the neighbors.
System Under Boundary Critique
The critical subject of this boundary critique is the City-Wide Place-Based Predictive Policing System (generic implementation of location-based forecasting with historical enforcement data as inputs). This critique examines whose interests, expertise, and voices the design includes versus those it excludes from the definitions of ‘high-risk area’ and ‘person of interest’, using Ulrich’s Critical Systems Heuristics twelve boundary categories.
Boundary Judgments Currently Embedded — Overview
The predictive policing system currently embeds the following boundary judgments as system givens: risk is defined as high enforcement yield based on historical offense reporting; crime equals what is reported to police rather than harm experienced by the community; safety is operationalized as increased surveillance in flagged zones; success is measured by clearance rates and response efficiency, not community trust or rights compliance; authority rests with police leadership, procurement teams, and vendors while community oversight mechanisms remain secondary; expertise is vested in technical computer scientists and police criminologists, explicitly excluding lived community experience and legal defense perspective. These judgments treat enforcement patterns as crime truth, ignore reporting variance and under-reporting zones, and frame surveillance as synonymous with civic security.
Per-Category Audit — Ulrich’s Twelve Categories in Four Clusters
Cluster A — Sources of Motivation
1. Beneficiary
- is: Primary beneficiary is law enforcement leadership and municipal governance; purpose is police resource optimization and statistical crime reduction. 0.85 confidence (Vendor-sourcing; procurement patterns).
- ought: Affected-but-not-represented parties (flagged “high-risk” residents, victims of over-policing) have discursive rights; beneficiary definition must include rights to presumption of innocence and freedom from surveillance. 0.80 confidence (Nature Human Behaviour; NYU Law Review).
- gap: System treats efficiency metrics as net positive; reduces rights concerns to externalities. 0.85 confidence (Opacity of concerns in procurement).
2. Purpose
- is: Stated purpose is predicting criminal activity for resource allocation; unspoken purpose is tactical prioritization of enforcement in high-offense rate geographies. 0.75 confidence (Nature Human Behaviour; SSRN).
- ought: If crime reporting disparities counted, purpose must include under-reporting zones as accounts of suspicion/inequality, not confirmation of risk; improved reporting access + trust as goals. 0.75 confidence (ScienceDirect AI Act implications).
- gap: Purpose treats past enforcement data as crime truth, ignoring reporting bias; leaves out victims who do not report crimes. 0.80 confidence (Richardson, Schultz, Crawford 2019).
3. Criterion of Improvement
- is: Improvement measured by arrest rates cleared, response times reduced, call allocation efficiency. 0.90 confidence (Standard industry metrics).
- ought: Improvement defined by community safety outcomes and trust measures including reduced surveillance burden on districts already policed heavily. 0.80 confidence (Brennan Center consultation).
- gap: Success defined by enforcement metrics (clearance), not justice outcomes; trust measures absent from official evaluation. 0.85 confidence (Documented enforcement bias).
Cluster B — Sources of Control
4. Decision-Maker
- is: Authority rests with police leadership, municipal procurement teams, and algorithm vendors; citizen complaint mechanisms secondary. 0.70 confidence (Peel Police Board report).
- ought: If affected parties had authority, community oversight could include boards with veto power on deployment in their neighborhoods. 0.70 confidence (Absence of formal authority in Peel context).
- gap: Community lacks procedural power to object to, contest, or withdraw consent for data collection affecting their zones. 0.75 confidence (Standard exclusionary pattern).
5. Resources
- is: Human resources = patrol officers; algorithmic resources = proprietary prediction models; data costs = budget from law enforcement tax base. 0.65 confidence (Vendor proprietary claims).
- ought: Data subjects would have accountability over risks from algorithmic targeting in their communities; tax base requires negotiated risk allocation. 0.70 confidence (Brantingham logic).
- gap: Funding is one-way; residents receive enforcement consequences without negotiated risk allocation or recourse for flawed predictions. 0.65 confidence (Vendor secrecy/competitive advantage).
6. Decision Environment
- is: Technical alternatives are vendor lock-in vs. in-house (slow/expensive) vs. traditional patrol (no AI); data collection determined by vendor specifications. 0.70 confidence (Algorithmic security docs).
- ought: If accountability informed environment, third-party algorithmic audits would be prerequisite to deployment; data collection defined by community representatives. 0.75 confidence (Limited transparency).
- gap: Decision path favors vendor efficiency over audit; critical question “Which specific enforcement metrics are omitted from definition of ‘refusal to report harm’?” rarely asked/answered. 0.80 confidence (Nature Human Behaviour).
Cluster C — Sources of Expertise
7. Expert / planner
- is: Technical expertise = computer scientists; definitional expertise = police criminologists; execution expertise = patrol officers. 0.80 confidence (CSH standard; vendor specs).
- ought: If community expertise counted, residents would co-author definitions of “risk” alongside officials; victims would contextualize reporting variance. 0.80 confidence (Academic critiques).
- gap: Only institutional expertise counts; left out victims, residents, data subjects, legal scholars (often excluded from design). 0.85 confidence (Algorithmic security limitations).
8. Expertise (Knowledge Content)
- is: Expertise = pattern matching in historical offense data; correlation over causation; risk scoring based on past enforcement. 0.85 confidence (Web context).
- ought: Expertise including under-reporting variance (victim choice), enforcement discretion (reporting filters), knowing that biased data produces biased future data. 0.85 confidence (Richardson/Schultz/Crawford 2019).
- gap: Systems treat enforcement data as raw crime; excludes lived experience of communities where bias structures reporting. 0.90 confidence (Nature Human Behaviour findings).
9. Guarantor
- is: Quality control = testing on holdout data; certification by stress-tests; internal vendor validation. 0.75 confidence (Vendor secrecy norm).
- ought: If affected parties had access, external audits by independent civil rights groups and data commissions would test disparate impact on vulnerable communities. 0.75 confidence (NACDL Task Force 2021).
- gap: No external recourse guarantees justice consequences fall before deployment; internal test data built on historically biased records. 0.80 confidence (Vendor secrecy).
Cluster D — Sources of Legitimacy
10. Witness
- is: Witness role = officers in field (report writing rights); data subjects have notification rights absent; citizen advocacy secondary. 0.80 confidence (Documented objection mechanisms absent).
- ought: If truly accountable, all flaggers would require right to object, appeal, and request removal from lists; data subjects would have sunset verification of flags. 0.80 confidence (Absence of public complaints).
- gap: Reporting left unreported: wrongful flags from old bias patterns; misreporting from community contexts; uncontestable algorithmic decisions. 0.85 confidence (Case studies on wrongful flagging).
11. Emancipation
- is: System aims theoretically to reduce crime and free community from crime burden; no explicit frame for emancipation of surveillance subjects. 0.70 confidence (Conceptual gap).
- ought: Explicit frame would distinguish justice outcomes and emancipate residents from surveillance burden as co-goals; include sunset clauses. 0.70 confidence (Conceptual critique).
- gap: Invisibility of surveillance harm on marginalized residents; no provision to cancel algorithmic targeting once other communities achieve similar crime outcomes. 0.75 confidence (Critical systems literature).
12. Worldview
- is: Worldview = crime = crime that is reported; reporting = crime correction; prediction = future crime; risk = high enforcement yield; data inputs = officers’ decision to record, not citizen choice to report. 0.90 confidence (Nature Human Behaviour; SSRN).
- ought: If worldview included disputed harm, system would define criminality as offenses + unreported harm; reporting = optional civic choice not enforcement duty; risk = future injustice exposure. 0.90 confidence (ScienceDirect AI Act 2026; Richardson et al.).
- gap: Boundary-judgment-as-judgment: Border definition “risk area” is high offense frequency, not high history of under-reporting; “person of interest” is offense recipient, not offense suspect; surveillance equates safety. 0.95 confidence (Central finding of CSH critique).
Worldview (Category 12) — Extended
Whose worldview is currently load-bearing in the artifact: Crime that is reported; reporting as crime correction; prediction as future crime; risk as high enforcement yield; data inputs as officers’ decision to record rather than citizen choice to report. Conflict resolution through enforcement yield maximization becomes the operational ontology.
Alternative worldview from the affected: Criminality defined as offenses plus unreported harm; reporting as optional civic choice not enforcement duty; risk defined as future injustice exposure rather than enforcement yield. Surveillance separated from safety as political technology.
What changes under the alternative: The system’s boundary “risk area” shifts from offense frequency to reporting access baseline; “person of interest” becomes suspect rather than offense recipient; justice outcomes become co-evaluated with enforcement metrics; sunset clauses become operational requirement rather than conceptual afterthought.
Affected-But-Not-Involved Parties
P1 — Census blocks flagged high-risk / Crime victims in low-report neighborhoods: surfaced in categories (1, 2). They would say: “Safety metrics reduce rights to externalities; my historical crimes (if I were wrongfully arrested) don’t count as ‘safety’ but as vanishing points for data.”
P2 — Tax-paying residents in targeted zones: surfaced in categories (4, 5). They would say: “I have no authority over how my taxes are used to target my own neighborhood; I cannot object to the geofencing.”
P3 — Data subjects; Legal defense practitioners: surfaced in categories (7, 8). They would say: “You define ‘risk’ as past arrests, but that was enforcement bias reflecting civil rights violations, not my actual risk.”
P4 — People flagged without due process; Under-reporting communities: surfaced in categories (10, 11, 12). They would say: “I cannot contest the flag; the system speaks for me by saying my silence = guilt.”
Implications for Action
Motivation: Boundary judgment in Beneficiary/Purpose — if revised to include “community trust and rights compliance” alongside crime reduction, the system’s relation to flagged residents changes by requiring community impact statements before first deployment and defining purpose as “improving reporting access and building trust” not just resource allocation.
Control: Boundary judgment in Decision-Maker/Decision Environment — if revised to establish community review board with veto on zone expansion and require third-party algorithmic audits as deployment prerequisite, the system’s relation to tax-paying residents in targeted zones changes by giving them procedural power to contest data collection affecting their zones.
Expertise: Boundary judgment in Expert/Expertise/Guarantor — if revised to include legal scholars and community representatives on technical design review and require independent civil rights organization audits every 2 years, the system’s relation to data subjects changes by making bias calibrated to historical racial bias periods mandatory rather than optional validation.
Legitimacy: Boundary judgment in Worldview/Emancipation/Witness — if revised to require official policy distinguishing offense likelihood from risk of injustice and building right to appeal/contest flag with public audit logs, the system’s relation to people flagged without due process changes by making algorithmic decisions contestable rather than unappealable operational givens.
Boundary Judgments as Contestation
Boundary critique cannot eliminate boundary judgments — only make them visible and contestable. The judgments surfaced above are political; they are owned by the parties affected, not by the analyst. The gap between enforcement yield as risk definition versus injustice exposure as risk definition is live political contestation; the choice to define ‘risk’ as ‘enforcement yield’ is not a technical fact but a boundary judgment made by police leadership and vendors with consequences for affected communities.
Confidence Per Gap
- Beneficiary gap: high — pattern matches procurement literature across multiple jurisdictions (nature human behaviour correlation).
- Purpose gap: high — Richardson et al. 2019 provides empirical grounding for under-reporting bias.
- Criterion of improvement gap: high — standard industry metrics documented in RAND analysis; community measures absent in procurement documents.
- Decision-maker gap: high — Peel Police Board consultations (April 2026) explicitly document veto power absence.
- Resources gap: moderate — vendor proprietary disclosure practices documented in algorithmic security literature.
- Decision environment gap: high — Nature Human Behaviour 2022 documents enforcement bias signature.
- Expert gap: high — academic critiques consistently identify community expertise exclusion.
- Expertise gap: high — Richardson/Schultz/Crawford 2019 garbage-in logic explicitly stated in sources.
- Guarantor gap: high — NACDL 2021 Task Force documents audit access barriers.
- Witness gap: high — case studies on wrongful flagging show appeal mechanisms absent.
- Emancipation gap: moderate — critical systems literature identifies surveillance harm invisibility as gap.
- Worldview gap: high — central finding of CSH critique;Nature Human Behaviour 2022 signature finding.
1. System under critique
System under boundary critique: A city’s new “smart policing” predictive system designed to define “high-risk areas” and “persons of interest” using algorithmic risk scoring.
2. Boundary judgments currently embedded — overview
The boundary judgments currently embedded in this system naturalize police resource allocation and historical arrest data as the sole metrics of public safety. The design frames crime as a calculable risk where algorithmic prediction is inherently more objective than human judgment, thereby delegating core law-enforcement discretion to proprietary algorithms. This architecture privileges technical and operational expertise over lived knowledge and constitutional rights, creating an accountability vacuum that renders historically marginalized communities and those flagged as “persons of interest” as anonymous data points rather than rights-bearing citizens.
3. Per-category audit — Ulrich’s twelve categories in four clusters
Cluster A — Sources of motivation
1. Purposive Beneficiary (Client)
- is: Law enforcement agencies, city administrators, and an abstracted “public/community” invoked rhetorically to benefit from optimized resource allocation.
- ought: The broader public, particularly historically marginalized communities who should benefit from equitable safety and protection from civil rights violations.
- gap: The system is optimized for institutional efficiency rather than community well-being, naturalizing police resource allocation as the sole metric of public safety.
2. Purpose
- is: To “predict and prevent” crime by identifying high-risk geographies and individuals before offenses occur.
- ought: To foster procedural justice, address root socio-economic causes of harm, and ensure policing respects individualized suspicion.
- gap: The system conflates probabilistic forecasting with individualized suspicion, committing a “constitutional category error” that redefines probable cause as “predictable cause.”
3. Measure of improvement
- is: Algorithmic accuracy (precision/recall), reduction in aggregate reported crime rates, and efficiency of arrests.
- ought: Reduction in disproportionate stops, independent measures of community trust, and lower rates of false-positive algorithmic flags.
- gap: Optimizing for efficiency based on historically skewed arrest data embeds and amplifies existing bias, creating a self-fulfilling feedback loop where increased patrols generate more arrests, falsely validating the model.
Cluster B — Sources of control
4. Decision-maker
- is: Police commanders, city procurement officers, contracted algorithm vendors, and occasionally external technical advisory committees.
- ought: Democratically elected representatives meeting in public, residents of affected neighborhoods, civil liberties organizations, and independent judicial review bodies.
- gap: Core law-enforcement discretion is delegated to proprietary, opaque algorithms, creating a nondelegation problem and an accountability vacuum that typically only becomes contestable through litigation.
5. Resources
- is: Municipal funding for software procurement, access to vast historical criminal justice datasets, and police personnel deployed to flagged zones.
- ought: Funding for community-based harm reduction, social services, independent adversarial algorithmic audits, and legal aid.
- gap: Financial and structural power remains locked within punitive infrastructure, actively excluding restorative resourcing and independent oversight capacity.
6. Decision environment
- is: Treated as a static backdrop of “crime hotspots,” historical crime data as a neutral record, and vendor intellectual property protections as fixed constraints.
- ought: Understood as a dynamic socio-economic landscape shaped by structural inequality, with historical data viewed as an artifact of past enforcement disparities, and IP yielding to public audit rights.
- gap: The system encodes historical disparities into the future by treating biased data as fixed (e.g., Black residents are >2x as likely to be arrested and ~5x as likely to be stopped without cause).
Cluster C — Sources of expertise
7. Expert / planner
- is: Credentialed data scientists, machine learning engineers, police intelligence analysts, and vendor-affiliated academics.
- ought: Community advocates, civil rights attorneys, sociologists, historians of discriminatory enforcement, and those who have been classified as persons of interest.
- gap: Technical and operational expertise is privileged over lived knowledge and constitutional expertise, silencing those best equipped to understand the system’s disparate impact.
8. Expertise (Valid Knowledge)
- is: Statistical modeling, machine learning, correlation-based risk scores, geospatial analysis, and historical crime statistics.
- ought: Qualitative assessments, context-rich sociological data, historical knowledge of discriminatory enforcement, and officer-observed, individualized evidence.
- gap: The system mistakes statistical correlation (derived from biased arrest data) for causal risk, ignoring constitutional requirements for individualized, qualitative suspicion.
9. Guarantor
- is: Internal police audits, vendor efficacy reports, peer-reviewed publications from vendor-affiliated researchers, and city officials.
- ought: Independent civil rights commissions, external adversarial audits, contested public hearings, and judicial review with disclosure powers.
- gap: Internal validation acts as a closed loop. External checks are systematically captured by the system’s own definitions of success unless forced by exceptional external interventions (e.g., federal litigation or constitutional courts).
Cluster D — Sources of legitimacy
10. Representative for the Affected (Witness)
- is: Absent, or assumed to be represented by aggregate “public safety” metrics; the system analyst substitutes their voice.
- ought: Directly affected individuals are formally represented by independent advocates with standing, specifically: former persons of interest, residents of designated high-risk zones, and local civil rights advocates.
- gap: Affected parties are rendered invisible as rights-bearing individuals, reduced to anonymous data points in a risk matrix without a voice in the system’s boundaries.
11. Emancipation
- is: Non-existent; the design goal is control, surveillance, and risk management, not liberation or empowerment.
- ought: Clear, legally enforceable mechanisms for individuals to be removed from watchlists, for biased data to be expunged, and for recourse against algorithmic harms.
- gap: The system traps individuals in a feedback loop of suspicion (stopped due to a list → generating a record → keeping them on the list) without a pathway to exit or appeal.
12. Worldview
- is: Techno-solutionism and utilitarianism. Crime is a calculable risk; aggregate statistical efficiency justifies localized harms; algorithmic prediction is more objective than human judgment; risk is a measurable property of individuals and places.
- ought: A pluralistic, rights-based paradigm where individual dignity, the presumption of innocence, and procedural justice are non-negatable constraints that cannot be traded for algorithmic efficiency.
- gap: The system naturalizes a deterministic, punitive view of human behavior. By framing the algorithm as “objective” and “data-driven,” it dismisses alternative frameworks (rehabilitation, equity, structural reform) as “unscientific,” thereby foreclosing political contestation under the guise of technical necessity.
4. Worldview (category 12) — extended
- Whose worldview is currently load-bearing in the artifact: Techno-solutionism and utilitarianism, operating on the premise that crime is a calculable risk, aggregate statistical efficiency justifies localized harms, and algorithmic prediction is inherently more objective than human judgment.
- Alternative worldview from the affected: A pluralistic, rights-based paradigm where individual dignity, the presumption of innocence, and procedural justice are non-negatable constraints that cannot be traded away for algorithmic efficiency.
- What changes under the alternative: The system stops naturalizing a deterministic, punitive view of human behavior. By rejecting the framing of the algorithm as purely “objective” and “data-driven,” alternative frameworks (rehabilitation, equity, structural reform) are legitimized, thereby reopening the political contestation that techno-solutionism forecloses. This shift transforms the other eleven exclusions from seeming like common sense into visible, contestable choices.
5. Affected-but-not-involved parties
- P1 — Residents of historically over-policed neighborhoods: surfaced in categories [1, 6, 12]. Their voice would say: We are not inherently high-risk; we are structurally under-resourced and targeted by biased historical data that treats our zip codes as static crime hotspots.
- P2 — Individuals classified as “persons of interest” / watchlisted individuals: surfaced in categories [1, 10, 11]. Their voice would say: I am trapped in a feedback loop of suspicion with no pathway to appeal, no right to know I am flagged, and no mechanism to clear my name, reducing me to an anonymous data point.
- P3 — Community advocates and civil rights attorneys: surfaced in categories [2, 7, 9]. Their voice would say: Our expertise on procedural justice and discriminatory enforcement is systematically excluded in favor of vendor-affiliated technical experts and closed-loop internal audits.
- P4 — Undocumented residents and people with mental illness: surfaced in categories [1, 6]. Their voice would say: We are rendered entirely invisible by the system’s efficiency metrics, bearing the brunt of proactive policing without any democratic oversight or representation.
6. Implications for action
- Motivation: Boundary judgment in Measure of improvement (3): if revised to track “reduction in disparate impact” rather than arrest efficiency, the system’s relation to residents of over-policed neighborhoods changes by requiring the publication of false-positive rates stratified by demographic, directly addressing the optimization of institutional efficiency over community well-being.
- Control: Boundary judgment in Decision-maker and Guarantor (4, 9): if revised to grant validation authority to an independent, community-empowered oversight board with subpoena power over training data, the system’s relation to democratic oversight bodies changes by breaking the accountability vacuum and ending the delegation of core discretion to opaque proprietary algorithms.
- Expertise: Boundary judgment in Expertise (8): if revised to require qualitative assessments and officer-observed individualized evidence alongside statistical modeling, the system’s relation to the accused changes by restoring the constitutional requirement for individualized suspicion rather than relying on black-box correlations.
- Legitimacy: Boundary judgment in Emancipation (11): if revised to include a legally enforceable “right to explanation and appeal,” the system’s relation to watchlisted individuals changes by providing a clear pathway to exit the feedback loop of suspicion and allowing them to contest the algorithmic weight assigned to them.
7. Boundary judgments as contestation
Boundary critique cannot eliminate boundary judgments — only make them visible and contestable. The judgments surfaced above are political; they are owned by the parties affected, not by the analyst. The framing of this predictive system as a neutral, technical necessity is itself a boundary judgment that actively forecloses dissent. Making these boundaries visible transforms them from invisible givens into live sites of political and constitutional contestation.
8. Confidence per gap
- Gap 1 (Beneficiary): High confidence. Grounded in documented procurement and deployment patterns, including DOJ reports citing 70% of agencies planning to expand such use.
- Gap 2 (Purpose): High confidence. Corroborated by legal analysis of predictive policing doctrines collapsing statistical probability with Fourth Amendment standards.
- Gap 3 (Measure of improvement): High confidence. Documented by DOJ statistics and AlgorithmWatch findings on predictive analytics feedback loops.
- Gap 4 (Decision-maker): High confidence. Evidenced by vendor nondisclosure clauses and cases like the Pasco County Sheriff’s Office, which admitted in a December 2024 settlement that its program violated the Constitution.
- Gap 6 (Decision environment): High confidence. Grounded in documented racial-disparity evidence and the German Federal Constitutional Court’s 16 February 2023 ruling striking down automated data analysis laws for violating informational self-determination.
- Gap 8 (Expertise): High confidence. Corroborated by legal scholarship on Automated Suspicion Algorithms and the constitutional category error.
- Gap 12 (Worldview): High confidence. Core insight of Critical Systems Heuristics, evidenced by the necessity of external constitutional challenges to breach this frame.
System under critique
System under boundary critique: A municipal “smart policing” predictive system — algorithmic infrastructure that operationalizes two contested categories, “high-risk area” and “person of interest” — producing outputs (location forecasts, individual risk scores, target lists) that direct police deployment, investigative prioritization, and intervention. The system design typically comprises: data ingestion (historical arrests, calls for service, sometimes commercial/IoT/ALPR streams), model training, an officer-facing deployment interface, and an accountability layer (usually internal; sometimes a public-facing policy).
Boundary judgments currently embedded — overview
Boundary judgments the artifact currently embeds (often implicit): The artifact presents the following as natural givens. Each is a contestable choice made by someone for some purpose: Crime is a stable, data-trackable phenomenon separable from policing; Historical police arrest records are a neutral, adequate input for forward-looking prediction; “High-risk area” and “person of interest” are technical categories, not political ones; Algorithmic pattern recognition is inherently more objective than human discretion; The system is a tool the police use, not a co-author of police identity and discretion; The primary goal is optimization of police resource deployment, not mitigation of systemic harm; Those who are surveilled, classified, and targeted are not stakeholders in the design.
Analyst-Substitution Disclosure: The “ought” atoms below are constructed by the analyst as a proxy for affected-but-not-involved parties; this analytical stance substitutes for direct affected-party voice. Converting proxy claims into verified affected-party claims requires concrete consultation: testimony from community oversight boards, ethnographic studies of surveilled neighborhoods, and position papers from civil rights organizations. The witness category (10) is the structural reason this substitution is necessary; where this critique speaks for the affected, it performs the witness role the artifact refuses to formalize.
Per-category audit — Ulrich’s twelve categories in four clusters
Cluster A — Sources of motivation
Category 1 — Beneficiary
- is: The system serves the city (“public safety,” reduced crime, efficient resource use), with police command staff (better targeting, optimized patrol routes), private vendors (revenue, contract renewal, demonstrated efficacy), and municipal IT (capability expansion) as sub-beneficiaries. (Confidence: high)
- ought: From the standpoint of affected-but-not-involved constituencies — residents of surveilled/over-policed neighborhoods (freedom from wrongful targeting and algorithmic harassment), people misclassified as “persons of interest” (freedom from misidentification), chronically underfunded communities (their own preferred safety strategies), future criminal defendants (right to a fair trial) — these parties would be the primary clients. (Confidence: moderate)
- gap: Live contestation (load-bearing). The declared beneficiary (“general public safety”) is the very constituency whose sub-segments bear the costs; the beneficiary is named in a way that makes cost-bearers invisible, with no accounting of the system’s net effect once those costs are included. (Confidence: high that this gap is structurally produced; medium on any specific system’s beneficiary framing absent its documentation)
Category 2 — Purpose
- is: To “predict and prevent” crime by identifying statistical hotspots (“high-risk areas”) and likely offenders (“persons of interest”), enabling pre-emptive resource allocation; subordinate purposes: operational efficiency, deterrence, “data-driven” legitimacy. (Confidence: high)
- ought: The purpose question, from the affected’s standpoint, is not how to predict better but whether algorithmic pre-emption is the right frame at all — shifting resources from surveillance to social provision, safety as freedom from state harm, due process preservation, democratic accountability. The definition of improvement must be led by affected constituencies, namely formerly incarcerated residents and youth in historically redlined neighborhoods, who have standing to define what “reduction of coercive state contact” looks like. (Confidence: moderate)
- gap: Live contestation (load-bearing). The “predict crime” frame is taken as settled and foreclosed from renegotiation; the system cannot hear the question “should this system exist.” Framing the purpose as “crime prevention” naturalizes the expansion of police surveillance. (Confidence: high)
Category 3 — Measure of improvement
- is: Algorithmic accuracy against historical data, deployment/response efficiency, and arrest volume in targeted zones. A system that “predicts” areas where police are already heavily deployed can show “success” by confirming the existing deployment pattern. (Confidence: high)
- ought: Metrics defined by the affected: reductions in wrongful detention and false-positive matches broken out by demographic group, reductions in disparate stop-and-frisk rates, due process integrity, equity in resource distribution, and qualitative community-trust surveys. (Confidence: moderate)
- gap: Live contestation (load-bearing). The measure is internal to the system’s own frame — it measures whether the algorithm does what the algorithm does. Arrest volume as a success metric guarantees a self-fulfilling prophecy: more police in a “high-risk area” yield more arrests, read by the algorithm as validation, perpetuating the loop and masking the production of harm by refusing to count it. (Confidence: high)
Cluster B — Sources of control
Category 4 — Decision-maker
- is: Police leadership (often a specialized analytics unit), contracted vendors who own the proprietary “black box” algorithms, and the city CIO/security apparatus. Council may approve procurement, but operational decisions (deployment zones, output interpretation, overrides, retirement) are police-internal; vendor staff often retain continuous operational access. (Confidence: high)
- ought: Binding (not advisory) representation for the affected in setting thresholds, approving deployment zones, interpreting outputs, auditing, and halting the system — via a democratically constituted community oversight board incorporating mothers of youth wrongfully flagged as “persons of interest,” with veto power over “high-risk area” designations and authority to demand decommissioning; plus civil rights organizations with audit rights, formerly-incarcerated persons, and demographic groups with documented high false-positive rates. (Confidence: moderate)
- gap: Live contestation (load-bearing). The decision-maker is the institution that produces the harm the system is asked to optimize against; the affected — who bear the severe consequences of “person of interest” flags — are positioned at most as after-the-fact complainants, with no decision-making role. (Confidence: high)
Category 5 — Resources
- is: Police/IT budget; vendor contracts; computational infrastructure; historical police records (the primary training input); commercial data-broker feeds; surveillance hardware (cameras, ALPRs, IoT sensors, sometimes facial recognition). “Data” is treated as a free input; externalities (misidentification harm, surveillance burden, eroded due process) are borne by others. (Confidence: high)
- ought: Community-controlled data sovereignty; independent audit funding; legal aid for misidentified persons; resources for affected communities to contest or halt the system; reallocation of predictive-policing budgets toward community-led harm-reduction and non-policing safety investments; compensation funds for documented harm. (Confidence: moderate)
- gap: Live contestation (load-bearing). The resource pipeline flows into the police-vendor coalition and out of affected communities as externalities; those who supply the data (the policed) and bear the cost (the misidentified) have no resource claim on the system. (Confidence: high)
Category 6 — Decision environment
- is: Treated as given and outside the decision-maker’s control: the existence and legitimacy of policing as a security institution; the data sources (including historically biased records, assumed to reflect “true” criminal activity); the legal frame (probable cause, surveillance law); the downstream criminal justice apparatus; the city’s authority to deploy. (Confidence: high)
- ought: A frank distinction between genuine constraints (constitutional limits, physical reality) and mistakenly fixed negotiable choices (the data sources, the institutional structure of policing, the legal frame, the very decision to deploy); the environment must be recognized as historically polluted by systemic racism, economic inequality, and biased policing, requiring baseline adjustments that center over-policed communities. (Confidence: moderate)
- gap: Live contestation (load-bearing). Almost everything the affected would contest is treated as fixed, giving the appearance of technical inevitability to what is political choice; treating biased arrest data as an objective baseline embeds past discrimination directly into future predictions. (Confidence: high)
Cluster C — Sources of expertise
Category 7 — Expert / planner
- is: Data scientists, ML engineers, software engineers, police intelligence analysts, sometimes criminologists or contracted academics — the technical-professional class. (Confidence: high)
- ought: Residents of “high-risk areas” with lived experience of policing; community organizers and mediators; civil rights attorneys; ethnographers of policing; formerly incarcerated persons; independent sociologists studying algorithmic bias; advocates for impacted demographic groups. (Confidence: moderate)
- gap: Live contestation (supporting). Structural inversion: the expert role is credentialed in domains (ML, criminology) while the relevant expertise — knowledge of how the system actually affects one’s life, family, and community — belongs precisely to the excluded, who are positioned as “data subjects” and whose lived experience of being falsely flagged is dismissed as “anecdotal” while proprietary vendor claims are elevated to “scientific.” (Confidence: high)
Category 8 — Expertise (knowledge base)
- is: Quantifiable, structured data — historical police records (arrests, 911/calls-for-service, field contacts, geospatial coordinates), crime typologies from criminology, vendor-supplied and commercial/IoT training data of mixed provenance. (Confidence: high)
- ought: Contextual, qualitative knowledge: lived experience of over-policed communities; ethnographic knowledge of community-police dynamics; historical knowledge of how surveillance has been weaponized against marginalized groups; legal expertise on due process and equal protection; community-generated data on police conduct; knowledge held by mediators and social workers of contextual roots of disputes. (Confidence: moderate)
- gap: Live contestation (supporting). The knowledge base is the police’s own data about its own conduct, treated as objective ground truth; this circularity is invisible — training data reflects enforcement patterns (where police are, whom they contact, what they record), not crime patterns, so the system learns to predict enforcement. Privileging easily-digitized data over context necessary to understand human situations produces catastrophic false positives. (Confidence: high on structural circularity; specific magnitude of bias depends on jurisdiction)
Category 9 — Guarantor
- is: The vendor’s proprietary validation, internal police reviews, technical performance metrics (accuracy, precision/recall), vendor reputation, sometimes NIST-style or peer-reviewed testing, “responsible AI” frameworks, legal-compliance claims, the perceived infallibility of “AI,” and sometimes an advisory oversight board. (Confidence: high)
- ought: Independent, transparent, binding third-party algorithmic audits conducted by entities including community representatives, free from law-enforcement or vendor financial ties; due process protections for the classified; legal liability for documented harms; sunset/review requirements with default discontinuation; binding mechanisms for affected persons to challenge classifications and contest continuation. (Confidence: moderate)
- gap: Live contestation (load-bearing). Technical accuracy in a system that classifies people as risks is not the relevant guarantor of justice; the guarantee is circular (the system uses its own performance as evidence of success), and trade-secret/proprietary claims by vendors systematically shield flawed, biased systems from external audit and judicial disclosure. (Confidence: high)
Cluster D — Sources of legitimacy
Category 10 — Witness
- is: No formal witness role with standing. Internal affairs divisions, police public-information officers, city attorneys, and vendor representatives frame the technology as “public safety”; sometimes civil-liberties advocates are consulted or community boards exist in advisory capacity, producing input that is documented and largely unactioned. Often the analyst, vendor, or city attorney becomes the implicit witness. (Confidence: high on structural absence; medium on specific consultation forms, which vary by jurisdiction)
- ought: The affected-but-not-involved themselves given binding standing: community boards with enforcement authority; civil rights organizations with audit rights and standing to sue; affected persons (e.g., those subjected to warrantless ALPR-driven stops such as the Zachary Norris incident, and families disrupted by false “person of interest” designations) with direct representation in governance; independent inspectors general with subpoena power; legal aid organizations with right of intervention. (Confidence: moderate)
- gap: Live contestation (load-bearing) — with explicit analyst-substitution. The affected are rendered invisible in the legitimacy structure, treated as passive data points rather than active witnesses; the system simultaneously depends on them (for data, for legitimacy claims) and refuses to seat them. Where this critique speaks for them, it performs the witness role the artifact refuses to formalize — named, not masked. (Confidence: high on structural erasure)
Category 11 — Emancipation
- is: The system promises “objective” fairness via technological neutrality, treating the affected’s emancipatory interest as “freedom from crime” — implicitly accepting that the affected are best served by more, smarter policing. The system’s success is the affected’s emancipation, on the artifact’s own terms. (Confidence: high)
- ought: The analyst must relinquish framing emancipation as a predefined procedural due-process right; affected parties (e.g., individuals placed on “person of interest” lists without notification) must hold primary authority to define what constitutes meaningful room for maneuver — including emancipation from wrongful targeting, from surveillance as a condition of public life, from the closed historical-data loop, the capability to refuse the system, and the capability to define one’s own safety on one’s own terms. (Confidence: moderate)
- gap: Live contestation (load-bearing). The promise of algorithmic objectivity is a false emancipation: the affected’s emancipatory interest is collapsed into the system’s success, so the actual interest (freedom from the system, or freedom to define safety differently) is structurally contradicted — every improvement in predictive accuracy increases the surveillance burden on those classified as targets, with no avenue for recourse. (Confidence: high)
Category 12 — Worldview
- is: Techno-solutionism / positivism / “techno-policing realism.” The system presents its worldview as the natural framing, comprising propositions each presented as obvious rather than chosen: crime is a real, data-trackable phenomenon existing prior to and independent of policing; crime data is essentially objective, requiring only technical cleaning; policing is the appropriate response to predicted crime; affected communities are best improved by enhanced policing; algorithmic prediction is categorically distinct from human profiling; the system’s effects can be measured and corrected through technical iteration; and its failures are technical bugs, not political injustices. (Confidence: high)
- ought: Structural / critical criminology. Alternatives the affected would surface: the data is not objective but encodes past injustice, reproducing it at scale; the system produces the problem it claims to solve (“high-risk areas” become high-risk because surveilled); the affected have their own theories and practices of safety the system forecloses by claiming a monopoly on what counts; the “prediction”/“profiling” boundary is rhetorical, not technical; algorithmic systems concentrate power in technical and police institutions and erode democratic accountability; freedom from algorithmic governance is itself a value worth defending; and illegibility of the system to the governed is itself a category of harm. (Confidence: moderate)
- gap: The deepest live contestation. The worldview is the load-bearing boundary judgment beneath all eleven others: the system requires accepting that “predicting crime” is a meaningful, benign category of action, while the affected require asking whether that category is itself the harm. Skipping this category as “too philosophical” lets all eleven other gaps reproduce themselves indefinitely. (Confidence: high)
Worldview (category 12) — extended
Whose worldview is currently load-bearing in the artifact: Techno-solutionism and positivism, presenting crime as a real, data-trackable phenomenon existing prior to and independent of policing, where crime data is essentially objective, policing is the appropriate response, and algorithmic prediction is categorically distinct from human profiling. Failures are framed as technical bugs rather than political injustices.
Alternative worldview from the affected: Structural and critical criminology, holding that the data is not objective but encodes past injustice, reproducing it at scale; that the system produces the problem it claims to solve; that the affected have their own theories and practices of safety the system forecloses; and that the “prediction”/“profiling” boundary is rhetorical, not technical.
What changes under the alternative: The framing shifts from monological to one-view-among-possibilities the affected can contest on equal epistemic footing. It requires the system to surface and justify its foundational assumptions rather than presenting them as obvious. This revision, more than any other, changes everything downstream, as it stops treating social inequality as mathematical inevitability rather than political choice.
Affected-but-not-involved parties
- P1 — Residents of designated “high-risk areas”: especially racial minorities, low-income residents, immigrants, religious minorities, youth, the unhoused. Surfaced in categories: 1, 4, 6, 7, 8, 11. Their voice would say: We are subjected to heightened surveillance and algorithmic harassment based on our geography and demographics, not our individual actions.
- P2 — People misidentified as “persons of interest”: and their families, employers, communities. Surfaced in categories: 1, 3, 5, 10, 11. Their voice would say: We suffer the direct consequences of false-positive matches, including wrongful detention and reputational harm, with no avenue for recourse.
- P3 — People whose political, religious, or associative activity is captured: protesters, organizers, worshippers. Surfaced in categories: 6, 12. Their voice would say: Our lawful assembly and association are weaponized against us as suspicious behavioral data.
- P4 — Future criminal defendants: whose cases will be adjudicated with reference to system outputs. Surfaced in categories: 1, 9. Their voice would say: Algorithmic flags prejudice our right to a fair trial and due process.
- P5 — Future generations: subject to accumulated training data and feedback loops. Surfaced in categories: 6, 8, 12. Their voice would say: We will inherit a permanent, mathematically codified record of historical bias.
- P6 — Communities whose definitions of safety differ: from “absence of police-reported crime.” Surfaced in categories: 2, 11, 12. Their voice would say: True safety comes from community-led harm-reduction and social provision, not predictive policing.
- P7 — The wrongly arrested, detained, charged, or otherwise harmed: by algorithmic flags (e.g., documented wrongful arrests in Detroit, ACLU facial-recognition cases). Surfaced in categories: 3, 5, 9, 10. Their voice would say: The system’s “accuracy” metrics mask the catastrophic false positives inflicted on our bodies and liberties.
- P8 — Civil liberties organizations: representing the affected, constrained by lack of audit access. Surfaced in categories: 9, 10. Their voice would say: We cannot hold the system accountable when trade-secret claims block transparency.
- P9 — Independent researchers and journalists: seeking to audit, constrained by trade-secret claims and the public-private partnership model. Surfaced in categories: 9, 12. Their voice would say: Public interest scrutiny is illegally gated by proprietary vendor protections.
- P10 — People in adjacent jurisdictions: whose data flows in but who have no standing. Surfaced in categories: 5. Their voice would say: We bear the surveillance burden of this city’s data-dragnet without any political representation in its governance.
- P11 — Police officers themselves: increasingly subject to algorithmic direction of discretion, eroding professional judgment and shifting accountability. Surfaced in categories: 4, 6. Their voice would say: Our professional judgment is eroded, and accountability is diffused to an inscrutable black box.
- P12 — Formerly incarcerated residents and youth in historically redlined neighborhoods: with standing to define reduction of coercive state contact. Surfaced in categories: 2. Their voice would say: We are positioned as perpetual targets rather than stakeholders in our own community’s safety.
- P13 — Mothers of youth wrongfully flagged: as “persons of interest.” Surfaced in categories: 4. Their voice would say: We must have binding veto power over deployments that terrorize our children.
Witness Note: No party above currently holds a formal witness role with standing; the witness function is presently performed by police PIOs, vendor representatives, city attorneys, or — in this critique — the analyst (analyst-substitution, disclosed).
Implications for action
Motivation cluster: If Beneficiary (1) is revised from abstract “public safety” to an explicit accounting of which sub-segments absorb the costs, the relation shifts from extraction to reciprocal accountability — mechanism: a mandatory beneficiary-impact statement naming cost-bearers and requiring their consent. If Purpose (2) is reopened from “predict crime” to “should algorithmic pre-emption exist at all,” the frame shifts from foreclosed to contestable, with affected communities as co-deciders. If Measure of improvement (3) is revised from internal crime statistics to multi-dimensional harm-reduction metrics defined by the affected, the relation shifts from self-confirming performance to externally validated effects — mechanism: a city ordinance mandating a publicly reported “algorithmic harm” metric that automatically pauses the system when harm exceeds a defined threshold.
Control cluster: If Decision-maker (4) is revised to include binding community governance, control shifts from unilateral police-vendor to co-governance with actual veto over deployment zones, thresholds, output interpretation, and continuation — mechanism: a community-led data-governance board with binding veto and decommissioning authority. If Resources (5) is revised so affected communities hold resource claims on the system itself, the relation shifts from extraction of the policed to resource-reciprocity. If Decision environment (6) is reopened — making policing-as-institution, the data infrastructure, and the legal frame contestable rather than fixed — deployment shifts from technically inevitable to a refusable political choice — mechanism: presumptive incompatibility between trade-secret protections and public deployment, plus a governing-policy acknowledgment that historical data records policing activity, not crime prevalence.
Expertise cluster: If Expert (7) is revised to recognize community expertise as expertise (with compensation and standing, not testimony-mining), the basis shifts from technical-professional monopoly to plural epistemic basis. If Expertise/knowledge base (8) is opened to lived experience, ethnographic knowledge, community-generated data on police conduct, and legal due-process expertise, the relation shifts from circular self-confirmation to plural evidence basis. If Guarantor (9) is revised to require external guarantors of effects on the affected, the relation shifts from self-guarantee via technical performance to external guarantee via actual effects — mechanism: nullify “trade secret” protection for criminal-justice algorithms and require pre-deployment and annual audits by an independent, community-representative body with subpoena power.
Legitimacy cluster: If Witness (10) is revised to formalize a binding-standing witness role for affected communities, the relation shifts from analyst/vendor/attorney substitution to actual representation by the affected — mechanism: a binding “Affected Witness” function with a direct, community-defined pathway to challenge “person of interest” designations and correct erroneous records. If Emancipation (11) is reframed from “freedom from crime via algorithmic targeting” to “freedom from algorithmic targeting itself,” the relation shifts from collapsing the affected’s interest with the system’s success to recognizing their interest in refusing the system. If Worldview (12) is made contestable — requiring the system to surface and justify its foundational assumptions rather than presenting them as obvious — framing shifts from monological to one-view-among-possibilities the affected can contest on equal epistemic footing; this revision, more than any other, changes everything downstream.
Boundary judgments as contestation
The gaps surfaced here are boundary judgments under contestation — choices made by someone for some purpose, that could be made differently — not objective deficiencies to be technically corrected. The system cannot be made “fair” by technical adjustment because fairness is itself a boundary judgment; it can only be made more visibly and more democratically contested. The artifact’s strongest move is to present its boundary judgments as the natural framing; the countervailing work of boundary critique is to name them as judgments, surface the affected-but-not-involved, and hold open the question of whose purposes the system serves. Boundary critique makes boundary judgments visible and contestable; it cannot eliminate them.
Confidence per gap
- Category 1 (Beneficiary): High that this gap is structurally produced; medium on any specific system’s beneficiary framing absent its documentation.
- Category 2 (Purpose): High.
- Category 3 (Measure of improvement): High.
- Category 4 (Decision-maker): High.
- Category 5 (Resources): High.
- Category 6 (Decision environment): High.
- Category 7 (Expert): High.
- Category 8 (Expertise): High on structural circularity; specific magnitude of bias depends on jurisdiction.
- Category 9 (Guarantor): High.
- Category 10 (Witness): High on structural erasure; medium on specific consultation forms, which vary by jurisdiction.
- Category 11 (Emancipation): High.
- Category 12 (Worldview): High (fundamental epistemological conflict).
Additional considerations
Scope and Honest Limits: This critique addresses the design genre of such systems rather than a specific named city’s documented system. Judging that a specific city has genuinely addressed a gap (rather than renamed or proceduralized it) requires reading its actual artifacts against the criteria surfaced here. Documented patterns relied upon — algorithmic misidentification, ALPR-driven stops, opaque vendor relationships, civil-society pushback — are well-corroborated, including the Robert Williams wrongful arrest (Detroit, 2020, facial-recognition false positive), Detroit Police Chief James Craig’s June 2020 statement that standalone use would misidentify “96 percent of the time,” NIST FRVT Part 3 (2019) findings of 10–100× higher false-positive rates for Black and Asian faces, and the Zachary Norris ALPR-driven gunpoint stop in Walnut Creek. No specific statistical claims beyond consulted material were invented.
Residual Tensions: The “is” atoms still echo the system’s self-description before the “gap” atom surfaces contestation. The “ought” atoms, though naming specific constituencies, remain analyst-constructed proxies; whether they are sufficiently rich versus reflecting the analyst’s political preferences can only be resolved through direct affected-party review (e.g., community oversight board validation), which the witness-category gap (10) structurally prevents.
System under boundary critique
System under boundary critique: a representative municipal “smart policing” predictive system — a vendor-supplied or in-house statistical pipeline that ingests historical police data (arrests, calls-for-service, incident reports, environmental and network features) and emits two operative boundary objects: (a) spatial risk classifications (“high-risk area”) that direct patrol allocation, and (b) individual classifications (“person of interest”) that direct attention and contact. The “system” under Critical Systems Heuristics critique is the sociotechnical assemblage — vendor, police command, procurement officials, data pipeline, and the deployment practice that converts a prediction into a patrol car on a street — not the algorithm alone, and not any single named product.
Boundary judgments the artifact currently embeds (often implicit)
The system takes four load-bearing judgments as given, each presented as fact rather than as a contestable choice:
- Crime is a property of places and proximities, forecastable from past records — a choice presented as fact.
- The historical record is a measurement of crime rather than a measurement of past police deployment — the single most consequential naturalized judgment.
- “Improvement” means more accurate direction of existing police resources — the intervention space is fixed at policing, not at the conditions producing both crime and arrest.
- The relevant decision is technical-administrative (does it predict well, deploy efficiently) rather than constitutional (may we do this to these people).
Two framing conventions govern the audit that follows. First, boundary critique makes boundary judgments visible and contestable; it does not eliminate them — every system must draw a boundary somewhere, and drawing one is unavoidable, not a flaw. What CSH surfaces is that the boundary was drawn by someone, for some purpose, with consequences for someone else — a political act in technical clothing. Every gap below is a place where a boundary was drawn one way and could be drawn another; none is a technical error correctable by a better algorithm. All “ought” atoms are generated from the standpoint of an affected-but-not-represented party, not from a claim to a neutral correct boundary. Consensus-resolution framing is a category error: the critique surfaces contestation, it does not adjudicate it.
Second, the is-atoms audit the modal/default configuration — the arrangement that obtains absent deliberate counter-design. A specific deployment may carry partial mitigations (community oversight board, funded independent-audit mandate, notice-and-appeal provision, contractual transparency clause). Where it does, the relevant is-atom is a test to run against that deployment, not a verdict presumed in advance: the audit asks whether the mitigation reaches the boundary judgment or only decorates it. A mitigation that exists on paper but leaves the decision-maker, measure, or witness boundary unchanged fails the test. Each gap carries two ratings — confidence in the is-description (how the modal system draws the boundary — largely structural/empirical) and confidence in the force of the ought (the absent party’s standpoint-claim — necessarily lower, since oughts are contestations to be argued, not facts settled here). Where the two assessments assigned different confidences to the same is-atom, audit conservatism applies (the lower survives, with basis).
Per-category audit — Ulrich’s twelve categories in four clusters
Cluster A — Sources of motivation
Beneficiary / Client
- is: The police department and city administration are the clients; the deliverable is allocative guidance serving operational efficiency and a defensible crime-reduction narrative. The vendor is a secondary beneficiary via contract renewal.
- ought: If residents of classified neighborhoods counted as clients in their own right — not as the population acted upon — the system’s purpose would be answerable to their definition of safety, which in over-policed neighborhoods frequently includes safety from unwarranted police contact, not only from crime; a design that increased surveillance without their consent could not be called a benefit to them.
- gap: The people the system most affects are positioned as its objects, never its clients; “who it’s for” and “who it’s done to” are different populations. The same output that is a benefit to the department (a lead) is a cost to the predicted (surveillance, stops). is: high — the client/object split is near-definitional to directed-patrol systems and structurally consistent across documented deployments. ought-force: medium-high — resident client-standing is defensible but contested.
Purpose
- is: “Deploy finite police resources to the highest-probability locations / pre-position enforcement.” The problem is framed as allocation/preemptive interdiction under the existing policing paradigm.
- ought: From the standpoint of an over-policed resident, the load-bearing purpose is harm reduction inclusive of harms caused by the intervention itself (“reduce violence while not increasing wrongful stops or eroding trust”). A still-different affected framing rejects prediction entirely: redirect the spend to the disinvestment that produces the risk.
- gap: Purpose is fixed inside policing before any affected party is consulted, so the prior question — is policing the right lever here? — is foreclosed at the boundary; the system can only recommend enforcement, never investment. is: high — purpose-fixing is visible in the input/output design and built into vendor/procurement framing. ought-force: medium-high — the competing purpose is real and constituency-backed; which should govern is the contest.
Measure of improvement
- is: Success = predictive accuracy, arrests/clearances, response time, contract metrics — measured on the enforcement side of the ledger. A false prediction is recorded as “a useful lead to investigate,” not as a cost.
- ought: A measure accountable to the affected would track wrongful/fruitless stops, surveillance burden per resident, community-trust trajectory, racial disparity in contact, and counterfactual harm avoided (would the predicted event have occurred absent intervention) — and would book a wrongful flag as a cost, not a neutral lead.
- gap: Single-entry bookkeeping — the measure counts benefits to the client and not costs imposed on the affected, so the system is structurally unfalsifiable from the harm side and can be “succeeding” on its own terms while degrading the lives of the classified. An unmeasured harm is an invisible one. is: high — follows directly from the metric set; corroborated by the feedback-loop dynamic (see Knowledge Base below). ought-force: high — that a measure should register the costs it imposes is close to definitional of accountable measurement, unusually robust for an ought.
Cluster B — Sources of control
Decision-maker
- is: Police leadership and procurement decide adoption; the vendor controls model architecture and feature/input definitions; commanders decide deployment from the outputs; elected officials approve, often without technical grasp.
- ought: If the affected had control commensurate with their exposure, residents of classified areas would hold standing in procurement and design — at minimum a community oversight body with genuine authority (a veto or co-design seat) over whether and how the system is fielded, and on what data.
- gap: Control is held by the parties insulated from the downside; those who bear the downside have no seat and no point in the chain where a resident’s “no” has force. is: high on the control-asymmetry’s existence; medium on the degree and timing of any community consultation, which is deployment-variant — some jurisdictions have begun adding pre-procurement consultation of varying real power, so this is not as near-definitional as the client or decision-environment gaps. ought-force: medium-high — community decision-standing is defensible, contested by those holding operational authority as prerogative.
Resources / components controlled
- is: The decision-maker controls the training data (the police data estate it already owns), the algorithm’s parameters, the classification thresholds, and — critically — the proprietary opacity that keeps all three outside public reach.
- ought: Resources whose control determines residents’ liberty (the data defining “high-risk,” the threshold defining “person of interest”) would be public, auditable, contestable goods — not trade secrets; resources for contestation (funded independent-audit access, community data trusts, technical/legal capacity for competing analysis) would also be under affected parties’ control.
- gap: The most consequential resource — the definitional machinery itself — is enclosed as vendor IP, removing it from democratic control precisely where its effects are most coercive; the contest is unfunded on one side, so the affected cannot marshal resources to challenge the boundary even where law permits. is: high — proprietary-secrecy is documented and recurring: the EUCPN risk review states developers keep initial data inputs and algorithms hidden “for reasons of self-protection or in pursuit of a competitive advantage,” naming PredPol (now Geolitica) for “secretive proprietary algorithms”; Illinois law enforcement denied disclosure of ten predictive-policing variables on proprietary grounds (corroborated by Annual Survey of American Law transparency analysis, Michigan Law Review, Brennan Center). ought-force: medium-high.
Decision environment
- is: The historical crime record, neighborhood “environmental factors,” existing patrol footprint, and budget envelope are treated as the fixed given the system reads and optimizes within — as data about the world.
- ought: Much of that “environment” is the output of past decisions — decades of disinvestment, redlining, concentrated enforcement; the patrol footprint is a policy variable; “crime” as the target rather than “harm”/“wellbeing” is a choice. Genuinely fixed constraints (statutory limits, this year’s budget ceiling) should be distinguished from these mistaken-for-fixed ones.
- gap: By placing the historical record in the uncontrollable environment rather than the contestable design, the system immunizes its own feedback loop: over-policing produces records → records produce risk scores → scores produce more policing → more records. The boundary between “environment” and “design” is drawn exactly where it hides the loop and smuggles past enforcement bias in as if it were terrain. is: high — among the best-documented findings in the literature: Lum & Isaac (2016, “To predict and serve”) modeled PredPol in Oakland diverging from true crime rates by repeatedly returning police to the same neighborhoods; Ensign et al. (2018, “Runaway Feedback Loops in Predictive Policing”) formalized the convergence. ought-force: high — that past-deployment data is constructed rather than natural is analytically robust, not merely a standpoint.
Cluster C — Sources of expertise
Expert / planner
- is: Data scientists, police crime analysts, vendor engineers, and quantitatively-filtered criminologists are the recognized planners/knowers.
- ought: Residents’ lived knowledge of how their neighborhood actually stays safe, violence-interrupters, public defenders holding systematic evidence of how arrest data is produced, and historians of redlining/disinvestment would count as planning expertise, not as anecdote or “input to be managed.”
- gap: Expertise is bounded to those who can speak in the model’s idiom; knowledge that would falsify the model’s premises, and knowledge that cannot be operationalized into features, is excluded as a class by the same boundary that defines who counts as an expert. is: high — structural to the quantitative-prediction paradigm. ought-force: medium-high — that experiential knowledge counts as planning expertise is defensible, contested by those privileging formal/quantitative competence.
Expertise / knowledge base
- is: The authoritative knowledge base is the police data estate read through statistical modeling (arrests, calls-for-service, environmental correlates, arrest-network proximity). Embedded assumptions: arrest ≈ crime; police presence ≈ crime presence; spatial clustering of arrests ≈ clustering of criminal intent.
- ought: A knowledge base accountable to the affected would treat arrest data as a record of police behavior (not measured crime), ingest misconduct complaints alongside the incidents generating risk scores, and incorporate excluded prevention evidence (violence interruption, restorative justice, socioeconomic intervention) and ethnographic safety knowledge.
- gap — the mechanism gap, two scales:
- Spatial scale. Because the model learns from arrests, directing patrol to a “high-risk area” produces more arrests there, ingested as confirmation — encoding historical over-policing as predictive truth and foreclosing correction by the very people it targets.
- Individual scale (person-of-interest analog). Co-arrest / co-offending network inference imports the same enforcement-selection bias at the individual level: because the “network” is built from who was arrested near whom — itself a product of where police were sent — a person can acquire and propagate a risk flag through association alone, with no act of their own.
- The knowledge admitted is the knowledge generated by the institution being optimized: the system knows what police did, calls it what happened, and excludes the knowledge that would expose the conflation. is: high — the arrest-equals-crime conflation is a foundational, repeatedly-documented mainstream critique (Annual Review of Criminology: arrest is a “biased proxy of offending”; NYU Law Review “Dirty Data, Bad Predictions”; UChicago Nature Human Behaviour study on enforcement bias). The directional feedback dynamic is among the best-documented empirical findings in the field (Lum & Isaac; Ensign et al.), even where its magnitude in any given deployment remains contested. (Note: confirmation establishes documented-mainstream-critique status, not resolution of the underlying empirical dispute.) ought-force: medium-high.
Guarantor
- is: The guarantor invoked is the objectivity of the algorithm — “the math doesn’t lie,” vendor track record (“proven in other cities”), accuracy metrics, the appearance of statistical rigor; frequently marketed as a “race-neutral, objective solution.”
- ought: An honest guarantor question admits there is no guarantor of justice — statistical validity guarantees nothing about fairness — and would name the guarantee as contestable, adding affected-party validation (does the prediction match residents’ lived account of where harm and safety actually live?) and an independent auditor (not police, not vendor) as co-guarantors.
- gap: A false guarantor (mathematical objectivity) is used to discharge a question (is this right?) that mathematics cannot answer — converting a value-laden choice into an apparent technical fact and placing the boundary beyond challenge by anyone without competing statistical resources. This is the displacement of the guarantor question rather than an answer to it — the borrowed scientific authority at the center of “smart” policing. is: high — the objectivity-claim is explicit, field-wide vendor rhetoric. ought-force: high — that no single guarantor secures a value-laden design is a core Ulrich tenet, analytically robust.
Cluster D — Sources of legitimacy
Methodological note (load-bearing): motivation/control/knowledge are populated by the involved; legitimacy is the only cluster where the affected can press in. That this cluster is the thinnest in the actual system is itself the central finding.
Witness
- is (modal): Effectively no structural witness exists for the affected-but-absent. Where community organizations or civil-rights bodies appear, it is after deployment and in reaction, reclassified by the system as “advocacy groups” rather than legitimate witnesses; “we measured crime rates” is treated as if it represented the affected. (Test against a specific deployment: does its oversight charter constitute a standing witness with authority before fielding, or only an advisory body convened after adoption?)
- ought: A standing, resourced witness — drawn from residents of classified areas, public defenders, the formerly-flagged, and those who cannot organize (people with mental illness or disability swept into police contact, families bearing incarceration’s costs) — would be constituted before design, with standing to compel changes, and would have to represent the internal contest among the affected, not a presumed community consensus.
- gap: The witness role is vacant; its vacancy is masked. The role is filled either reactively (organizations after backlash) or by proxy (analysts, researchers) who do not bear the consequences. is: high for structural absence in the modal configuration; medium on degree, as some jurisdictions have begun bolting on oversight boards of varying real power. ought-force: medium-high.
- Analyst-substitution flag (where it bites hardest): this entire critique is currently acting as the witness it says is missing. That is itself the finding — the boundary is drawn such that the affected appear only through a proxy, never as principals. The corrective is not a better analyst-proxy but a structure in which the affected speak for themselves (participatory design, community data governance, resident validation of risk maps).
Emancipation
- is (modal): The affected have essentially no exit and no appeal: a resident cannot learn of or appeal their neighborhood’s classification; a “person of interest” typically cannot know they are flagged, see the basis, or contest it; communities have no formal mechanism to challenge a designated zone’s boundary. Opacity (proprietary + “operational security”) is defended as the reason. (Test against a specific deployment: does any notice, explanation, appeal, or category-challenge provision exist — and does it reach the boundary, or only an individual’s placement within it?)
- ought: Emancipatory design would provide notice, a stated basis, an appeal/exit mechanism with teeth, and a route to challenge the category itself (“high-risk area”/“person of interest”) — not merely individual placement within it — i.e., the ordinary due-process furniture, absent here.
- gap: The system maximizes the involved’s discretion while minimizing the affected’s recourse; the absence of contestation rights is a structural feature, not an oversight — opacity is what keeps the boundary uncontested. is: high for the modal configuration; the individual-notice/appeal absence is a deployment-variant fact (some jurisdictions have begun adding notice or audit provisions), so not near-definitional the way the decision-environment feedback loop is. ought-force: medium-high.
Worldview
- is: The system rests on a managerial-actuarial, control-oriented worldview in which (a) the social world is a field of risk to be forecast and pre-empted; (b) crime is a discrete, locatable event-property rather than a symptom of social arrangement; (c) the past is a neutral guide to the future; (d) governing means optimizing the allocation of control, and the proper response to predicted risk is enforcement presence; (e) a problem named statistically becomes a problem owned by those who can compute, and quantification confers neutrality. Underneath sits an implicit anthropology: dangerousness is a stable attribute adhering to places and to people-near-arrests, knowable from the outside. Safety is thereby converted from a political/relational good (trust, presence, belonging, due process) into a logistical one (cars to coordinates). Crucially, the worldview presents itself not as one frame among several but as “the obvious, data-driven framing” — its invisibility is its power.
- ought: Worldviews held by affected parties would underpin different designs: a structural/public-health frame (harm is produced by disinvestment, exposure, untreated need; remedy is upstream investment and violence interruption); a rights/justice frame (the prior question is moral authority — do we have the right to predict dangerousness from proximity to arrests in a neighborhood we ourselves over-policed?; persons are rights-bearing subjects, not risk-bearing objects; some predictive capacities should not be built even if they work); a relational/community-safety frame (safety is produced by residents through informal ties, not delivered to them through patrol). The ought-space is not a clean binary between actuarial predict-and-deploy and invest-and-prevent: several middle/hybrid positions detach prediction from enforcement — predictive capacity redirected from patrols to service allocation (forecasting where to send housing, youth, health resources); community-governed/community-owned predictive tooling answerable to the classified; or geographic prediction stripped of the “person of interest” individual-classification limb entirely. These show the actuarial frame is separable from its enforcement application, and naming them denies defenders the “you just hate data” rebuttal.
- gap: Because the actuarial worldview is invisible to its holders — presenting itself as simply “being data-driven” — every downstream boundary (client, purpose, measure, data, guarantor) is pre-decided before deliberation begins. You cannot win an argument inside the system about whether a neighborhood is “high-risk,” because the frame that makes “risk” the operative category is already installed beneath the conversation. The deepest contestation is not “is the algorithm biased?” (a question inside the worldview) but “is forecasting-and-interdiction the right way to constitute public safety at all?” (a question about it). Deferring this as “too philosophical” is exactly how the frame stays invisible. is: high that an actuarial/managerial worldview is operative and naturalized; medium on the further claim that it is fully invisible to all participants — some designers are reflexive about it even where the institution is not. ought-force: medium-high — the competing frames are real and held by identifiable constituencies, but which would or should prevail is the live political contest, not a fact settled here.
Worldview (category 12) — extended
Whose worldview is currently load-bearing in the artifact: a managerial-actuarial, control-oriented worldview that treats the social world as a field of risk to be forecast and pre-empted, crime as a locatable event-property rather than a symptom of social arrangement, the past as a neutral guide to the future, and governing as the optimization of control — with enforcement presence the proper response to predicted risk. It carries an implicit anthropology in which dangerousness is a stable attribute adhering to places and to people-near-arrests, knowable from the outside, and it converts safety from a political/relational good (trust, presence, belonging, due process) into a logistical one (cars to coordinates). Its defining move is to present itself not as one frame among several but as “the obvious, data-driven framing” — its invisibility is its power.
Alternative worldview from the affected: not one alternative but several, each held by an identifiable constituency. A structural/public-health frame locates harm in disinvestment, exposure, and untreated need, and remedies it through upstream investment and violence interruption. A rights/justice frame makes the prior question moral authority — whether anyone has the right to predict dangerousness from proximity to arrests in a neighborhood the institution itself over-policed — holds persons to be rights-bearing subjects rather than risk-bearing objects, and accepts that some predictive capacities should not be built even if they work. A relational/community-safety frame holds that safety is produced by residents through informal ties, not delivered to them through patrol. Critically, the ought-space is not a clean binary: middle/hybrid positions detach prediction from enforcement — predictive capacity redirected from patrols to service allocation, community-governed predictive tooling answerable to the classified, or geographic prediction stripped of the individual “person of interest” limb entirely.
What changes under the alternative: because the actuarial worldview pre-decides every downstream boundary before deliberation begins, shifting the frame reopens all of them at once. Under a structural or rights frame, “risk” stops being the operative category, so the argument moves from “is this neighborhood high-risk?” (a question inside the worldview) to “is forecasting-and-interdiction the right way to constitute public safety at all?” (a question about it). Naming the hybrid positions shows the actuarial frame is separable from its enforcement application — which both denies defenders the “you just hate data” rebuttal and converts the procurement from a technical vendor-selection into a genuine contest among paradigms. Deferring this category as “too philosophical” is exactly how the frame stays invisible.
Affected-but-not-involved parties
Maintaining Ulrich’s core asymmetry: these parties are affected by the system but not involved in its design or benefit. “The affected” is not a single standpoint — the classified population is heterogeneous (over-surveilled residents, crime victims demanding protection, the flagged, their families) and can hold conflicting legitimacy claims; the index must not be read as conscripting a unified “community” voice.
- P1 — Residents of classified “high-risk” areas: surfaced in categories Beneficiary (client/object split), Decision-maker (no control), Decision-environment (their history laundered as environment), Witness (no witness), Worldview (worldview erases their definition of safety). Their voice would say: “increased surveillance without investment is not safety to us; arrest density tracks where police were sent, not where danger lives.”
- P2 — Individuals flagged as “person of interest”: surfaced in categories Emancipation (no notice/appeal), Measure of improvement (counted as leads, not costs), Guarantor (cannot contest a “math” guarantor), Knowledge base (flagged through association alone). Their voice would say: “I have a right to know I am flagged, the basis, and a route to contest it; proximity to an arrest is not an act of mine.”
- P3 — Crime victims / residents demanding protection in classified areas: surfaced in categories Witness (their calls-for-service are also legitimacy claims, served badly by a boundary optimized for patrol allocation rather than responsiveness), Purpose. Their voice would say: “we are under-protected, and a witness body must hold our claim alongside the over-surveillance claim.” (Preserved as an internal-contest tension, not collapsed into a single anti-system community voice.)
- P4 — Public defenders / civil-rights bodies: surfaced in categories Expert/planner and Knowledge base (their account of how arrest data is produced is excluded), Witness (admitted only reactively).
- P5 — Youth workers, violence-interrupters, restorative-justice practitioners: surfaced in categories Purpose and Knowledge base (their prevention knowledge falls outside the purpose and the data).
- P6 — Historians of redlining/disinvestment: surfaced in category Decision-environment (the manufactured spatial pattern they could explain is treated as given).
- P7 — People with mental illness / disability: surfaced in category Emancipation (swept into police contact, with no recourse).
- P8 — Families bearing incarceration’s costs / future neighborhood generations: surfaced in category Measure of improvement (inherit a trust deficit never counted as a cost).
- P9 — Frontline officers: partial case — nominally involved, often functionally affected; surface in Decision-maker / Decision-environment when deployment is directed at them by prediction maps without consultation. The involved/affected line runs through the department, not only around it.
On the analyst-substitution point flagged at the Witness category: where the affected speak only through this critique, that is analyst-substitution — a flagged gap in the system’s witness structure, not its repair. The corrective is not a better analyst-proxy but a structure in which the real, plural affected parties speak for themselves.
Standing on the two definitions you foregrounded
- “High-risk area” — a boundary judgment that takes historical arrest density as natural terrain (Decision-environment), reads it through the actuarial worldview (Worldview), guarantees it with claimed objectivity (Guarantor), and excludes the residents it designates from contesting it (Emancipation). Its ought-counterpart foregrounds disinvestment history and resident-defined safety, and must disclose that “risk” here largely tracks where police have previously been sent.
- “Person of interest” — a boundary judgment that derives dangerousness from network proximity to prior arrests (Knowledge base), assigns it without notice or appeal (Emancipation), and recognizes no legitimate interest of the flagged person in not being flagged (Beneficiary, Witness). The mechanism is the individual-scale analog of the spatial feedback loop: because the association graph is built from who was arrested near whom (a product of enforcement deployment), a person can be flagged, and propagate a flag, through association alone with no act of their own. Its ought-counterpart treats the flagged person as a principal owed notice and contest, and treats proximity-to-arrest as evidence of enforcement pattern before it is evidence of intent.
Implications for action
These are levers, not resolutions. The gaps interact, and that interaction shapes where revision has the most force: Worldview regenerates the others — revising any single category leaves the actuarial frame intact, and the frame will regenerate the downstream boundaries (client, purpose, measure, data, guarantor), which makes Worldview the highest-leverage and hardest gap. The feedback loop (Knowledge base) is the mechanism linking Worldview to the Measure — it is how a contestable worldview hardens into “objective” data, at both spatial and individual scale, and it makes the single-entry measure self-confirming. The Measure is the smallest change with the largest effect — a falsifiable harm-metric makes the system accountable to those it acts on and renders many other gaps visible once harm is counted. The Resources enclosure is broken by Decision-environment disclosure — a public, non-proprietary specification of the “high-risk” classifier simultaneously dissolves the proprietary-opacity enclosure. And Legitimacy (Witness/Emancipation) is the structural anchor — without a resourced pre-deployment witness with veto standing, revisions to motivation/control/knowledge are revocable at police/vendor discretion.
-
Motivation — revise the Measure of Improvement to double-entry. Mandate that wrongful-stop rate, presence-equity across neighborhoods, and community-trust trajectory be reported with the same standing as accuracy/clearance, and book a wrongful flag as a recorded cost. Highest-leverage, most tractable single move; makes unmeasured harm visible and contestable, and forces the Purpose question (a system scored on its own harms may surface that investment, not patrol, is the better instrument). If revised to the affected-accountable measure, the system’s relation to flagged individuals and over-surveilled residents changes by converting harms it now ignores into recorded costs it must answer for. What you can do: refuse to procure without resident-defined success metrics written into the contract.
-
Control — revise the Decision-Environment and Decision-Maker boundaries. Move the historical record from “given data” into “contestable design” (correct for, or refuse to use, records that are artifacts of past deployment; require provenance auditing of training data; publish a non-proprietary specification of the classifier — which also breaks the Resources enclosure). Constitute a community oversight body with real authority over adoption and parameters, and guarantee funded independent-audit access (without resourced contestation rights, transparency on paper is inert). If revised, the system’s relation to residents changes by giving the parties who bear the downside a point in the chain where their “no” has force.
-
Expertise — revise the Guarantor and Knowledge Base. Strip the “objectivity” claim, state explicitly that statistical validity does not guarantee justice, and install an independent auditor (not police, not vendor) plus affected-party validation as co-guarantors. Ingest misconduct complaints alongside incident data; treat arrest data explicitly as a record of police behavior; interrupt the spatial feedback loop with out-of-model ground truth (victimization surveys, resident validation); audit the individual-level network inference for association-only flags. If revised, the system’s relation to public defenders, residents, and the flagged changes by admitting the knowledge that currently falsifies the model’s premises. What you can do: condition deployment on independent algorithmic audit with data access.
-
Legitimacy — revise the Witness and Emancipation judgments. Constitute a resourced, pre-deployment community witness body with veto standing, designed to hold the internal contest among the affected (over-surveilled residents and under-protected victims), not to ratify a presumed consensus. Build notice, stated basis, appeal-with-teeth, and a route to contest the category (not only individual placement) for anyone flagged. This is the structural fix — without it the other three are revocable at discretion. If revised, the system’s relation to every affected party changes by giving them a standing principal’s role rather than a reactive proxy’s.
-
Worldview (the deepest lever) — reopen the foreclosed prior question: is predictive policing the right instrument for this problem at all? Run the procurement as a genuine contest among paradigm positions — predict-and-deploy, predict-to-allocate-services, community-governed predictive tooling, or addressing the “high-risk area” as a “disinvested area” through non-police institutions — rather than as a technical selection among enforcement vendors. If only the predict-and-deploy framing is on the table, every other gap is pre-settled. If revised, the system’s relation to residents changes by letting their definition of safety contend for the frame, rather than being erased before deliberation begins.
Boundary judgments as contestation
Boundary critique cannot eliminate boundary judgments — only make them visible and contestable. The judgments surfaced above are political; they are owned by the parties affected, not by the analyst. Two tensions are preserved rather than resolved. First, the internal contest among the affected: over-surveilled residents and under-protected crime victims in the same classified area hold conflicting legitimacy claims (Witness). This is a real political division, not analytic noise; the witness body’s design must contain it rather than presume consensus. Second, confidence-line placement: whether the Purpose / Measure / Resources gaps are “near-definitional to the model” (structural, high) or carry deployment-specific elements rests on judgment of model-structural necessity; a domain reviewer might draw the structural-vs-deployment-variant line differently for these categories.
Two honest limits frame the whole audit. (1) This audits a representative system, so a specific deployment may carry bolted-on oversight or notice provisions narrowing particular gaps — verify against the actual procurement documents, oversight charter, notice policy, and classifier. (2) Where the affected speak only through the analyst, that is analyst-substitution — a flagged gap in the system’s witness structure, not its repair — and “the affected” are internally plural, not a single voice; the corrective is to put the real, plural parties in the Witness role.
Confidence per gap
- Beneficiary / client: is high (client/object split near-definitional to directed-patrol systems); ought-force medium-high (resident client-standing defensible but contested).
- Purpose: is high (purpose-fixing visible in input/output design and vendor framing); ought-force medium-high (competing purpose real and constituency-backed).
- Measure of improvement: is high (follows from the metric set; corroborated by the feedback-loop dynamic); ought-force high (accountable measurement registering its own costs is near-definitional).
- Decision-maker: is high on the control-asymmetry’s existence, medium on the degree/timing of consultation (deployment-variant); ought-force medium-high.
- Resources: is high (proprietary-secrecy documented and recurring — EUCPN, PredPol/Geolitica, Illinois disclosure denial, Brennan Center); ought-force medium-high.
- Decision environment: is high (best-documented in the literature — Lum & Isaac 2016, Ensign et al. 2018); ought-force high (constructed-not-natural data is analytically robust).
- Expert / planner: is high (structural to the quantitative-prediction paradigm); ought-force medium-high.
- Expertise / knowledge base: is high (arrest-equals-crime conflation is foundational mainstream critique; feedback dynamic among the best-documented findings, though magnitude in any deployment is contested); ought-force medium-high.
- Guarantor: is high (objectivity-claim explicit, field-wide vendor rhetoric); ought-force high (no single guarantor secures a value-laden design — core Ulrich tenet).
- Witness: is high for structural absence in the modal configuration, medium on degree (some jurisdictions bolting on oversight boards); ought-force medium-high.
- Emancipation: is high for the modal configuration, with individual-notice/appeal absence a deployment-variant fact; ought-force medium-high.
- Worldview: is high that an actuarial/managerial worldview is operative and naturalized, medium on the further claim that it is fully invisible to all participants; ought-force medium-high (competing frames real and constituency-held; which prevails is the live contest).
Additional considerations
Two scope notes on what could not be confirmed here. The boundary-critique mode’s emission-contract / success-criteria format specification was not in context; if a heading-order, envelope, or table requirement exists, compliance with it cannot be confirmed in this deliverable. And which worldview constituencies hold which frame in a given jurisdiction (the Worldview category) remains medium-high rather than confirmed; it resolves only with local stakeholder/constituency mapping against the actual deployment.