Requests to Refuse
The asks that arrive once a system exists, why each should be declined, and what to offer instead.
Reference
A working camera system attracts requests. Some would destroy it, and the answer is easier if it was decided before it was asked.
"Can it tell us who that was?"
Why to refuse: identification is a different tier with a different legal position, and the request usually arises from curiosity rather than necessity.
Offer instead: the time and location, joined to the access control record if identity is genuinely required and lawful to establish.
"Can we check whether someone is taking long breaks?"
Why to refuse: purpose drift from safety or security into individual performance monitoring, which produces exactly the avoidance behaviour that degrades the safety data.
Offer instead: nothing from the camera system. That is a management conversation.
"Can we add demographic estimation for marketing?"
Why to refuse: biometric categorisation, contested accuracy, and inferring sensitive attributes is prohibited in the EU.
Offer instead: aggregate counts by time and area, which answers the actual planning question.
"Can we detect suspicious behaviour?"
Why to refuse: not a definable class, no ground truth, and the labels encode whoever's judgement produced them.
Offer instead: detection of defined events — an unattended item, a door propped, entry to a restricted area — which is checkable and evaluable.
"Can we run it without telling people?"
Why to refuse: notice is a legal requirement with narrow procedural exceptions that a standing capability does not meet.
Offer instead: the defined investigation process, if the conditions are genuinely met.
"Can we keep the footage longer, just in case?"
Why to refuse: excess retention is itself a failure, and the "just in case" is not a purpose.
Offer instead: a hold mechanism for specific matters, and longer retention of derived events rather than video.
"Can we use the detections for discipline automatically?"
Why to refuse: every system has an error rate that falls unevenly, and automated decisions with significant effects carry specific requirements including human involvement.
Offer instead: human review with context before any consequence, and the contest route.
What not to help improve
Some requests should be declined rather than refined.
Making a covert deployment less noticeable, making emotion inference more accurate, making a prohibited categorisation more defensible — none is a partial improvement. Assistance makes the thing more likely to exist.
Say that explicitly: a better version of this is still this.
Recording it
What was asked, by whom, when. What was declined and why. What was offered instead. Who decided.
Findable, so the second identical request is answered by reference.
Reviewed annually, because circumstances change — which is different from being overturned under pressure.
If overruled, say so to the people affected, insist on the mitigations you would have required anyway, and record your position in writing, dated.
Answering the underlying concern
Almost every request has a real question behind it, and it is usually answerable.
"Who was that" is usually "was someone unauthorised in the area", answered by access control.
"Are they taking long breaks" is usually "is this team struggling", answered by asking.
"Detect suspicious behaviour" is usually "reduce theft", answered by detecting defined events.
"Keep it longer just in case" is usually "we lost something we needed once", answered by a hold mechanism.
Offering the answer to the real question turns a refusal into a consultation, which is what keeps you in the room next time.
Deciding who decides, in advance
The arrangement that prevents a refusal becoming one person's judgement under pressure.
Name the person or forum that rules on exceptions.
Name what evidence an exception requires: legal basis, assessment, performance figures, consequence procedure.
Agree it with whoever owns risk before anything is asked.
Publish it internally, so a requester encounters a process rather than an obstacle.
Record every decision, because the first one becomes the precedent whether or not anyone intended it to.
More in this section