The $1,500 Question: Who Owns the Footage of Your Staff?
Every small business with a camera system faces the same uncomfortable truth: the footage belongs to whoever controls the cloud. When a Ring doorbell captures your break room, Ring sees it. When a Flock camera scans your lobby, Flock decides who gets access. The footage of your employees eating lunch, stretching between shifts, or having a private conversation in the hallway — it lives on someone else’s server, subject to someone else’s subpoena policy, and available to someone else’s data-sharing agreements.
The Sovereign Sentry O1 — Shop Shield — is the office tier that eliminates that exposure. It is a $1,500 kit designed for the places where employees spend eight hours a day and where the line between “security” and “surveillance” is a legal, cultural, and moral question. The O1 answers that question the way the Trust Costs chapter predicted: by making the answer architecturally enforceable, not policy-dependent.
What Ships in the Box
The O1 kit contains four Vigil camera nodes, two Listener audio sensors, two Threshold contact sensors, a Spine mesh router, and a Council hub. The Sovereign Stack as a product line means each component is purpose-built for the privacy-first model — not a repurposed consumer camera with a privacy sticker slapped on.

Four Vigil cameras cover the register area, lobby entrance, stockroom corridor, and exterior perimeter. Each runs local H.265 recording with E2E encryption. Motion-intent AI distinguishes between a customer browsing and someone lingering near the cash register — not because the system is suspicious, but because it needs to know when to flag and when to stay quiet. The footage never leaves the building. No cloud upload, no remote access, no third-party viewer.
Two Listener nodes are placed only in the lobby and break room — the two spaces where glass-break detection and voice-intent sensing matter most. Both are consent-posted: a visible plaque in each room declares that audio monitoring is active, what it detects, and how long the data is retained. This is not a privacy theater exercise. The Trust Chains chapter established that consent is a real boundary in the mesh, not a line of fine print. The Listener nodes honor that.

Hard-OFF Privacy Zones
The O1 introduces a concept that consumer security systems never address: hard-OFF zones. Locker rooms, restrooms, changing areas, and any space where employees have a reasonable expectation of physical privacy are designated as sensor-blessed but camera-free. The Council hub enforces this at the mesh level — a camera placed in a hard-OFF zone is not just “turned off” in software; it is physically excluded from the recording graph.
This is the distinction between a policy and a system. A Flock camera system might have a “privacy mode” that an admin can toggle. The O1’s hard-OFF zone is a governance rule baked into the Council’s access model. The Zero-Trust Agent Comms chapter established that trust must be architectural, not ceremonial. The same principle applies here: you do not trust the manager to not enable recording in the locker room. The system makes it impossible.
The Council hub auto-generates a compliance report that documents which zones are monitored, which are hard-OFF, what the retention policy is, and who has access. This report is the document your HR department hands to new hires on day one. It is also the document your insurance company asks for after an incident.
Retention and Access: The Numbers That Matter
The O1 runs 60 days of local retention. Not 30, not 90 — sixty. This is the window where workplace incidents, theft claims, and liability questions actually get resolved. After 60 days, footage is purged automatically. There is no “archive tier” where old footage sits indefinitely on someone else’s server waiting to be discovered in discovery.
Access is restricted to two key tiers: owner and manager. No third-party security vendor. No cloud dashboard. No “share with law enforcement” button. If the police need footage, they come to you with a warrant, and you decide what to release. The Geo-Sovereignty chapter called this “data that lives where you live.” The O1 makes it literal: the data never leaves the building, and the keys never leave the owner’s hands.

Who This Is For
The O1 targets the business types where employee privacy is not theoretical: retail shops, dental and medical clinics, law firms, salons, cafes, and coworking pods. These are spaces where cameras are necessary — for theft prevention, liability protection, and insurance compliance — but where the cameras also watch the people who work there. The O1 solves the tension by building the privacy boundary into the hardware and the governance model, not into a policy manual that gets ignored after the first quarter.
If you are running a Flock camera system or a Ring-for-business setup, the O1 is a direct replacement. The Sandbox to Sovereign Stack chapter described the migration path: you do not rip and replace overnight. You deploy the Council hub first, connect the new mesh nodes, and run both systems in parallel until the old footage ages out. The transition is clean because the new system does not depend on the old one.
The Compliance Report as a Product
The auto-generated compliance report is not a side effect. It is a core feature. The report documents:
- Which zones are monitored and which are hard-OFF
- The retention period (60 days, enforced at the mesh level)
- Who holds access keys (owner and manager only)
- What consent plaques are posted and where
- The last access log entry (who viewed what, when)
This is the document that satisfies OSHA, your insurance carrier, and the state-level employee privacy statutes that are multiplying across the US. The Identity as Sovereign Territory chapter made the case that identity is a first-class concern in the sovereign stack. For the O1, employee identity is the first-class concern — the system is designed around the premise that the people who work in the building have sovereignty over their own image.

Why $1,500 Is the Right Price
A comparable Flock Safety deployment for a small retail space runs $2,000–$4,000 annually in subscription fees. That is $6,000–$12,000 over three years, and you own nothing at the end. The O1 is a one-time purchase. The mesh nodes are yours. The footage is yours. The governance model is yours. After the initial deployment, the ongoing cost is electricity and the occasional firmware update — both local, both under your control.
The Billing the Sovereign Way chapter established the pricing philosophy: transparent, one-time where possible, and never designed to extract recurring rent from infrastructure the customer already owns. The O1 is the physical expression of that philosophy.
You are your own cloud. Your employees deserve a camera system that protects them without surveilling them. The Shop Shield makes that the default, not the exception.


