CJIS Scope Determination Guide
Effective July 2026
This document is written for a TAC or CSO. If you are a chief or a team commander, forward it — it is the information your agency's terminal agency coordinator needs to make a determination.
Command Post is not advertised as “CJIS certified.” No such certification exists for software, and any vendor claiming it is telling you something that cannot be true. We also do not tell you whether your use of Command Post is in scope. That determination is yours to make. What follows is what the application does and does not do, so you can make it.
1. The application provides no field for the identifiers used to query CJI systems
There is no structured field for date of birth, Social Security number, or system return. Command Post never asks for them. An operator cannot enter an NCIC, III, or state-system response into a purpose-built field, because none exists.
2. Subject information is meant to be sourced from the case file
What makes information CHRI is where it came from, not what it says. Subject details in Command Post are intended to be drawn from the search warrant, the affidavit, the case file, and public court record — sources your agency already handles under existing policy.
3. Narrative notes and attachments are unfiltered, and can carry content into scope
Command Post accepts free-text notes and document uploads, including warrants, affidavits, and court orders. We do not filter their contents and cannot. If your personnel paste or upload a system return, that content is in the application regardless of how the fields are designed — and your determination has to account for that possibility, not just for the schema.
The control here is policy, not product. If your determination is that system returns must not be entered, that instruction belongs in your agency's use policy for the application, and it is enforced by your people. We will support whatever determination you reach, in writing.
4. Your agency owns and controls its data
Your agency decides who sees an operation and which teams it is shared with. Every cross-jurisdictional share is your agency's logged decision, not an open door. Command Post LLC administers accounts — teams, users, tiers — and holds no standing access to your operational content.
What we will sign
- A written scope determination recording the conclusion your TAC or CSO reaches.
- The CJIS Security Addendum, where your agency requires one.
Other terms your agency needs in the service agreement are reviewed case by case. We would rather tell you that than promise on a web page to sign something we have not read.
Questions this document does not answer
Infrastructure-level questions — hosting region, encryption at rest and in transit, authentication controls, audit logging, personnel screening — are answered directly, in writing, on request. They are deliberately not asserted on a public page, because an unverified security claim is worse than no claim. Email isaac@getcommandpost.org and you will get specifics.
Prepared by Command Post LLC. This guide describes how the application is designed. It is not legal advice, it is not a compliance certification, and it does not substitute for your agency's own scope determination.