Give a public service the aggregate picture and the citizen contact it needs, without exposing a single subscriber's data.
Citizen contact journeys, emergency alerts, population and mobility analytics and social-protection support run as lawful, purpose-limited workflows that aggregate where possible and act only with explicit agency authority.
For Government CIOs, agency and city heads, emergency management and public-service operations.
A river is rising and the agency has to warn the people in its path within the hour, without a list of who they are.
The lawful warning of an area, the number of people in it, and the person who decides to send the alert.
An approved alert to the area, through the operator, on the agency's decisionConsidered
A narrower area or window, where the group size or the basis failsConsidered
Referral to an authorised officerConsidered
No alert, where no emergency authority existsConsidered
Before anything reaches the customer: Legal basis, emergency authority, re-identification risk, minimum group size and stale-data checks pass.
What would reach them: The agency decides; the approved alert goes to the area through the operator, and nobody's identity leaves the network. On Cell broadcast, SMS.
The lawful warning of an area, the number of people in it, and the person who decides to send the alert.
A river is rising. The agency has to warn the people in its path within the hour, and it has no list of who they are and no right to one.
An approved alert to the area, through the operator, on the agency's decision
A narrower area or window, where the group size or the basis fails
Referral to an authorised officer
No alert, where no emergency authority exists
What it does
Three things it helps you decide or do.
Answer and route the citizen's contact
A voice bot and a service chatbot handle a bounded journey from disclosure and authentication to resolution or a warm handoff; calls are routed, appointments booked and cases triaged, with referral to an authorised officer.
Publish aggregate
route case
allocate resources
send approved alert
schedule appointment
investigate
suppress
refer to authorised officer
Publish the aggregate, never the individual
Population density, crowd safety, transport and mobility analytics publish privacy-protected aggregates for approved geographies and time windows; a group too small, a re-identification risk or a missing legal basis stops publication.
No legal basis
re-identification risk
group too small
emergency authority absent
bias/exclusion risk
stale data
agency cannot act
Keep the purpose approval and the impact review with every use
The purpose approval, the data agreement, the aggregation test, the agency's decision and the impact and bias review are recorded, and public reporting follows from them.
Purpose approval
data agreement
aggregation test
model/logic version
agency decision
action log
impact/bias review
public reporting
The journey
Warn the people in an area, without a list of who they are
No demonstration is configured for this product yet.
Emergency management and public-service operations
Step
What the customer experiences
What the operator does
The momentThe moment that started it.
A river is rising and the agency has to warn the people in its path within the hour, without a list of who they are.
Reads the approved area and time window, aggregate device counts and the minimum group size, the legal basis and the emergency authority, data freshness.
The decisionThe decision to be made.
Nothing reaches the customer yet.
Prepares an aggregate of devices in the approved area and time window, checks the group size and the legal basis, and recommends the alert's reach.
The safeguardsThe conditions that stop it.
Still nothing. No action is sent until every check has passed.
Legal basis, emergency authority, re-identification risk, minimum group size and stale-data checks pass.
The actionThe action that reaches the customer.
The agency decides; the approved alert goes to the area through the operator, and nobody's identity leaves the network. Reaches them on Cell broadcast, SMS, in English, Kiswahili.
Recommends. The system that holds the right confirms, charges or provisions.
When it goes wrongRefusal, failure and recovery.
The aggregate is built on counts from the previous evening, and the alert reaches an area the people have already left while missing the one they moved to.
The stale-data check refuses the aggregate, a fresh window is drawn, and the impact review records the gap so the freshness rule is tightened for alerts.
The resultThe change it made.
What changed for them is what is counted; nothing else is claimed.
People reached in the area within the window, against alerts sent outside it.
The proofThe proof anyone can check.
Can be answered for, later, from the record.
Purpose approval, data agreement, aggregation test, agency decision, alert log, impact review and public report.
Purpose approval; data agreement; aggregation test; model/logic version; agency decision; action log; impact/bias review; public reporting
04
Costs and risks
The cost, and the ways it can go wrong.
Costs: Fixed project + annual managed service; government framework contract; outcome milestone only where measurement and authority are agreed
If it fails: Withhold unsafe output; escalate to agency privacy/command authority; fall back to official data/process; never expose raw subscriber records
05
Measurement approach
The measure that shows it helped.
Geographic/time phased rollout; process baseline; independent privacy and bias review; publish limitations; never infer causal impact without design
Measured on: Response time; queue reduction; service completion; coverage; false alert; excluded population; resource efficiency; public outcome metric
Nothing has been observed for this product. Every line above is the record's own design intent; measurement begins in a pilot's validate stage, on your systems, with the comparison agreed first.
The business side
The change
People reached in the area within the window, against alerts sent outside it.
Running cost
Fixed project + annual managed service; government framework contract; outcome milestone only where measurement and authority are agreed
What evidence supports it
Purpose approval, data agreement, aggregation test, agency decision, alert log, impact review and public report.
Technical detail
Inputs, decision logic, systems touched, records kept.
Four questions an evaluation asks in a different order every time. Every field is the workbook’s own, unedited.
What would we need from your systems, and how much history?
Attributes required
time_window
approved_geography
aggregated_count
service_demand
channel
case_status
infrastructure_status
data_purpose
aggregation_threshold
audit_id
Also useful, not required
Survey/census
weather
transport
public-health aggregates
satellite
IoT
network outages
national ID for authorised verification only
Written public purpose; legal basis/data-sharing agreement; aggregation/privacy threshold; agency owner; operational response path; impact metric
How is the action chosen, and what stops it?
Actions it may choose between
Publish aggregate
route case
allocate resources
send approved alert
schedule appointment
investigate
suppress
refer to authorised officer
Conditions that stop execution
No legal basis
re-identification risk
group too small
emergency authority absent
bias/exclusion risk
stale data
agency cannot act
Withhold unsafe output; escalate to agency privacy/command authority; fall back to official data/process; never expose raw subscriber records
What does it connect to, and what stays authoritative?
Your systems involved
Agency case system
GIS
emergency command
contact centre
operator analytics
IAM
audit/records management
Interfaces
Secure data exchange
GIS
case management
alerting/cell broadcast
CAMARA Population Density/Location where lawful
identity verification
Channels
Agency dashboard
secure API
contact centre
SMS/cell broadcast
field operations
citizen portal
HeuriTel recommends or prepares evidence; the regulated lender/agency and source system decide and execute.
What is kept, and how would a claim be tested?
Evidence required
Purpose approval
data agreement
aggregation test
model/logic version
agency decision
action log
impact/bias review
public reporting
The measures
Response time
queue reduction
service completion
coverage
false alert
excluded population
resource efficiency
public outcome metric
Privacy and regulation
High sensitivity
aggregation/pseudonymisation
proportionality
non-discrimination
transparency
redress
retention
procurement and public-record rules
Geographic/time phased rollout; process baseline; independent privacy and bias review; publish limitations; never infer causal impact without design
The 28 definitions underneath
28 in this product
HeuriTel Citizen Contact Centre Voice BotDecision definitionHT-0453
Handle a bounded citizen contact centre voice journey from disclosure and authentication through resolution or warm human handoff.
/d/HT-0453
HeuriTel Government Service ChatbotDecision definitionHT-0454
Provide government service chatbot through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
/d/HT-0454
HeuriTel Public Service Call RoutingDecision definitionHT-0455
Provide public service call routing through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide citizen appointment booking through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
/d/HT-0456
HeuriTel Public Service Case TriageDecision definitionHT-0457
Provide public service case triage through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide emergency alert targeting through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide disaster connectivity monitoring through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Use network, customer and economic data to support emergency network resource prioritisation, with operator-approved actions, change controls and post-action verification.
/d/HT-0460
HeuriTel Population Density AnalyticsDecision definitionHT-0461
Provide privacy-protected aggregate device/population counts for approved geography and time windows to support planning, safety or operational decisions.
Provide crowd safety analytics through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
/d/HT-0462
HeuriTel Transport Demand AnalyticsDecision definitionHT-0463
Provide transport demand analytics through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide urban mobility planning through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
/d/HT-0464
HeuriTel Public Health Mobility AnalyticsDecision definitionHT-0465
Provide public health mobility analytics through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide disease response communication through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
/d/HT-0466
HeuriTel Social Protection Targeting SupportDecision definitionHT-0467
Provide social protection targeting support through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide poverty mapping support through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
/d/HT-0468
HeuriTel Digital Identity VerificationDecision definitionHT-0469
Provide digital identity verification through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide benefit recipient verification through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
/d/HT-0470
HeuriTel Public Sector Fraud DetectionDecision definitionHT-0471
Detect and prioritise public sector fraud detection risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
/d/HT-0471
HeuriTel Taxpayer Service AssistantDecision definitionHT-0472
Provide taxpayer service assistant through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide permit application triage through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide smart waste route optimisation through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
/d/HT-0474
HeuriTel Public Infrastructure Demand PlanningDecision definitionHT-0475
Provide public infrastructure demand planning through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide tourism flow analytics through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
/d/HT-0476
HeuriTel Public Safety ConnectivityDecision definitionHT-0477
Provide public safety connectivity through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide agriculture advisory service through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Provide education access analytics through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
/d/HT-0479
HeuriTel Government AI GovernanceDecision definitionHT-0480
Provide government ai governance through a lawful, purpose-limited public-sector workflow using aggregation where possible and explicit agency authority.
Four stages, and what has to be true before the next one starts.
12-16 weeks for a bounded pilot after legal/data-sharing approval; emergencies require pre-approved operating procedures. A team of 7 roles, named in the record rather than promised.
01
Scope
One use case, one value unit and a denominator finance has agreed to. Without these there is nothing a later result can be compared against.
Define public purpose
assess law/ethics
agree aggregation
02
Connect
The attributes mapped from your systems, and the decision and outcome interfaces working in both directions.
data agreement
03
Validate
Eligibility agreed, a dry run with nothing sent, then a controlled pilot with a holdout that is actually respected.
build synthetic proof
security review
shadow
agency-approved pilot
04
Operate
The live loop: decide, check, execute through your systems, capture what came back, and measure against the control.
Authorise purpose
prepare/aggregate
analyse
apply thresholds
agency review
act
log
publish impact and bias checks where appropriate
Who does it. 1 public-sector lead · 1 privacy/data-governance lead · 1 telecom data engineer · 1 data scientist · 1 integration developer · 0.5 QA/security · 1 local coordinator
Four states are tracked, and each is assessed against your systems.
Readiness is assessed per client: nothing is offered as pilot-ready until your data, your integration and your authority have been checked.
Readiness
Needs client data and integration review
The client’s data and integration position.Runtime / build state
Target product definition
What exists as running software.Surface state
Not audited
Whether this product shows the entry anywhere.Client status
Not assessed
Where a named client has reached.
Next steps from here.
28 definitions sit under Government & Public Sector. The two links that matter first are the journey this page describes, and the rest of the family it belongs to.
What can the network itself do for a bank, an agency or a planner?
CAMARA & GSMA Open Gateway APIsLet a bank or an app verify a number, a SIM change or a location from the network itself, with the customer's consent recorded.
Network Investment & IntelligencePut the next site, upgrade or fibre route where the customers and the revenue are, and show afterwards what the money did.
Fraud, Identity & Customer ProtectionStop the SIM swap, the takeover and the subscription fraud before the money moves, and let the fraud system make the call.