Observability Is Not Surveillance

Whether an environment identifies people is a design decision — not a side effect of how much it watches them

A two-by-two diagram with axes labeled Observability and Identifiability. Four points are plotted: a loyalty program (high identifiability, low observability), an anonymous sensor (high obser

An environment is not surveillance because it observes more. It is surveillance when what it keeps can point back to one person.

Working proposition

Whether an environment identifies the people inside it is a design decision, not a byproduct of how closely it observes them.

Ask most people to describe a ceiling sensor that tracks how long someone lingers in front of a shelf, and they'll describe a camera that knows who you are. Same word for both: surveillance. It's usually the wrong word, and getting it wrong costs organizations on both sides. Some block systems that carry no real privacy risk, because "it watches people" sounds disqualifying on its own. Others hand their trust to systems that quietly do identify people — because nobody stopped to ask the more precise question.

Observability is how much a system can perceive — dwell time, cohort composition, journey stage, product proximity. Identifiability is a different question: can what it keeps be traced back to one specific person, now or later? People treat these as the same dial, turned up or down together. They aren't. Whether an environment ends up identifying anyone is something someone decided, deliberately or by neglect — it doesn't just happen because the system got better at watching.

I'm using "surveillance" narrowly here, on purpose: not any act of observation, but observation that can trace back to one identifiable person — the same standard regulators now use to decide whether data has actually been anonymized. That's a tighter definition than the word carries in everyday use. A system can still raise real governance questions, about how it treats a group it observes, without meeting that narrower standard. Hold onto that — it matters, and we'll come back to it.

What actually decides identifiability has nothing to do with how much gets perceived. It comes down to a handful of specific choices: can a record be isolated to one person? Linked to another record to find that same person again? Used to infer something specific about them? Get any one of those wrong, and identifiability climbs, even if the underlying observation was narrow to begin with. Get all three right, and it stays low, even on a system that sees an enormous amount. Two different dials, two different sets of decisions.

Two systems already sitting in most retail stores make this concrete. A loyalty program is highly identifiable — a name, an email, every purchase tied to one account, for as long as that account exists — but barely observable in a behavioral sense: it knows what left the store, not what happened on the way to the register. An anonymous ceiling sensor can be the opposite: rich behavioral observability, dwell time, hesitation, which cohort walked past which shelf, while retaining nothing that isolates, links, or infers anything about one specific, returning person. Same store, same commercial purpose, opposite corners of the same two axes. The difference isn't how much either one is watching. It's what happens to what gets kept.

That's a different question from deciding context matters more than identity for making a good commercial decision — that's about what's worth collecting in the first place. This is about what happens afterward: whether whatever you collected can be traced back to a person, and who signed off on that.

None of this settles everything, though. A system can pass every test above — nothing isolated, nothing linked, nothing inferred about any one person — and still treat a group differently once it's noticed: a better offer for shoppers who linger, a different price for a cohort that skews younger. Nobody got identified. Somebody still decided to treat that group differently, and that decision doesn't answer itself just because no name was attached to it. Fixing identifiability closes one question. Not the other one.

The right question was never how much a system sees. It's whether what it holds onto could ever point back to one person. Different question, different answer — and organizations have been building the wrong systems for years because they kept asking the first one instead of the second.

This essay is part of the In-Store Retail Media Framework under Observability. New readers can begin with Start Here or explore the Principles that guide the Journal.

Subscribe to Agustín Gutiérrez

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe