More cities, counties, school districts and public agencies are publishing the progress of their strategic plan. That is a good thing, and it is a more delicate decision than it looks.
Publish too little and it reads as concealment. Publish too much and you expose internal trade-offs, delays that have not been explained yet, and occasionally information that should never have left the building. Between the two sits a level of publication that is useful, sustainable and defensible.
Here is how to find it, and more importantly how to avoid the version that ages badly.
The real risk is not publishing, it is publishing once
A progress page posted when the plan launched and never updated since does more damage than no page at all. A resident, a reporter or a board member who sees two-year-old data draws one conclusion: this plan is not being tracked.
So the first question is not what to publish. It is how often you are committing to update. The content follows from that frequency, never the other way around. A quarterly high-level update beats a detailed page promised as continuous and abandoned after six months.
Three levels of detail, three audiences
A strategic plan naturally produces three different readings.
- The internal level: actions, tasks, owners, tracking notes, variances and open trade-offs. This is where staff work.
- The governance level: goals, objectives and their indicators, with highlights and areas of concern. This is what the council or the board receives.
- The public level: progress on commitments, expressed in language that makes sense without knowing the org chart.
Public reporting is built on the second level, simplified. It does not descend to the task level, not out of secrecy but because that detail cannot be interpreted from outside. An action status named after an internal process means nothing to someone who was not in the meetings.
What does not get published
A few categories deserve an explicit decision, made once and written down.
- Detailed execution tracking. Tasks, internal deadlines and week-to-week progress on the projects and work streams attached to a goal stay internal. That is the working level. Published, it creates false precision and draws questions about details that change every week, while the thing that matters, progress on the goal itself, goes unnoticed.
- The names of the people responsible. Accountability is an internal mechanism. Publishing a staff member's name next to a late action tells the public nothing and exposes the person.
- Working notes and interim reviews. They contain assumptions, discarded options and sometimes information about third parties.
- Anything tied to an active negotiation: land acquisition, an interlocal agreement, a procurement file, labor relations.
- Indicators whose raw value invites misreading without context. Publish them with the note attached, not on their own.
The rest benefits from being visible. An organization that explains a delay clearly builds more credibility than one that shows only its wins. Public records requirements already point in that direction. Deciding in advance what the page shows is easier than deciding under deadline.
The privacy question, stated precisely
Two things often get conflated. A strategic plan and its action plans contain sensitive information about the organization's projects. They do not normally contain personal information about residents.
That distinction changes the nature of the obligation. The content of a strategic plan is not personal data, with one exception: the accounts of the staff working in it, meaning their names, work email addresses and roles.
In other words, the useful caution is not about the plan. It is about user accounts and about the documents attached to plan elements. That is where the real access and retention questions sit.
Knowing who your data is shared with
As soon as a cloud tool enters the picture, another question follows: what leaves the organization, and to whom?
Every software product relies on other suppliers: hosting, email, support, analytics, and now AI model providers. The relevant question in 2026 is no longer only where the data is hosted. It is which third parties receive a portion of it, which portion, and why.
This is now squarely a public sector concern. Over the past month, states have moved to tighten oversight of AI systems and to require greater transparency from data centre projects, including disclosure obligations and community engagement. Whatever a given jurisdiction adopts, the direction is consistent: agencies are expected to know and to be able to state who handles their data. A vendor should be able to provide that list in writing, and the response says a great deal about its maturity.
Four decisions to make before you publish
- The update frequency, and the person answerable for it. Both written down.
- The level of detail published, decided once for the whole plan rather than element by element.
- How delays are handled. Decide in advance whether variances are published with an explanation or held until the annual report. The first option is harder and considerably stronger.
- Where the published page draws from. A public page maintained by hand from an internal spreadsheet will eventually diverge. A page generated from the same data as the internal tracking, with a detail filter applied, stays accurate at no extra cost.
What publishing changes internally
The most interesting effect of public reporting is not external, it is internal. An organization that knows its progress is visible updates its data differently. Empty fields become obvious, vague labels become awkward, and indicators without targets stand out.
Many organizations discover this way that their internal tracking was not ready to be shown. That is good news. It is exactly the kind of finding a well-run tracking cycle lets you fix before someone else raises it.
Where to start
Start small and regular. A page showing goals, objectives and one progress indicator per goal, updated quarterly, is plenty for a first year.
Add detail once the internal cycle is solid, never before. A modest page that is reliably current earns more trust than a rich dashboard frozen in time.
What Planivore makes visible, and to whom
Our Data Security page covers hosting, access and transparency about third parties : https://planivore.app/en-us/data-security/
To see what a public view fed by internal tracking looks like, book a demo : https://planivore.app/en-us/book-demo/