Every asset carries its rights, and publishing is blocked by default.
A clip, a still, a piece of music or a chapter card is not a file here. It is a file plus a rights status, plus an Amazon window, plus a geographic scope — and if any of those three says no, the publish button does not work.
The rights fields every asset carries.
Seven fields. Every one of them is marked due, because this is a demonstration build with no assets, no rights holder and no licence to manage.
A register that shows only green is not a register.
How the block actually works.
The default
- Unknown rights status
- BlockedThe default for anything ingested without a status is unknown, and unknown does not publish.
- A closed Amazon window
- BlockedRegardless of who is asking, what the page is, or how close the release is.
- Outside the geographic scope
- Blocked, per requestEvaluated at request time against the viewer’s territory, not at publish time.
- Expired licence
- Blocked, automatically, overnightThe nightly job unpublishes rather than warning. A warning gets ignored; an unpublish gets fixed.
The override
- Who can override
- A named human, from a short listNot a role, not a group and not an API key. A person.
- What is recorded
- Who, when, which asset, and whyThe why is a free-text field and it is mandatory.
- How long it lasts
- Until the underlying field changesAn override is not permanent and does not survive a rights update.
- Reviewed
- Monthly, by somebody who did not grant itBecause an override log nobody reads is a rubber stamp with extra steps.
What has no override at all
- Music without clearance
- No override existsIt is the commonest reason a clip cannot run and the most expensive one to get wrong.
- A child without consent
- No override existsNot for anybody, at any level, for any reason.
- A closed window, in territory
- No override existsThe window belongs to somebody else. It is not ours to override.
The distinction that makes this work is between fields a named person may override and fields nobody may. Three of the seven are in the second category.
Why blocked-by-default rather than warn-and-proceed.
Because a warning is a thing somebody clicks through at half past six on a Friday when a clip has to go out. Every content operation that has ever run a warn-and-proceed model has published something it should not have, and usually within the first year.
Blocked by default inverts the effort. Publishing something with unclear rights requires a named person to do something deliberate and leave their name on it, and that single friction removes almost all of the accidental cases, which are almost all of the cases.
It also produces the only thing that helps afterwards: a log of who decided what, and why. When somebody asks in eighteen months why a particular clip ran in a territory where it should not have, the answer is a row rather than a conversation.
What each rights status means in practice.
| Status | What it is | Publishes? | Typical example |
|---|---|---|---|
| Owned | Created for this platform, by us | Yes, everywhere, permanently | A photograph taken in the yard for a chapter card |
| Licensed | Somebody else’s, used under terms | Yes, within scope and until expiry | A stock image, a font, a piece of production music |
| Third-party | Somebody else’s, with no licence held | No | A frame from the programme. The rights sit with Amazon and the production companies |
| Unknown | Ingested without a status | No, and this is the default | Almost everything, on the day it arrives |
| Restricted | Ours, but not for this use | No, without a named override | A photograph of a member of staff who consented to internal use only |
Nothing on this site is licensed from anybody
This is an unsolicited third-party demonstration build. It holds no programme footage, no production stills and no licensed assets of any kind. Every image on it is a generated illustration produced for this build. The rights manager described here is a design, not an inventory.
The rights manager, questioned.
Because rights are territorial and a cache is not. Evaluating at publish time produces a page that is correct in one country and wrong in another, which is the failure mode that gets noticed by a rights holder rather than by you.
The nightly job unpublishes it. Not a warning, not a flag on a dashboard — it comes down, and somebody has to deliberately put it back with a current licence.
A named person from a short list, with a mandatory written reason, reviewed monthly by somebody else. Three of the seven fields have no override at all.
The card generator, exposed as a service.
The thing that makes a chapter card, offered to certified producers under a narrow contract.