Synthetic Media & Provenance · Capstone brief
PROV-02 · Content Credentials in practice
What does a recipient see at each step, and where exactly do the credentials stop existing?
The question
Attach Content Credentials to one asset, then follow them through the operations a newsroom actually performs — export, crop, re-encode, upload, screenshot. What does a recipient see at each step, and where exactly do the credentials stop existing?
System / materials
One asset the student creates, with no person as its subject. A capture or editing tool that implements C2PA (https://c2pa.org/) and a verification path a recipient would realistically use. A written operation list, fixed before testing, of at least eight steps covering both the ideal chain and the everyday ones — a screenshot, a phone-to-phone send, a social upload, a document paste. Where the school's tools do not write credentials at all, that is the finding, and the brief becomes a documented account of what a program would have to change to get any provenance at all.
Expected failure modes
Testing only the export step, which is the one place it always works. Reporting "credentials survived" from the authoring tool's own viewer rather than from a recipient's position. Assuming a stripped credential means someone acted maliciously — the usual cause is an ordinary tool that never implemented the standard. Concluding the standard is useless from one broken path, or that it works from one intact one.
Done looks like
A survival matrix: every operation as a row, with what a recipient can see afterward, which tool performed the operation and its version, and whether the manifest survived, was stripped, or was invalidated. Plus a short recipient-view note — what a reader with no special software actually sees — and a one-paragraph verdict on where in your program's real workflow credentials could survive today.
Five C's
CT: separating what the standard specifies from what the tools implement. CR: choosing the operations that reflect real use. CO: a peer receives the asset cold and reports what they can verify without instructions. CM: a matrix a newsroom could act on. CZ: who is misjudged when absent credentials are read as a signal.
Mentor role
A photo editor, digital asset manager, or media technologist reviews the operation list before testing. Standing instruction: reject a test that never leaves the authoring tool. School-supervised.
Rubric calibration
R1: one asset, one operation list. R2: matrix reproducible with tool versions named. R3: comparator is the recipient with no tooling. R4: strips distinguished from invalidations. R5: matrix is decision-ready. R6: refuses to read absence as evidence.
Two ways this goes wrong
(a) Credentials verified in the tool that wrote them, and nowhere else. (b) A stripped credential reported as tampering.
Credit lane fit
Lane A immediately (journalism, broadcast, or media-technology capstone). Natural precursor to PROV-04. No verified credit claim.