Synthetic Media & Provenance · Capstone brief

PROV-04 · Ship a verified package

Produce a short, publishable news or feature package — and carry provenance end to end, from capture through edit to the surface a reader actually sees. Then write the failure log: every step where the chain broke, what operation broke it, and what a newsroom would have to do differently. The clean package is the easy half. The failure log is the deliverable.

The question

Produce a short, publishable news or feature package — and carry provenance end to end, from capture through edit to the surface a reader actually sees. Then write the failure log: every step where the chain broke, what operation broke it, and what a newsroom would have to do differently. The clean package is the easy half. The failure log is the deliverable.

System / materials

Teacher approves the story, the subjects, and the publication surface in writing before Checkpoint 1. The student needs:

  • A real, small story they can shoot or record themselves — a school event, a process explainer, a scene. Two to four minutes of video, or an audio piece, or a photo essay with a written story. Small enough to actually finish the chain.
  • A publication surface named up front — the student news site, a program YouTube channel, a printed page, an Instagram post. This matters more than students expect: the surface usually decides whether provenance survives, and finding that out is half the finding.
  • A provenance method the tools actually support. Content Credentials / C2PA where the capture and editing tools implement it (https://c2pa.org/), and where they do not, a documented manual chain: capture notes, original files with hashes, an edit log, and a written custody record. A manual chain is a complete answer to this brief. Do not skip the brief because the school's tools do not support C2PA — document that, because it is the true state of most newsrooms.
  • An ethics reference the program already uses, or the SPJ Code of Ethics as a starting point (https://www.spj.org/spj-code-of-ethics/).

If any AI-assisted element appears anywhere in the package — upscaling, noise reduction, generated b-roll, a synthesized transition, an AI-written caption — it is disclosed, and the consent and likeness rule governs it absolutely.

Expected failure modes

Producing the package first and reconstructing the "chain" afterward from memory — the log has to be kept as you go, and a reconstructed one is fiction. Testing only the export and never the actual upload, so the platform strip goes unrecorded. Screenshotting a frame and continuing, which quietly ends the chain. Treating a manual chain as a lesser result. Claiming the package is "verified" when what you can show is that you handled it consistently. Losing the originals — no originals, no chain, no brief.

Done looks like

A verified package with five pieces:

  1. The package itself — publishable quality by your program's standard, on the named surface.
  2. Chain-of-custody record — every step from capture to publish: device or source, who handled it, what operation was applied, what tool and version, and whether provenance survived that step. One row per operation.
  3. Failure log — every break, with the operation named and, where you can tell, the reason: format conversion, platform re-encode, a tool that does not write credentials, a screenshot, a crop. A log with no breaks means the chain was not actually tested end to end — go test the upload.
  4. Reader-facing disclosure — what a reader sees about origin and any AI assistance, placed where they will see it, in language a reader outside your program understands.
  5. Refusal log — what you declined: no synthetic likeness, no "verified authentic" claim, no detector score presented as proof, no subject synthesized or re-voiced.

Originals and custody records stay on school-managed storage. The showcase version carries the package, the chain record, the failure log, and the disclosure.

Five C's

CT: distinguishing "provenance survived" from "I remember what I did." CR: designing a chain that fits how your program actually works. CO: a peer re-verifies one branch of the chain from your record alone and reports where they got stuck. CM: a disclosure a reader outside journalism understands on first read. CZ: who is harmed if this package is later doubted — the subject, the source, or the publication's standing.

Mentor role

A working journalist, photo editor, broadcast producer, or newsroom standards editor reviews the story and consent plan at Checkpoint 1 — before shooting — and the failure log and disclosure at Checkpoint 2. Standing instruction: reject any package containing a synthetic likeness of a real person, and reject "verified authentic" as a claim. School-supervised, both times.

Rubric calibration

R1: one package, one surface, one origin claim. R2: another student could re-verify from the record. R3: comparator is what a reader can check unaided. R4: every break logged with its operation. R5: disclosure survives a non-journalist reader. R6: refusal log names specific declined claims and artifacts.

Two ways this goes wrong

(a) A beautiful package and a chain record written the night before from memory, with no breaks logged — which means the upload was never tested. (b) The student concludes "Content Credentials work" from a single export that never left their laptop.

Checkpoint suggestions

  • Week 1–2: Story, subjects, and publication surface approved; consent handled through the program's existing release process; custody log started before the first capture.
  • Week 4–5: Capture and edit complete with the log kept live; the actual upload tested to the real surface and the strip behavior recorded.
  • Week 7–8: Failure log finished with reasons; disclosure drafted and read by someone outside the program; refusal log complete.

Credit lane fit

Lane A immediately (journalism or broadcast capstone, student publication project, or AP Research). Lane B with a division Internship wrapper and a real host newsroom — the brief alone is not HQWBL. No verified credit claim.