
Guides
How to build a consent and rights record for a creator asset library
A creator asset library rights record ties every file to the people, releases, licenses, approvals, statuses, and takedown routes behind it.
What to take away
- Assign a stable asset ID before files spread across tools.
- Preserve the original while registering every reviewed version separately.
- Link subjects, owners, releases, licenses, and approvals to the exact asset.
- Record permitted purpose, channels, territory, term, edits, and restrictions in plain language.
- Separate searchable operational fields from sensitive supporting evidence.
- Test the record with a real publication question before importing the whole library.
This process creates a creator asset library rights record. It does not decide whether a release or license is valid: in the United States that turns on state right-of-publicity and privacy law, 17 U.S.C. § 2257 for sexually explicit content, COPPA for children's data, and DMCA § 512 for platform notices. Legal review may still be needed for disputed authority, minors, sensitive material, changed uses, or multiple jurisdictions.
Step 1: Define the decision the record must support
Write a test question: "May this exact image version be used in a paid product post in Canada next month?" The system must return the owner, people depicted, permission scope, license scope, approval status, restrictions, expiration date, and reviewer. If it returns only a folder name, it is not ready.
Step 2: Create stable identifiers
Assign an asset ID that does not depend on a campaign name, employee, platform, or storage path. Assign separate IDs to releases, licenses, approvals, people, projects, and publications. Connect them through fields rather than squeezing all facts into a filename.
Example: master AST-00184; crop AST-00184-v03; release REL-00091 signed by SUB-00012; license LIC-00047 tied to the master; approval APR-00056 tied to the crop and its reviewer; publication PUB-00033.
| Record | Identifier |
|---|
Stable IDs Connect Records
- Source photograph: AST-004821
- Subject record: PER-000317
- Release: REL-000194
- Photographer license: LIC-000266
- Paid-post approval: APR-000089
Step 3: Register the master and versions
Keep the source file unchanged. Record its filename, format, size, creation information, ingest date, source, and checksum where appropriate. Each crop, retouch, composite, captioned version, and export receives a version entry connected to the master. Standards such as IPTC photo metadata and C2PA Content Credentials can carry some of this inside the file, but they do not prove consent.
Master and Version Records
- Master source file stays unchanged
- Record filename, format, size, checksum
- Each crop gets a version entry
- Each retouch gets a version entry
- Each export gets a version entry
- Approval of one version does not cover another
Do not assume that approval of one version covers another. A new crop can expose a bystander; a caption can create a false implication; a product logo can turn an editorial portrait into advertising.
Step 4: Add people and authority
For every recognizable person, record a subject ID and the evidence used to identify them. Record age status at creation and publication where relevant. If the person is a minor, name the guardian, keep the signed consent, and note that COPPA requires verifiable parental consent for online services directed to children under 13. If a guardian, agent, employer, or representative signed, record the claimed authority and supporting document.
Limit access to identity documents, contact details, signatures, and sensitive notes. The searchable library can show "release on file" and a controlled record ID without exposing the underlying evidence to every editor.
Step 5: Translate documents into bounded fields
Read the release and license. A release that holds up names the person or guardian who signed, the rights holder, the shoot or specific images covered, the permitted uses, any limit on editing or sensitive contexts, the term and territory, and the signature date. Translate it into bounded fields — parties, dates, rights, purpose, media, channels, territory, term, exclusivity, editing permission, sublicensing, credit, payment, withdrawal or termination, synthetic-use terms, and prohibited categories — and keep the source document, recording any uncertainty instead of guessing.
Bounded Rights Fields
- Parties and signature dates
- Rights, purpose, media, channels
- Territory, term, exclusivity
- Editing, sublicensing, credit, payment
- Withdrawal or termination terms
- Synthetic-use terms and prohibited categories
The National Archives' page on metadata requirements for permanent electronic records is aimed at U.S. federal transfers, not creator businesses.
Step 6: Record each proposed use
Create a use record with the asset version, product or story, caption, audience, channel, paid status, territory, dates, edits, and publisher. Compare the proposed use with the linked documents. Record approved, approved with conditions, rejected, or pending.
Approve Proposed Use
Does the proposed use match the linked documents?
approved or approved with conditions
rejected or pending
The approval must identify the person who decided, their authority, date, evidence reviewed, and conditions. If approval expires or is withdrawn under applicable terms, preserve the earlier record and change the current status.
Step 7: Add removal and incident fields
Record a current contact for the subject, rights owner, publisher, and internal escalation owner where appropriate. Add fields for withdrawal request, dispute hold, platform report, takedown, correction, deletion decision, and completion evidence, and log which route was used: a DMCA § 512 notice to the platform's designated agent from the U.S. Copyright Office directory, the platform's own reporting form, StopNCII.org for intimate images, or NCMEC's Take It Down for anyone under 18. Set a retention period for each record type; sexually explicit content carries its own federal record-keeping duty under 17 U.S.C. § 2257. Do not promise that a single system action erases every copy.
Step 8: Test, import, and sample
Build ten records representing simple, expired, disputed, restricted, minor-related, licensed, and multi-version assets. Ask editors to answer real use questions. Fix confusing labels and permissions before importing thousands of files.
After import, sample records against original documents. Check broken references, missing owners, invalid dates, broad free-text permissions, duplicated masters, and assets that remain public after approval ends.
Common questions
Can a spreadsheet work?
Yes, for a small controlled library. Protect it, restrict editors, preserve versions, and avoid storing sensitive evidence in broadly shared cells.
Should the release be renamed to match the image?
Use stable IDs and links. Renaming the only copy can weaken its history or create duplicates.
What status should an uncertain asset receive?
Use pending or restricted, state the open question, and name the reviewer. Do not convert uncertainty into approval.
How often should records be sampled?
Set a schedule based on volume and risk, and also sample after imports, migrations, incidents, and team changes.







