{
  "schema_version": "1.0.0",
  "revision": "r000072-m018-media-governance",
  "updated_at": "2026-09-15T10:27:00-05:00",
  "core_rule": "A remote source URL may be provenance, never a publication shortcut. New documentary media requires explicit rights review plus exact-byte same-origin localization and integrity metadata.",
  "csp_rule": "Do not expand img-src/media-src merely to render a candidate. Current CSP is preserved.",
  "new_publication_gate": [
    "stable source identity",
    "raw rights statement and reviewed eligibility",
    "representation class: documentary/generated/visualization/illustrative",
    "same-origin local path for public runtime media",
    "SHA-256 and MIME",
    "dimensions for layout-bearing raster/vector/video when determinable",
    "alt text/caption or transcript as appropriate",
    "provenance/source linkage",
    "derivative/change disclosure when applicable",
    "fallback state if acquisition fails"
  ],
  "existing_unmapped_assets": "Existing R000072 runtime assets are not silently unpublished by this delta. Any new replacement, derivative, or publication action is held until mapped.",
  "fallback_states": {
    "held_record_only": "Show metadata/provenance/source link without runtime image/audio.",
    "reference_only": "Keep source as evidence/context; do not imply the source media is bundled.",
    "localization_deferred": "Retain current approved local representation and explain that documentary bytes are unavailable.",
    "asset_failure": "Preserve caption/source/rights text and meaningful alternative content; never swap in an unreviewed remote hotlink."
  }
}
