What the current deployment contains
This R000072 audit inventories 296 local image/audio media files. 65 are mapped to reviewed/eligible rights or media-governance records, 12 more are preserved as existing O037 procedural media with a deliberately unnormalized reuse boundary, and 219 stay visible as existing runtime assets but are held from new derivative/publication decisions until a rights mapping exists.
The deployment has no remote runtime image/audio/video references in its HTML/CSS/JS media paths. The global CSP remains strict rather than being widened for visual completeness.
Publication firewall
New documentary media must have a stable source identity, reviewed rights basis, representation label, same-origin localized bytes, SHA-256, MIME type, dimensions where relevant, accessibility text, provenance, and any derivative/change notice. If those gates cannot be met, the correct state is held, reference-only, or localization-deferred.
Documentary versus generated
Documentary/source media, ICU originals, explanatory visualizations, and generated or illustrative media are not interchangeable. The current ASEU Hooke rendition is labeled documentary and carries CC BY 4.0 attribution. BVU’s current subject visuals remain source-backed explanatory visualizations, not copied documentary images.
When acquisition fails
ICU keeps the caption, source, rights state, and useful text available rather than inserting an unreviewed remote image. A missing documentary asset may stay record-only while an already approved local visualization remains in place. Failed acquisition never relaxes CSP.
Integrity and duplicate handling
Media bytes are fingerprinted with SHA-256. Content-addressed assets must match the hash encoded in their filename. Duplicate bytes are reported instead of deleted automatically because two paths can have different compatibility or route obligations.
Machine-readable records
Current media-governance pointer · Audit summary · Publication policy · Held/localization queue