The Consent Graph — performer-level permissions for every image, clip, product, share-link, and deletion
The Consent Graph is the permission substrate under every gallery, clip, product, share-link, and deletion request on the platform. Every performer has a guardian-controlled consent record: the guardian chooses, before delivery, whether their child’s image appears in the shared studio gallery, in individual-family products, in both, or in neither. That choice is machine-readable, time-stamped, and enforced at the engine layer — not by a policy reminder the photographer might miss. An unconsented performer cannot appear in a shared gallery, a family product cart, or a share-link sent to a grandparent, because the engine refuses to include them — not because someone remembered to remove them manually. Consent covers depiction (who appears), access (who sees the gallery), sharing (who can receive a link), and deletion (the request is logged, the record is updated, and downstream products are invalidated). The consent substrate and depiction-ledger are built and production-ready. The self-service guardian interface for real-time consent changes is in active development.
Consent Graph built · depiction-ledger enforced at engine layer
Gallery organized by studio, show, act, class, costume, and stage time — not a flat event album
A recital gallery organized as one undivided album forces a family to scroll a hundred photos to find their child’s number. Recital Photos organises every gallery by studio, then show or event, then act or number, then class, then costume group, then stage time. A family looking for their child’s jazz number in the second act of the Saturday evening show navigates there directly. Roster mapping ties each image set to the performers in that act and class — so the gallery a family sees is pre-filtered to the acts their child participated in, with no cross-visibility to other performers. A studio administrator can publish one show’s gallery while the next show is still in proofing, without exposing unreviewed images. Gallery organization and roster-mapped delivery are built and production-ready. The pro-capture workflow tool that assists the photographer in tagging acts and costumes on the day is in active development.
Gallery organization built · roster-mapped delivery built
Branded parent storefront and package / print / album fulfillment — live checkout honest-off
The parent storefront is the branded product page a family sees after accessing their consent-gated gallery. Print packages, digital downloads, and album products are configured by the studio per event or per season. The fulfillment engine manages product types, pricing tiers, package bundles, and album layout rules. A studio can offer a basic digital download for the class photos and an album upgrade for the full recital season — separately priced and separately gated by the performer’s consent record. A parent whose child opted out of the shared gallery cannot land on a product page for that gallery: consent gates the cart, not just the photo view. The storefront substrate and fulfillment engine are built. The live checkout interface that accepts payment from parents is honest-off — present in the platform, not yet enabled for live transactions.
Storefront substrate built · live checkout honest-off
No-skim fundraiser-split payouts to the studio — fee off gross first, exact-cent, largest-remainder
A dance studio that offers recital photography as a service earns a share of print and product revenue. The split engine divides gross proceeds with exact-cent precision: the fee is deducted from gross proceeds first — before any split is calculated — and splits are applied to the net remainder. Parties sum to exactly 10,000 basis points. A largest-remainder reconciliation pass ensures the total distribution equals the net cent for cent, with nothing silently coerced into a platform margin. A studio treasurer sees the exact projected payout per event before the charge rail runs — the actual amount, not a percentage estimate. The no-skim split engine is built and production-ready. The charge rail that moves money is honest-off — present in the platform, not enabled for live transactions today.
Split engine built · charge rail honest-off
Rush-turnaround delivery and video-clip bundles — early access, in active development
Rush-turnaround delivery is the workflow that delivers an edited gallery within a defined window after the recital closes — 24-hour, 48-hour, and 72-hour tiers, configured by the studio per event. Families see the turnaround window at the gallery access page before the event day. Video-clip bundles allow a studio to attach a short edited clip of a performer’s number to the photo gallery for that act — purchased by the family as an add-on, subject to the same Consent Graph rules as photos. A performer whose guardian did not consent to video cannot be sold a clip of that performer, even if the photographer captured the footage. Rush delivery configuration and video-clip bundle support are early-access — in active development and not yet live in the platform. They are named here because they are real planned features, not because they are available today.
Rush delivery early-access · video-clip bundles early-access