OFM content studio and generative-media domain
Date: 2026-08-29 Status: full research campaign complete; final callback delivered Owner: OFM-CONTENT
Executive decision (provisional)
HALO should own the creator-safe content control plane: creator boundaries and consent, briefs, work-item state, asset provenance, approvals, rights/expiry, delivery evidence, and the links back to creator/custom/request truth. It should integrate specialist media review, DAM/MAM, generative-media, and publishing systems where those systems are materially better at bytes, codecs, frame review, or platform delivery. Google Drive can remain a human-friendly byte/archive surface during migration, but its folders and filenames should not be the authoritative workflow state.
Fact from the read-only clone: HALO already has useful foundations—creator/model profiles and content limits, model announcements and a calendar, a public creator upload handoff, a Google Drive index with unused/used tracking, custom-request metadata, and an ElevenLabs voice-clone/generation queue. Inference: those foundations are not yet a content studio because no single HALO state machine connects idea → brief → versioned review → creator approval → publishing/retry → performance feedback → rights-aware reuse. The full campaign below tests which parts to build and which to buy.
Persona and authority map
This is the target authority boundary for the complete operating loop. The “current HALO evidence” column records what the clone actually exposes; it is not a claim that the target control is already implemented.
| Persona / service | Must see | May change | Authoritative record and hard boundary | Current HALO evidence |
|---|---|---|---|---|
| Creator / model | Own profile, boundaries, consent grants and revocations, briefs assigned to them, their uploads, review comments, approval history, publish/reuse outcomes, export | Supply or withdraw consent; upload; answer brief questions; approve/reject a specific version; request correction; choose availability | Creator/rights record in HALO; explicit version-level approvals; no internal chatter notes, credentials, or staff compensation | Public /upload/:id upload surface and model-profile data are present, but no complete creator portal is proven (repo/src/App.tsx:169-193, repo/src/pages/CreatorUpload.tsx:1-148). |
| Content producer / photographer | Briefs, shot lists, rights constraints, assigned work, quarantined assets, version history, review feedback | Create briefs and derivatives; attach provenance; submit a version for review; never alter a creator’s rights | Work item, asset lineage, and derivative records in HALO; source bytes may live in a DAM/Drive | No content work-item or version UI was found in the known route map; Drive exposes files rather than production state. |
| Editor / reviewer | Asset versions, frame/timecode comments, technical checks, creator constraints, unresolved review notes | Upload a derivative; respond to comments; request changes; never silently replace an approved version | Review-thread and version record in HALO; no silent overwrite of a prior version | Shared Drive exposes previews and “mark used,” not frame-accurate review or version lineage (repo/convex/driveIndex.ts:183-238, repo/convex/driveContent.ts:76-112). |
| Manager / content lead | Pipeline, workload, briefs, approvals, rights expiries, publishing queue, performance feedback | Prioritize and assign; approve operational readiness; schedule; escalate; publish only after required human approvals | HALO work-item state and audit trail; manager cannot grant creator likeness rights by implication | Model calendar and announcements exist, but they are per-model informational records, not an asset pipeline (repo/convex/creatorData.ts:14-135). |
| Chatter / sales operator | Only approved/released assets linked to a fan/custom request, safe usage notes, delivery status | Propose or link a request; report a correction; cannot change rights, edit source assets, or publish | Customs/request record plus asset ID; platform conversation remains outside this lane’s authority | customs stores model/fan/description/status/due date/attachments, but the schema has no asset-version or consent linkage (repo/convex/schema.ts:410-445). |
| Admin / owner / compliance | Full audit, access grants, rights evidence, expiry/revocation, incident queue, export/retention controls | Grant/revoke role access; hold or release a workflow; approve break-glass actions; never erase immutable evidence | HALO authorization and audit records; destructive actions require explicit reason and recovery path | Role checks are mostly client-side and several content paths straddle Supabase and Convex; this is a trust-boundary risk, not a reason to move authority into Drive. |
| Finance / rights or compliance specialist | Compensation/usage terms, consent evidence, expiry, takedown/export proof; not raw media by default | Validate commercial/rights conditions; place a hold; approve a contract-dependent use | Contract/rights and audit records; finance does not edit creative content | Contracts and creator profile data exist elsewhere in HALO; no content-rights ledger was identified in the content surfaces. |
| Publisher / platform adapter | Approved delivery package, target/account scope, idempotency key, platform response and retry state | Execute an already-approved delivery; report success/failure; never approve its own use | HALO delivery attempt record plus platform-specific receipt; platform remains authoritative for publication | No publishing adapter or retry state appears in the route map or content/Drive tables. |
| Generative-media provider | Minimum necessary prompt/reference and a consent/usage token | Generate a candidate or derivative only; return provenance metadata; cannot decide publication | HALO stores provider/job/model/version, input references, consent scope, and human decision; provider is never the rights authority | ElevenLabs voice cloning/TTS is implemented, but its current rows do not include consent scope, rights expiry, approval, or likeness revocation (repo/convex/voice.ts:163-337, repo/convex/schema.ts:544-599). |
| Buzz collaboration / agent plane | Typed links, scoped summaries, assignments, review events, escalation notifications | Coordinate people and bounded tools; no raw authority over creators, rights, assets, money, or publishing | HALO/domain services remain authoritative; Buzz owns communication/event surfaces per campaign brief | Buzz is fixed by the brief; this report will not substitute a chat-product survey for content truth. |
End-to-end operating journey
The authoritative record named in each step is the proposed target record. Current HALO coverage is called out separately below so the journey does not collapse into today’s screens.
- Enter with an active creator and a rights boundary. The creator is onboarded and
identity/contract/consent evidence is available; content permissions, exclusions, likeness/voice scope, geography, channel, expiry, and revocation are explicit. If a boundary is missing or expired, the work item starts blocked, not “approved by default.” Authority: HALO creator + rights/consent record.
- Create an idea, request, or campaign brief. A manager, producer, creator, or a
chatter-linked custom request creates an idempotent work item with objective, audience, deliverables, content class, due date, creator, rights scope, safety notes, and target channel. Authority: HALO brief/work-item record; a custom request remains the commercial source of truth for its promise and price.
- Resolve the brief into a script and shot list. The producer versions the copy,
references, wardrobe/prop constraints, required framing, accessibility/localization, and expected derivatives. Creator questions and boundary changes become explicit decisions on the brief rather than disappearing into chat. Authority: versioned brief.
- Schedule people and capture. The manager schedules a shoot or creator submission;
the creator or capture team records the source and uploads it. The upload is quarantined until type, size, malware, identity, rights scope, and destination are checked. A Drive outage or upload retry must not create a second logical asset. Authority: capture/upload receipt and immutable source hash. Current /upload/:id is only a thin file handoff.
- Ingest and normalize. The ingest worker records source URI, checksum, media kind,
dimensions, duration, capture/modified timestamps, uploader, import time, and parent work item. It strips or quarantines sensitive EXIF/GPS data according to policy, creates safe previews, and retains the original only under the appropriate access boundary. Authority: asset/provenance record; bytes may be in a DAM, object store, or Drive.
- Classify, deduplicate, and link. Taxonomy is a controlled vocabulary (creator,
content class, channel, campaign, request, safety/rights labels). Exact hashes catch duplicates; perceptual similarity is a review signal, never an automatic deletion verdict. A reused source links to its existing lineage. Authority: asset identity and lineage graph.
- Edit into immutable versions. Editors create derivatives with parent pointers,
tool/provider versions, prompts or source references where applicable, and a machine check result. Replacing a file creates a new version; it does not overwrite the approved history. Authority: version record and its source lineage.
- Run technical and human review. Automated checks can flag dimensions, audio,
watermark, duplicate, unsafe prompt/output, missing consent, or rights expiry. Reviewers attach frame/timecode comments and resolve them against a specific version. A creator approval and the agency/manager operational approval are separate decisions. Authority: review threads plus explicit approval records. Failure state: changes_requested, blocked, or expired, never an implicit pass.
- Package and deliver. Only an approved version produces a delivery package with the
target channel, caption/copy, price or request link where relevant, disclosure/watermark requirements, and idempotency key. The publisher adapter attempts delivery and records attempts, response, retryability, and human takeover. Platform publication is authoritative for “live”; HALO is authoritative for why this version was allowed. Failure state: retryable, needs_reauth, rejected_by_platform, takedown_pending, or manual_hold.
- Connect the result back to work and revenue. The published asset, custom request,
platform post/content ID, campaign, and approved creator scope stay linked. Performance feedback records observations and source windows without rewriting the original asset or approval. Chatter operators see released content and request links, not hidden rights or raw private material. Authority: platform receipt for delivery and HALO link/attribution record for agency operations.
- Reuse safely. A reuse creates a new planned use with the old asset lineage, a fresh
rights-scope check, channel restrictions, and (if needed) new creator approval. “Used” means consumed in one workflow, not “safe everywhere.” Current Drive’s USED : POSTED folder is a useful operational signal but too coarse for this rule.
- Expire, revoke, archive, and exit. Expiry or revocation places affected uses on
hold, identifies published copies and derivatives, records takedown/export actions, and preserves the audit trail. On staff turnover or creator departure, export a manifest containing asset IDs, hashes, lineage, approvals, rights scope, delivery receipts, linked requests, and retention decisions; revoke access and provider tokens. Authority: HALO rights/audit/export records, with storage deletion performed only after policy and legal holds are satisfied.
Feature and sub-app tree
Content operating system
├── Creator control and rights
│ ├── creator boundaries, consent grants, likeness/voice scopes, expiry/revocation
│ ├── creator portal: briefs, upload receipt, review, approve/reject, export
│ └── access, geographic restrictions, redaction, audit and wellbeing safeguards
├── Planning and intake
│ ├── ideas, campaigns, recurring content plans, briefs, scripts, shot lists
│ ├── creator availability / shoot schedule
│ ├── chatter-linked custom requests and promised deliverables
│ └── dependencies, assignments, SLAs, holds and exception queues
├── Production
│ ├── capture/upload quarantine and resumable ingest
│ ├── metadata normalization, taxonomy, hash/dedup and EXIF/privacy policy
│ ├── asset lineage, versions, derivatives and edit-tool/provider receipts
│ └── storage adapters: Drive, object storage, DAM/MAM
├── Review and approval
│ ├── frame/timecode/image-region review threads
│ ├── technical/safety/rights checks
│ ├── creator approval separate from manager/agency approval
│ └── immutable decision history, changes requested and escalation
├── Delivery and publishing
│ ├── channel-specific packaging, captions, pricing and disclosure
│ ├── human-approved publish queue, idempotency and retry/backoff
│ ├── platform receipts, re-auth/hold/takedown states
│ └── approved asset links for chatter/custom fulfillment
├── AI media studio
│ ├── prompt/reference registry and consent-scoped jobs
│ ├── image, video, voice and audio generation adapters
│ ├── provenance/watermark/content credentials and safety evaluation
│ └── human review, rollback, provider deletion and revocation handling
├── Feedback and reuse
│ ├── performance observations linked to post/asset/version
│ ├── reuse requests with fresh rights checks
│ ├── archive, retention, export and offboarding manifests
│ └── creator-facing progress and transparent status
└── Shared primitives
├── stable IDs, event timestamps, idempotency, audit and typed links
├── fine-grained RBAC and break-glass access
├── secrets/token vault and provider scopes
└── Buzz notifications, assignments and agent tools via server-side adapter
Current HALO coverage and gaps (read-only map)
| Area | Evidence in HALO | What is covered | Material gap for the content loop |
|---|---|---|---|
| Route and model-facing surface | repo/src/App.tsx:1-193; repo/src/pages/CreatorsData.tsx:1-45 | Internal protected “Model Profile” data; public/tokenized onboarding, contract signing, and /upload/:id are real routes. | The route map does not prove a dedicated creator portal with briefs, approvals, rights, status, or export. The claimed model app remains an open evidence question—not a license to call every creator feature missing. |
| Creator upload | repo/src/pages/CreatorUpload.tsx:1-148 | Multi-file browser upload; files go to Supabase Storage bucket creator_files under ${creator.id}/unsorted; success list and retry-visible errors. | /upload/:id is not wrapped in ProtectedRoute; no visible token/creator authentication, resumable upload, quarantine, checksum, MIME/policy enforcement beyond “all file types,” EXIF handling, asset ID, provenance, or work-item link. upsert: true can overwrite the same path. |
| Profile boundaries and content limits | repo/src/components/creators-data/CreatorDataModal.tsx:803-832,918-1004; repo/src/components/creators-data/ContentLimitations.tsx:1-92; repo/convex/creatorData.ts:137-150 | Structured onboarding data includes content/service fields; the UI displays five boolean limitations and lets Admin toggle them; location/time, announcements and calendar are visible in the model profile modal. | Limitations are a small free-form boolean set, not scoped consent/rights (asset, channel, likeness, duration, geography, revocation). The modal still looks up and writes some profile data through Supabase while the newer Convex path also exists, creating split-brain authority risk. |
| Planning and creator communication | repo/src/components/creators-data/CreatorDataModal.tsx:1008-1055; repo/convex/creatorData.ts:14-135; repo/src/components/creators-data/calendar/useSchedules.ts:32-144 | Per-creator announcements and editable calendar entries with Admin-only UI controls; Convex rows are reactive and archived announcements can remain recoverable. | No idea/brief/script/shot-list/work-item state, dependency graph, shoot plan, content SLA, review queue, or asset-linked calendar. Announcements are broadcast text, not decision/evidence records. |
| Google Drive | repo/convex/driveStructure.ts:1-128; repo/convex/googleDrive.ts:28-97,336-423; repo/convex/driveScan.ts:13-360; repo/convex/driveIndex.ts:33-276; repo/convex/driveContent.ts:76-112 | Creator folder provisioning; media/streaming category taxonomy; scheduled scan; metadata and thumbnail index; 48-hour unused/7-day inactivity signals; stable creator-folder mapping; “mark used” moves to USED : POSTED. | Index keeps only unused metadata; it has no content work item, version/lineage, rights, EXIF/privacy result, comments, approval, publish receipt, or archive/export manifest. Scan only reads immediate category children. The live Drive actions also need trust-boundary hardening before becoming a content authority. |
| Custom requests | repo/convex/schema.ts:410-445; repo/src/pages/CustomsTracker.tsx and repo/src/components/customs/* | A kanban-like customs tracker records model/fan, description, price/downpayment, due/status, optional attachments and status history. | Attachments are opaque strings; no asset IDs, version/approval/rights link, delivery attempt, platform receipt, or content reuse lineage. |
| AI voice | repo/src/pages/AIVoice.tsx:1-788; repo/convex/voice.ts:159-628; repo/convex/schema.ts:544-599 | Admin/Chatter UI can upload an audio sample, clone/reuse an ElevenLabs voice, choose three emotions, enqueue TTS, observe queue status, play/download/delete output; Convex retries transient jobs. | Voice-only: no image/video generation, likeness registry, consent scope/expiry/revocation, source approval, watermark/provenance, prompt/output safety review, asset/version linkage, or usage/publish gate. Current modelName strings are not stable creator IDs. |
| Authority and security | repo/CLAUDE.md (auth/Drive architecture notes); repo/src/context/SupabaseAuthContext.tsx; repo/convex/haloAuth.ts; repo/convex/rolePermissions.ts | Bespoke session/profile and role labels exist; newer modules use Convex tables and internal helpers in places. | The clone’s own architecture notes report no server auth context in the Convex modules and mixed Supabase/Convex permissions. Content and AI actions must not be promoted to production authority until server-side identity, authorization, audit, and secret scoping are characterized. |
Claimed existing model app: evidence status
Observed fact: the known route map contains a public creator upload screen, tokenized onboarding and contract-signing routes, and internal Model Profile surfaces. Observed fact: the bounded internal note says the route map alone cannot prove or disprove a dedicated model-facing app. Conclusion: this report treats /upload/:id, onboarding, signing, and Model Profile as the actual HALO surfaces currently evidenced; it does not label a complete creator portal “missing” until the repository/deployment/product evidence search is complete. A separate creator app, route hidden behind auth, or another deployment would change the map and will be recorded if found.
Initial search vocabulary and coverage receipt (urgent milestone)
The search must be intent-led rather than “OnlyFans CRM” led. Candidate families and query terms are:
- Planning / production tracking: media production management, content operations,
VFX production tracking, animation pipeline, game art pipeline, shot list, asset task, editorial workflow, approval gates, change requests, custom content fulfillment.
- DAM / MAM / provenance: digital asset management, media asset management, asset
lineage, derivative graph, checksum/dedup, perceptual hash, EXIF/GPS scrubbing, archive manifest, rights-managed media, expiry/revocation, content credentials, C2PA.
- Review: frame-accurate video review, timecode comments, image annotation, version
compare, review-and-approve, client proofing, human-in-the-loop media QA.
- Publishing / feedback: social publishing API, content calendar, publish retry,
idempotent delivery, platform receipt, takedown workflow, post-level analytics, asset performance feedback.
- Creator / talent workflows: creator portal, model release, likeness consent, talent
rights, influencer content operations, casting/ATS handoff, client approval portal.
- Generative media: voice cloning consent, likeness management, synthetic media safety,
AI image/video generation workflow, prompt registry, model provenance, watermarking, human approval, provider deletion/revocation.
- Adjacent operator language: “content backlog,” “unused content,” “content day,”
“custom request fulfillment,” “approval bottleneck,” “content vault,” “content manager,” “churn from posting,” “faceless/AI creator,” “voice note workflow,” and creator complaints about lost files, missed deadlines, leaked metadata, or unapproved reuse.
Receipt at urgent boundary: HALO read-only map and the required feature/journey tree are written above. The full local-corpus, GitHub, live-product, and operator campaign is completed below; promoted candidates and rankings are evidence-scoped, not inferred from the initial vocabulary alone.
Evidence labels and decision rule
This report uses the following labels so a polished product page, a README, and a checked runtime observation do not collapse into the same kind of evidence:
- [FACT] observed directly in the HALO clone, the protected Oracle source, a read-only
gh api response, a first-party product/API document, or an identified academic paper.
- [VENDOR CLAIM] a supplier's own feature, maturity, outcome, or security statement. It
is useful for a trial checklist, not proof that HALO's adult-content workflow is supported.
- [OPERATOR SELF-REPORT] a practitioner post, agency page, or workflow guide describing
practice. It is a vocabulary and hypothesis source unless independently reproduced.
- [INFERENCE] a conclusion drawn from more than one fact. It is explicitly marked and is
not presented as a current system capability.
- [PROPOSAL] a target HALO/Buzz design or a proof plan. Proposals never change authority
boundaries by implication.
Stars, list placement, freshness, and search rank are discovery signals only. A high-star repository is not automatically safer, more mature, adult-policy-compatible, or licensable.
Internal prior art and crossover
HALO model-facing evidence found
The “existing model-facing app” request changes the correct question. The repository and its deployed bundle do contain real creator-facing surfaces; the evidence does not yet prove a separate, complete model content-studio application.
| Surface | Read-only evidence | What the model can actually do | Honest boundary |
|---|---|---|---|
| Tokenized onboarding | repo/src/pages/CreatorOnboardForm.tsx:1-33; repo/src/components/onboarding/multi-step/MultiStepForm.tsx:1-100,121-370; repo/src/utils/onboardingUtils.ts:1-54; repo/convex/creatorInvitations.ts:1-145 | Open /onboarding-form/:token, validate a pending invitation, complete four tabs (personal info, physical attributes, preferences, content/services), submit structured data, and receive a content-guide download path after success. The submission mutation marks the invitation completed and stores a pending review record. | This is onboarding, not a content brief, asset workspace, review queue, or publish state machine. The alternate /onboard/:token implementation (repo/src/pages/CreatorOnboarding/CreatorInviteOnboarding.tsx:1-250) visibly contains placeholder tab copy, so it is not used as evidence of a richer portal. |
| Contract review/signing | repo/src/pages/ContractSigning.tsx:1-167; repo/src/App.tsx:150-193 | Open /contracts/sign/:token, read a contract, enter a confirmed name/date/drawn signature, submit the signature, and download a completed PDF after both parties sign. | Contract signing is meaningful rights-adjacent evidence, but the cited surface does not expose asset-level usage scope, channel, geography, duration, likeness/voice permission, derivative approval, or revocation. |
| Creator upload handoff | repo/src/pages/CreatorUpload.tsx:1-148; repo/src/App.tsx:169-193 | Open /upload/:id, select multiple files, and upload them to Supabase Storage bucket creator_files under ${creator.id}/unsorted/<safe-name>. The page shows a local success list and error toast. | The route is a thin handoff. The inspected code shows no visible token check, creator authentication, resumable transfer, quarantine record, checksum, MIME/policy decision, EXIF result, asset ID, work-item link, version, or approval. upsert: true means a repeated path can replace the stored object. This is a concrete hardening gap, not proof that no model surface exists. |
| Internal Model Profile | repo/src/pages/CreatorsData.tsx:1-45; repo/src/components/creators-data/CreatorDataModal.tsx:803-832,918-1062; repo/src/components/creators-data/ContentLimitations.tsx:1-92 | Staff can inspect structured model information, social handles, content/service fields, five visible limitation flags, announcements, and a creator calendar. | This is an internal staff profile with creator facts and a small limitations widget. It is not a creator-owned review/approval/export portal, and its mixed Supabase/Convex reads and writes need an authority decision before expansion. |
| Creator profile/contracts | repo/src/pages/CreatorProfile.tsx:1-122 | An Admin or creator-self view can render profile sections and a contracts card; the route redirects users without the expected permission. | The permission decision is a UI/session concern in this clone, not evidence of server-enforced content-rights authorization. No content work-item, version, publish, or reuse state is connected here. |
| AI voice | repo/src/pages/AIVoice.tsx:1-788; repo/convex/voice.ts:159-628; repo/convex/schema.ts:544-599 | Admin/Chatter users can upload a reference recording, clone or reuse an ElevenLabs voice, pick Normal/Flirty/Sad, enqueue TTS, inspect queue state, play/download output, and remove generated audio. | This is real AI-media prior art, but it is a voice job/provider queue, not an adult-creator consent registry. The inspected voice rows do not carry consent scope, expiry, revocation, likeness approval, source/derivative linkage, or a publish gate. |
| Tasks & Rewards | repo/src/pages/TasksRewards.tsx:1-187; repo/src/components/gamification/* | Staff/player surfaces support quests, evidence uploads, progress, supply-depot actions, and Admin preview. | This is useful internal work/progress prior art; it is not creator consent, content approval, or a substitute for a rights ledger. |
[FACT] Live deployment check. On 2026-08-29, read-only GET requests to the public HALO deployment returned 200 for the root, /upload/test, /onboarding-form/test, and /contracts/sign/test. The root HTML identified HALO Creator Management and loaded /assets/index-LD33amar.js. A read-only scan of that deployed bundle contained the route strings for /upload/:id, /onboarding-form/:token, /contracts/sign/:token, the Complete Your Creator Profile onboarding copy, and the AI-voice/upload code. SPA fallback means the 200 response alone is not route-level proof; the bundle strings plus the local source are the stronger evidence. No credentials, mutation, or live account action was used.
[CONCLUSION] HALO has an actual model-facing route set: onboarding, signing, and upload, plus a model-self profile path and staff-facing profile/voice surfaces. [UNRESOLVED CLAIM] The existence, URL, auth boundary, or current build identity of a dedicated model content app beyond these surfaces is still unverified. Therefore this report does not declare the dedicated app absent; it records the exact HALO evidence found and keeps the discovery/proof request open.
Protected Oracle prior art, verified at the routed read-only source
The Oracle repository was used only as protected read-only prior art. Its AGENTS.md and CLAUDE.md route the current Mac worker to Rust/Tauri, keep Electron scoped to the VPS engine and browser shell, and prohibit treating labels or historical proofs as current runtime procedure. No Oracle launch, credential use, live action, or edit was performed.
| Oracle fact | Direct source read | Content-lane implication |
|---|---|---|
| A single live cockpit orchestrates go-live, multi-platform state, readback, chat, stage, goal, and layout. | apps/oracle-streaming/oracle-worker/src/renderer/domains/webcam/cockpit/OnePageCockpitPage.tsx:1-105,230-620,620-770 (oracle-context calls it the single live cockpit); apps/oracle-streaming/oracle-worker/src/renderer/app/sectionRenderer.tsx:1-44 | A content studio can borrow the “one place for the next safe action” interaction idea, but its action must assemble or advance an approved content work item—not publish or alter creator rights implicitly. |
| Model navigation is a compact set of Live/History surfaces, while legacy Studio Controls, Cockpit Detail, Goal, Tip Menu, Tasks, and Live Feed are mapped into the surviving cockpit/settings structure. | apps/oracle-streaming/oracle-worker/src/renderer/app/sectionNavigation.ts:8-114 | Prefer a small creator-facing “Today / Assigned / Review / History” surface over a second sprawling admin application. This is a UX transfer hypothesis, not a claim that HALO should copy Oracle's screens. |
| Reactive Convex hydration is the live path with a polling fallback; the hook exposes the event window used by chat/tip panels. | apps/oracle-streaming/oracle-worker/src/renderer/domains/webcam/state/backend-sync/useControlPlaneHydration.ts:1-111 | The useful primitive is an explicit read/write adapter with degraded-state visibility. HALO still needs a content-specific server authority; shared Convex is not shared auth or shared tenancy. |
| The overlay renderer consumes active goals, tip-menu rows, and recent tips from local or hosted snapshots; the snapshot is signature-compared and backs off when unchanged. | apps/oracle-streaming/oracle-worker/src/renderer/domains/webcam/overlay/OverlayRoot.tsx:1-180 | Typed snapshot contracts, changed-only updates, and honest idle/degraded states transfer to creator progress/review feeds. Streaming goals/tips and OBS overlay transport do not transfer. |
| The model-assistant hook has one lifecycle, model-scoped local thread storage, fallback copy, a bounded context of recent public-room chat/tips/tasks, and explicit autonomy states. | apps/oracle-streaming/oracle-worker/src/renderer/domains/webcam/cockpit/panels/Orb/useModelAssistant.ts:1-220; apps/oracle-streaming/oracle-worker/src/renderer/domains/webcam/cockpit/panels/Orb/OracleThread.tsx:1-240 | A creator/content copilot could offer “what should I do next?” from grounded briefs, due work, review notes, and approved assets. It must never infer rights, invent a missing asset, or send/publish without a human-controlled boundary. |
| Goal progress is an explicit data model with an honest empty state, history, and re-segmentation rather than fake near-complete progress. | apps/oracle-streaming/oracle-worker/src/renderer/domains/webcam/cockpit/panels/GoalBar/GoalBar.tsx:1-220 | Creator-visible content progress should distinguish planned, in production, in review, approved, and published. Rewards/XP cannot stand in for consent or approval. |
| Key moments write structured evidence/marker rows and the renderer displays server labels. | apps/oracle-streaming/oracle-worker/src/renderer/domains/webcam/cockpit/panels/ChatRail/KeyMomentChatRail.tsx:1-150 | Content review comments, approval decisions, and delivery receipts should be event/row-shaped and auditable; Buzz may announce them by stable ID. |
| The proven ledger records real go-live/chat/tip proofs with explicit limits, current-proof decay, and safety boundaries; it also says proofs are evidence, not procedures. | apps/oracle-streaming/docs/PROVEN-LEDGER.html:16-26,64-73,115-161 | Transfer the proof discipline—named receipt, scope, limit, and fresh observation—rather than importing the live-stream implementation. |
Oracle crossover: transferable and non-transferable
| Pattern | Evidence status | Transfer to HALO/content | Hard non-transfer boundary |
|---|---|---|---|
| One-action cockpit | [FACT] Oracle's page owns one press-engine seam and the cockpit exposes the next live action. | [INFERENCE → PROPOSAL] “Prepare this approved package” could resolve the next missing brief, asset, reviewer, or delivery action in one bounded action. | Never turn a one-action affordance into auto-publish, silent creator approval, rights grant, or provider upload. |
| Typed event vocabulary | [FACT] Oracle normalizes chat/tip/goal/readback events and records key-moment evidence. | [PROPOSAL] Define brief.created, asset.ingested, version.submitted, review.comment_added, creator.approved, agency.approved, delivery.attempted, delivery.succeeded, rights.expired, and rights.revoked with stable IDs and timestamps. | Oracle platform event shapes, public-room chat, tip semantics, and live-session IDs are not content-rights records. |
| Truth-grounded progress | [FACT] Oracle's goal bar has an honest empty state and server-backed goal/tip snapshots. | [INFERENCE → PROPOSAL] Creator Today could show only assigned work, approved next actions, and evidence-backed completion. | XP, streaks, goals, or a green status cannot satisfy consent, contract, safety, or legal requirements. |
| Agent/copilot thread | [FACT] Oracle's useModelAssistant bounds context and supports local fallback/offline copy. | [PROPOSAL] Buzz/agent prompts can summarize a brief, identify the next review decision, or link the exact version needing attention. | No raw private media, credentials, hidden staff notes, or unscoped creator data should enter Buzz; the agent cannot become rights/publish authority. |
| Identity/media controls | [FACT] Oracle's safety ledger treats human presence, account scope, and platform identity as separate gates. | [INFERENCE] HALO should model creator identity, consent, media provenance, and staff authority as separate gates too. | Streaming transport, OBS/OME, browser partitions, platform credentials, and go-live account safety remain Oracle-only boundaries. |
| Proof-ledger discipline | [FACT] Oracle distinguishes code-proven, live-observed, decayed, and unrunnable proofs. | [PROPOSAL] Every content release should retain version ID, approvals, rights scope, provider receipt, delivery attempt, and platform receipt with evidence grade. | A screenshot, folder move, vendor badge, or agent statement cannot substitute for the underlying receipt. |
[FACT / BOUNDARY] Oracle's Tasks/Rewards-like progress, live cockpit, tips, overlays, and account-safety controls are not an OnlyFans messaging surface and do not solve creator consent, content rights, or asset lineage. [INFERENCE] The strongest crossover is the control-plane discipline and one-next-action UX; the weakest crossover is direct feature reuse.
What are we still missing?
The precise gap statement
[CONCLUSION] We are not missing “a model app” in the broad sense: HALO already exposes model-facing onboarding, contract signing, and upload, and a deployed bundle contains those routes. We are missing evidence and implementation of the connected, rights-aware content loop that turns those surfaces into a creator-safe operating system.
| Open item | What is proven now | What is still missing / how to prove it |
|---|---|---|
| Dedicated model content app identity | [FACT] Actual HALO model-facing routes and deployed bundle strings exist. [UNRESOLVED CLAIM] Dedicated app URL/build/auth is not identified. | Obtain the deployment/build identity or a read-only product walkthrough from the client; inspect its route map and auth boundary without credentials. Do not infer absence from HALO's current SPA. |
| Rights and consent registry | [FACT] Contract signing and five content-limit booleans exist. | Versioned consent grants with creator, participating people, asset/use scope, channel, geography, duration, likeness/voice, derivative permission, approver, expiry, revocation, and legal hold. Prove deny-by-default behavior on synthetic fixtures. |
| Brief/work-item authority | [FACT] Announcements, calendars, and customs metadata exist. | Link idea → brief → script/shot list → assignment → creator submission → version. A calendar date must not imply approval or readiness. |
| Asset identity and provenance | [FACT] Supabase upload and Drive index/used-folder operations exist. | Quarantine, stable asset/version IDs, checksum, perceptual-duplicate signal, MIME/dimension/duration, EXIF/GPS decision, uploader, source URI, parent lineage, provider/tool receipt, and export manifest. |
| Review and two-party approval | [FACT] Drive previews and customs attachments exist; vendor tools demonstrate review patterns. | Frame/timecode/region comments against immutable versions; separate creator approval from agency/compliance approval; lock approved package; retain changes-requested history. |
| Publishing and retry | [FACT] No content publishing adapter or delivery state was evidenced in the HALO route/schema map. | Package approved media/copy/price/disclosure per target; record idempotency key, attempt, platform response, retryability, re-auth/manual hold, and final platform ID. Keep Buzz out of execution authority. |
| Reuse, performance, takedown | [FACT] Creator analytics and Drive unused/used signals exist. | Link observations to a post/version, create fresh reuse decisions, find all derivatives on revocation, record takedown/export and retention/legal holds. “Used” must not mean “safe everywhere.” |
| Server-side authorization and tenant safety | [FACT] UI role labels and mixed Supabase/Convex helpers exist; the clone's architecture notes flag trust-boundary concerns. | Prove server-side creator/agency scopes, stable creator IDs, role separation, break-glass logging, secret isolation, and negative tests. UI hiding is not authorization. |
| AI provenance and voice/likeness controls | [FACT] ElevenLabs clone/TTS queue exists. [VENDOR CLAIM] ElevenLabs documents its own-voice verification and sharing rules. | HALO consent token, allowed use, expiry/revocation, provider/job/model version, prompt/reference lineage, human review, C2PA/watermark result, provider deletion, and publish block must be recorded. |
| OFM operator truth | [OPERATOR SELF-REPORT] Public workflow pages and community posts describe batching, approval bottlenecks, version confusion, handoff, and boundaries. | Conduct direct interviews with creators, content leads, editors, chatters, and publishers. Vendor pages and Reddit cannot establish the actual client's shift handoff, approval SLA, or private tooling. |
First-principles test
The content system is correct only if an authorized replacement operator can answer these five questions without opening raw private material or asking a side channel:
- What exactly is this asset/version, and where did it come from?
- What did this creator and any other participant consent to, for which channel and until when?
- Who approved this exact version, and what changed after approval?
- Which delivery attempt published it, to which account, and can the platform receipt be found?
- If consent expires or is revoked, which derivatives and published uses are held, removed,
exported, or legally retained?
[INFERENCE] HALO's present profile, Drive, customs, upload, and voice surfaces answer parts of question 1 and provide inputs to questions 2–4, but not the complete chain. That is why the right next product proof is a connected synthetic fixture loop, not a larger navigation menu.
Adjacent-market evidence
| Adjacent product / standard | Evidence observed | Decision for HALO |
|---|---|---|
| Frame.io V4 ↗ | [FACT from first-party docs] Supports single-frame, range, and anchored comments; its permissions documentation distinguishes account/resource roles and comment/view-only access. Its API migration/access docs are explicit about server-side integrations. | [PROPOSAL] Integrate or study as a review sidecar if adult-content, retention, export, and account policy pass a real trial. Do not make it the creator-rights authority. |
| Autodesk Flow Production Tracking ↗ | [VENDOR CLAIM / PRODUCT FACT] Autodesk describes tracking projects/shots/assets, tasks, reviews, approvals, feedback/version history, and integrations for VFX/animation/games. The official API ecosystem is visible in shotgunsoftware/python-api and tk-core, with license boundaries below. | Study the production data model; buy/integrate only for a materially more complex studio. It is a heavy VFX-shaped system, not a drop-in OFM creator portal. |
| Iconik ↗ | [VENDOR CLAIM] Iconik describes structured metadata, AI transcripts/object/face enrichment, hybrid storage, review/approval, automation, APIs, and publishing. | Strong MAM/DAM sidecar candidate, subject to adult-content policy, data residency, cost, deletion/export, API scope, and proof that metadata/rights can remain HALO-authoritative. |
| Cloudinary asset-management APIs ↗ | [FACT from first-party API docs] Upload/Admin APIs cover asset and metadata management; the Creative Approval API covers proofs, multiple review stages, reviewers, and status; Analyze API supports asset analysis. | Strong programmable bytes/metadata/approval adapter candidate. HALO must still own consent, creator approval, and release authority. |
| Planable approvals ↗ and API scheduling guide ↗ | [FACT from first-party docs] Planable describes idea→copy/design/account/approval, locking approved posts, multi-level approvals, client-facing links, campaign/calendar, and statuses around draft/scheduled/published/error. These are product capabilities, not proof of adult-policy support. | Good external-channel approval/scheduling comparator; use only behind an approved package adapter and a platform-policy/security trial. Do not put raw creator rights or source material there by default. |
| Filestage version comparison ↗ | [FACT from first-party docs] Version compare, comment/to-do behavior, approver/change-request history, timestamps, and review-report export are explicit. | Review-sidecar study/buy candidate; it does not replace HALO's brief, rights, asset lineage, or delivery ledger. |
| Bynder API ↗ | [FACT from first-party API docs] Bynder exposes assets, brands, collections, metadata fields, destinations, and OAuth access. | Enterprise DAM comparator; evaluate only if its tenant, policy, and export controls fit the agency. |
| ElevenLabs voice cloning docs ↗ | [VENDOR POLICY FACT] Its documentation says a Professional Voice Clone is limited to the speaker's own voice, even with consent; sharing is separately controlled and documented. | Treat ElevenLabs as a scoped provider. HALO must record creator consent and a provider-use token before any job; provider verification is not agency approval. |
| C2PA specification ↗ | [STANDARD FACT] C2PA defines signed claims/assertions/manifests and content bindings for tamper-evident provenance, with explicit privacy/control considerations. It does not judge whether a use is legally permitted. | Adopt as a provenance layer when supported by the selected media path. Do not mistake a valid manifest for creator consent or approval. |
Public/private/GitHub/operator reasoning
[PUBLIC VENDOR CLAIM] OFMLab describes a Drive-centered OFM agency loop with creator Today views, review inbox, approve/reject, recurring tasks, XP, and per-creator dashboards (public product page ↗). Empire of Agency describes a private CRM joining creators, managers, chatters, content, conversations, tasks, approvals, and reporting (public agency page ↗). AfterDark LAB presents an agency OS with content/fan/revenue operations (public product page ↗). These pages are valuable because they use domain vocabulary—Today, assignments, approval, publish, next decision—but they expose no independent tenant walkthrough, source code, audit export, or creator-consent proof in this campaign. Treat them as vendor/marketing claims until verified.
[PUBLIC OPERATOR/EDITORIAL CLAIM] A public OFM SOP guide describes scheduling, creator confirmation, briefs, raw submission, editing queue, technical/brand/compliance/creator gates, publishing confirmations, missed-window escalation, and rogue-publish checks (guide ↗). It is useful for a candidate state vocabulary, but its conversion benchmarks and timing targets are not accepted as HALO metrics.
[OPERATOR SELF-REPORT] An agency operator post says shared Drive comments, Notion, email, and generic project tools caused wrong-version confusion, while one review link, staged approval, separate client/internal views, named ownership, and visible stuck states helped (r/agency workflow post ↗). It is one self-report and vendor-adjacent, not a population estimate. Separate OnlyFans creator posts discuss batching shoots, scheduling, reuse, final upload QC, and the danger of selecting the wrong file; these are directional operator signals, not validated product requirements.
[ACADEMIC FACT] A qualitative study of 22 U.S. OnlyFans creators identifies boundary setting, privacy, and content archives as important platform affordances (Hamilton et al., 2022 ↗). A later USENIX Security study of 43 creators documents content leakage, stigma, platform precarity, watermarks, identity separation, and proactive safety practices (Soneji et al., USENIX Security 2024 ↗). These support the design priority of creator control and privacy; they do not prove the exact HALO workflow or a willingness to adopt any vendor.
[INFERENCE] Public information has abundant content-calendar/approval/DAM patterns and abundant AI generation demos, but little independently verifiable public evidence of a single OFM-specific system that joins creator rights, private adult media lineage, two-party approval, platform delivery, and takedown/export. The private-client evidence and direct interviews are therefore the highest-value next research, not another star-count sweep.
Search campaign and coverage receipt
Search date: 2026-08-29. Scope was read-only. No Convex mutation, seed/reset/migration, credential use, protected Oracle launch, commit, push, or deployment was performed.
Local corpus
| Corpus | Read-only source | Verified count | Use |
|---|---|---|---|
| Identity/repository cards | /Users/shaansisodia/SISO_Workspace/SISO_Agent_Base/research/repo-catalog/identity/identity.sqlite, table repo_card | 1,358,200 | Broad candidate generator with descriptions, language, stars, license field, branch, archive flag, and timestamps. |
| Curated GitHub catalog | /Users/shaansisodia/SISO_Workspace/SISO_Research/siso-foundry/pipelines/github/awesome/catalog_full.sqlite, table repo | 307,180 | Curated repository rows. |
| Curated placements | Same catalog, table entry | 652,851 | List-placement/repetition signal; not a quality verdict. |
The queries were intent-led across planning/production tracking, DAM/MAM, review and approval, publishing/retry, creator/talent operations, voice/likeness, provenance/C2PA, and adjacent operator vocabulary. Candidate names were then exact-matched in both databases to prevent a description-only hit from becoming a promoted repo. Selected local signals included:
| Candidate signal | Identity snapshot | Curated snapshot | Interpretation |
|---|---|---|---|
n8n-io/n8n | 199,194 stars | 75 placements | Broad automation; high discovery value, not content-rights authority. |
toeverything/AFFiNE | 71,128 stars | 32 placements | Planning/knowledge workspace; not media approval or rights. |
gitroomhq/postiz-app | 34,217 stars | 21 placements | Social scheduling/publishing; licensing and platform policy require review. |
myshell-ai/OpenVoice | 37,079 stars | 20 placements | Voice model/provider layer, not consent or workflow. |
RVC-Boss/GPT-SoVITS | 60,376 stars | 18 placements | Voice-cloning model layer, not creator rights. |
HKUDS/ViMax | 11,597 stars | 9 placements | Agentic video pipeline; human approval/rights remain external. |
OrangeViolin/content-pipeline | 207 stars | 4 placements | AI content-production skill; useful workflow vocabulary, not a server authority. |
eoyilmaz/stalker | 206 stars | 1 placement | Production asset data model; no graphical UI in the README. |
elonen/clapshot | 250 stars | not present in the exact curated subset | Self-hosted collaborative review; strong review pattern, GPL and operations burden. |
The corpus was used to generate candidates, not to award adoption rank. The current GitHub screen below is the authority for metadata and license handling.
GitHub search and verification method
Live gh search repos queries covered: digital asset management, video review approval, content operations, social media scheduler, production tracking, creator content, voice cloning consent, and content approval workflow. Search results were noisy—many were portfolio/demo repositories—so the promoted set was screened for a direct match to a content job before verification.
For every GitHub repository linked in this report, gh api repos/OWNER/NAME was run on 2026-08-29 and the following fields were recorded: full_name, html_url, stargazers_count, license.spdx_id, pushed_at, archived, and default_branch. For NOASSERTION, the root tree and license-like files were inspected with gh api; no SPDX label was invented. The individual results are in the verification ledger below.
Live-product and operator search
- Review/DAM: Frame.io V4 help, Autodesk Flow, Iconik, Cloudinary DAM APIs, Filestage,
and Bynder API docs. The search favored first-party docs for capability facts.
- AI/provenance: ElevenLabs voice-cloning/sharing docs and C2PA specification/standard
pages. These establish provider/standard boundaries, not HALO permission.
- OFM/operator: public OFM agency/product pages, the public SOP guide, practitioner posts,
OnlyFans creator discussions, and the 22-/43-creator academic studies. Vendor metrics and conversion claims were excluded from rankings; direct OFM interviews remain open.
- Search tooling note: the configured Perplexity
websearchcommand was unavailable because
OPENROUTER_API_KEY was not present. The built-in web reader and first-party URLs above were used instead. This did not block the required evidence pass.
Ranked full-system and live-product candidates
Rank means fit to the OFM content-control problem, not market size or stars. “Integrate” means sidecar/adaptor evaluation; it never transfers HALO's creator, rights, approval, or audit authority.
| Rank | Candidate | Exact job | Decision | Authority/data boundary | Evidence and confidence |
|---|---|---|---|---|---|
| 1 | HALO content control plane + specialist sidecars | Join creator/rights truth to brief, version, review, approval, delivery, reuse, and offboarding. | BUILD core; integrate sidecars | HALO owns stable IDs, rights, approvals, work state, audit, and delivery receipts. Sidecars own bytes, codecs, frame review, or provider execution only. | [INFERENCE/PROPOSAL] Best fit because it preserves the domain's non-transferable truth. High confidence in the boundary; implementation proof still open. |
| 2 | Iconik | Hybrid MAM, metadata/search, review, automation, and publishing-adjacent media operations. | BUY/integrate candidate; trial required | Iconik may own media indexing/preview; HALO owns creator permission and release decision. | [VENDOR CLAIM] Structured metadata, hybrid storage, APIs, review, AI enrichment, and publishing are documented on the product page. Medium confidence until adult-content policy, export, deletion, pricing, and API behavior are tested. |
| 3 | Frame.io V4 | Frame/timecode/region review, client/reviewer access, comments, version feedback. | BUY/integrate review sidecar | Frame.io is a review surface; HALO keeps rights, creator approval, and package lock. | [FACT from first-party docs] Exact-frame/range/anchored comments and granular roles are documented. High confidence for review; low confidence for OFM policy/rights fit until a controlled trial. |
| 4 | Cloudinary DAM | Upload, metadata, transformations, analysis, and multi-stage creative proofs. | BUY/integrate bytes + proof adapter | Cloudinary can store/transform/proof; HALO remains consent and publication authority. | [FACT from first-party API docs] Upload/Admin/Creative Approval/Analyze APIs are explicit. Medium-high capability fit; policy/retention and adult media need verification. |
| 5 | Planable | Social content drafting, approval, calendar, external review links, and channel scheduling. | BUY/integrate only for approved package delivery | Planable sees the minimum approved derivative and copy; HALO owns source/rights/version. | [FACT/VENDOR DOC] Lock-after-approval, approval levels, client/internal comments, campaigns and status flows are documented. Medium fit; channel coverage, adult policy, and publication receipts require proof. |
| 6 | Filestage | Review rounds, compare versions, comments, approvals, and exportable review reports. | BUY/study review | Review report is evidence linked back to HALO version; no rights or publish authority. | [FACT from first-party docs] Strong version/report semantics; narrower than a content operating system. Medium confidence. |
| 7 | Autodesk Flow Production Tracking | Production tracking for assets/shots/tasks, review, approval, and studio pipeline. | STUDY; buy only for high-complexity studio | Could track production objects; HALO still needs creator/rights adapter and adult policy. | [VENDOR CLAIM/PRODUCT FACT] Very strong adjacent production model, but VFX/games orientation and operational weight make it a poor first dependency. Medium confidence. |
| 8 | Bynder | Enterprise DAM, metadata, collections, destinations, OAuth/API. | STUDY/buy for scale | DAM sidecar only; consent and approval remain HALO. | [FACT from API docs] API shape is relevant; enterprise cost/policy/residency and rights semantics are unknown here. Medium-low confidence. |
| 9 | OFMLab | OFM-specific task/review/Drive/gamification workflow. | BUY candidate; private trial and evidence request | If used, it must not become the sole rights/audit authority without export/API proof. | [VENDOR CLAIM] Public page names review inbox, approvals, Drive sync, per-creator dashboards, and isolated workspaces. High domain vocabulary fit; low independent evidence. |
| 10 | Empire of Agency / AfterDark LAB | Public examples of private-agency command/workspace and creator operations language. | STUDY operator vocabulary; do not infer product availability | No authority transfer. | [VENDOR/AGENCY CLAIM] Useful public-private signal (plan→coordinate→execute→review; creator stays creator), but no independent product proof in this campaign. Low confidence. |
| 11 | ElevenLabs | Voice cloning/TTS provider already adjacent to HALO. | INTEGRATE provider adapter only | HALO consent token and use scope gate every job; provider verification is an additional check. | [VENDOR POLICY FACT] Own-voice PVC and sharing restrictions are documented. High confidence in adapter boundary; no confidence that provider policy alone meets client rights needs. |
| 12 | C2PA | Signed provenance manifests and content bindings. | INTEGRATE standard layer | Manifest records origin/edit assertions; HALO still decides allowed use and approval. | [STANDARD FACT] Strong provenance primitive, not a workflow or consent system. High confidence as optional evidence layer. |
Ranked verified GitHub candidates
The table is intentionally conservative. “Study” means extract a data/UX pattern in a clean fixture; “integrate” means a narrowly scoped adaptor after legal/security review; “build” means reimplement the domain contract inside HALO; “reject” means do not make it a dependency for this wave. Metadata is a 2026-08-29 gh api snapshot and may change.
| Rank | Repository (direct link) | Exact signal | Decision | API-verified metadata | Fit / duplication / Buzz boundary |
|---|---|---|---|---|---|
| 1 | Leon-bo-He/Orbit ↗ | Creator content operations: ideas, AI briefs, Kanban lifecycle, calendar, publishing records, analytics, JSON portability. | STUDY; build the rights-aware subset | MIT; 61 stars; pushed 2026-05-13T21:32:23Z; not archived; default master. | Closest public workflow shape, but README says collaboration/RBAC is planned and it is not adult-rights aware. Do not duplicate its whole app; extract state vocabulary. Buzz may link work-item IDs only. |
| 2 | arita-yuto/video-review ↗ | Timeline comments, frame drawing, Jira/Slack integration, self-hosted review hub. | STUDY/integrate narrow review pattern | MIT; 43 stars; pushed 2026-08-11T22:04:42Z; not archived; default main. | Direct review job; low evidence of rights/publish/asset authority. Keep review comments tied to HALO version IDs; Buzz announces decisions, not media mutation. |
| 3 | elonen/clapshot ↗ | Self-hosted video/media review, ingestion, synchronized playback, frame annotations, threaded comments, FFmpeg/thumbnailing, auth integrations. | STUDY; sidecar only | GPL-2.0; 265 stars; pushed 2026-08-12T03:46:46Z; not archived; default master. | Strong review/ingest pattern; GPL and Linux/network operation are material adoption friction. No creator consent/publish graph. Buzz gets typed review links only. |
| 4 | awslabs/visual-asset-management-system ↗ | AWS-native visual asset storage, search, versioning/lineage, REST/CLI, ABAC/RBAC, pipelines. | STUDY; integrate only if AWS sidecar is justified | Apache-2.0; 137 stars; pushed 2026-08-25T17:58:16Z; not archived; default main. | Good sovereignty/metadata/permissions reference, but specialized spatial/AWS architecture duplicates too much for HALO. No adult consent semantics. |
| 5 | daminikhq/daminik ↗ | DAM/CDN “single source of truth,” S3-compatible storage, EXIF-capable PHP app, workers. | STUDY DAM primitives | MIT; 292 stars; pushed 2026-07-27T08:17:47Z; not archived; default main. | Useful byte/metadata pattern; PHP/MySQL/S3 stack and no visible approval/rights model make direct adoption duplicative. |
| 6 | eoyilmaz/stalker ↗ | Production asset management library, project/tasks/milestones, asset references, customizable object model, PostgreSQL/SQLite. | STUDY data model | LGPL-3.0; 207 stars; pushed 2025-06-09T13:15:45Z; not archived; default develop. | Valuable production lineage vocabulary; README explicitly says no graphical UI and points to other applications. Not a content studio or creator portal. |
| 7 | gitroomhq/postiz-app ↗ | Agentic social scheduling, multi-platform publishing, public API/SDK. | INTEGRATE only after license/policy review | AGPL-3.0; 35,242 stars; pushed 2026-08-29T00:07:57Z; not archived; default main. | Useful publisher sidecar; AGPL and external platform account policies matter. It cannot decide whether a creator may be represented by a post. |
| 8 | brightbeanxyz/brightbean-studio ↗ | Self-hostable creator/agency social management: workspaces, RBAC, version history, approvals, retries, audit log, media library, client portal. | STUDY; possible sidecar only | AGPL-3.0; 2,214 stars; pushed 2026-08-13T09:13:17Z; not archived; default main. | Broadest publishing/approval comparator in the screened set; still generic social content and AGPL. Verify claims in code/trial before relying on them. |
| 9 | shoz496351/reelbase ↗ | Recent prototype claiming creator portal, tokenized upload, rights-aware library, deterministic candidate validation, AI strategist. | STUDY only; reject adoption this wave | NOASSERTION; 0 stars; pushed 2026-08-09T09:12:27Z; not archived; default main. | README is unusually close to the problem and explicitly calls itself a take-home prototype. Recursive tree inspection found no license-like path; no license source to rely on. The rights-before-model and invented-ID rejection ideas are worth fixture tests. |
| 10 | pavlohushuliak/my-influencer ↗ | UGC creator/brand matching, briefs, applications, content delivery/performance. | STUDY vocabulary; reject dependency | NOASSERTION; 21 stars; pushed 2025-10-24T22:58:42Z; not archived; default main. | Direct creator/brief signal but no verified license source (recursive tree contained no license-like path), no proven adult rights, and no evidence of production maturity. |
| 11 | OrangeViolin/content-pipeline ↗ | Claude Code skill claiming material→draft→layout→image→multi-platform distribution with human direction. | STUDY agent workflow; do not embed | MIT; 216 stars; pushed 2026-04-12T18:56:12Z; not archived; default main. | Good proposal for prompt-to-derivative orchestration; a skill is not a media/rights authority. Buzz can invoke a bounded proposal action after HALO supplies approved context. |
| 12 | QmiAI/Qmedia ↗ | Local multimodal content search/RAG for image/text/short video, with local deployment. | STUDY/search adapter | MIT; 633 stars; pushed 2026-04-09T05:48:58Z; not archived; default main. | Could help private discovery, but search must be rights-filtered before indexing and cannot grant reuse. |
| 13 | HKUDS/ViMax ↗ | Director/screenwriter/producer/generator agentic video pipeline, artifacts/storyboards/render checkpoints. | STUDY generation pipeline | MIT; 12,142 stars; pushed 2026-07-29T08:56:47Z; not archived; default main. | Strong generation/iteration analogy; README does not establish creator consent, adult safety, version approval, or delivery authority. Keep as a provider job behind HALO. |
| 14 | RVC-Boss/GPT-SoVITS ↗ | Few-shot TTS/voice conversion WebUI, training data and multilingual inference. | STUDY/provider adapter; no direct rights transfer | MIT; 61,311 stars; pushed 2026-08-18T09:16:25Z; not archived; default main. | Model capability only. Consent, likeness, provenance, deletion, and human release are HALO responsibilities. |
| 15 | myshell-ai/OpenVoice ↗ | Instant voice cloning, style control, cross-lingual generation. | STUDY/provider adapter | MIT; 37,348 stars; pushed 2025-04-19T16:00:00Z; not archived; default main. | Similar to GPT-SoVITS; useful comparative provider evidence, not a safe content workflow. |
| 16 | kukuhtw/ppv_stream_rust ↗ | Creator video upload/catalog, protected HLS, watermarking, access/payment ledger, storage workers. | STUDY delivery/protection | Apache-2.0; 61 stars; pushed 2026-06-21T09:02:35Z; not archived; default main. | Relevant to paid delivery and watermark language, but it is a creator commerce app, not agency approval/rights control; README itself says production hardening remains. |
| 17 | c2pa-org/specifications ↗ | Public C2PA provenance specification. | INTEGRATE standard, not app | CC-BY-4.0; 204 stars; pushed 2026-08-20T12:07:15Z; not archived; default main. | Use the standard/specification through a maintained library or provider. Do not treat the repo as a rights system. |
| 18 | shotgunsoftware/python-api ↗ | Official Autodesk Flow Production Tracking Python API. | STUDY/API comparator; legal review | NOASSERTION; 321 stars; pushed 2026-08-24T15:08:58Z; not archived; default master. | LICENSE was inspected: BSD-style redistribution text with Shotgun-specific attribution/disclaimer, but GitHub still reports NOASSERTION. Do not relicense or copy without review. |
| 19 | shotgunsoftware/tk-core ↗ | Official Flow Production Tracking Toolkit core API. | REJECT direct reuse; study boundary | NOASSERTION; 104 stars; pushed 2026-08-28T15:41:23Z; not archived; default master. | LICENSE was inspected and expressly limits use to eligible Shotgun/Flow customers and internal/non-commercial use. This is not a general OSS dependency. |
| 20 | Comfy-Org/ComfyUI ↗ | Node/graph-based generative media workflow UI. | REJECT as control plane; study provider seam | GPL-3.0; 130,515 stars; pushed 2026-08-29T06:47:39Z; not archived; default master. | Powerful generation graph, but no creator consent, version approval, delivery receipt, or OFM rights semantics. Keep generation behind HALO's job/approval boundary. |
Patterns worth rebuilding in HALO
These are ranked by domain value and safety, not by whether a repo can be copied:
- One review link per immutable version. The link should show only the approved scope,
exact version, comments, decision state, and expiry; internal notes remain private.
- Rights-first candidate filtering. Before AI search or sequencing sees an asset, a
deterministic service filters by creator, scope, channel, geography, expiry, revocation, participant releases, and legal hold. AI can interpret the brief only over permitted IDs.
- A real content state machine. Make
changes_requested,creator_approved,
agency_approved, retryable, needs_reauth, takedown_pending, and manual_hold first-class states rather than text labels.
- Two approvals, one version. Creator/participant consent and agency/compliance release
are separate decisions. Approval locks the package; edits create a new version.
- One work item, many channel records. Keep one brief and lineage graph, then separate
per-channel copy/media/settings/delivery attempts. A publisher cannot change the source asset or consent record.
- Content calendar as a projection. A date points at an approved package; it does not
promote raw footage or a draft to ready.
- Quarantine and provenance on ingest. Hash before dedup, preserve original lineage,
record EXIF/GPS policy, and create safe previews without treating a preview as the source.
- Creator Today view. Show assigned work, due dates, exact upload/review action, rejected
reason, and next step. Hide credentials, fees, internal notes, and unrelated fan data.
- Evidence-backed copilot. Offer concise brief summaries, missing-footage explanations,
and next-review prompts with source IDs. A missing candidate must be reported, not invented.
- Offboarding as a first-class journey. Export IDs/hashes/lineage/approvals/rights and
delivery receipts, revoke access/tokens, enumerate derivatives, and preserve legal holds.
Rejected famous or tempting options
| Temptation | Why it is rejected for authority | Safe use |
|---|---|---|
| Direct Google Drive folders as the workflow database | HALO's current Drive index knows unused/used files and coarse activity, but folder placement has no version, rights, approval, or delivery semantics; USED : POSTED is too coarse for reuse/revocation. | Keep as a byte/archive surface during migration; mirror every operation into HALO records. |
| Generic Notion/Trello/Asana/Monday board | Useful coordination, but public operator evidence specifically reports wrong-version and client-adoption problems; generic cards do not prove media lineage or creator consent. | Link to HALO IDs for non-sensitive planning if a team already uses one. |
| n8n ↗ as content authority | [FACT] Its README advertises broad AI/workflow automation; the inspected LICENSE.md is Sustainable Use and LICENSE_EE.md adds enterprise production restrictions. It has no domain-specific creator rights semantics. | Consider a narrow internal adapter only after legal review; never let a workflow node approve or publish by itself. |
| AFFiNE ↗ as content studio | [FACT] It provides a local-first docs/canvas/database workspace; root LICENSE says MIT outside backend/native, while backend/native licensing is separate. It is planning/knowledge infrastructure, not adult media provenance. | Study local-first notes/plan UX; no raw rights authority. |
| ComfyUI / ViMax / GPT-SoVITS / OpenVoice as a product | Models and graphs generate output; they do not establish who may be depicted/heard, for which use, until when, or who approved the derivative. | Provider adapters behind HALO consent/job/version/provenance gates. |
| Social schedulers as the source of truth | Postiz/BrightBean/Planable-like tools are strong at channel mechanics, but an external post status cannot explain creator consent or source lineage. | Deliver only a HALO-approved package and ingest the platform receipt. |
| OFM chat/DM tools as content control | Fan communication is a separate surface; it can originate a custom request but cannot authorize asset reuse or creator likeness. | Chatter links to a customs/request ID; HALO resolves approved deliverables. |
| Gamification as consent | Tasks, XP, streaks, and rewards can make creator work visible, but a completed quest is not a legal release or content approval. | Use progress as a voluntary creator-facing projection after rights checks. |
| AI/provider “safety” as agency approval | ElevenLabs verification, C2PA validation, or a model safety score is one control signal, not the client's rights decision. | Record the provider/standard result as evidence and still require human approval. |
Recommended HALO + Buzz composition
Ownership boundary
[PROPOSAL] Keep HALO as the content control plane and make every sidecar replaceable:
Creator / manager / producer
│
▼
HALO content control plane
creator + consent + contract scope
brief/work item + assignments + approvals
asset/version lineage + rights/expiry/revocation
delivery attempts + platform receipts + audit/export
│ typed adapters, stable IDs, idempotency keys
├── byte/DAM sidecar (Drive, Cloudinary, Iconik, or object store)
├── review sidecar (Frame.io, Filestage, Clapshot, or built review)
├── generation provider (ElevenLabs / image / video adapter)
└── publisher adapter (channel-specific, human-approved)
│
▼
Buzz = coordination/event surface
assignments, summaries, review links, escalation, callbacks
no raw authority over creator, rights, source bytes, money, or publish
Buzz remains fixed as block/buzz. It may receive review.requested, approval.recorded, delivery.failed, or rights.expiring events containing stable HALO IDs and a scoped summary. Its server-side adapter may call a bounded HALO tool such as “open this review” or “prepare a retryable delivery,” but it must not mutate a creator boundary or send a platform action from chat alone. The final publish action is a HALO/server-side adapter operation gated by the exact approved version, rights check, account scope, and idempotency key.
Minimal state contracts
[PROPOSAL] Keep work state, rights state, review state, and delivery state orthogonal:
work: idea → briefed → assigned → capture_due → ingesting → quarantined
→ editing → review → changes_requested → creator_approved
→ agency_approved → ready_to_publish → publishing → published
→ observed → reusable | archived
rights: pending | active | expiring | expired | revoked | legal_hold
review: not_started | technical_failed | changes_requested | creator_approved
| agency_approved | rejected | superseded
delivery: not_ready | queued | attempting | succeeded | retryable
| needs_reauth | rejected_by_platform | takedown_pending | manual_hold
The transition record must include actor, timestamp, prior/new state, reason, version ID, rights snapshot ID, and correlation/idempotency key. A sidecar callback can advance delivery only after verifying the package and scoped account; it cannot advance creator_approved or agency_approved.
Build/buy/integrate/study/reject ledger
| Capability | Default | Why |
|---|---|---|
| Creator/participant rights, consent, expiry, revocation | BUILD in HALO | Domain authority and client-specific boundary; no adjacent tool is a safe substitute. |
| Briefs, shot lists, assignments, custom-request links | BUILD in HALO | Must connect creator truth, promised deliverable, content class, and approvals. |
| Stable asset/version/lineage/provenance records | BUILD thin contract; buy/integrate bytes | Keep identity and lineage portable even if storage changes. |
| Raw bytes, transcoding, thumbnails, search index | INTEGRATE/buy | Cloudinary/Iconik/Drive/object storage may outperform a bespoke first version; policy and export are gates. |
| Frame/timecode review | BUY/integrate or build narrow | Frame.io/Filestage/Clapshot demonstrate mature review interactions; HALO owns version/decision linkage. |
| Creator-facing Today/upload/review/approve/export | BUILD thin HALO surface | Actual HALO model routes exist; make the next loop explicit without inventing a second app. |
| Social/channel publishing | INTEGRATE | Use Planable/Postiz/BrightBean-like adapters only for approved derivatives and receipts. |
| Voice/likeness/image/video generation | INTEGRATE providers | Keep provider/model/prompt/reference/version metadata and consent in HALO. |
| Provenance/content credentials | INTEGRATE C2PA-compatible layer | Useful tamper-evident evidence; not a legal/rights substitute. |
| Buzz collaboration and agent prompts | USE fixed Buzz adapter | Typed links, scoped summaries, assignments, and escalation only. |
| Generic workflow engines / broad AI agents | STUDY or narrowly integrate | They can execute a recipe, but must never become policy authority. |
Phased proof plan (synthetic data first)
No real adult media, real creator account, platform login, or Convex mutation is required for the first proof. The following is a future implementation/evaluation plan, not an action run in this campaign.
| Phase | Synthetic proof | Pass criteria |
|---|---|---|
| 0 | Create synthetic creator, participant, contract, rights scopes, expiry/revocation, brief, custom request, and staff roles. | Every record has stable IDs; default-deny query returns no asset without an active scope; UI role hiding is backed by server authorization tests. |
| 1 | Upload synthetic image/video/audio fixtures through an intake adapter. | Quarantine before preview; checksum and media facts recorded; EXIF/GPS outcome explicit; repeat upload is idempotent; original is never silently overwritten. |
| 2 | Produce edit versions and deliberately introduce duplicates, changed crops, and provider outputs. | Parent lineage is preserved; perceptual match is a review signal; every derivative has tool/provider/model/reference metadata; invented IDs are rejected. |
| 3 | Run technical, rights, creator, and agency review on exact versions. | Frame/timecode comments attach to a version; creator and agency decisions are separate; an approved package locks; any change creates a new version; expired/revoked rights block transition. |
| 4 | Send a synthetic approved package to a fake publisher returning success, timeout, duplicate, re-auth, and rejection outcomes. | Idempotency prevents duplicate delivery; retry/backoff and manual hold are visible; platform receipt links to package/version; Buzz receives an event but cannot publish. |
| 5 | Run voice/image/video provider fixtures with fake consent scopes and C2PA-like manifests. | Provider job is denied without the consent token; output carries provenance; revoke/expiry blocks reuse and schedules derivative enumeration; human approval is required. |
| 6 | Simulate creator offboarding, staff turnover, export, deletion, and legal hold. | Export manifest includes IDs/hashes/lineage/approvals/rights/delivery; access/tokens are revoked; held evidence is retained; removed derivatives are enumerated. |
| 7 | Run adversarial security and operational tests. | Cross-creator reads/writes fail; Buzz cannot call unscoped tools; stale callbacks cannot advance state; audit records are immutable; sidecar outage leaves HALO state explicit and recoverable. |
GitHub verification and license ledger
This is the compact receipt for every GitHub link in this report. Each row was checked with the GitHub REST repository endpoint on 2026-08-29. NOASSERTION means GitHub did not provide an SPDX assertion; the source inspection result is stated separately.
| Repository | gh api result | License-source inspection |
|---|---|---|
Leon-bo-He/Orbit | MIT · 61 · pushed 2026-05-13 · master · archived false | GitHub license metadata was MIT; README features were read as repository claims. |
arita-yuto/video-review | MIT · 43 · pushed 2026-08-11 · main · archived false | GitHub license metadata was MIT; README/demo feature claims were not treated as production proof. |
elonen/clapshot | GPL-2.0 · 265 · pushed 2026-08-12 · master · archived false | GitHub license metadata was GPL-2.0; README describes review/ingest/auth features. |
awslabs/visual-asset-management-system | Apache-2.0 · 137 · pushed 2026-08-25 · main · archived false | GitHub license metadata was Apache-2.0; README describes AWS-native versioning/ABAC/RBAC and warns to consult organizational security. |
daminikhq/daminik | MIT · 292 · pushed 2026-07-27 · main · archived false | GitHub license metadata was MIT; README describes DAM/CDN and S3-compatible storage. |
eoyilmaz/stalker | LGPL-3.0 · 207 · pushed 2025-06-09 · develop · archived false | GitHub license metadata was LGPL-3.0 and README carries an LGPL badge; README says it is a library without graphical UI. |
gitroomhq/postiz-app | AGPL-3.0 · 35,242 · pushed 2026-08-29 · main · archived false | GitHub license metadata was AGPL-3.0; README links its public API/SDK and social scheduling claims. |
brightbeanxyz/brightbean-studio | AGPL-3.0 · 2,214 · pushed 2026-08-13 · main · archived false | GitHub license metadata was AGPL-3.0; README claims approvals, retries, audit log, client portal, and social integrations. |
shoz496351/reelbase | NOASSERTION · 0 · pushed 2026-08-09 · main · archived false | Recursive tree inspection found no LICENSE, COPYING, or NOTICE-like path; README calls it a 96-hour prototype. No adoption license inferred. |
pavlohushuliak/my-influencer | NOASSERTION · 21 · pushed 2025-10-24 · main · archived false | Recursive tree inspection found no license-like path. No adoption license inferred. |
OrangeViolin/content-pipeline | MIT · 216 · pushed 2026-04-12 · main · archived false | GitHub license metadata was MIT; README identifies a Claude Code skill and self-reported workflow maturity. |
QmiAI/Qmedia | MIT · 633 · pushed 2026-04-09 · main · archived false | GitHub license metadata was MIT; README describes local multimodal search/RAG. |
HKUDS/ViMax | MIT · 12,142 · pushed 2026-07-29 · main · archived false | GitHub license metadata was MIT; README describes an agentic video generation pipeline and Web UI updates. |
RVC-Boss/GPT-SoVITS | MIT · 61,311 · pushed 2026-08-18 · main · archived false | GitHub license metadata was MIT; README describes zero-/few-shot TTS and voice conversion. |
myshell-ai/OpenVoice | MIT · 37,348 · pushed 2025-04-19 · main · archived false | GitHub license metadata was MIT; README says V1/V2 are MIT and describes voice cloning/style control. |
kukuhtw/ppv_stream_rust | Apache-2.0 · 61 · pushed 2026-06-21 · main · archived false | GitHub license metadata was Apache-2.0; README explicitly calls it a reference implementation requiring production hardening. |
c2pa-org/specifications | CC-BY-4.0 · 204 · pushed 2026-08-20 · main · archived false | GitHub license metadata was CC-BY-4.0; README says it contains the public C2PA specifications. |
shotgunsoftware/python-api | NOASSERTION · 321 · pushed 2026-08-24 · master · archived false | Root LICENSE was read via gh api: BSD-style redistribution/attribution/disclaimer text with Shotgun-specific terms. Because GitHub remains NOASSERTION, no SPDX label was assigned. |
shotgunsoftware/tk-core | NOASSERTION · 104 · pushed 2026-08-28 · master · archived false | Root LICENSE was read via gh api: customer-eligibility and internal/non-commercial Shotgun Toolkit terms, with no general OSS permission. Rejected for direct reuse. |
Comfy-Org/ComfyUI | GPL-3.0 · 130,515 · pushed 2026-08-29 · master · archived false | GitHub license metadata was GPL-3.0; treated as a generation graph, not a rights workflow. |
n8n-io/n8n | NOASSERTION · 202,751 · pushed 2026-08-29 · master · archived false | Root LICENSE.md was read: Sustainable Use License with internal/non-commercial limitations; LICENSE_EE.md was read: enterprise production-use license. No OSS adoption claim made. |
toeverything/AFFiNE | NOASSERTION · 71,986 · pushed 2026-08-28 · canary · archived false | Root LICENSE and LICENSE-MIT were read: MIT applies outside packages/backend and packages/common/native; those areas point to separate backend/native licensing. No single MIT label was inferred for the full repository. |
Negative findings and open questions
- Dedicated app: actual HALO model-facing routes are proven; a separate dedicated model
content app/build/auth boundary is still unresolved. Do not close this by saying “no model app exists.”
- Content state machine: no connected idea→brief→version→review→creator approval→agency
approval→publish/retry→performance/reuse chain was evidenced in the HALO route/schema map.
- Rights: current content-limit booleans, contract signing, and profile fields are not a
versioned consent/likeness/voice/channel/expiry/revocation registry.
- Drive: folder/index/
USED : POSTEDsignals are useful migration evidence, not durable
authority for lineage or safe reuse; live Drive operations need hardening.
- Publishing: no HALO content publishing adapter/receipt/retry state was evidenced. A
generic social scheduler cannot fill the rights gap.
- AI media: the ElevenLabs queue is real, but image/video generation, consent-scoped jobs,
provenance, provider deletion, and human release are open.
- Public evidence: vendor pages and community posts provide vocabulary and workflow
hypotheses; vendor metrics are untrusted; direct OFM interviews remain open.
- Platform policy: adult-content storage, AI likeness, privacy, retention, deletion, and
distribution policies must be checked per selected sidecar/provider. No product was promoted on a generic “supports video” claim alone.
- C2PA limit: a valid signed manifest can establish an edit/provenance assertion; it does
not establish consent, contract scope, or permission to publish.
- Buzz limit: Buzz may coordinate and surface evidence-linked decisions; it is not content,
rights, money, credential, or publish authority.
- Oracle limit: the protected Oracle cockpit is validated prior art for one-next-action UX,
event/control-plane discipline, goal/progress honesty, and proof receipts. Streaming, platform chat/tips, OBS/OME, account safety, and live credentials do not transfer.
Final recommendation
[PROPOSAL] Build the smallest HALO-native content control loop around the real surfaces that already exist: tokenized onboarding and contract evidence feed a creator/rights record; the existing upload route becomes a quarantine/intake handoff; customs and calendar become linked work-item inputs; Drive remains a storage adapter; the AI voice queue becomes the first provider job wrapped in consent/provenance gates; and Buzz exposes only typed, scoped coordination.
The first ship bar is not “AI makes content.” It is: a synthetic creator can see one assigned brief, submit one asset, receive a versioned review note, approve/reject the exact version, see the rights state, and produce one idempotent delivery receipt—with every denial, retry, expiry, revocation, and offboarding export provable. Only after that bar passes should HALO decide which specialist DAM/review/publishing provider earns an adapter.