Direct implementation answer
Protect journalism by separating source identity from reporting content, minimizing metadata, securing administrative authority, binding vendors, creating emergency publication and archive continuity, distinguishing imminent operational harm from protected investigation, and measuring institutional readiness rather than tracking readers or sources.
Do not collapse different people into one surveillance category.
The same technology can create different risks depending on power, age, role, location, legal authority, and the consequences of disclosure.
KIT-JRN-POP-01Sources and whistleblowers
Consent, confidentiality, safe recontact, metadata, relatives, and the consequences of disclosure must be handled as separate risks rather than one generic source record.
KIT-JRN-POP-02Staff journalists and editors
Protect reporting, editorial judgment, labor activity, and disagreement from topic-based monitoring while maintaining accountable security and publication controls.
KIT-JRN-POP-03Freelancers, fixers, translators, and local partners
Do not shift the highest physical, legal, payment, or identity risks onto people with the least institutional protection.
KIT-JRN-POP-04Exile and diaspora media
Plan for transnational repression, family intimidation, cross-border legal uncertainty, payment interruption, and loss of hosting or identity services.
KIT-JRN-POP-05Readers and communities
Avoid reader dossiers and analytics that expose people seeking sensitive reporting, especially in restricted or conflict-affected environments.
KIT-JRN-POP-06Public-interest archives
Preserve provenance, chain of custody, correction history, multilingual relationships, and redundant custody without exposing protected contributors.
Controls must stay inside the context that justifies them.
KIT-JRN-CTX-01Reporting and research
Investigation of violent, extremist, criminal, military, or controversial subjects is not itself evidence of endorsement or intent.
KIT-JRN-CTX-02Publication and immediate danger
A narrow delay or redaction may be justified by concrete, time-sensitive danger to an identifiable person or operation; institutional embarrassment is not enough.
KIT-JRN-CTX-03Source protection and legal process
Promises, privilege, warrants, subpoenas, emergency demands, and cross-border duties require qualified local review and documented authority.
KIT-JRN-CTX-04Archive and correction
Preservation must retain authentic history while supporting corrections and preventing a revised public page from silently overwriting source evidence.
Name systems, protected activity, and credible failure paths.
Scope: Source intake, messaging, notes, raw evidence, drafts, editorial systems, AI transcription and translation, cloud collaboration, analytics, publication, archives, domains, DNS, hosting, application stores, payment, legal demands, device compromise, physical seizure, harassment, and cross-border operations.
Protected activity: Lawful investigation, source contact, adversarial research, editorial judgment, confidential drafting, criticism of powerful actors, multilingual publication, public-interest archiving, and access to independent reporting.
KIT-JRN-TH-01Worldwide principleSource identification through metadata
Contact channels, cloud logs, account recovery, document history, payment, location, and analytics can reveal a source even when message content is encrypted.
KIT-JRN-TH-02Technical recommendationAccount, device, and administrator compromise
Phishing, malware, spyware, device seizure, recovery abuse, and overbroad administrator access can expose sources, drafts, and publishing credentials.
KIT-JRN-TH-03Jurisdiction-specific legal questionLegal and informal coercion
Subpoenas, emergency requests, injunctions, licensing, regulatory threats, national-security claims, and informal pressure can bypass ordinary editorial independence.
KIT-JRN-TH-04Worldwide principleInfrastructure and financial chokepoints
A newsroom can lose reach through domain, DNS, hosting, cloud, app-store, identity-provider, advertising, payment, or crowdfunding termination.
KIT-JRN-TH-05Technical recommendationPlatform and search invisibility
Demotion, labeling, suspension, demonetization, false reporting, and citation exclusion can suppress lawful reporting without an explicit ban.
KIT-JRN-TH-06Worldwide principleTransnational repression and family pressure
Exile journalists and their relatives may face surveillance, threats, doxxing, travel pressure, financial coercion, and violence across borders.
KIT-JRN-TH-07Technical recommendationSynthetic evidence and provenance attacks
Deepfakes, altered documents, context stripping, impersonation, and provenance removal can corrupt reporting and discredit authentic evidence.
KIT-JRN-TH-08Worldwide principleArchive deletion and narrative replacement
Takedowns, account loss, automated moderation, censorship, compromised backups, or silent edits can erase records needed for history and accountability.
Build a rights-preserving floor before adding complexity.
These safeguards state the purpose that must survive local implementation. They are not a claim that every jurisdiction uses identical law or procedure.
KIT-JRN-SG-01Operational practiceDefine source states and authority
Record whether a source is anonymous, confidential, pseudonymous, attributable, embargoed, or on the record, who may change that state, and what consent actually covers.
KIT-JRN-SG-02Technical recommendationSeparate identity, content, and publication authority
Compartmentalize source identity, communications, notes, raw evidence, drafts, legal records, publishing credentials, translation files, analytics, and archives.
KIT-JRN-SG-03CognitiveLiberties.com policy proposalMinimize metadata and reader observation
Disable unnecessary analytics, session replay, cross-site tracking, detailed referrers, and identity-linked readership histories for sensitive reporting.
KIT-JRN-SG-04Technical recommendationUse strong authentication and recoverable custody
Use password managers, phishing-resistant authentication, separated administrator roles, protected recovery material, and tested emergency reassignment.
KIT-JRN-SG-05Worldwide principleProtect secure intake honestly
Describe what a channel can and cannot hide, provide safer alternatives, and do not call a channel anonymous when providers or metadata can identify the source.
KIT-JRN-SG-06Operational practiceBind cloud, AI, and collaboration vendors
Prohibit undisclosed model training, unrelated profiling, sale, and onward use; require subprocessors, retention, deletion, breach notice, export, and remedy.
KIT-JRN-SG-07Worldwide principlePreserve editorial independence
Document ownership, regulator, funder, advertiser, donor, platform, and government pressure while protecting good-faith editorial judgment and corrections.
KIT-JRN-SG-08CognitiveLiberties.com policy proposalDistinguish imminent operational harm from criticism
Require a defined person, operation, vulnerability, probability, time horizon, and least-restrictive mitigation before delaying or limiting publication.
KIT-JRN-SG-09Technical recommendationCreate redundant publication and domain continuity
Maintain independent domain and DNS custody, alternative hosting, exportable publishing systems, mirrors where lawful, and emergency communication channels.
KIT-JRN-SG-10Technical recommendationMaintain authenticated, distributed archives
Preserve source bytes, hashes, provenance, timestamps, corrections, translations, and independent custody across organizational failure.
KIT-JRN-SG-11Operational practiceProtect collaborators and wellbeing
Include freelancers, fixers, translators, photographers, local partners, and relatives in physical, legal, payment, mental-health, and relocation planning.
KIT-JRN-SG-12Worldwide principleProvide correction, appeal, and restoration
Create visible paths for sources, subjects, staff, and publishers to challenge errors, unauthorized disclosure, platform actions, or internal misuse.
Move from visibility to enforceable controls to durable resilience.
KIT-JRN-STAGE-30Map source risk and secure administrative control
Outcome: The newsroom knows where source identity and reporting content live, removes avoidable exposure, and can preserve publication authority through a basic incident.
KIT-JRN-ACT-30-01Operational practiceAssign accountable owners
Name owners for source protection, security, legal review, publication, archives, translation, payments, and staff safety.
KIT-JRN-ACT-30-02Technical recommendationMap sensitive systems and trust boundaries
Inventory intake, messaging, notes, cloud documents, email, AI tools, devices, accounts, admins, hosting, DNS, payments, analytics, and backups.
EvidenceCL-10-01KIT-JRN-ACT-30-03Technical recommendationSecure privileged accounts and recovery
Move critical accounts to phishing-resistant authentication, split custody, named recovery, and documented emergency succession.
EvidenceCL-41-04KIT-JRN-ACT-30-04Operational practicePublish source and correction boundaries
Explain confidentiality choices, channel limits, correction practices, urgent contact, and what the newsroom cannot promise.
KIT-JRN-STAGE-90Make source protection and continuity testable
Outcome: The newsroom has contractual controls, compartmentalized workflows, publication continuity, archive redundancy, and practiced legal and security response.
KIT-JRN-ACT-90-01Operational practiceCreate source-state and disclosure workflows
Document consent, safe recontact, authority changes, emergency exceptions, relatives, and final publication decisions without overcentralizing identities.
EvidenceCL-41-04KIT-JRN-ACT-90-02Operational practiceRewrite vendor and AI terms
Require no undisclosed training, no advertising, retention limits, subprocessor control, export, audit, incident notice, and verified deletion.
KIT-JRN-ACT-90-03Technical recommendationBuild and test emergency publication
Exercise loss of an account, device, host, domain, payment provider, or office and publish a signed test artifact through the fallback path.
KIT-JRN-ACT-90-04Operational practiceExercise a source-exposure incident
Use synthetic identities and documents to test containment, legal review, safe notice, credential rotation, correction, and family or collaborator support.
EvidenceCL-23-04
KIT-JRN-STAGE-365Build durable cross-border information resilience
Outcome: Editorial work, source protection, multilingual correction, financing, publication, and authenticated archives can survive coercion, termination, relocation, and organizational failure.
KIT-JRN-ACT-365-01CognitiveLiberties.com policy proposalEstablish independent governance and review
Create recurring source-protection, security, legal, editorial, accessibility, and conflict-of-interest review with authority to require correction.
EvidenceCL-41-04KIT-JRN-ACT-365-02Operational practiceDiversify infrastructure and revenue
Reduce dependence on one cloud, platform, identity provider, app store, advertiser, donor, payment processor, or jurisdiction.
KIT-JRN-ACT-365-03Technical recommendationBuild multilingual correction and provenance
Bind derivatives to controlling sources, record assistance, omissions, reviewer authority, hashes, and correction propagation.
KIT-JRN-ACT-365-04CognitiveLiberties.com policy proposalFund archive and exile continuity
Maintain authenticated copies, cross-border custody, staff relocation and succession, emergency grants, and knowledge transfer.
Do not buy a promise. Require inspectable evidence.
A policy statement is not proof of system behavior. Require architecture, configuration, tests, contracts, logs with bounded retention, deletion evidence, and a remedy when the provider is wrong.
KIT-JRN-PROC-01Operational practiceComplete data and metadata inventory
Require every content field, identifier, log, device signal, inferred risk, document history, location, and support copy to be named.
KIT-JRN-PROC-02Technical recommendationSource-confidentiality design evidence
Require architecture showing who can see source identity, content, metadata, recovery records, backups, and administrator actions.
KIT-JRN-PROC-03Technical recommendationEncryption and key custody
Require transport and storage encryption, key ownership, rotation, recovery, compelled-access behavior, and administrator separation.
KIT-JRN-PROC-04Technical recommendationRetention and verified deletion
Require deletion schedules and tests for messages, files, metadata, logs, AI prompts, embeddings, backups, exports, and subprocessors.
KIT-JRN-PROC-05CognitiveLiberties.com policy proposalNo advertising, sale, or source profiling
Prohibit use of reader, source, journalist, or editorial activity for advertising, sale, eligibility, reputation, or unrelated risk scoring.
KIT-JRN-PROC-06Operational practiceTraining and evaluation use
Require explicit authorization before source material, unpublished work, translations, recordings, or prompts enter model training or evaluation.
KIT-JRN-PROC-07Operational practiceSubprocessors and cross-border access
Require a current register, locations, purposes, legal exposure, notice, objection, export, and deletion for each subprocessor.
KIT-JRN-PROC-08Operational practiceModel and policy changes
Require notice and review before changes to moderation, transcription, translation, identity, retention, ranking, or safety behavior.
KIT-JRN-PROC-09Technical recommendationAccount and administrator controls
Require phishing-resistant authentication, role separation, logs, recovery authority, emergency succession, and revocation timing.
KIT-JRN-PROC-10Operational practiceIncident notification and disclosure process
Require notice deadlines, evidence preservation limits, government-demand handling, user notice where lawful, and post-incident assistance.
KIT-JRN-PROC-11Technical recommendationExport, portability, and continuity
Require usable export of content, media, metadata, access controls, translation relationships, corrections, subscriber records, and configuration.
KIT-JRN-PROC-12Operational practiceAccessibility and low-bandwidth alternatives
Require accessible intake, reading, correction, and emergency publication paths that do not force insecure workarounds.
KIT-JRN-PROC-13Operational practiceIndependent audit and transparency
Require security, privacy, moderation, deletion, provenance, availability, and government-request evidence open to qualified review.
KIT-JRN-PROC-14Operational practiceRemedy, exit, and secure destruction
Require correction, restoration, migration support, reasonable exit cost, secure destruction, and survival of confidentiality duties.
Good intentions can still create cognitive surveillance.
KIT-JRN-FAIL-01Technical recommendationCalling a channel anonymous without testing metadata
Encryption of content does not hide IP, account, device, payment, or cloud metadata.
KIT-JRN-FAIL-02Technical recommendationCentralizing every source identity
A single searchable source database creates catastrophic breach, insider, subpoena, and seizure risk.
KIT-JRN-FAIL-03Worldwide principleTreating controversial research as intent
Topic, query, contact, travel, or draft alone cannot establish endorsement, criminal purpose, or a credible threat.
KIT-JRN-FAIL-04CognitiveLiberties.com policy proposalConfusing provenance with mandatory identity
Authenticity signals can protect evidence, but compulsory creator identity can expose whistleblowers and excluded communities.
KIT-JRN-FAIL-05Operational practiceDepending on one platform or provider
A single host, identity provider, payment processor, domain registrar, or social platform can become an emergency kill switch.
KIT-JRN-FAIL-06Operational practiceShifting risk to freelancers and local partners
Institutional staff may be protected while fixers, translators, photographers, and relatives carry exposure without contracts, equipment, or support.
KIT-JRN-FAIL-07Worldwide principlePublishing silent corrections or overwriting evidence
Unversioned edits can destroy accountability and let a compromised editor replace the historical record.
KIT-JRN-FAIL-08CognitiveLiberties.com policy proposalMeasuring reach through reader dossiers
Detailed audience tracking can expose people seeking independent reporting and can become a map for repression.
Contain concrete harm without multiplying exposure.
KIT-JRN-IR-01Operational practiceProtect people in immediate danger
Prioritize a specific source, staff member, collaborator, relative, victim, or active operation; avoid broad disclosure.
EvidenceCL-23-04KIT-JRN-IR-02Worldwide principleClassify the event and evidence
Distinguish compromise, legal demand, physical threat, doxxing, synthetic media, platform action, payment loss, archive tampering, and protected reporting.
EvidenceCL-09-04KIT-JRN-IR-03Technical recommendationContain access and propagation
Revoke exposed credentials, isolate systems, pause unsafe synchronization, preserve publication continuity, and stop automated downstream decisions.
EvidenceCL-41-04KIT-JRN-IR-04Operational practicePreserve only necessary incident evidence
Retain a documented minimum for recovery, accountability, and lawful process without copying unrelated sources, readers, drafts, or communications.
EvidenceCL-10-01KIT-JRN-IR-05Operational practiceNotify affected people through safe channels
Coordinate timing, language, relocation, legal support, and family risk; do not repeat the exposure in the notice.
EvidenceCL-23-04KIT-JRN-IR-06Worldwide principleRequire independent editorial and legal review
Separate immediate operational containment from final publication, disclosure, takedown, or correction decisions.
EvidenceCL-26-04KIT-JRN-IR-07CognitiveLiberties.com policy proposalCorrect, restore, and support
Restore accounts and publication, correct records and translations, revoke exposed links, delete unsupported labels, and provide staff or source support.
EvidenceCL-07-04KIT-JRN-IR-08Operational practicePublish aggregate lessons without exposing protected work
Report cause, response, continuity, correction, and control changes while withholding identities and sensitive operational detail.
EvidenceCL-15-01
Make safeguards operational rather than ceremonial.
KIT-JRN-REV-01Operational practiceMonthly privileged-access and deletion review
Review administrators, recovery paths, dormant accounts, failed deletion, legal holds, and exceptional source records.
KIT-JRN-REV-02Operational practiceQuarterly source-protection exercise
Test intake, safe recontact, metadata, device loss, legal demand, and family or collaborator support with synthetic data.
KIT-JRN-REV-03Technical recommendationQuarterly publication-continuity exercise
Test domain, DNS, hosting, identity, payment, and distribution failure without risking live sources.
KIT-JRN-REV-04Operational practiceAnnual vendor, archive, and translation audit
Review training use, subprocessors, cross-border access, model changes, deletion, export, provenance, corrections, and restoration.
KIT-JRN-REV-05Worldwide principleImmediate review after threat or policy change
Reopen controls after a breach, coercive demand, attack, relocation, conflict escalation, new vendor, or material platform rule change.
A safeguard is incomplete when no one can reverse a mistake.
KIT-JRN-REM-01Operational practiceSource complaint and consent correction
Allow sources to report unauthorized attribution, unsafe contact, consent mismatch, or identity exposure through a protected route.
KIT-JRN-REM-02Worldwide principleSubject right of reply and factual correction
Provide a documented process for evidence submission, editorial review, correction, and explanation without compelled false balance.
KIT-JRN-REM-03Operational practiceInternal appeal for staff and collaborators
Provide independent review of security restrictions, retaliation, credit, payment, risk transfer, and access decisions.
KIT-JRN-REM-04Technical recommendationPlatform and infrastructure escalation
Maintain evidence packages, reason requests, appeal contacts, alternative distribution, and public transparency for suspension or demotion.
KIT-JRN-REM-05Technical recommendationCorrection across languages and archives
Propagate material corrections to derivatives, syndication partners, mirrors, feeds, archives, and structured records.
KIT-JRN-REM-06CognitiveLiberties.com policy proposalDownstream deletion of unsupported labels
Require vendors and internal systems to remove false source, threat, authenticity, or policy labels and their consequences.
KIT-JRN-REM-07CognitiveLiberties.com policy proposalMeaningful restoration and support
Restore publication, credentials, compensation, credit, services, and reasonable safety support where the organization caused avoidable harm.
Delete the cognitive trail when the authorized need ends.
KIT-JRN-DEL-01Technical recommendationSource intake metadata
Delete unnecessary IP, device, referrer, analytics, upload, and account metadata as soon as routing, security, and agreed recontact needs end.
KIT-JRN-DEL-02Operational practiceMessages and contact records
Use source-specific schedules and delete unnecessary copies, contact graphs, notifications, previews, and synchronized history.
KIT-JRN-DEL-03Operational practiceNotes, drafts, and document history
Retain only what reporting, accountability, archive, and legal needs justify; remove abandoned copies and uncontrolled histories.
KIT-JRN-DEL-04Technical recommendationAI transcription and translation artifacts
Delete prompts, audio, transcripts, embeddings, model caches, intermediate translations, and provider copies unless explicit authority supports retention.
KIT-JRN-DEL-05CognitiveLiberties.com policy proposalReader and audience data
Use aggregate, privacy-preserving measurement and delete person-level reading histories, detailed referrers, and inferred interests not required for service delivery.
KIT-JRN-DEL-06Technical recommendationSecurity and fraud logs
Apply short, risk-based retention; separate abuse indicators from editorial topics and delete resolved false positives.
KIT-JRN-DEL-07Jurisdiction-specific legal questionLegal holds and compelled preservation
Record authority, scope, notice limits, custodian, review date, and end condition; release unrelated and expired material promptly.
KIT-JRN-DEL-08Technical recommendationBackups and subprocessors
Propagate expiry and correction to backups, support systems, data lakes, collaboration tools, archives under newsroom control, and third parties.
KIT-JRN-DEL-09CognitiveLiberties.com policy proposalIdentity and risk labels after correction
Remove unsupported authenticity, source, threat, policy, or trust labels and correct every downstream use.
Measure systems, controls, response, and recovery—not what named people think.
No metric in this kit requires an identity-linked history of lawful questions, reading, research, beliefs, associations, or use of privacy tools.
KIT-JRN-OUT-01Operational practicePrivate source-intake availability
Percentage of editorial desks with tested, accessible intake choices and accurate channel limitations.
Measurement boundary: Measure channels and synthetic test transactions, not source identities.
KIT-JRN-OUT-02Technical recommendationDeletion assurance
Percentage of scheduled deletion and subprocessor deletion events completed and independently sampled on time.
Measurement boundary: Use test records and aggregate jobs rather than live source histories.
KIT-JRN-OUT-03Technical recommendationPrivileged-account protection
Percentage of publishing, domain, DNS, cloud, payment, and archive administrators using phishing-resistant authentication and separated recovery.
Measurement boundary: Measure account controls, not editorial activity.
KIT-JRN-OUT-04Operational practiceVendor-control coverage
Percentage of relevant contracts covering training, profiling, retention, deletion, subprocessors, incident notice, audit, remedy, and exit.
Measurement boundary: Measure contractual evidence without disclosing sources or readers.
KIT-JRN-OUT-05Operational practiceSource-state and consent completeness
Percentage of high-risk source relationships with an explicit current disclosure state, authority, safe-contact plan, and review date.
Measurement boundary: Count governance records; do not publish identities or reporting topics.
KIT-JRN-OUT-06Operational practiceAppeal and correction timing
Median time to acknowledge, decide, correct public and internal records, propagate translations, and restore access.
Measurement boundary: Publish aggregate process timing and categories.
KIT-JRN-OUT-07Technical recommendationInfrastructure continuity
Recovery time in exercises involving domain, DNS, hosting, identity, payment, or publication loss.
Measurement boundary: Use controlled exercises without live source material.
KIT-JRN-OUT-08Technical recommendationArchive integrity and recovery
Percentage of sampled artifacts whose hashes, provenance, correction history, and independent restoration validate.
Measurement boundary: Measure artifact integrity, not audience identity.
KIT-JRN-OUT-09Operational practiceMultilingual correction propagation
Percentage of material corrections reaching known derivatives and partners within the defined target.
Measurement boundary: Track publication objects and partners, not reader behavior.
KIT-JRN-OUT-10Operational practiceIncident containment and corrective action
Time to contain, notify, restore, and close verified corrective actions in synthetic or real incidents.
Measurement boundary: Report aggregate incident classes without exposing protected work.
Ask these questions locally before claiming compliance.
The worldwide baseline is a rights and architecture framework. Binding duties vary across constitutions, human-rights systems, privacy, consumer, education, press, labor, accessibility, cybersecurity, records, procurement, contracts, and court procedure.
KIT-JRN-LAW-01Jurisdiction-specific legal questionWhat source-protection and privilege rules apply?
Identify constitutional, statutory, common-law, professional, contractual, and procedural protections and their exceptions.
KIT-JRN-LAW-02Jurisdiction-specific legal questionWhat process governs compelled disclosure?
Determine warrants, subpoenas, production orders, emergency demands, secrecy orders, notice, standing, challenge, minimization, and appeal.
KIT-JRN-LAW-03Jurisdiction-specific legal questionWhat national-security and wartime limits apply?
Identify the exact legal authority, public-interest defenses, classified-information rules, operational-harm standards, and independent review.
KIT-JRN-LAW-04Jurisdiction-specific legal questionWhat privacy, data, and communications duties apply?
Map protection, localization, interception, retention, breach, cross-border, employee, freelancer, and reader rights.
KIT-JRN-LAW-05Jurisdiction-specific legal questionWhat defamation, correction, and right-of-reply rules apply?
Determine burdens, public-figure standards, deadlines, remedies, injunctions, anti-SLAPP protections, and correction obligations.
KIT-JRN-LAW-06Jurisdiction-specific legal questionWhat duties govern synthetic media and provenance?
Identify impersonation, election, evidentiary, privacy, copyright, labeling, and authentication rules without assuming provenance requires public identity.
KIT-JRN-LAW-07Jurisdiction-specific legal questionWhat employment and contractor protections exist?
Identify safety, retaliation, whistleblower, collective-bargaining, insurance, relocation, payment, and duty-of-care rules for staff and collaborators.
KIT-JRN-LAW-08Jurisdiction-specific legal questionWhat cross-border and exile risks require local counsel?
Map sanctions, immigration, extradition, data transfer, local-agent, licensing, registration, surveillance, and transnational-repression exposure.
Research, standards, law, technical guidance, and site proposals remain distinguishable.
The kit translates supplied reporting, exile-media, privacy, archive, platform, and due-process research into operational guidance. It does not establish journalist privilege, source immunity, legal compliance, physical safety, or the truth of a specific allegation in every jurisdiction.
Section-level evidence units
Current law, vendor behavior, system configuration, and local risk must be independently rechecked before deployment. The exact 64-report archive remains preserved separately from this implementation derivative.
What this kit does—and does not—require.
Does this kit require publishing information that would immediately endanger someone?
No. It supports narrow delay, redaction, or alternate handling where evidence shows concrete and time-sensitive danger to an identifiable person, active operation, victim, or system. It rejects vague safety labels as a substitute for that showing.
Can a newsroom promise complete anonymity?
Only when the whole path—including device, network, account, provider, metadata, payment, recovery, and internal access—has been evaluated. The kit requires accurate limitations rather than an absolute promise the architecture cannot keep.
Does content provenance require identifying every creator?
No. Provenance can authenticate an artifact or custody event while protecting the source. Mandatory public identity may expose whistleblowers and should not be treated as a universal condition of credibility.
How can a newsroom measure reach without tracking sensitive readers?
Use privacy-preserving aggregate measurement, voluntary feedback, public distribution statistics, synthetic availability checks, and infrastructure evidence rather than person-level reading histories.