Every source or generated public person has an explicit image-integrity state. Only identity-checked, reusable, locally served portraits are labeled verified.
Integrity rules
- A remote URL can never occupy the
local field. - Verified entries require source, author, reusable license, and local file.
- New v0.34 approvals also require a SHA-256 checksum.
- Ambiguous identity and incompatible licensing fail closed.
- Browser-time remote lookup is disabled; unresolved people show initials until the offline review workflow approves a local asset.
Report concerns through Corrections.