Consent-first, not compliance-after — every student photo carries its consent state
Every student photo in the system carries its parental consent state as part of the data layer — not as a spreadsheet column managed separately, but as a field the engine reads before any photo is displayed, included in a proof gallery, exported to a lab, or included in a yearbook layout. When a family revokes consent, the photo is immediately invisible: removed from the parent portal, removed from school admin views, excluded from any pending lab export. Revocation is atomic, not a request that clears in the next batch run. A studio can show a district the consent audit log for any photo session — who consented, when, what they consented to, and when any change was made — in a ledger the platform maintains, not in an email chain the studio reassembles under pressure. Consent is affirmative and per-use: a family that consents to yearbook use has not consented to digital download sales or event gallery sharing. Silence is never consent. The consent substrate is built and production-ready.
Consent substrate built · production-ready
Per-school commission ledger — rep assignment, projected split, studio earnings
A studio that runs dozens or hundreds of schools needs a real commission ledger, not a spreadsheet reconciled at year-end. The commission ledger tracks each school as a separate record: which rep is assigned to it, what the agreed commission structure is, what the projected split looks like before orders ship, and what the studio’s net looks like after the school fundraising leg is separated. A rep assigned to a school can see their pipeline for that school. A studio owner can see the full portfolio. The split engine applies three rules in order: processing and lab costs come off the gross first; the studio leg and the school fundraising leg are each a share of the net that remains; and the platform’s take is the residual left after those legs — earned on the same orders, computed last, not skimmed off the top. The studio leg and the school fundraising leg are maintained as separate ledger entries, never commingled. The commission ledger and split engine are built and production-ready. The charge rail that moves money — the live payout to the studio — is honest-off: present in the platform, not enabled for live transactions today.
Ledger + split engine built · live payouts honest-off
Multi-school branded parent stores — the studio’s name, not ours
Each school gets a parent store branded as the studio — the studio’s name, the studio’s color, the studio’s product catalog. A parent ordering prints from Lincoln Elementary sees the studio’s brand; they do not see the platform. The product catalog is studio-configured: wallets, portrait packages, digital downloads, and the options the studio actually offers, not a generic template list. The parent store substrate and catalog management are built and production-ready. The checkout interface is honest-off — it accepts no live payment from families today; present in the platform, not enabled for live transactions. There is no live storefront checkout in operation right now; we say so directly because studio owners need to know the difference between what is built and what is live.
Store substrate built · live checkout honest-off
Roster-driven capture, PSPA export, and lab fulfillment — the full workflow
The shoot workflow starts with the school roster: students are pre-loaded before picture day so the photographer matches a photo to a student record at the moment of capture, not in post. QR-code and barcode matching tie the photo to the correct student on the spot; unmatched photos surface as a red-flag list for the photographer to resolve before proof delivery. After the shoot, PSPA/SPOA export produces the delivery format labs and school systems expect. The PhotoLabProvider fulfillment seam handles order routing to the print lab: ship-to-photographer or direct-to-family. Retake management is built into the workflow: retake flags carry forward from the original session, and the studio sees which students are scheduled for a retake before the second day arrives. Roster-driven capture, PSPA export, retake management, and the PhotoLabProvider fulfillment seam are all built and production-ready.
Roster capture + PSPA export + fulfillment seam built
School admin portal — consent dashboard, delivery status, fundraising leg
The school admin portal gives a principal or yearbook coordinator a real-time picture of the session: consent coverage by homeroom (what percentage of students have a consent decision on file), delivery status (which photos are in proof, which are ordered, which are shipped), and the school’s fundraising leg from the split engine. A consent audit export is available for FERPA-aware record-keeping: a log of which student photos carry what consent state, when consent was recorded, and when any change occurred. The platform does not claim FERPA compliance as a certified badge — it says FERPA-aware architecture: every photo access is logged, consent state is tied to the student record, and the export is available on request. The admin portal and consent audit export are built and production-ready.
Admin portal + consent audit export built