Skip to content
Picdar

The picture desk, the archive and the rights behind them

Workflow

Business continuity for a newsroom that still has to publish

· Workflow

Most continuity plans are written for organisations that can pause. A newsroom cannot. The deadline does not move because the asset library is unreachable, and the story that made the systems fail is frequently the story that has to be…

That makes newsroom continuity a different discipline from ordinary disaster recovery. The question is not how quickly everything can be restored. It is what the minimum path to publication looks like when most of the stack is unavailable, and whether anybody has ever walked it.

Identify the minimum path

Write down the shortest sequence of steps by which a story gets from a reporter to a reader, using the fewest systems.

For most publications it comes to something like: text reaches an editor, an image is obtained and cleared, the two are assembled, and the result is published somewhere readers can reach. Four steps. Each depends on a system, and for each system there needs to be an answer to "what if not".

The exercise is more revealing than it sounds. Almost every newsroom discovers a dependency nobody had counted — a single authentication service, one person's access to the publishing platform, a template that lives on a machine under a desk.

Rank what actually has to survive

Not everything needs the same protection, and pretending otherwise produces a plan too expensive to implement.

Must survive an outage: the ability to publish text, the ability to reach readers, and access to the rights information for any image being considered. That third one is easy to omit and it is the one that produces a legal problem on top of an operational one.

Should survive within hours: the asset library's read access, the caption and credit records, the archive of what has already been published.

Can wait days: ingest workflows, full search, derivative generation, analytics, everything to do with the back catalogue.

Ranking honestly means accepting that some things will be down for a while. A plan that refuses to accept that protects nothing, because it never gets funded.

Publishing without the main platform

Decide in advance where you publish when the publishing system is unavailable, and make sure it is somewhere you control.

A static fallback page, on separate infrastructure, under a domain you own, that can be updated by more than one person with tools that do not depend on the primary stack. It does not need to be pretty. It needs to exist before it is needed, and somebody needs to have published to it at least once.

Relying on a third-party platform as the fallback is a common choice and a poor one. It puts your continuity plan inside somebody else's terms of service, and a platform outage and a newsroom outage are not independent events.

Images under degraded conditions

The picture problem during an outage is rights, not storage.

If the asset library is unreachable, the newsroom loses its record of what may be used. The temptation is to publish something found elsewhere and sort it out afterwards, which is how unlicensed images get published under exactly the circumstances that attract attention.

The mitigation is a small, current, locally-held set of cleared material: owned photographs, staff frames, generic imagery with permanent rights, and the publication's own graphics. Refreshed regularly, held somewhere that does not depend on the library, and documented so that whoever reaches for it knows what it covers.

Alongside it, a standing rule: during an outage, no image is published unless its rights are known from that cleared set or from a fresh, documented licence. A story can run without a picture. It cannot run with the wrong one.

Backups have to be tested by restoring

A backup that has never been restored is an assumption.

Test by actually restoring — to separate hardware, from the backup alone, with no access to the live system — and then check that the restored copy is usable rather than merely present. Metadata intact, relationships intact, permissions intact.

Keep at least one copy that is offline or otherwise immutable. Replication is not backup: it faithfully replicates a deletion, and it replicates an encryption event just as faithfully.

The people part

Systems fail predictably. Access fails personally.

Somebody has to be able to publish at three in the morning while the person who normally does it is unreachable. That means more than one holder of every critical credential, a contact list that exists on paper as well as in the systems that may be down, and a designated decision-maker for the calls that will have to be made quickly.

Write down who declares an incident, who talks to readers about it, and who decides that a story runs without its usual checks. Those decisions get made either way; the plan only determines whether they are made by the right person.

Rehearse it

A plan that has not been walked through is a document, not a capability.

Once or twice a year, publish something real through the fallback path. Not a simulation — an actual piece, actually published, using the actual fallback. It takes a morning and it finds the expired certificate, the credential that only one person holds, and the template that no longer renders.

Those things are always there. The only question is whether you find them during the rehearsal or during the incident.

Conclusion

Map the minimum path to publication, rank what must survive and accept what need not, hold a fallback publishing route on infrastructure you control, keep a small cleared image set outside the library, test backups by restoring them, spread the critical access across people, and rehearse the whole thing by publishing something real through it. The newsroom that can still publish a plain page with a cleared photograph has kept the thing that matters.

More in workflow

Section index