How a Post House Proves Chain of Custody on a Pre-Release Screener Cut
High-profile clients want proof of who saw a pre-release cut and when before they will send it out. Here is how post houses build that chain of custody.
A studio legal team calls before they'll even confirm the screening slot, and the first question isn't about the cut itself, it's about who's going to see it, how, and what stops it from ending up somewhere it shouldn't. If you've ever handled a pre-release screener for a network drama, an unreleased trailer, or a film still months from its theatrical window, you know this conversation isn't optional, it's the gate you have to clear before the file ever leaves your building. And the uncomfortable truth for a lot of post houses is that when a high-profile client asks "prove that only these five people saw this cut, on these dates, and that nothing was downloaded," they don't actually have a clean answer, because the review process they've been running was built for internal notes, not for chain of custody.
Why This Is a Different Problem Than Ordinary Client Review
Most video review is about getting feedback fast, timestamped comments, quick turnarounds, easy sharing. Chain of custody flips the priority entirely, the goal isn't speed, it's control and proof. A studio or network client sending a pre-release cut out for review, whether that's for a test screening, a marketing partner, or an internal executive, needs to know exactly who accessed the file, from where, on what device, and whether it was ever possible for that person to download or forward it. This isn't paranoia, it's standard practice for anything with real leak risk attached, and the Sharing Security expectations on this kind of work look nothing like a typical client approval round.
It's about being able to prove, after the fact, exactly who had access and when, because "we trust our reviewers" isn't an answer that satisfies a legal team.
What Chain of Custody Actually Requires in Practice
Break it down and there are really four pieces a post house needs to nail. First, identity, you need to know it was actually the intended reviewer who watched the cut, not someone using a shared link. Second, a visible deterrent, forensic or visible watermarking tied to that specific viewer so if a clip does leak, you can trace it back to the exact access session. Third, a full access log, every view, every timestamp, every IP or device where reasonably available. Fourth, an expiration, because access that never ends is access that eventually gets forgotten about and left open indefinitely.
The Watermarking Question Everyone Gets Wrong First
A lot of teams think watermarking alone solves this, slap a burned-in code on the corner of the frame and call it done. It helps, but it's only one layer. A visible watermark deters casual screen recording, but it doesn't tell you who actually opened the file at 2am from an unfamiliar location, and it definitely doesn't stop someone from screen-recording around it if they're motivated enough. The stronger approach pairs watermarking, ideally dynamic and tied to the individual viewer's name or email so it's traceable per person, with an access log that's just as detailed. If a clip does leak, the watermark tells you whose copy it was, and the access log tells you the full story of how they got it and when, which matters enormously if you ever need to demonstrate to a client that the leak happened outside your process rather than because of a hole in it. Some studios go a step further and use frame-level forensic watermarking, the kind of technology vendors like NexGuard or Vobile provide, where the mark is invisible to the eye but recoverable even from a low-quality re-recording, which matters because a determined leaker filming a screen with a phone will defeat almost any visible watermark within seconds of basic editing.
That last step matters more than people expect. The access log isn't just useful in the moment, it becomes part of the permanent record of that project, the same way we talk about keeping the full approval trail intact in archiving a finished project without losing the approval trail. If a dispute or a leak investigation surfaces months later, you want that log sitting somewhere retrievable, not gone because the review link expired and took the history with it.
What Happens When You Can't Produce the Record
Here's the scenario that should worry every post house handling this kind of work: a clip from an unreleased cut surfaces online, the client calls asking for the access log to help trace where it came from, and you've got nothing, because the tool you used for review didn't keep detailed logs, or worse, the sharing was done through a generic file transfer service that never tracked individual access at all. At that point you're not just losing this client, you're the studio that can't be trusted with sensitive material, and word travels fast in an industry where reputation among a handful of major clients is basically the whole business. We've heard this exact fear from post houses who do broadcast and studio work regularly, that one loose screener process could undo years of relationship-building with a client who has plenty of other vendors to choose from.
We've also heard the reverse version of this scenario, where a post house could prove exactly who had access, and it turned out the leak traced back to a legitimate reviewer's device that had simply been left logged in on a shared family computer, no malice involved, just a screening session nobody thought to close. In that case the studio's reputation actually held up, because the access log let everyone see clearly that the process itself hadn't failed, one specific access point had, and that's a very different conversation to have with a client than "we don't know what happened."
A leaked screener is bad. A leaked screener you can't explain is the kind of bad that ends a client relationship for good.
How PlayPause Handles Sensitive Screener Access
This is exactly the kind of use case we built the tighter end of PlayPause's sharing controls around. Reviewers get individually verified access rather than an open link, viewing sessions get logged with timestamps, and Expiring Share Links mean a screener doesn't sit accessible forever just because someone forgot to revoke it after the review window closed. Because the access log lives in the same workspace as the review itself, you're not stitching together data from three different tools to answer a client's question, it's one export away.
Generic file transfer link, no per-viewer tracking, no real proof of what accessed what
Named viewer access, timestamped logs, watermarking, and expiration built into the same review workspace
Who Actually Needs This Level of Control
Not every project warrants full chain-of-custody treatment, and applying it everywhere just slows down routine review work for no reason. This is really about matching the control level to the actual risk. A rough cut going to an internal producer for notes doesn't need forensic watermarking, but a marketing partner getting early access to a trailer before a public embargo lifts absolutely does, and so does anything heading to press, festival programmers, or awards voters ahead of a public release. Broadcast News packages carry a similar sensitivity when a story hasn't aired yet and a competing outlet could scoop it from a leak. The judgment call is knowing which projects sit in that higher-risk category before the client has to spell it out for you, because by the time they're asking, they're already wondering whether you'd have thought of it yourself.
- Reviewer list is named and verified, never an open link
- Watermark is tied to the individual, not generic to the project
- Access window has a defined start and hard expiration
- Every view is logged with a timestamp, exportable on request
- The log itself is retained after the review window closes, not deleted with it
Where This Overlaps With Delivery-Spec Pressure
High-security screeners often show up at the exact moment a project is already under pressure from something else, a platform change, a rushed turnaround, a client escalation. If your studio is also navigating shifting delivery requirements mid-project, it's worth a look at what to do when a streaming platform changes delivery specs mid-project, because the two problems tend to compound when they land in the same week, tighter security expectations on top of a moving technical target.
How Long to Keep the Access Log Once the Screening Window Closes
A question we hear constantly once a studio has the logging piece figured out is how long to actually hold onto that record after the review window itself has closed. The honest answer is longer than most teams initially assume, because the risk period for a leak surfacing isn't limited to the days the screener was actively accessible, a clip recorded during a legitimate viewing session can resurface months later, sometimes timed deliberately to land right before a premiere or an awards announcement when it does the most damage. We tell studios to treat the access log with the same retention discipline as the rest of a project's approval history rather than letting it expire with the share link, the same principle behind archiving a finished project's sign-off trail, just applied to a narrower and more sensitive slice of the record.
The Cost of Treating This as an Afterthought
We've seen the alternative play out, and it's rarely dramatic in the moment, that's what makes it dangerous. A producer sends a screener through whatever tool is fastest because the deadline is tight and nobody wants to slow things down for a "quick internal check." Three weeks later a clip surfaces on a fan forum before the official announcement, the client's legal and PR teams both get involved, and the studio is now spending days reconstructing who might have had access instead of pointing to a clean log that already answers the question. The time you save skipping proper access controls on the front end gets paid back with heavy interest the moment something actually goes wrong, and by then it's the client's trust on the line, not just your afternoon.
Making This a Standard Part of How You Quote Sensitive Work
The studios that handle this best don't scramble to figure out chain of custody after a client asks for it, they build it into how they quote and scope sensitive projects from the start. If a job involves an unreleased trailer or a screener for a high-profile client, the access controls, watermarking, and logging requirements get built into the review setup before the first cut ever goes out, not retrofitted after a legal team raises a red flag. It's a genuinely small amount of upfront setup, maybe fifteen minutes configuring reviewer access and expiration windows, compared to the alternative of trying to explain after the fact why you can't answer a basic question about who saw a file. As the Motion Picture Editors Guild has noted in discussions of post-production security practices, the studios that consistently win repeat high-profile work are the ones treating access control as a baseline expectation rather than a special request.
Prove Custody Before a Client Ever Has to Ask
If your current sharing setup can't answer "who saw this, when, and how" in under a minute, you're carrying more risk than you probably realize on your most sensitive work. PlayPause builds named access, watermarking, and full view logs into the same workspace you're already using for review, so proving chain of custody doesn't mean assembling records from three different places under pressure. Look at PlayPause vs Wetransfer if you're still sending sensitive cuts through a generic file transfer tool, and see what a purpose-built review workspace actually protects you against.
Neha Sharma writes about content and collaboration for PlayPause. She focuses on feedback loops, remote review, and how distributed teams keep everyone aligned on the latest cut.
Related resources
Keep reading
Bring your team into one review space
Centralize feedback, lock approvals, and deliver faster, start free today.
Sign Up for Free