# Evidence-Bound Feature Episodes

For a feature episode, lock a `feature-proof-episode` production plan before final render. The plan binds runtime to meaningful product actions and limits repeated visual families. Generate final evidence from the exact MP4 with the installed reference probe, then record it before final audit.

```bash
sdtk-marketing video project production <project-id> record --file production-plan.json
sdtk-marketing video project production <project-id> check --phase pre-render --json
node "$(npm root -g)/sdtk-marketing-kit/scripts/reference-production-probe.js" \
  --video /absolute/path/final.mp4 \
  --plan "$SDTK_MARKETING_HOME/video-projects/<project-id>/production/production-plan.json" \
  --out "$SDTK_MARKETING_HOME/video-projects/<project-id>/production/evidence/derived-production-evidence.json"
sdtk-marketing video project production <project-id> evidence \
  --file "$SDTK_MARKETING_HOME/video-projects/<project-id>/production/evidence/derived-production-evidence.json" \
  --render-sha "$(sha256sum /absolute/path/final.mp4 | awk '{print $1}')"
```

The evidence probe writes representative frames at product-action timestamps and compares product ROI motion against motion outside that ROI. Decorative background motion is not a meaningful product action.

# High-Quality Video Workflow

This optional path extends the existing renderer-neutral `video project` ledger. It does not
replace existing Remotion, ComfyUI, VHS, asset verification, or attended publishing.

## Local-only Provider Path

```bash
sdtk-marketing video provider doctor hyperframes --json
sdtk-marketing video project preview <project> --mode storyboard --port 4173 --dry-run
sdtk-marketing video preview <project> --mode timeline --port 4173 --tunnel
sdtk-marketing video project preview stop <project> --dry-run
sdtk-marketing video project snapshot <project> --provider hyperframes --scene SC01 --phase entry
sdtk-marketing video project check <project> --provider hyperframes --snapshots --json
```

The operator owns these delegates. Each must run locally, return JSON only, and never expose credentials:

- `SDTK_MARKETING_VIDEO_PROVIDER_HYPERFRAMES_DOCTOR_CMD`
- `SDTK_MARKETING_VIDEO_CMD_HYPERFRAMES_PREVIEW`
- `SDTK_MARKETING_VIDEO_CMD_HYPERFRAMES_PREVIEW_STOP`
- `SDTK_MARKETING_VIDEO_CMD_HYPERFRAMES_SNAPSHOT`
- `SDTK_MARKETING_VIDEO_CMD_HYPERFRAMES_CHECK`

Preview start must return a local URL, PID, session ID, and ownership token. Preview stop must echo
the exact session ID and ownership token. The toolkit never sends a kill signal itself.

`--tunnel` is an explicit owner-authorized request for an operator-owned Cloudflare Quick Tunnel. The core package never installs, downloads, or invokes `cloudflared`; it only accepts a receipt with an HTTPS `*.trycloudflare.com` URL, an owned PID, timestamp, and ownership token. The receipt is stored with the preview session and the project motion-map SHA. A normal preview must return no tunnel object. Stop must prove that the same owned tunnel stopped before its session can be removed. The feature does not publish, create a named hostname, or use Cloudflare account credentials.

Provider checks are bound to the locked motion-map SHA. They block blank or black media, overflow,
unapproved overlap/occlusion, unsafe title placement, caption collision, bad frame fit, unsafe area,
clipped wordmark, fake terminal, and unapproved adjacent duplicate motion treatment. `--snapshots`
requires entry, representative, and final frames for every declared scene.

## Media and Audio

Record `media-ledger` and `audio-plan`, then verify local bytes before a provider-path render:

```bash
sdtk-marketing video production verify <project> --json
```

This command performs no download, TTS, cloud lookup, or generation. Every local media file must
stay inside the project ledger and match its recorded SHA-256. Voiceover mode requires a local cue.

## LM Studio Scene Executor

The local executor is constrained to one locked scene at a time:

```bash
sdtk-marketing video agent doctor lmstudio --json
sdtk-marketing video scene task <project> <scene> --provider hyperframes --json
sdtk-marketing video scene execute <project> <scene> --model <allowlisted-local-model> --approve <task-sha>
```

Configure:

- `SDTK_MARKETING_VIDEO_LOCAL_MODELS`: comma-separated explicit local model IDs.
- `SDTK_MARKETING_VIDEO_AGENT_LMSTUDIO_DOCTOR_CMD`: a read-only local capability receipt.
- `SDTK_MARKETING_VIDEO_AGENT_LMSTUDIO_EXECUTE_CMD`: an operator-owned local executor receiving `{task}` and `{model}`.

The result binds the exact task SHA, uses an allowlisted model, and contains at most one structured
provider-source fragment. Shell commands, URLs, arbitrary paths, claim/CTA changes, owner decisions,
child dispatch, and publishing are rejected. A result still requires provider checks before render.

## GPU Lease Boundary

```bash
sdtk-marketing video render lease request <project> --provider hyperframes --out <operator-output-reference> --json
```

The portable package only records this request. An operator wrapper, maintained outside the package,
must persist local executor output, unload the local LLM, free renderer cache, run one approved render,
bank output and intermediate frames, then emit a redacted receipt. It must not publish, reload a model,
or create an accepted asset implicitly.

## Operator HyperFrames Delegates

The portable package does not install or manage HyperFrames. A local operator must provide the five runtime-only delegates documented in the Hermes plugin at docs/HIGH_QUALITY_HYPERFRAMES_PROVIDER.md. The provider doctor must report node, chrome, ffmpeg, and shm as available. shm is required because a container with the default 64 MB /dev/shm can pass superficial executable checks while Chrome preview/render fails later.

Snapshots are scene-bound only through provider/hyperframes/snapshot-times.json, which binds entry, representative, and final timestamps to the recorded motion-map SHA. This is intentionally explicit: the toolkit must not label an arbitrary global frame as evidence for a scene.
