Skip to content
Inkstand

for in-house teams

Your markets can only make your rules stricter

One brand team sets what has to hold everywhere. Every market and product line inherits it, may sharpen it locally, and cannot remove it or drop it to advisory. And the agency you hired works inside your account, on the brands you granted them, reaching nothing else in the company.

This page is for a company running its own brands — markets, product lines, therapy areas.

Running brands for clients instead? →

Consistency across markets and product lines

Set once at the top, and it only ever gets stricter on the way down

Four levels, and each one inherits from the level above it. A workspace is a brand — a market, a product line, a therapy area — so the thing an agency uses to keep fifteen clients apart is the thing you use to keep eleven markets aligned.

A level below can always add a rule and always tighten one. It can never delete or weaken what it inherited — and an attempt is reported at the moment it is made, not silently undone.

Which levels set what, and exactly what a level below may do →

What a narrower level may do to a rule it inherited

The direction is the whole contract, and a direction is the one thing a sentence is worst at. So: four things a market or a campaign can try, and the four answers. Both hops are the same fold handed one more level, so the contract does not change on the way down.

Allowed

It adds a rule of its own

A market’s rule applies to that brand and to every campaign inside it. A campaign’s applies to that launch and no other.

Allowed

It raises an inherited rule from advisory to blocking

Stored as an override carrying the rule’s id and the harder severity — never a copy of the rule, so the wording above keeps tracking the level that set it.

Refused

It rewords an inherited rule

A collision on the same rule id keeps the definition from above — statement, pattern, replacement wording, the lot. A market cannot restate a global rule in words of its own while appearing to obey it.

Refused

It removes one, or drops it from blocking to advisory

The attempt is named — removed or downgraded, rule by rule — and reported back rather than silently undone, so nobody finds out at export.

And the rules are not only about words

A market that writes perfectly and posts in the wrong red is still off-brand. Five visual checks, each set on the brand and each running in the same audit as the words, so a deck comes back as one list of what is wrong with it rather than two.

CheckWhat it compares
Approved paletteEvery background colour an author chose directly, against the brand’s named swatches. A colour that is not approved is reported with the closest one that is, by name.
Approved colourwaysThe colourway the deck is set in, against the list the brand allows.
Approved typeface pairingsThe pairing the deck is set in, against the list the brand allows.
Contrast floorText against the ground it sits on, measured frame by frame, against the ratio the brand set.
The markWhether the brand’s logo is present at all, where the brand requires one.
  • Advisory until you say otherwise

    Visual rules arrive set to advise. A brand kit gains its palette long after the decks do, and a kit that starts refusing releases the moment somebody describes their brand teaches people that describing their brand is punished. An account that wants an off-palette colour to block a release sets that deliberately, and by then it means it.

  • A colour that cannot be measured is not a colour that passed

    Where the checker cannot parse the two colours it is comparing, the contrast rule comes back steered — in force, and nothing inspected it — with the counter of what still needs a person including it. It is the same tier, meaning the same thing, as everywhere else in the product.

  • An embargo cannot outlive its launch

    A campaign’s rules are folded onto the kit while one of its posts is open and taken back off before anything is written, so an embargo written for the Q3 launch cannot copy itself into the brand — where it would apply to every other campaign and could no longer be lifted by ending the one it was for.

  • And an edit to one is reported, not swallowed

    The brand kit screen cannot tell a campaign’s rule from a brand’s. Editing one there is correctly refused at the brand level and correctly named, rather than quietly coming back on the next load with nobody told.

  • Context accumulates too

    The writer is handed the account’s standards, then the brand’s story, then the campaign’s brief, each under its own heading and ordered widest to narrowest. They stack rather than overriding one another.

  • Sources belong to the brand

    The domains a claim is checked against — investor relations, the newsroom — are a property of the company, not of a campaign, so they sit on the brand and are entered once. Claim research is restricted to that allowlist rather than the open web.

  • A rule that knows which markets it is for

    One of the nine rule kinds carries the list of markets a phrase is restricted in, and names them back in the finding. Code sweeps for the phrase; only the review pass can clear the rule, and every finding says which of the two it came from.

  • Where the markets are recorded

    Alongside the brand’s sources, next to the ticker and the legal entity, because a market list that lives in a campaign gets re-entered for every launch and answers differently depending on which one you are in.

The review cycle

Sign-off is attached to the words, not to a status field

Medical, legal and regulatory review in pharma. Compliance sign-off before publication in financial services. Whatever it is called in your company, the failure mode is the same one: somebody edits a headline after the reviewers said yes, and the status still says approved.

Here an approval is bound to a fingerprint of the exact content that was reviewed, so the question anyone actually cares about — was this content approved? — stays answerable after the content moves.

What the bar saysWhen
Not yet approvedNo approval has been recorded against this post.
ApprovedThe fingerprint of the words on screen matches the fingerprint that was signed off. The bar names the approver and the date.
Edited since approval — needs re-approvalThe two fingerprints differ. Nobody has to notice and nobody has to revoke anything: the comparison runs on every render, so there is no window in which the screen says approved about words that have changed.
Approval expired — needs re-approvalThe approval carried an expiry date and it has passed. Seasonal and regulatory claims should not be approved forever.
  • What the fingerprint covers

    Every frame’s headline, body, list items, caption, statistic, sign-off line and call to action; the images placed on it; its layout and composition; and the post caption underneath. That is what a reviewer read.

  • What it deliberately does not

    Editor-local position state. Nudging a text box two pixels does not void an approval, because a signal that fires on things nobody reviewed is a signal people learn to ignore.

  • Who it names

    The approver is written by the database from the authenticated caller rather than sent by the browser, so an approval cannot be recorded on somebody else’s behalf. Withdrawing one clears the name with it.

  • An ordinary edit does not restamp it

    Editing a headline leaves the original approval’s date and attribution exactly where they were, and marks the state stale. It does not quietly reattribute the approval to whoever typed last.

Read what the release record keeps, and how a finding is tiered: governance.

The party outside your rules is the agency

For an agency the outsider is the client. For you it is the agency.

An agency buys this to keep fifteen clients apart. You are buying the same mechanism pointed the other way. Your roster agency needs to work in two of your brands; it does not need the rest of your company, your unlaunched product lines, or the markets it does not hold.

The fourth seat is exactly that shape. Limited says somebody belongs to your account and nothing more: no account-wide reach at all, and their reach is the list of brands you granted them, one at a time. The other three seats — owner, editor, viewer — each reach every brand in the account, which is why none of them is the right one to hand outside.

A limited seat holding a grant on one brandIn that brandAnywhere else in your account
See the brand exists at allyesno
Read its posts, its campaigns and its uploaded imagesyesno
Create and edit postsyesno
Upload images into ityesno
Rename the brandyesno
Set or tighten the rules on the brandyesno
Delete the brandnono
Change the account rules they work undernono
See who else is in the account, or invite anyonenono
Read the account-wide overviewnono

Every yes and every no in that table is an assertion in the isolation suite, run against the real database rather than a mock. A button that is not rendered is a courtesy; the policy is the control. How isolation is asserted.

  • Bound by your rules, not theirs

    A limited seat is inside your account, so the rules you set at account level apply to everything they make. They may tighten the regime on the brand they were hired for, and the guarded function refuses them the account rules outright.

  • Granted with the invitation

    The brands and the level of access are chosen when the invitation is written, so the grant lands the moment the seat is accepted rather than in a second pass afterwards.

  • An agency that also works for your competitor

    They hold a separate seat in each company’s account and switch between them. Switching account changes the governance regime entirely — different rules, different colleagues, different audit trail.

  • Nothing can be carried across

    Somebody holding a seat in two accounts — the ordinary position of an outside consultant — cannot move a brand, a campaign or a post from one account into the other. Reaching across and carrying across are different questions, and both are asserted.

The people who approve are not seats

A review link reaches one post, expires, and needs no account

The reviewers in a regulated company are the people least likely to want another login and most likely to be asked for one. So they are not given a seat: they are sent a link, and the link is the whole of the authorisation.

1post
A link is minted against one carousel and resolves to that one. It is not a door into the brand, the campaign, or anything else in the account.
0seats
It opens with no account and no sign-in. A review board of twelve people who each touch the tool four times a year costs nothing in licences.
90days, at most
The database clamps whatever lifetime is asked for to between one and ninety days. Fourteen is the default. There is no never.
  • Revocable, and revocation wins

    A link can be cut off at any moment. One that was revoked and then also ran out of time still reads as revoked, because showing “expired” would describe a deliberate act as the calendar doing its work.

  • It carries a yes, not only an objection

    A reviewer who can record an objection but not an approval is a reviewer the release record cannot hear say yes. A sign-off through a link is stored with the approver’s name, their role, their words, and the fingerprint of what they were looking at — and a named person inside the account acknowledges it.

  • What the outsider is shown

    Enough of the brand to see the post as it will publish — name, colours, type, logo. Not the voice rules, the design rules, the source allowlist or the legal entity. That is your governance material and it is a narrower shape by construction, not by a component remembering to hide it.

  • The token is never stored

    Thirty-two random bytes, hashed before storage, so the database never holds a usable share credential. The review route carries a no-index tag and is the one path the site’s robots file refuses outright.

A viewer seat inside your account cannot write a comment or record a sign-off — the policies refuse both. The link is the path for that, which keeps an external reviewer outside your account entirely rather than inside it holding a role.

The artefact you hand over

One market’s record, without disclosing the other ten

Ask most tools in this category how they know the content was checked and you get a screenshot. There are two records here, and the difference between them is the useful part.

Account-wide

Every brand in the company, in one file

The right file for the person accountable for all of them, and the wrong one to send anywhere: it names every other market, their campaigns, their release times and the rules they waived. Owner or editor only.

One brand

One market, and nothing about any other

Not a filtered view of the file above — that one is never run — so there is no payload holding the other brands for a filter to be trusted to strip. No other brand is named, counted, or read to produce it.

What each release carriesWhy it is there
The rules in force at that momentSnapshotted at release, so a later edit to the brand kit cannot re-describe what a past release was checked against.
The audit that ranEvery finding, with its tier — and whether the review pass ran at all, with the model named.
What was waived, and whyA blocking rule released over takes a written reason, and the reason is in the file.
What was set aside without a reasonKept in its own field, apart from the waivers. Rendering the two alike would erase the distinction the record exists to preserve.
Who released it, and what they acknowledgedThe named person, and the statement generated from that specific check which they accepted.
A fingerprint of what shippedSo the entry can be tied to an artefact rather than to a title somebody may since have changed.
  • The file states its own scope

    It carries, in words and inside the file itself, what it covers and what it excludes — so a reader holding only the attachment knows what they may conclude from it without being told separately.

  • Thirty days, ninety days, or a year

    Generated on demand for the period you choose. It comes back as JSON, without asking us for it.

  • Nobody can edit their own record

    Release records carry a policy for reading and a policy for inserting, and none for updating or deleting — so an update or a delete affects no rows, for anyone, including the person who released. A trail the audited party can rewrite is not a trail. The isolation suite asserts the same directly of the generation audits and of the ledger of overridden findings: even the account owner cannot rewrite or delete one.

  • Your agency can produce it for their brand, and only theirs

    The per-brand record is guarded on reaching that brand rather than on holding a seat of some rank, so a limited seat granted one market can produce that market’s record and is refused every other in the company.

Run it on a post you already cleared.

Six minutes, no account, nothing transmitted. It will tell you more about whether this fits your review cycle than the rest of this site put together.