Scene production.
A deployed managed product that turns a reference image and product packshots into brand imagery. Every model step is gated by an operator, and both gates exist because their absence already caused a failure.
Deployed system — this configuration is running in production. Client identities are withheld.
Classified as a system: an arrangement of automations, capabilities and human judgment responsible for an outcome. The outcome belongs to the arrangement, not to any one component in it.
A model does part of the work here, under a fixed prompt. It interprets or generates; it is not what grants this entry its authority.
Objective
Let a brand operator produce publishable scenes without touching infrastructure, while keeping a human judgment step at each point where a model's output would otherwise ship unexamined.
Runtime
01
Describe
A reference image is converted to prose. Nothing is copied from the image itself.
02
Approve
The operator reads and edits the description before anything renders from it.
03
Render
Scenes are generated from the approved prose, with a generic placeholder in the product slot.
04
Place
The real product is composited into selected scenes.
05
Compare
The packshot sits beside every result so product errors are visible feature by feature.
Anatomy
Context
- Operator reference image
- Product packshots
- An editable scene description
- Per-job output history
Capabilities
- Describe a reference as prose
- Generate scenes from a description
- Place a real product into a scene
- Record estimated cost per call
- Fail over between serving pools
Activation
- Operator action at each of the three steps
Authority
What can it change?
- Autonomy
- Recommend
- Horizon
- Operator-invoked
Read
- Uploaded reference and packshots
- The operator's own job history
Write
- Generated images in the operator's workspace
- An append-only cost ledger
Conditional
- Render only from a description the operator has seen and approved
Prohibited
- Render before the description is shown
- Reproduce a face or identity from the reference
- Name a brand in a generated description
- Publish anything — output leaves only when the operator takes it
Escalate
- Description wrong or incomplete — the operator edits it
- Product detail wrong in a result — the packshot comparison surfaces it
- Transient model outage — noted to the operator when a fallback served the call
Composition and verification
Made from explicit parts.
Composition
- Hosted operator interface
- Language and image models
- Two human approval gates
- Append-only cost ledger
- Access control in front of the application
Verification
- Estimated cost recorded per call against dated list prices
- Fallback engages only after the provider's own retry policy is exhausted
- Identity excluded at the prompt level, not filtered after
- Release-based deploys with the previous release kept for rollback
- Both gates added after the failure each prevents
No evidence is published for this entry. The items above are our own account of its source, read before publishing — not something you can check without taking our word for it.
Next step
What you can do with this.
This configuration runs in production, client identity withheld. To discuss the same for your operation, start with the problem rather than the system: a first call is thirty minutes and costs nothing.
Related entries