Skip to content
The 21st Century Learning Initiative

Provenance for Student Work: Content Credentials in the Classroom

A photograph submitted for a media project, or a short documentary cut for a history unit, arrives as a file, and a file carries no visible account of where it came from. Content credentials are an attempt to make the file itself carry one: a signed record of which device or program produced it, what was done to it, and whether a generative tool was involved.

A media studies class: a student holds up a printed photograph while a teacher points to a seal on its corner, others examine prints with magnifying glasses. Engraved duotone plate, ink blue on cream paper.
Plate VIIA media studies class: a student holds up a printed photograph while a teacher points to a seal on its corner, others examine prints with magnifying glasses. Plate drawn in the archive's ink and paper style.

The technology deserves a place in a school's thinking about authorship, with its limits stated plainly. This publication's position, set out in our essay on proof of work, is that process evidence is the reliable witness and inspection of the finished artifact the weak one. Content credentials sit between the two: evidence embedded in the artifact, but evidence about the process.

The short answer. Content credentials are cryptographically signed provenance metadata, defined by the open C2PA standard, that record how a media file was made and edited. They are useful in classrooms for media projects and media literacy teaching, they are easily stripped and unevenly adopted, and they cover images, video and audio far better than prose.

What content credentials are

The standard behind the label is published by the Coalition for Content Provenance and Authenticity, an industry body formed in 2021. Its technical specification describes a manifest: a structured record attached to an image, video, audio file or document. The manifest holds assertions about the asset (the tool that made it, the actions applied, the earlier files it was built from, whether a generative model produced any of it) and a digital signature over them, made with a certificate belonging to the device or software that generated it. A hash of the content is included, so any later change to the pixels or samples breaks the match between file and manifest.

First, the manifest is layered. When a signed photograph is cropped in a credential-aware editor, the editor writes a new manifest that lists the original as an ingredient, records the crop as an action, and signs the whole, so the result is a chain with each link signed by the tool that made it. Second, the record is about tools and actions rather than people. A certificate identifies the camera model or the editing program; the human behind it is inferred.

Anyone can inspect a manifest. The public verification tool accepts a file, checks the signatures and displays the chain in readable form.

Where students already meet them

A small number of camera bodies now sign images at capture, and at least one phone manufacturer has built credentials into its default camera app. The major commercial image editors write manifests when a user opts in, several image generators attach a credential to every output declaring it as generated, and a few large platforms show a label beside images that carry one. A student with a recent phone and a mainstream editor may already have produced a provenance chain without knowing it.

Coverage is patchy in ways that matter. Most phones, most cameras and nearly all free editing apps write no credentials. Messaging apps and many social platforms strip metadata on upload, and a screenshot of a signed image is a new, unsigned image. Far more often no manifest is present, and that condition means nothing at all.

Three uses a school can make of provenance

Students attach credentials to their own media work

The first use turns the standard toward the student's own output. In a photography or film unit, students working in a credential-aware tool can export their pieces with a manifest recording the capture, the edits, the ingredients and the export. The artifact then carries its own account of the making, which is the principle behind the process portfolio: work that shows its history is work whose authorship rarely needs arguing. A student who reads their own manifest also sees composition as a sequence of recorded decisions: crops, colour correction, a stock clip brought in as an ingredient. That is the apprentice's view of the work, the one Collins, Brown and Holum argued for in the flagship essay on making expert thinking visible, delivered here by the file format.

A media literacy lesson on reading a manifest

The second use is a lesson. Give a class a set of images: one signed straight from a camera, one signed by a generator and declared as generated, one edited in a credential-aware tool, and two with no manifest at all, one of which is a screenshot of a signed original. Ask students to run each through the verifier and record what each manifest shows. The exercise teaches the discipline Wineburg and McGrew (2019) found in professional fact-checkers and rarely in students: leaving the artifact to check its sources rather than staring harder at it. The last two images teach the harder lesson, that a missing record is silence rather than a verdict.

This belongs in the media literacy strand of AI literacy for educators, beside the lesson on text detectors: Liang and colleagues (2023) showed that widely used detectors flagged most essays by non-native English writers as machine generated. A credential is a signed record of what a tool did rather than a statistical guess about a text's origin, and students should be taught the difference.

A provenance line in the portfolio

The third use is administrative. A school that already asks students to keep a portfolio of drafts and disclosures can add a provenance line for media pieces: whether the file carries a credential, what it records, and, where a manifest is absent, a short note on how the piece was made. The line sits beside the disclosure statement a student writes for machine assistance and does the same job.

What a manifest records, proves and cannot prove

What the manifest recordsWhat that establishesWhat it cannot establish
Signing tool and certificateA particular device or program produced the record; the file is unchanged sinceWho was holding the device or signed into the program
Capture details: time, device, sometimes locationA capture event was recorded then, by that deviceThat the scene was real or the student composed the shot
Actions: crop, adjust, composite, generateWhich edits were applied in credential-aware toolsEdits made in tools that write no credentials
Ingredients: earlier files and versionsThe file's lineage through each signed stepAnything upstream of the first signed step
Generative source declarationA signing generator labelled the output as generatedThat an unlabelled file was not generated
Content hashPixels or samples match the signed recordThat the content was truthful when signed

A credential is strong evidence about a file's journey through tools that participate in the standard and silent about everything else. It can corroborate a student's account of how a piece was made, but it cannot by itself convict or acquit.

The limits, stated plainly

Credentials can be stripped, and stripping is rarely a sign of bad faith. Re-encoding, screenshotting, sending through a messaging app or uploading to a platform that discards metadata will each remove a manifest, and students do these things constantly. A policy that treated a missing credential as suspicious would flag nearly all student work, the failure mode of an over-sensitive detector. Absence proves nothing.

The standard covers media far better than prose. The specification supports documents, and some office and PDF tools are beginning to write manifests, but the essay and the report are usually written in tools that record nothing of this kind. For text, the reliable evidence remains version history, drafts and conversation rather than signed metadata.

Adoption is uneven. The chain is only as complete as the tools a student happens to use, a school cannot require families to buy signing cameras or licensed editors, and a manifest is only as trustworthy as the certificate behind it. None of this makes the standard useless; it makes it one instrument among several.

Frequently asked questions

What are content credentials?

Content credentials are a signed record, defined by the C2PA open standard, that travels with an image, video, audio file or document and states which tool produced it, what edits were applied, which earlier files it was built from and whether a generative tool was used. A public verifier checks the signature and displays the chain.

Can content credentials detect AI-generated student work?

Only when the generator that produced the work signed it and the credential survived to submission. A signed generation declaration is reliable evidence. An unsigned file tells a teacher nothing, because most tools write no credentials and most sharing routes strip them. Credentials label output from cooperating tools; they are no detector.

Do content credentials work for essays and written assignments?

Poorly, at present. The standard supports documents and a few office tools have begun writing manifests, but ordinary word processors and learning platforms record nothing of this kind. For written work the useful evidence is the draft trail, version history, oral discussion and a written disclosure of assistance.

Should a school require content credentials on student media work?

Not as a condition of acceptance, since many students lack tools that write them. A school can reasonably require credentials where it supplies the tools, in a media lab for instance, and elsewhere ask for a provenance note in the portfolio describing how a piece was made. The requirement attaches to the account rather than the technology.

Where this leaves a school

Content credentials give a school a signed account of a media file's making, produced by the tools rather than by suspicion. Used for what they are, a provenance record for media made in cooperating tools, they strengthen the process-evidence approach this lane describes. Used as a detector, or read as damning when absent, they repeat the errors already documented for automated text detection. The Academic Integrity hub sets out the full toolkit, and the essay on what the research shows about detector accuracy explains why signed records and process evidence are worth wanting.