
Insights — Technology
Identity lock: why the face must never change
A guest steps in front of the mirror. Ninety seconds later they are a samurai, a sprinter, a queen of Egypt. The wardrobe is not the hard part. Fabric, armour, stage light, a marble hall: a generative video model will give you all of that on request. The hard part is that the person in the mirror still has to be them.
We call the constraint identity lock, and it is the single property the whole product rests on. Everything else in a session is negotiable — the world, the moment, the look, the length. The face is not.
The failure mode nobody forgives
Generative video has one characteristic failure in front of a live audience, and it is not a glitch. It is drift. The jaw narrows by a few degrees. The nose shortens. Skin tone warms toward an average. The eyes acquire a symmetry their owner has never had. Frame by frame the system produces a competent, well-lit, entirely different person.
No one needs to be told. The guest stops smiling. The friend holding the phone lowers it. A moment that was about them has quietly become a moment about somebody else, and the room can feel the substitution before anyone says a word.
Why trust collapses at the face
People read faces with a precision they cannot articulate. We recognise our own across bad light, odd angles and twenty years. We also detect the near-miss instantly, and we dislike it. A stranger wearing our clothes is not a flattering portrait; it is an uncanny one.
So the guest in front of a mirror is not evaluating image quality. They are asking one question: is that me? Once the answer is no, nothing else in the frame matters. The costume stops being a costume and becomes a mask.
There is a second reason, less obvious and more serious. A face that drifts toward an idealised average is making an editorial statement. It tells the guest, quietly and without permission, what they ought to look like. A medium built on giving value to the person standing in front of it cannot also be in the business of correcting them.
A brand world is a costume, not a replacement. The guest is the constant. Everything else is set dressing.
Identity first, identity last
Identity lock is not a filter applied at the end. It is the shape of the instruction stack itself. A session is assembled in layers — brand world, then moment, then look — and identity preservation is stated at the top of that stack and repeated as the final instruction, after every creative direction has been given. The last word belongs to the guest.
What is held: face, skin tone, age, expression and body proportions. What is transformed: wardrobe, setting and lighting. The separation is deliberate and it is narrow, because every additional degree of freedom is another chance for the model to reinterpret a person who did not ask to be reinterpreted.
The medium raises the stakes. This is continuous video, not a still. A single photograph can be lucky. Ninety seconds cannot: the guest turns, laughs, steps closer, checks the mirror the way people check mirrors. Every frame is subject to the same constraint, and the constraint has to survive movement, not just pose.
Creative work is bounded by the same rule. Brand worlds are reviewed by people before they are published to venues, and a moment that pulls too hard on the face — heavy helmets, masks, extreme stylisation — is rewritten or dropped. It is cheaper to lose a moment in the studio than to lose a guest in a lobby.
Outfit only, when the world can wait
Venues can go further and change less. In outfit-only mode the real background stays — the shop floor, the colonnade, the lobby behind the guest — and only what they wear is transformed. Full world changes the setting too. The venue chooses, and the choice is not merely aesthetic: fewer variables mean fewer opportunities for drift, which is why a try-on in a store is usually better served by the conservative setting.
Transparency is part of the lock
A guest who cannot tell what is happening cannot consent to it. So the mirror shows an AI notice before the camera starts, no biometric templates are stored, and guest footage is never used to train the model. Recordings are deleted after seven days and email deliveries after thirty.
Identity lock is the technical half of that promise; consent, retention and deletion are the legal half. The guest should never have to know which is which. They should simply be able to assume that the person who walks away from the mirror is the same person who walked up to it.
The test
We use one test, and it needs no instrumentation. Show the recording to someone who knows the guest well. If they name the person before they name the costume, the lock held. If they hesitate — even for a beat — it did not, and the moment goes back to the studio.
The rules
Three rules the engine will not break
Identity lock is easier to describe as prohibitions than as features. These three hold for every world, every moment and every look.
The face is not a variable
No brand world, moment or UI look may adjust facial geometry, skin tone, apparent age or expression. A creative brief that requires it is not accepted into the library.
The body is not idealised
Proportions are preserved as they are. The mirror dresses the guest who is present; it does not offer a corrected version of them as a side effect of the costume.
Consistency across the whole session
The constraint applies for the full ninety seconds and across every outfit switch, not to a single lucky frame. Movement is the test, not the pose.
Outfit-only mode: the store stays, the kit changes.
Two modes
Change less, and the lock holds harder
Every element a model is asked to invent is an element it can get wrong. Outfit-only mode narrows the brief to the wardrobe and leaves the room exactly where it is.
- Outfit only. The real background is kept. Useful wherever the space itself is part of the proposition — a shop floor, a gallery, a lobby.
- Full world. Wardrobe, setting and lighting are transformed together, for premieres, exhibitions and brand events where the room should disappear.
- Set by the venue. The mode is part of the configuration, not a guest decision, so an installation behaves the same way all day.
- Same constraint either way. Identity lock does not relax when the background changes. It simply has fewer neighbours to argue with.
At a glance
What is held, what is handed over
| Preserved | Face, skin tone, apparent age, expression, body proportions |
|---|---|
| Transformed | Wardrobe, setting, lighting |
| Modes | Outfit only (real background kept) or full world |
| Output | Continuous real-time video, not a still image or photo filter |
| Session | 90 seconds by default, centrally configurable per venue |
| Notice | AI disclosure shown to the guest before the camera starts |
| Storage | No biometric templates; guest footage is not used to train the model |
| Retention | Recordings deleted after 7 days, email deliveries after 30 days |
| Review | Brand worlds reviewed by people before publication to venues |
Session behaviour, modes and retention are platform defaults. Venues may set shorter retention or stricter configuration; they cannot switch identity lock off.
The guest is not the raw material of the image. The guest is the point of it.
Manifest Media manifesto
Where it lives
The lock is enforced in three places
A principle that exists only in a document is a preference. This one is written into the engine, the review process and the data lifecycle.
Manifest Engine
The instruction stack that assembles every session — world, moment, look — with identity preservation stated first and repeated last.
The intelligence layerIdentity & AI
What the model may change, what it must keep, and how transparency notices, guardrails and human review of worlds fit together.
Read the deep divePrivacy & compliance
Consent before the camera, ephemeral sessions, fixed retention windows and no ad-tech — written for the people who have to sign it off.
GDPR by designContinue reading
More from the series
Essays on physical media, participation and the mechanics of a ninety-second session.