Concepts · Characters

Characters

A character is a face a project uses again and again: a presenter for a dentist’s explainer videos, a bakery’s mascot, a founder who appears in every ad without filming every week. Some are invented. Some are real people who agreed to be made into an avatar. Esy keeps one record for each, makes sure it looks the same every time, and will not make anything with a real person’s likeness unless their permission covers it.

On screen, Avatars

The API and this page say character; the studio calls them avatars. They are the same thing.

Two kinds

Every character is one of two kinds, and the kind is the one thing that changes the rules.

syntheticlikeness
DepictsNobody realA real, identifiable person
Before making anythingNothingAn active consent that covers the use
In adsA synthetic-performer disclosureConsent law applies; platforms label AI
Can be withdrawn by—The person, at any time

A character prompted with a real person’s name or photo is a likeness character. Esy treats “made to look like someone” as depicting them.

The parts

CHARACTER · A COLLECTION OF REFERENCESDr. Maya · char-7f3a91c2portrait · turnaround · expressionsfreezev1 · retiredv2v3run-0c7d9e21pins v3THE PERSON · OWNERS AND ADMINS ONLYSubjectMaya Patel · adult · not politicaldepictsLikeness consent · activeface · organic · US · to 2027-10-01allowedHistoryrecorded · activated · …
A character, its versions, and the permission behind themThe reference set is a collection. Versions freeze it. A run pins one version and records the consents that allowed it.
PartWhat it is
CharacterThe avatar a project uses. Its references (pictures, a voice sample) are members of a collection, redone one at a time.
VersionOne frozen state: the references by artifact id, the persona, and who it depicts. Never edited; retired instead.
SubjectThe real person a likeness character depicts. Not necessarily an Esy user.
Likeness consentThe person’s permission: face and/or voice, for which uses, where, from when to when, with the evidence.
Provider bindingA provider’s copy of a version (an avatar or a voice at a video or voice provider), with that provider’s own consent status.

Versions keep the face the same

Editing a character’s references or persona changes its draft. Nothing reaches work until someone freezes a new version. A campaign approved with version 3 keeps getting version 3 even after version 4 exists; “latest” is resolved once, when a run is made, and recorded on the run. Retiring a version stops new work on it; everything it already made stays valid.

Consent is its own record

A likeness character needs the depicted person’s permission, and that permission has terms. The scope is structured so Esy can check every run against it, not just store it:

a consent's scopejson
{
  "version": 1,
  "uses": ["organic"],                 // organic | ads
  "media": ["image", "video"],         // image | video | audio
  "channels": ["instagram", "web"],    // or ["any"]
  "territories": ["US"],               // ISO 3166 alpha-2, or ["WORLDWIDE"]
  "advertisers": [],                   // empty: your own work and your clients'
  "productLines": []
}
RuleWhy
Face and voice are separate permissions, and a consent covers at least one.Providers treat them separately; so do the laws on digital replicas.
Every consent ends, at most 10 years after it starts.Nothing is forever; the term the NO FAKES Act proposes for a living adult.
Once active, its terms can’t change. A broader use needs a new consent.California and New York void replica clauses without a reasonably specific description of uses.
Revoked is final, and revoking never needs an up-to-date etag.The person’s withdrawal wins over any edit in flight.
Training on the likeness is a separate permission, off unless granted.The SAG-AFTRA commercials contract requires separate consent.
Subjects are adults who are not political candidates or officials.Platforms and providers bar minors’ likenesses and political impersonation; the database refuses both.

A consent is recorded as pending and does nothing until someone activates it. It can be suspended and resumed. Its history (recorded, activated, suspended, resumed, revoked) is append-only. Erasing a person blanks what identifies them, revokes every consent and retires every version that depicts them; the consent records stay, as the proof that past work was permitted.

The gate

One check decides whether a character can be used, and every run that features one passes it twice: when the run is made (a failure is a 422 naming why, before anything is priced) and again just before it starts, so a consent withdrawn while a run waited in the queue still stops it. You can ask the same question in advance for a planned use:

POST /v1/characters/{characterId}:check · can Dr. Maya appear in paid TikTok ads?json
{
  "ok": false,
  "version": 3,
  "reasons": ["out_of_scope"],
  "message": "The permission on file doesn't cover this use.",
  "consentIds": [],
  "disclosure": null
}
ReasonMeaning
no_versionNothing frozen yet, or every version retired.
consent_missingNo consent covers this (the face, or the voice).
consent_pending · consent_suspended · consent_revokedThere is one, but it isn’t active.
consent_not_started · consent_expiredThere is one, outside its dates.
out_of_scopeThere is one, but it doesn’t cover this use, channel, territory or advertiser.
provider_consent_pending · …_rejected · …_missingThe provider hasn’t accepted the person’s consent for its copy.
subject_erased · character_archived · character_scopeThe person was erased, the avatar archived, or the run is in another workspace.

A run asks for a character with characterId in its intake, and optionally characterVersion to pin one. What the template makes decides what the gate checks: pictures and video need the face, audio needs the voice. Orders that feature a character run in standard mode only, so every child passes the gate.

Disclosure and provenance

Every run with a character records the version and the consents that allowed it. That is the record a disclosure or a provenance manifest points to. The check returns the label to show: for a synthetic performer in an ad, wording that meets New York’s synthetic-performer law and California’s. Platform AI flags and signed C2PA manifests on rendered files come with publishing.

Kept by the database

The rules that protect real people aren’t left to careful code. The database refuses edits to a frozen version, to an active consent’s terms, and to consent history; refuses a minor or a political figure; refuses a consent longer than 10 years; and refuses any link between workspaces.

The endpoints are in the Characters API. A character belongs to a project, so it belongs to that project’s client too.

In short
  • A character is synthetic or depicts a real person, and that decides the rules.
  • Versions never change; runs pin one.
  • A real person’s consent is a record with terms, checked on every run, twice.
  • Withdrawal is immediate for anything not yet started, and final.