Avatar consent register keyed by avatar handle: a Python CSV script

Keep a consent register keyed by Sume avatar_handle: person, photo source, approved uses, expiry. A stdlib Python CSV checker blocks videos for expired consent.

5 min readSume
All posts

The simplest consent register for Sume avatars is a CSV file with one row per avatar_handle, because the handle is the key every later video request uses. Record who the person is, where the photo came from, which uses they approved, when the permission expires, and whether it was withdrawn. A short Python check before each talking-video call then refuses to render for a handle that is missing, expired or withdrawn.

The handle is the identity that you send as avatar_handle in Generate avatar video requests, read 2026-10-05, so a register keyed by it cannot drift from what you render.

The columns

Keep the columns few and plain. The register is useful only if people fill it in.

The expires column is a text date in ISO format on purpose. ISO dates sort and compare correctly as strings, so the check can use a plain comparison, and a spreadsheet exports them without surprises. Leave withdrawn empty for active consent and put any text, such as the date, when it is withdrawn. A single clear rule is better than a set of statuses that people interpret differently.

Consent register columns, read 2026-10-05
ColumnHoldsWhy
avatar_handleThe handle used in API callsKey; matches what you render
personWho is shownWho to ask about changes
photo_sourceWhere the photo came fromProof of right to use
approved_usesUses they agreed toScope check
expiresISO datePermission is not forever
withdrawnyes or emptyHard stop

The check

The script reads consent.csv, finds the handle, and exits with a message and a non-zero code unless consent is current. It uses only the standard library. Run it before the render call, in the same job.

The function returns a pair, a boolean and a reason, so a calling program can log why it refused. The command line wrapper prints the reason and sets the exit code, which lets a shell script or a CI job stop. To try it, create a file with the header avatar_handle,person,photo_source,approved_uses,expires,withdrawn and one row, then run python3 check.py presenter_01.

import csv, sys
from datetime import date

def allowed(path, handle, today=None):
    today = today or date.today().isoformat()
    with open(path, newline="") as f:
        for row in csv.DictReader(f):
            if row["avatar_handle"] == handle:
                if row["withdrawn"].strip():
                    return False, "consent withdrawn"
                if row["expires"] < today:
                    return False, "consent expired " + row["expires"]
                return True, "ok"
    return False, "no consent row"

if __name__ == "__main__":
    ok, why = allowed("consent.csv", sys.argv[1])
    print(why)
    sys.exit(0 if ok else 1)

Make it binding

Make the check part of the render path, not a step someone has to remember. A wrapper that calls allowed and only then posts to /v1/avatar-1.0/talking-video makes the register binding. Handle names also need to be stable: if two people use the same handle in two environments, the register cannot tell them apart, so keep one register per workspace.

Review the register on a schedule, for example monthly, and look at three things: rows about to expire, handles used in recent renders that have no row, and rows marked withdrawn that still appear in scheduled work. A register that is only written once becomes wrong within a season.

Withdrawal

Sume's docs list no route to delete an avatar, so the register is also where you record a withdrawal and the follow-up. When someone withdraws, mark the row, stop new renders with the check, and use the withdrawn consent post to find published videos that need replacing. Ask Sume support how removal of the avatar itself is handled, and write the answer in the register.

What it is not

This is a bookkeeping tool, not a legal document. The release checklist covers what to get from the person, and the GDPR post covers why a photo is still personal data. Handle format rules are in the handle rules post.

Sources

Related posts

More in Use cases

All Use cases posts

Written by Sume