High-risk productions and multi-factor authentication
A production can be marked High Risk, which demands multi-factor authentication on every single access and can watermark its exports — for the titles where a leaked script is the story.
Some productions cannot afford a leak. A franchise title, an unannounced project, anything where the plot turning up online is itself the news. For those, ordinary access control is not enough: it protects against the wrong people getting in, not against the right people being careless.
A production can be marked High Risk, which changes how everyone reaches it.
What happens on a high-risk production
Opening one does not show you the production. It shows an Authorization screen, and you have to authorise before anything else loads.
This happens on every access, not once per device. It is not a trusted-device arrangement or a periodic re-check — the gate is there each time, by design. A borrowed laptop or a session left open on a unit base does not become a way in.
You need multi-factor authentication on your account
To pass the gate at all, your account must have at least one multi-factor authentication method active in Your Profile.
If it does not, the Authorization screen tells you so and sends you to your profile rather than letting you in. There is no way around it and nobody can grant an exception — being invited to a high-risk production is not sufficient on its own.
So if you are adding someone to a high-risk production, tell them to set up MFA first. Otherwise their first experience of the production is a wall.
Watermarked exports
A production can also watermark its exports. PDFs generated from it carry a mark identifying where they came from, so a document that escapes can be traced rather than merely regretted.
This is worth turning on alongside High Risk: the gate controls who gets in, the watermark deals with what leaves.
The thing that is not obvious
High Risk is not a permission level. It sits alongside roles and departments rather than replacing them — passing the authorization gate gets you into the production, and then your role and department decide what you can actually do once inside.
A Subscriber on a high-risk production still only reads; someone restricted to costume still only sees costume. See roles, departments and who can see what.
Turning it on
High Risk and watermarked exports are production security settings, edited with the production itself rather than from the team page. That is the same place the cross-department access setting lives — the three together are the security posture of a production, and it is worth setting them deliberately at the start rather than after something has already circulated.