What this SOP is for
An agency adding a creator to a protection roster is doing four things: collecting what is needed to file on their behalf, establishing a baseline so later progress is measurable, running the first sweep, and setting the recurring routine. Done ad hoc it takes a week and misses things. Written down it takes about two hours of work spread across the first month, and it survives the person who set it up leaving.
Stage 1 — Intake, day one
- Collect the creator's legal name and the signature they want on notices. Notices name a complainant; decide now whether that is the creator or the agency as authorized agent.
- Get written authorization to act as their agent. Keep it on file. Without it you cannot make the sworn statement a notice requires.
- Collect every stage name, handle and spelling variant, including retired ones. Leaks are indexed under old names for years.
- List every platform they publish on, with the profile URL for each.
- List the domains that are legitimately theirs — their own site, their link page, any partner sites — so a scan does not report their own content as a leak.
- Agree what happens when something is found: who is told, how fast, and whether the creator wants to see the URLs or only the counts.
Stage 2 — Baseline, first week
The baseline is the number every later report is measured against. Take it before you file anything, and write it down somewhere that is not a chat message.
- Run a scan on every handle and variant. Record the count per source, not just the total.
- Note which hosts appear, and how many URLs on each. The distribution matters more than the total — thirty URLs on one host is one notice.
- Check whether any of it is indexed in search, and record that separately from whether it is online.
- Save the baseline with a date. Progress reported without a baseline is an assertion.
Stage 3 — First sweep, first two weeks
- Group URLs by host and send one notice per host rather than one per URL.
- File search removal requests in parallel with the host notices, not after them.
- For hosts with no working abuse contact, go to the CDN or the network operator instead.
- Log what was sent, to whom, and when. A dispatch log is what makes round two possible.
- Re-check every URL a week later. Sent is not removed, and only the re-check tells you which is which.
Stage 4 — The recurring routine, from week three
- Weekly: re-scan the handles, file for anything new, re-check anything previously removed.
- Monthly: report to the creator with the baseline, the current count, and what was removed. Include what did not work.
- Quarterly: re-check the handle list for new stage names, and the whitelist for new legitimate domains.
The two mistakes agencies make
The first is reporting sent as though it were removed. It corrodes trust the first time a creator checks a link themselves and finds it live, and it will happen. The second is running protection per creator by hand, which works at three creators and quietly stops working at eight, usually without anyone deciding to stop.
Where openDMCA fits
openDMCA runs this routine across a roster from one account, with per-creator whitelists, a dispatch log, and status that distinguishes submitted from removed. The API returns the same data if you would rather report from your own system than another dashboard.