# Publishing

Publishing gives one asset a permanent public URL. Anyone can open it, with no account and
no link expiry, and the address stays the same for the life of the asset. A new version
replaces what the URL serves rather than producing a second address.

**Media → any asset → Publishing.**

This is not the same thing as a [share link](/guide/media/share-links). A share link hands
a set of files to named recipients for a while. Publishing puts one asset on the open web
for as long as you leave it there, which is what you want behind a website, a datasheet
link or a partner portal.

## Publish an asset

Open the asset, choose **Publishing**, and answer one question before the button works:
where the asset may be distributed.

| | |
|---|---|
| **Worldwide** | No country rules of its own. The workspace's own rules still apply. |
| **Restricted** | Choose the named restrictions that govern it, and add individual countries if this asset needs them. |

There is no default. Every published asset carries a distribution decision somebody made,
recorded with who made it, which is the point of asking.

Publishing copies the current version into the delivery store, checks the copy against the
asset's checksum, and only then opens the URL. A photograph or a document takes seconds; a
large video takes minutes, and the panel says **Copying** until it is live.

## Availability windows

**Schedule availability** sets a start, an end, or both.

A start date in the future holds the publication as **Scheduled**: nothing is copied and
the URL answers nothing until the date arrives, when it publishes itself. An end date
withdraws the asset when it passes, deletes the published copy and leaves the URL
answering **Gone**. Both run without anyone watching a calendar, which is what makes a
licensing expiry safe to set months ahead.

## Country rules

Country rules are enforced at the delivery edge, by the address the request comes from,
before any bytes are sent. A cached asset is checked the same way, so an asset that has
been served a million times is refused the moment its rules say so. Rule changes reach
every location worldwide within about a minute.

Two layers combine, and a block always wins:

- **Workspace-wide restrictions** apply to every published asset whether or not it names
  them. No asset can opt out. This is where trade compliance rules belong: one mis-set
  field on one asset then cannot serve into a sanctioned country.
- **The asset's own restrictions** are anything narrower: a market hold, regional
  rights, a launch embargo.

The map on the publish panel shows the two together before you publish, so what the edge
will enforce is visible rather than reconstructed. Administrators maintain the named sets
under **Administration → Distribution control**; see
[Distribution control](/guide/admin/distribution-control).

A refused request is answered with a plain refusal and no bytes. It is enforced by the
address the request comes from, which is what the rule can see; someone deliberately
routing around it through another country is outside what any geographic rule can promise.

## Everything that is public

**Media → Publications** lists every published asset in the workspace: which version is
live, what governs it, how much it was delivered, who published it and when. It is also
the answer to "what is public right now" when an auditor asks.

Two states in that list are worth knowing:

- **Newer version**: the library has moved on and the URL is still serving an older
  copy. Publishing the current file from the asset's panel moves it forward.
- **Scheduled** and **Gone**: a window that has not opened, and one that has closed.

## Delivery statistics

**Administration → Delivery** shows what the edge did: requests served, requests blocked
and where both came from, on a map you can read by country, plus the assets at the top of
each list. Opening one asset shows its own history, the countries asking for it, and the
sites embedding it.

The counts come from the delivery edge itself, so they carry the same country the rule was
evaluated against rather than a second guess at where a request came from. That makes the
blocked view usable as evidence that the rules are working.

The edge keeps about 90 days, which is the longest range the screen offers. Export what you
need before it ages out if you have to keep it for longer.

## Unpublish

**Unpublish** deletes the published copy and retires the URL within about a minute. The
address is kept and never reissued: publishing the asset again revives the same URL rather
than minting a second one.

Anything already downloaded cannot be recalled. What unpublishing guarantees is that the
address stops handing out the file.
