Rapid Response Pipeline
Breach news becomes a finished, branded video — with nobody touching a keyframe
Breach news in the morning, branded video by the afternoon — 24 feeds read hourly, copy written, art generated, and the designers' live Figma templates animated in Jitter by a daemon. Nobody set a keyframe.
The templates were never files — each one was the designers' live Figma board, brought into Jitter, the only tool that could animate a real Figma frame. Automation could touch exactly five fields per template, by node id, so a design change upstream shipped in the next hour's run and the brand system stayed out of reach.
Watch a single post become the video.
Every stage below is a real artifact from one run of the pipeline — the Google Security post about Chrome defaulting to HTTPS. Nobody touched it between the feed and the export.
-
The article
The hourly run reads 24 feeds. Among 942 items that morning is a Google Security post: Chrome will default to HTTPS. It is fetched, stripped to clean text, and pushed through the sieve — breach-pattern regexes plus a fuzzy title match against everything already in the ledger. It survives.
-
The brief
One model call turns the article into a fixed-shape brief: headline, brand, severity, attack vector, and twenty carousel snippets — every slot any template could ask for, written once. Severity 4 clears the bar; anything under 3 is dropped before art is ever generated.
{ "headline": "Chrome to Enable HTTPS by Default", "brand": "Google", "severity": 4, // under 3 is dropped "attack_vector": "Insecure HTTP connections", "when": "2026-10-01", "tags": ["Chrome", "HTTPS", "Security", "Web Safety"], "carousel_snippets": { "alert_primary": "Urgent Security Update", "alert_detail": "Chrome will default to HTTPS, enhancing your online safety.", "stat_primary": "95% HTTPS usage", "stat_detail": "Most Chrome navigations are now secure.", "action_primary": "Stay Informed", "action_detail": "Always check for HTTPS before entering sensitive information.", … 14 more slots, one per template field } } -
The photos
Three of the five comps carry a photograph: the alert, the detail and the endcard. They come from the brand's own approved photo library, rotated by story so no two carousels in a run open on the same face. Story 1 draws the first three. An image agent can render bespoke shots with gpt-image-1 instead; this run stayed on-brand with the library.
01 · alert
03 · detail
05 · endcard New stills can be generated on-brand, too. These three came out of the GenAI Brand Manager dashboard: pick Norton, a type and a variation, and the prompt is written in the brand's own visual language. The dashboard →
lifestyle · family
product · protection
lifestyle · work -
The rows
The mapper is deterministic — no model in the loop. Copy is clamped to each comp's type spec, the icon is chosen by rule, and five rows are written out with the source URL riding along on every one. This is the whole hand-off: five comps, five fields each.
comp style copy it carries Carousel_1-1 TopicFeature Urgent Security Update — Chrome will default to HTTPS, enhancing your online safety. Carousel_1-2 StatTile 95% HTTPS usage — Most Chrome navigations are now secure. Carousel_1-3 DetailBody Chrome's HTTPS Default — Starting October 2026, Chrome will prioritize secure connections. Carousel_1-4 Solution Stay Informed — Always check for HTTPS before entering sensitive information. Carousel_1-5 LogoTile Google Security — Google is committed to keeping you safe online. -
The template — the designers' live Figma board
The four templates were never exported files. Each one is the design team's own Figma board, brought into Jitter — at the time the only tool that could animate a real Figma frame. When a designer changed a colour, a type size or a motion beat in Figma, the next hourly run picked it up; nobody re-exported anything. The daemon knows five node ids per comp — headline1, headline2, buttonICON, buttonCTA, image — and a refresh script re-reads them whenever the board changes. Everything else on the board stays the designers'.
the board as the designers left it
the same board, filled by the daemon -
The daemon in Jitter
A local daemon opens Jitter inside a Playwright-driven Chromium, duplicates the current template — whatever the designers last pushed from Figma — fills the five nodes per comp from the rows, and clicks export — Video · 1080p. A second rail hands the same payload to After Effects for the other template family. This is a screen recording of the daemon working; nobody is at the keyboard.
from the designers’ Figma templates into Jitter — real time, unattended -
The deliverable
Five slides, one carousel, in the brand's own template — the alert, the stat, the detail, the solution, the endcard. Same morning, four template families, one payload. This is the one story; the page below shows the rest of the run and lets you drive the mapper yourself.
01 · alert 02 · stat 03 · detail 04 · solution 05 · endcard
The pipeline has two halves and they are not equally reproducible. Severity triage and
summarisation are a language model making a judgement; the rest — which icon, which comp, which cells go
in the spreadsheet After Effects renders from — is rules. Rules can run honestly in a browser,
so they do. What you see below is rapid_response/mapper.py: _normalize()
truncating summaries at 50 and 120 characters, _choose_icon() testing tags in its real
order, and to_ae_rows() emitting one row per slide.
The tags below are the boundary. In production a model assigns them from the article body; here you set them yourself, which makes visible exactly where judgement stops and determinism starts. Everything to the right of that line is reproducible forever.
model — judgement, not reproduced here
rules — running now
One breach story — Chrome moving to HTTPS by default — composed into a five-slide carousel: an alert, a statistic, the detail, the product line, the endcard. The headline, supporting line, icon, call to action and background image on every slide were chosen and placed by the system from a single summarization pass. The animation itself was built by designers months earlier and never touched again.
Ten stages, hourly, unattended. The spine runs left to right; the middle fans into the paper trail every run leaves behind; the end splits into two render rails that were both live — the same story payload driving a browser tool and After Effects.
Jitter has no API, so the daemon uses the editor like a person. The brand animation lived in a browser tool with no automation surface at all. Rebuilding it somewhere scriptable would have thrown away the designers' work, so instead a local service drives the real editor: it logs in once through a real Chromium window — MFA included — and keeps the session, then duplicates the template, selects a comp, and types each headline as genuine keyboard events. It reads every field back to verify what landed, because a dropped keystroke in a headline is invisible until it ships. When the tool has no API, resourcefulness is the skill.
Automation was allowed to touch exactly five layers. Per comp:
headline1, headline2, buttonICON, buttonCTA,
image — verified identical across all eighteen comps in the node map, with no escape
hatch. Animation curves, easing, timing, layout, type and colour were not addressable by the
pipeline, so they could not drift. Copy that would overflow was clamped upstream at composition time
rather than breaking a layout downstream. This is what made the system safe to run unattended: it was
structurally incapable of overwriting the brand system.
One payload, two render engines. The same composed story data drove the Jitter
rail and the After Effects rail — a watcher picking up render sheets and calling
aerender against the original template. Both were live; After Effects came first and kept
working after Jitter became primary. A tool change was a new rail, not a new pipeline.
Worth being precise about: the severity gate is the part people expect to do the filtering, and it accounts for five rejections. Stories overwhelmingly die earlier — at the keyword sieve or at the fetch. The gate's real job was keeping model spend proportional to the news, not culling the feed.
| artifact | count | what it is |
|---|---|---|
| RSS feeds | 24 | breach reporters, CISA, MSRC, NVD |
| story ledger | 942 items | SQLite, 1.50 MB, status per row |
| export sessions | 95 | 62 of them produced video; 20 more archived |
| exported MP4s | 289 | 272 in VIDEO/, 17 held in the old folder |
| final-frame stills | 272 | captured per comp at export |
| copy-block documents | 733 | one per story, across 8 dated folders |
| render + QA sheets | 1,181 | 651 AE render sheets, the rest editorial QA |
| image sessions | 55 | 108 generated stills |
| Jitter wiring map | 4 × 18 × 5 | templates × comps × mutable slots |
Built solo for a real client context and run through late 2025. It is archived now — the point of this page is the preserved evidence, not a system waiting to be restarted. The class of problem it answers is the one where the volume or speed a brand needs exceeds what a manual team can produce, and the brand system still has to survive contact with the automation.
Project Elements
Have a Project in Mind?
Animation direction, VFX and creative technology. Message me on LinkedIn or get in touch.