A photograph of a defect is worth exactly as much as your ability to prove four things about it: when it was taken, where it was taken, who took it, and that nobody changed it afterward. Strip those away and you do not have evidence. You have a picture a determined opponent can wave off as taken anywhere, anytime, by anyone.
Most site photos have all four facts and then throw them away. Here is how we keep them.
The four facts a defect photo has to carry
When you capture a defect photo in IssuesId, the device knows more than the image. We capture and bind four things to it.
Timestamp: the moment of capture, from the device clock, recorded when you take the shot rather than when it uploads. Location: GPS latitude and longitude, plus compass heading, so the photo records not just where the photographer stood but which way they were facing. Identity: which signed-in user, on which registered device, took it. Integrity: a record that the original bytes have not changed since capture.
None of this is visible in the photo. All of it is attached to the photo, travels with it through sync, and shows up in the report.
Why heading matters more than you would think
GPS on its own puts the photographer at a point. In a building a point is not enough. The same spot on level 4 looks into two apartments and a corridor. Heading settles it. "Standing here, facing 270 degrees" resolves to one wall, one defect, one place you can walk back to and re-shoot the same view for the close-out photo.
That before-and-after pair is the most persuasive thing you can put in front of someone in a dispute, and it only works if both photos can be proven to look at the same wall from the same spot.
Annotations never touch the original
This is the rule that makes the whole thing hold up: the original photo is immutable.
When a super circles a crack, drops an arrow, or writes "regrout" on an image, none of that is painted into the source file. Annotations are a separate layer, stored as their own data, drawn over the original when you view it. The defect view shows the marked-up version because that is what is useful on site. The evidence keeps the untouched original because that is what is defensible. The day someone claims a photo was doctored, you produce two files, the pristine original and the annotation layer, and the claim goes away.
Capture-time, not upload-time
Small detail, big consequence: every fact above is recorded the instant the shutter fires, on the device, before any network is involved. A photo taken in a basement at 9:14 and synced at 4:30 when the super reaches the office has to carry 9:14, not 4:30. Upload-time metadata is worthless as evidence. It records when the wifi came back, not when the condition existed. Because capture is local-first, the timestamp, GPS, and identity are sealed at the moment of truth and just carried forward when sync happens.
What this is really for
Ninety-nine times out of a hundred nobody asks. The defect is captured, fixed, verified, closed, and the metadata is never looked at.
It is the hundredth time the system is built for. The contested handover, the insurance claim, the tribunal. On that day, the gap between a tool that quietly kept the four facts and one that did not is the gap between evidence and a story. We keep the facts.
