Back up footage on set
Everything else on a shoot can be fixed with money: gear breaks, people cancel, weather turns. Lost footage is the one failure with no vendor, so backup discipline is the least negotiable habit on set.
What this is about
Data loss on productions rarely looks dramatic. It looks like a card formatted because someone thought the copy was done, a copy made by drag-and-drop that silently skipped files, a single drive with the whole day on it left on a car roof. Every one of those stories has the same root: no named owner and no verified process. The countermeasures are old and boring — checksum copies, two independent targets, formatting only after double verification — and they work precisely because they remove judgment calls from tired people at 9 p.m.
The order matters more than the tools. Skip a step and you usually notice two steps later — by which point the fix costs several times as much.
What runs differently here
In planning terms, that means:
- One named media owner per day — backups done by whoever has a free minute are backups nobody did
- Copies count only when verified by checksum; a progress bar reaching 100 percent proves nothing about the files
- 3-2-1 starts on set: two copies on two different drives before the crew leaves, and they ride home in different cars
- A card gets formatted by the person who verified both copies, and by nobody else, ever
Step by step
This order gets you there fastest:
- Appoint the media owner in the call sheet, with the authority to say 'this card is not cleared yet' to anyone on set, including the DP who needs it back.
- Offload with software that verifies checksums, not with the file manager. The tool re-reads what it wrote and proves the copy matches the source — that proof is the entire point.
- Copy to two independent targets, ideally in one verified pass. A backup of a backup made later inherits any error the first copy already contained.
- Run a physical card system everyone understands at a glance: cleared cards in one pouch, exposed cards in another, a marker convention on the cards themselves. Ambiguity is how formatting accidents happen.
- Offload continuously through the day instead of collecting everything for the evening. A card that dies at lunch then costs a morning, not the whole shoot.
- Log every offload — card, clips, sizes, checksum result, drive — in a simple report. When someone asks in three weeks whether card B was ever copied, the answer is a lookup, not a feeling.
- Separate the copies physically at wrap: different bags, different vehicles, ideally different addresses overnight. Theft and accidents are location events; your copies should not share a location.
- Format cards for the next day only after both copies verified and the log says so — announced out loud, so the whole set shares the state of the media.
Common pitfalls
What most often goes wrong in practice:
- Formatting a card on the camera's own 'copy looked fine' evidence
- Both backup drives riding home in the same backpack
- Postponing offloads to the hotel, where the tired mistake is waiting
With TillyGen
The wrap section of a TillyGen day plan carries media verification as its own line item with a name attached — the shoot is not wrapped until that box is checked, and the report says who checked it.
Change one constraint and the consequences travel through the whole plan: affected shots are flagged, the call sheet is regenerated, and nobody keeps working from yesterday's version.
Frequently asked
Is copying to one big drive on set enough?
No. One drive is one failure away from total loss of irreplaceable material. Two independent, verified copies before the crew disperses is the floor, not the ambition.
What checksum verification actually buys me?
Proof that every byte written equals every byte read from the card. Copies without it can silently truncate or corrupt files, and you find out during the edit, after the cards are long formatted.
How long does it take to get started with TillyGen?
A first project takes under an hour to set up. There is no configuration phase in which templates and fields have to be defined before the tool produces anything.
Can the results be exported?
Yes — as PDF for the crew, CSV for downstream systems and through the API for anything automated. The plan stays the source; the exports are views of it.