Getting permission to talk about the work
The client said yes on a call. That covers none of the four things you were about to do.
Publishing work is governed by three separate permissions that agencies routinely collapse into one: naming the client, stating a result, and quoting a person. Each has a different approver and a different standard. Naming is a marketing decision, stating a result is a claim that has to be supported by a test done beforehand, and quoting a person involves their personal information. Ask at the right moment, in writing, and record what was actually approved.
Three permissions, not one
The conversation usually goes: would you be alright with us writing this up. The client says yes. Nine weeks later a page goes live with the client's logo, a percentage improvement and a quote from their marketing manager, and one of those three things causes a problem.
Separate them from the start, because they are approved by different people and constrained by different rules.
Naming the client is a brand decision, usually owned by their communications or legal function rather than by the person you work with. Your day-to-day contact frequently does not have the authority to grant it and will not say so.
Stating a result is a factual claim about performance, and the obligation attaches to you as the publisher rather than to them as the subject.
Quoting a named individual involves their personal information and their reputation, and consent for it belongs to that person rather than to their employer.
A fourth thing hides inside the third: agreeing to take reference calls. That is an ongoing commitment of somebody's time, not a one-off approval, and it should be asked for separately with an expiry.
What a performance claim requires
| What you want to publish | Whose permission | Standard it has to meet |
|---|---|---|
| The client's name and logo | Their communications or legal function | Brand approval, often with usage rules |
| A result or performance number | Yours to get right, theirs to confirm | A measurement taken before the claim |
| A named quote | The individual, in writing | Their words, approved as written |
| Agreement to take reference calls | The individual and their manager | Time-limited and revocable |
| Screenshots of their data | Their data owner | Redacted, and check for personal information |
This is the part most likely to be got wrong and it has a documented standard.
Canada's competition regulator is explicit that you should not make a claim about a product or service's performance or effectiveness unless it is based on an adequate and proper test, and the test has to have been done before the claim is made. The order matters. Measuring afterwards to justify something you already published is the failure the rule describes.
Applied to a case note, that produces a practical rule. Every number on the page has to trace to a measurement that existed before you wrote it, taken from a defined period, with the definition stated. A number reconstructed from memory or from a dashboard whose filters nobody recorded is not a measurement.
It also constrains the framing. A result that occurred while several things changed at once cannot be attributed to one of them, and writing it as though it can is a claim you cannot support. The honest form names what you did and states the outcome without asserting sole causation.
The same discipline is why a case note should record what was owned versus what a wider team executed. A note implying sole delivery is a claim that fails a reference call, which is why the 154-source migration case note names the delivery lead role and the partner consultancy separately.
Numbers that cannot be supported should simply be left out. A case note with no percentages and a precise description of the work is more persuasive to a technical buyer than one full of figures that dissolve under a question.
Quoting a person is a privacy question
A testimonial attributed to a named individual at a named company is personal information being used for your commercial purpose, and the rules about that are not vague.
Under Canada's federal private sector privacy law, the knowledge and consent of the individual are required for the collection, use or disclosure of personal information, and consent is only meaningful if it is reasonable to expect the person understood what they were agreeing to.
There is a second principle that people miss and it is the one that bites later. Purposes have to be identified at or before the time of collection, and information collected for one purpose cannot be used for another without fresh consent. A quote given for a website page is not automatically available for a sales deck, an award submission and a conference talk.
So ask for the uses you actually want, listed, at the time you ask. Website, sales materials, award submissions, and social posts is a normal list and it is a normal thing to ask for. Asking again in six months for each new use is not.
Get it in writing from the person quoted, not from their employer on their behalf. An email saying they approve the quote as written and are happy for it to be used in the listed places is enough, and it takes them one minute.
The wider set of obligations that applies to a marketing team handling personal information is covered in PIPEDA basics for a marketing team, and the consent standard specifically in what meaningful consent actually requires.
Testimonials have their own rule
Beyond privacy, there is a specific requirement about publishing somebody else's endorsement.
The competition regulator's guidance on the use of tests or testimonials sets out two obligations that are easy to breach without meaning to. You need approval and permission to use the testimonial, and what you publish has to accord with what the person actually said or approved.
The second one is where agencies get into trouble, and almost always through editing. Tightening a quote for length, moving a clause, or removing a qualifier changes what was approved. A quote that read well because you removed the word mostly is no longer their statement.
The workable process is simple. Write the quote if they ask you to, send it to them, and publish exactly the version they approve. Then keep the approval email with the quote, in a place somebody will find it in two years.
Disclose a material connection where one exists. If the person quoted received anything for the endorsement, or has a relationship beyond being a client, say so on the page.
Ask at the right moment
Timing changes the answer more than wording does, and there are two good moments and several bad ones.
The best moment is immediately after something visibly worked, while the person who benefited still remembers what it was like before. Ask then, even if you have no intention of writing anything for six months, because the permission and the enthusiasm both decay.
The second good moment is at renewal, where the conversation is already about value and the case note is a natural extension of a discussion both sides are having anyway.
The bad moments are predictable. During a dispute. Immediately after a missed date, even a resolved one. During a procurement process on their side, when any public association with a supplier is politically inconvenient. And at the very end of an engagement, when the person you are asking may be the person who decided to end it.
One practical move that costs nothing: put the possibility in the agreement at the start. A single clause stating that either party may request approval to reference the engagement publicly, with approval not unreasonably withheld and each publication approved individually, makes the later conversation routine rather than novel. It belongs in the same part of the document as the exclusions that prevent disputes.
When the answer is no, publish anyway
Roughly half of good work belongs to clients who will never let you name them, and that is not a reason to have no case notes.
An anonymised note works if it is specific about everything except identity. Sector, size band, the technical situation, what was done, what the constraints were, and the outcome. The identifying details are the client's name and anything that makes them uniquely identifiable, which is usually a combination of sector plus location plus size rather than any single fact.
Check that combination honestly. A note describing a public transit authority in a named province with a specific vendor deadline identifies the client to anybody in that industry, whether or not you named them.
Still get approval for an anonymised note. It is a courtesy, it takes one email, and a client who discovers an unapproved anonymised note about themselves will not distinguish it from a named one.
The strongest version of an anonymised note is one where the technical detail is rich enough that a reader in the same situation recognises their own problem. That is what makes it useful, and it is entirely compatible with saying nothing about who the client was.
Keep a record of what was approved
The approval is an asset with a shelf life, and treating it as a one-time event is how a case note outlives its permission.
Record four things per published item: who approved it, what exactly they approved, which uses were covered, and the date. That is one row in a spreadsheet and it answers every question that comes up later.
Two events should trigger a review. The contact who approved it leaves, or the client's ownership changes. Neither automatically revokes anything, and both are worth a short message confirming the reference is still fine, because a new marketing director discovering an old case note they never approved is an avoidable and entirely unnecessary problem.
Set an expiry on reference-call agreements specifically. Somebody who agreed two years ago to take calls should not still be receiving them, and the agency that keeps sending them is spending goodwill it stopped tracking.
The general principle is the same one that governs any other commitment made to a client verbally: it did not happen unless it exists as a written record, which is the case made in meeting notes that count as a decision record.