Most companies keep a folder of case studies and call it proof. Then a deal needs a reference in the buyer's exact vertical, someone goes looking, and the piece that fits either does not exist, cannot be cleared, or rests on a number nobody can reconstruct.
A proof library is not a folder. It is three columns: the claim, the evidence behind it, and the permission to use it. Almost everyone has the first, some have the second, and the third is the one that goes missing at exactly the moment the deal needs it.
TL;DR
Build the library as three columns rather than as a folder, and record the permission at the same time as the story, because permission is the column that decays and the one nobody writes down. Two legal points shape how you do that, and both are commonly misread. The FTC's Rule on the Use of Consumer Reviews and Testimonials, in force since 21 October 2024, bans fake reviews, incentives conditioned on a particular sentiment and undisclosed insider reviews, and the FTC has already sent warning letters citing civil penalties of "up to $53,088 per violation". But by the FTC's own account that Rule applies to consumer reviews rather than business-to-business ones, which is a fact about a rule and not a licence, because the Endorsement Guides still hold that an endorsement "can't be used to make a claim the marketer of the product couldn't legally make". Separately, a company name is not personal data while a named individual's quote is, which the European Commission sets out plainly, and that difference decides what you need on file. The practical consequence is that anonymised, substantiated, permissioned proof beats a named logo you cannot clear.
Three columns, not one folder
Column one is the claim. The sentence you would actually say to a buyer. Not "we helped them grow", but the specific thing, in the words a salesperson would use on a call.
Column two is the evidence. Where the number came from, who calculated it, over what period, and against what baseline. If the person who produced it left, could someone else rebuild it from what is stored? If not, you have an anecdote with a number attached rather than evidence.
Column three is the permission. Who agreed, in what form, to what exactly, and with what expiry. Named or anonymised. Logo or no logo. Quote attributable to a person, to a job title, or to nobody.
Most libraries fail on the third column and discover it late. The claim and the evidence sit in a slide from eighteen months ago. Nobody wrote down whether the client agreed to be named, and the person who would know has moved on. Our note on win-loss analysis makes the same argument about a different record: the thing you need is usually already in the building, just not in a form anyone can use.
So the unit of the library is an entry, not a document. One row per claim, with all three columns filled, and a case study assembled from rows rather than rows extracted from case studies.
What the rules actually say, and what they do not
Start with what the FTC's fake review rule covers. It prohibits selling consumer reviews, creating fake consumer or celebrity testimonials, offering "compensation or other incentives conditioned on the writing or creation of consumer reviews expressing a particular sentiment", failing to disclose insider relationships, suppressing reviews through "unfounded or groundless legal threat" or intimidation, and distributing "fake indicators of social media influence".
Then read the scope carefully. The FTC's own questions and answers state the Rule applies to consumer reviews rather than business-to-business ones. That is worth knowing precisely because so much B2B marketing advice repeats the rule as though it binds every review of every product.
Which is a fact about a rule, not a licence. The Endorsement Guides are separate and their logic is the one that matters for a proof library: "An endorsement must reflect the honest opinion of the endorser and can't be used to make a claim the marketer of the product couldn't legally make." A testimonial cannot launder a claim you could not make yourself.
And atypical results carry a specific obligation. The Guides state that where an advertiser lacks proof the endorser's experience represents what people generally achieve, the advertisement "must make clear to the audience what the generally expected results" are. A small-print disclaimer that results are not typical does not discharge that.
Take that as a discipline rather than as a jurisdictional question. We are not going to tell you which of these binds your company in your market, because that is a question for your counsel and the answer varies. What we will say is that a proof library built as though the substantiation standard applies is a better library, because the test it imposes, can we support this claim on its own, is the test a sceptical buyer applies anyway.
Enforcement is not theoretical. The FTC has sent warning letters over fake reviews and incentives for positive reviews, and its own post puts civil penalties at "up to $53,088 per violation". Whatever your jurisdiction, a proof library that cannot survive that question is a liability sitting in a shared drive.
Company names and people's names are different problems
A company is not a data subject. The European Commission defines personal data as "any information that relates to an identified or identifiable living individual", and states plainly that a company registration number is not personal data, nor is a generic address like info@company.com.
A named quote is a different matter. "A name and surname" is given as a first example of personal data. So a testimonial attributed to a named person, with their role and photograph, is personal data processing and needs to be treated as such, while the client company's name on a logo wall is a contractual question rather than a data protection one.
Which is genuinely useful in practice. It tells you that the permission column has two different shapes. Naming the company is a commercial permission, usually sitting in the master agreement or a marketing clause. Naming the person is that plus a personal one, and the person can change their mind independently of their employer.
And it explains why proof breaks quietly. The company keeps trading, the contract keeps running, and the individual who gave you the quote takes a job elsewhere. Nothing has been revoked, but the quote now names someone who no longer works there, describing a project at a company they have left.
So record the permission at the level you will use it. Company only, company plus job title, or company plus named person, each with its own line. Collapsing them into "they said yes" is how you end up unable to answer a simple question two years later.
When to capture proof, which is not when you need it
At kickoff, agree the measurement. Not the case study, the measurement. What we will both look at, from what baseline, at what point. Proof is almost always weak because nobody agreed the baseline while it was still observable.
At the first result, ask while it is news. The willingness to be quoted is at its peak in the fortnight after something works, and it falls from there. This is also the cheapest moment to get the permission recorded, because you are already in a positive conversation.
At renewal, upgrade the permission. A client renewing has told you something with their budget. It is the natural moment to move from anonymous to named, or from a quote to a reference call, and the ask lands as a compliment rather than a favour.
At offboarding, capture what you can while goodwill lasts. Clients who leave for good reasons will often still give you the number and the quote, and almost nobody asks. Six months later they will not remember the detail and the goodwill will have cooled.
And write the entry the same week, every time. The gap between the thing happening and the record being made is where proof dies. Our note on positioning for B2B services covers why the specificity you lose in that gap is the specificity that would have won the deal.
What you can actually publish
Substantiated and permissioned is the only quadrant you publish from. Everything else is a task, not an asset.
Substantiated but not permissioned is the most common trap. The number is real and reconstructible, and you cannot use the name. Publish it anonymised rather than sitting on it. "A payments company with about 200 staff" carries most of the persuasive weight of the logo and none of the clearance risk.
Permissioned but unsubstantiated is the more dangerous one. The client is happy for you to say it and you cannot show where the number came from. This is the entry that gets quoted in a pitch, questioned by a procurement team, and cannot be defended.
Neither is a story, not proof. Keep it if it is useful colour, label it as such, and never let it into a deck.
Anonymised proof is not a consolation prize. We do not name clients anywhere, and the library still works, because the vertical, the shape of the company and the number carry the argument. Our notes on getting listed on G2 and on Clutch profiles cover the third-party side, where the review sits under the client's name rather than yours and the permission problem inverts.
What we do not publish here
A legal opinion on which rules bind you. We quote what the FTC and the European Commission publish and stop there. Which regime applies to your marketing, in your market, is a question for your own counsel.
A template contract clause. Publicity and reference clauses are negotiated per relationship, and a clause we drafted for a general audience would be wrong for most readers and reassuring in the worst way.
Conversion figures for named versus anonymised proof. We do not have a clean measurement of it, and the number would be doing a lot of work in this argument if we published one.
Any client name or example. We do not cite client work by name anywhere on this blog, which is also the practice this article recommends, so the piece would be self-contradicting if it did.
A tool recommendation. A proof library is a spreadsheet until it is big enough to be something else, and the discipline is the asset rather than the software.
FAQ
What goes in a B2B proof library?
Entries, not documents. Each entry holds three columns: the claim in the words you would say to a buyer, the evidence behind it including baseline and method, and the permission covering exactly what you may use and in what form. A case study is then assembled from entries rather than being the unit of storage.
Does the FTC's fake review rule apply to B2B?
By the FTC's own questions and answers, the Rule on the Use of Consumer Reviews and Testimonials applies to consumer reviews rather than business-to-business ones. That does not make B2B claims unregulated: the Endorsement Guides hold that an endorsement cannot be used to make a claim the marketer could not legally make. Take your own legal advice on what applies to you.
Can you use a client testimonial without permission?
Treat it as two permissions rather than one. Naming the company is a commercial question usually governed by your contract. Naming an individual involves personal data, since the European Commission gives a name and surname as a first example, and that person can withdraw independently of their employer. Record both separately.
Is anonymised proof worth anything?
Yes, and it is often the version you can actually use. A described company, the vertical, the rough size and a substantiated number carry most of the persuasive weight of a named logo. We name no clients anywhere and the approach works, which is why the article treats anonymisation as a first choice rather than a fallback.
When should you collect proof from a client?
At four moments, none of which is when you need it. Agree the measurement at kickoff while the baseline is still observable, ask for the quote in the fortnight after the first result, upgrade the permission at renewal, and capture what you can at offboarding while goodwill lasts.
What makes a claim substantiated?
That somebody other than its author could rebuild it. Source of the number, who calculated it, over what period, against what baseline. If the answer depends on a person who has left, the claim is an anecdote with a number attached rather than evidence, and it will not survive procurement.
Bottom line
Stop treating case studies as the unit and start treating the entry as the unit: a claim, the evidence that supports it, and the permission that governs it, all recorded the same week the thing happened. The permission column is where libraries fail, because it is the only one nobody thinks to write down and the only one that changes without telling you. Record it at the level you will use it, and separately for the company and for any named individual, since the European Commission is clear that a company registration number is not personal data while a person's name is. Build the whole thing as though a substantiation standard applies, whether or not one binds you, because the test it imposes is the test a sceptical procurement team applies anyway and the FTC's own warning letters put a number on getting it wrong. And when permission is not available, publish the anonymised version rather than nothing. The vertical, the shape of the company and a number you can defend will do most of the work the logo would have done.
Want the pipeline built rather than the proof filed? Book a call with GROU. We run lead generation and outbound inside B2B revenue engines across verticals.
We are GROU, a B2B pipeline agency that runs lead generation, outbound, and LinkedIn content for clients across manufacturing, fintech, iGaming, software, and professional services. The library structure and the capture moments are our own working practice. The rules and definitions quoted are taken from published US Federal Trade Commission and European Commission material and verified in August 2026, and are a summary of public sources rather than legal advice.
Most companies keep a folder of case studies and call it proof. Then a deal needs a reference in the buyer's exact vertical, someone goes looking, and the piece that fits either does not exist, cannot be cleared, or rests on a number nobody can reconstruct.
A proof library is not a folder. It is three columns: the claim, the evidence behind it, and the permission to use it. Almost everyone has the first, some have the second, and the third is the one that goes missing at exactly the moment the deal needs it.
TL;DR
Build the library as three columns rather than as a folder, and record the permission at the same time as the story, because permission is the column that decays and the one nobody writes down. Two legal points shape how you do that, and both are commonly misread. The FTC's Rule on the Use of Consumer Reviews and Testimonials, in force since 21 October 2024, bans fake reviews, incentives conditioned on a particular sentiment and undisclosed insider reviews, and the FTC has already sent warning letters citing civil penalties of "up to $53,088 per violation". But by the FTC's own account that Rule applies to consumer reviews rather than business-to-business ones, which is a fact about a rule and not a licence, because the Endorsement Guides still hold that an endorsement "can't be used to make a claim the marketer of the product couldn't legally make". Separately, a company name is not personal data while a named individual's quote is, which the European Commission sets out plainly, and that difference decides what you need on file. The practical consequence is that anonymised, substantiated, permissioned proof beats a named logo you cannot clear.
Three columns, not one folder
Column one is the claim. The sentence you would actually say to a buyer. Not "we helped them grow", but the specific thing, in the words a salesperson would use on a call.
Column two is the evidence. Where the number came from, who calculated it, over what period, and against what baseline. If the person who produced it left, could someone else rebuild it from what is stored? If not, you have an anecdote with a number attached rather than evidence.
Column three is the permission. Who agreed, in what form, to what exactly, and with what expiry. Named or anonymised. Logo or no logo. Quote attributable to a person, to a job title, or to nobody.
Most libraries fail on the third column and discover it late. The claim and the evidence sit in a slide from eighteen months ago. Nobody wrote down whether the client agreed to be named, and the person who would know has moved on. Our note on win-loss analysis makes the same argument about a different record: the thing you need is usually already in the building, just not in a form anyone can use.
So the unit of the library is an entry, not a document. One row per claim, with all three columns filled, and a case study assembled from rows rather than rows extracted from case studies.
What the rules actually say, and what they do not
Start with what the FTC's fake review rule covers. It prohibits selling consumer reviews, creating fake consumer or celebrity testimonials, offering "compensation or other incentives conditioned on the writing or creation of consumer reviews expressing a particular sentiment", failing to disclose insider relationships, suppressing reviews through "unfounded or groundless legal threat" or intimidation, and distributing "fake indicators of social media influence".
Then read the scope carefully. The FTC's own questions and answers state the Rule applies to consumer reviews rather than business-to-business ones. That is worth knowing precisely because so much B2B marketing advice repeats the rule as though it binds every review of every product.
Which is a fact about a rule, not a licence. The Endorsement Guides are separate and their logic is the one that matters for a proof library: "An endorsement must reflect the honest opinion of the endorser and can't be used to make a claim the marketer of the product couldn't legally make." A testimonial cannot launder a claim you could not make yourself.
And atypical results carry a specific obligation. The Guides state that where an advertiser lacks proof the endorser's experience represents what people generally achieve, the advertisement "must make clear to the audience what the generally expected results" are. A small-print disclaimer that results are not typical does not discharge that.
Take that as a discipline rather than as a jurisdictional question. We are not going to tell you which of these binds your company in your market, because that is a question for your counsel and the answer varies. What we will say is that a proof library built as though the substantiation standard applies is a better library, because the test it imposes, can we support this claim on its own, is the test a sceptical buyer applies anyway.
Enforcement is not theoretical. The FTC has sent warning letters over fake reviews and incentives for positive reviews, and its own post puts civil penalties at "up to $53,088 per violation". Whatever your jurisdiction, a proof library that cannot survive that question is a liability sitting in a shared drive.
Company names and people's names are different problems
A company is not a data subject. The European Commission defines personal data as "any information that relates to an identified or identifiable living individual", and states plainly that a company registration number is not personal data, nor is a generic address like info@company.com.
A named quote is a different matter. "A name and surname" is given as a first example of personal data. So a testimonial attributed to a named person, with their role and photograph, is personal data processing and needs to be treated as such, while the client company's name on a logo wall is a contractual question rather than a data protection one.
Which is genuinely useful in practice. It tells you that the permission column has two different shapes. Naming the company is a commercial permission, usually sitting in the master agreement or a marketing clause. Naming the person is that plus a personal one, and the person can change their mind independently of their employer.
And it explains why proof breaks quietly. The company keeps trading, the contract keeps running, and the individual who gave you the quote takes a job elsewhere. Nothing has been revoked, but the quote now names someone who no longer works there, describing a project at a company they have left.
So record the permission at the level you will use it. Company only, company plus job title, or company plus named person, each with its own line. Collapsing them into "they said yes" is how you end up unable to answer a simple question two years later.
When to capture proof, which is not when you need it
At kickoff, agree the measurement. Not the case study, the measurement. What we will both look at, from what baseline, at what point. Proof is almost always weak because nobody agreed the baseline while it was still observable.
At the first result, ask while it is news. The willingness to be quoted is at its peak in the fortnight after something works, and it falls from there. This is also the cheapest moment to get the permission recorded, because you are already in a positive conversation.
At renewal, upgrade the permission. A client renewing has told you something with their budget. It is the natural moment to move from anonymous to named, or from a quote to a reference call, and the ask lands as a compliment rather than a favour.
At offboarding, capture what you can while goodwill lasts. Clients who leave for good reasons will often still give you the number and the quote, and almost nobody asks. Six months later they will not remember the detail and the goodwill will have cooled.
And write the entry the same week, every time. The gap between the thing happening and the record being made is where proof dies. Our note on positioning for B2B services covers why the specificity you lose in that gap is the specificity that would have won the deal.
What you can actually publish
Substantiated and permissioned is the only quadrant you publish from. Everything else is a task, not an asset.
Substantiated but not permissioned is the most common trap. The number is real and reconstructible, and you cannot use the name. Publish it anonymised rather than sitting on it. "A payments company with about 200 staff" carries most of the persuasive weight of the logo and none of the clearance risk.
Permissioned but unsubstantiated is the more dangerous one. The client is happy for you to say it and you cannot show where the number came from. This is the entry that gets quoted in a pitch, questioned by a procurement team, and cannot be defended.
Neither is a story, not proof. Keep it if it is useful colour, label it as such, and never let it into a deck.
Anonymised proof is not a consolation prize. We do not name clients anywhere, and the library still works, because the vertical, the shape of the company and the number carry the argument. Our notes on getting listed on G2 and on Clutch profiles cover the third-party side, where the review sits under the client's name rather than yours and the permission problem inverts.
What we do not publish here
A legal opinion on which rules bind you. We quote what the FTC and the European Commission publish and stop there. Which regime applies to your marketing, in your market, is a question for your own counsel.
A template contract clause. Publicity and reference clauses are negotiated per relationship, and a clause we drafted for a general audience would be wrong for most readers and reassuring in the worst way.
Conversion figures for named versus anonymised proof. We do not have a clean measurement of it, and the number would be doing a lot of work in this argument if we published one.
Any client name or example. We do not cite client work by name anywhere on this blog, which is also the practice this article recommends, so the piece would be self-contradicting if it did.
A tool recommendation. A proof library is a spreadsheet until it is big enough to be something else, and the discipline is the asset rather than the software.
FAQ
What goes in a B2B proof library?
Entries, not documents. Each entry holds three columns: the claim in the words you would say to a buyer, the evidence behind it including baseline and method, and the permission covering exactly what you may use and in what form. A case study is then assembled from entries rather than being the unit of storage.
Does the FTC's fake review rule apply to B2B?
By the FTC's own questions and answers, the Rule on the Use of Consumer Reviews and Testimonials applies to consumer reviews rather than business-to-business ones. That does not make B2B claims unregulated: the Endorsement Guides hold that an endorsement cannot be used to make a claim the marketer could not legally make. Take your own legal advice on what applies to you.
Can you use a client testimonial without permission?
Treat it as two permissions rather than one. Naming the company is a commercial question usually governed by your contract. Naming an individual involves personal data, since the European Commission gives a name and surname as a first example, and that person can withdraw independently of their employer. Record both separately.
Is anonymised proof worth anything?
Yes, and it is often the version you can actually use. A described company, the vertical, the rough size and a substantiated number carry most of the persuasive weight of a named logo. We name no clients anywhere and the approach works, which is why the article treats anonymisation as a first choice rather than a fallback.
When should you collect proof from a client?
At four moments, none of which is when you need it. Agree the measurement at kickoff while the baseline is still observable, ask for the quote in the fortnight after the first result, upgrade the permission at renewal, and capture what you can at offboarding while goodwill lasts.
What makes a claim substantiated?
That somebody other than its author could rebuild it. Source of the number, who calculated it, over what period, against what baseline. If the answer depends on a person who has left, the claim is an anecdote with a number attached rather than evidence, and it will not survive procurement.
Bottom line
Stop treating case studies as the unit and start treating the entry as the unit: a claim, the evidence that supports it, and the permission that governs it, all recorded the same week the thing happened. The permission column is where libraries fail, because it is the only one nobody thinks to write down and the only one that changes without telling you. Record it at the level you will use it, and separately for the company and for any named individual, since the European Commission is clear that a company registration number is not personal data while a person's name is. Build the whole thing as though a substantiation standard applies, whether or not one binds you, because the test it imposes is the test a sceptical procurement team applies anyway and the FTC's own warning letters put a number on getting it wrong. And when permission is not available, publish the anonymised version rather than nothing. The vertical, the shape of the company and a number you can defend will do most of the work the logo would have done.
Want the pipeline built rather than the proof filed? Book a call with GROU. We run lead generation and outbound inside B2B revenue engines across verticals.
We are GROU, a B2B pipeline agency that runs lead generation, outbound, and LinkedIn content for clients across manufacturing, fintech, iGaming, software, and professional services. The library structure and the capture moments are our own working practice. The rules and definitions quoted are taken from published US Federal Trade Commission and European Commission material and verified in August 2026, and are a summary of public sources rather than legal advice.
Most companies keep a folder of case studies and call it proof. Then a deal needs a reference in the buyer's exact vertical, someone goes looking, and the piece that fits either does not exist, cannot be cleared, or rests on a number nobody can reconstruct.
A proof library is not a folder. It is three columns: the claim, the evidence behind it, and the permission to use it. Almost everyone has the first, some have the second, and the third is the one that goes missing at exactly the moment the deal needs it.
TL;DR
Build the library as three columns rather than as a folder, and record the permission at the same time as the story, because permission is the column that decays and the one nobody writes down. Two legal points shape how you do that, and both are commonly misread. The FTC's Rule on the Use of Consumer Reviews and Testimonials, in force since 21 October 2024, bans fake reviews, incentives conditioned on a particular sentiment and undisclosed insider reviews, and the FTC has already sent warning letters citing civil penalties of "up to $53,088 per violation". But by the FTC's own account that Rule applies to consumer reviews rather than business-to-business ones, which is a fact about a rule and not a licence, because the Endorsement Guides still hold that an endorsement "can't be used to make a claim the marketer of the product couldn't legally make". Separately, a company name is not personal data while a named individual's quote is, which the European Commission sets out plainly, and that difference decides what you need on file. The practical consequence is that anonymised, substantiated, permissioned proof beats a named logo you cannot clear.
Three columns, not one folder
Column one is the claim. The sentence you would actually say to a buyer. Not "we helped them grow", but the specific thing, in the words a salesperson would use on a call.
Column two is the evidence. Where the number came from, who calculated it, over what period, and against what baseline. If the person who produced it left, could someone else rebuild it from what is stored? If not, you have an anecdote with a number attached rather than evidence.
Column three is the permission. Who agreed, in what form, to what exactly, and with what expiry. Named or anonymised. Logo or no logo. Quote attributable to a person, to a job title, or to nobody.
Most libraries fail on the third column and discover it late. The claim and the evidence sit in a slide from eighteen months ago. Nobody wrote down whether the client agreed to be named, and the person who would know has moved on. Our note on win-loss analysis makes the same argument about a different record: the thing you need is usually already in the building, just not in a form anyone can use.
So the unit of the library is an entry, not a document. One row per claim, with all three columns filled, and a case study assembled from rows rather than rows extracted from case studies.
What the rules actually say, and what they do not
Start with what the FTC's fake review rule covers. It prohibits selling consumer reviews, creating fake consumer or celebrity testimonials, offering "compensation or other incentives conditioned on the writing or creation of consumer reviews expressing a particular sentiment", failing to disclose insider relationships, suppressing reviews through "unfounded or groundless legal threat" or intimidation, and distributing "fake indicators of social media influence".
Then read the scope carefully. The FTC's own questions and answers state the Rule applies to consumer reviews rather than business-to-business ones. That is worth knowing precisely because so much B2B marketing advice repeats the rule as though it binds every review of every product.
Which is a fact about a rule, not a licence. The Endorsement Guides are separate and their logic is the one that matters for a proof library: "An endorsement must reflect the honest opinion of the endorser and can't be used to make a claim the marketer of the product couldn't legally make." A testimonial cannot launder a claim you could not make yourself.
And atypical results carry a specific obligation. The Guides state that where an advertiser lacks proof the endorser's experience represents what people generally achieve, the advertisement "must make clear to the audience what the generally expected results" are. A small-print disclaimer that results are not typical does not discharge that.
Take that as a discipline rather than as a jurisdictional question. We are not going to tell you which of these binds your company in your market, because that is a question for your counsel and the answer varies. What we will say is that a proof library built as though the substantiation standard applies is a better library, because the test it imposes, can we support this claim on its own, is the test a sceptical buyer applies anyway.
Enforcement is not theoretical. The FTC has sent warning letters over fake reviews and incentives for positive reviews, and its own post puts civil penalties at "up to $53,088 per violation". Whatever your jurisdiction, a proof library that cannot survive that question is a liability sitting in a shared drive.
Company names and people's names are different problems
A company is not a data subject. The European Commission defines personal data as "any information that relates to an identified or identifiable living individual", and states plainly that a company registration number is not personal data, nor is a generic address like info@company.com.
A named quote is a different matter. "A name and surname" is given as a first example of personal data. So a testimonial attributed to a named person, with their role and photograph, is personal data processing and needs to be treated as such, while the client company's name on a logo wall is a contractual question rather than a data protection one.
Which is genuinely useful in practice. It tells you that the permission column has two different shapes. Naming the company is a commercial permission, usually sitting in the master agreement or a marketing clause. Naming the person is that plus a personal one, and the person can change their mind independently of their employer.
And it explains why proof breaks quietly. The company keeps trading, the contract keeps running, and the individual who gave you the quote takes a job elsewhere. Nothing has been revoked, but the quote now names someone who no longer works there, describing a project at a company they have left.
So record the permission at the level you will use it. Company only, company plus job title, or company plus named person, each with its own line. Collapsing them into "they said yes" is how you end up unable to answer a simple question two years later.
When to capture proof, which is not when you need it
At kickoff, agree the measurement. Not the case study, the measurement. What we will both look at, from what baseline, at what point. Proof is almost always weak because nobody agreed the baseline while it was still observable.
At the first result, ask while it is news. The willingness to be quoted is at its peak in the fortnight after something works, and it falls from there. This is also the cheapest moment to get the permission recorded, because you are already in a positive conversation.
At renewal, upgrade the permission. A client renewing has told you something with their budget. It is the natural moment to move from anonymous to named, or from a quote to a reference call, and the ask lands as a compliment rather than a favour.
At offboarding, capture what you can while goodwill lasts. Clients who leave for good reasons will often still give you the number and the quote, and almost nobody asks. Six months later they will not remember the detail and the goodwill will have cooled.
And write the entry the same week, every time. The gap between the thing happening and the record being made is where proof dies. Our note on positioning for B2B services covers why the specificity you lose in that gap is the specificity that would have won the deal.
What you can actually publish
Substantiated and permissioned is the only quadrant you publish from. Everything else is a task, not an asset.
Substantiated but not permissioned is the most common trap. The number is real and reconstructible, and you cannot use the name. Publish it anonymised rather than sitting on it. "A payments company with about 200 staff" carries most of the persuasive weight of the logo and none of the clearance risk.
Permissioned but unsubstantiated is the more dangerous one. The client is happy for you to say it and you cannot show where the number came from. This is the entry that gets quoted in a pitch, questioned by a procurement team, and cannot be defended.
Neither is a story, not proof. Keep it if it is useful colour, label it as such, and never let it into a deck.
Anonymised proof is not a consolation prize. We do not name clients anywhere, and the library still works, because the vertical, the shape of the company and the number carry the argument. Our notes on getting listed on G2 and on Clutch profiles cover the third-party side, where the review sits under the client's name rather than yours and the permission problem inverts.
What we do not publish here
A legal opinion on which rules bind you. We quote what the FTC and the European Commission publish and stop there. Which regime applies to your marketing, in your market, is a question for your own counsel.
A template contract clause. Publicity and reference clauses are negotiated per relationship, and a clause we drafted for a general audience would be wrong for most readers and reassuring in the worst way.
Conversion figures for named versus anonymised proof. We do not have a clean measurement of it, and the number would be doing a lot of work in this argument if we published one.
Any client name or example. We do not cite client work by name anywhere on this blog, which is also the practice this article recommends, so the piece would be self-contradicting if it did.
A tool recommendation. A proof library is a spreadsheet until it is big enough to be something else, and the discipline is the asset rather than the software.
FAQ
What goes in a B2B proof library?
Entries, not documents. Each entry holds three columns: the claim in the words you would say to a buyer, the evidence behind it including baseline and method, and the permission covering exactly what you may use and in what form. A case study is then assembled from entries rather than being the unit of storage.
Does the FTC's fake review rule apply to B2B?
By the FTC's own questions and answers, the Rule on the Use of Consumer Reviews and Testimonials applies to consumer reviews rather than business-to-business ones. That does not make B2B claims unregulated: the Endorsement Guides hold that an endorsement cannot be used to make a claim the marketer could not legally make. Take your own legal advice on what applies to you.
Can you use a client testimonial without permission?
Treat it as two permissions rather than one. Naming the company is a commercial question usually governed by your contract. Naming an individual involves personal data, since the European Commission gives a name and surname as a first example, and that person can withdraw independently of their employer. Record both separately.
Is anonymised proof worth anything?
Yes, and it is often the version you can actually use. A described company, the vertical, the rough size and a substantiated number carry most of the persuasive weight of a named logo. We name no clients anywhere and the approach works, which is why the article treats anonymisation as a first choice rather than a fallback.
When should you collect proof from a client?
At four moments, none of which is when you need it. Agree the measurement at kickoff while the baseline is still observable, ask for the quote in the fortnight after the first result, upgrade the permission at renewal, and capture what you can at offboarding while goodwill lasts.
What makes a claim substantiated?
That somebody other than its author could rebuild it. Source of the number, who calculated it, over what period, against what baseline. If the answer depends on a person who has left, the claim is an anecdote with a number attached rather than evidence, and it will not survive procurement.
Bottom line
Stop treating case studies as the unit and start treating the entry as the unit: a claim, the evidence that supports it, and the permission that governs it, all recorded the same week the thing happened. The permission column is where libraries fail, because it is the only one nobody thinks to write down and the only one that changes without telling you. Record it at the level you will use it, and separately for the company and for any named individual, since the European Commission is clear that a company registration number is not personal data while a person's name is. Build the whole thing as though a substantiation standard applies, whether or not one binds you, because the test it imposes is the test a sceptical procurement team applies anyway and the FTC's own warning letters put a number on getting it wrong. And when permission is not available, publish the anonymised version rather than nothing. The vertical, the shape of the company and a number you can defend will do most of the work the logo would have done.
Want the pipeline built rather than the proof filed? Book a call with GROU. We run lead generation and outbound inside B2B revenue engines across verticals.
We are GROU, a B2B pipeline agency that runs lead generation, outbound, and LinkedIn content for clients across manufacturing, fintech, iGaming, software, and professional services. The library structure and the capture moments are our own working practice. The rules and definitions quoted are taken from published US Federal Trade Commission and European Commission material and verified in August 2026, and are a summary of public sources rather than legal advice.
Pipeline OS Newsletter
Build qualified pipeline
Get weekly tactics to generate demand, improve lead quality, and book more meetings.






Trusted by industry leaders
Trusted by industry leaders
Trusted by industry leaders
Ready to build qualified pipeline?
Ready to build qualified pipeline?
Ready to build qualified pipeline?
Book a call to see if we're the right fit, or take the 2-minute quiz to get a clear starting point.
Book a call to see if we're the right fit, or take the 2-minute quiz to get a clear starting point.
Book a call to see if we're the right fit, or take the 2-minute quiz to get a clear starting point.
Copyright © 2026 – All Right Reserved
Copyright © 2026 – All Right Reserved
Copyright © 2026 – All Right Reserved






