The Permission Register: A Consent Log for Everyone Your LinkedIn Content Names

A client of ours published a case study in March 2025. It named a supplement brand, gave the before-and-after conversion rate, and included a quote from the brand's marketing lead. The post did well. It sent two inbound calls from operators in the same category, and one of them signed.

Fourteen months later the supplement brand had a new CEO, and he found the post. He sent a polite, very clear email asking why his company's conversion data was on a vendor's LinkedIn profile. Our client said the marketing lead had approved it. She had, in a Slack DM. But that workspace had been archived when her contract ended, and she had left the brand in January.

Nobody lied, and nobody was careless by the standards anyone was applying at the time. The permission was real. It was granted by one person, for one moment, in one context, and the post outlived all three.

That is the problem a permission register solves. It's the least glamorous content system we run for ecommerce founders, and the one that prevents the most uncomfortable phone calls.

Why ecom founders are more exposed than most

A B2B software founder writes mostly about their own product. An ecommerce founder's best material is almost always about somebody else: the 3PL that mis-shipped a pallet, the agency whose restructure worked, the supplier who changed a coating, the client whose return rate fell, the ops lead who found the problem. The access that makes the content credible is access to other people's businesses.

So every good post carries a quiet dependency. It names someone, or describes them precisely enough that they'd recognize themselves. And the category is a small town. The 3PL account manager reads your feed. The supplement brand's new CEO was connected to three people who liked the original post.

Founders tend to handle this in one of two ways, and both are expensive:

  • They name freely, on the assumption that a verbal "sure, go ahead" from someone on a call covers it forever.
  • They anonymize everything into mush, "a brand we work with" or "a partner," which strips out exactly the specificity that made the post worth reading.

A register lets you do the thing in between: name precisely when you have permission, know exactly what that permission covers, and know when it runs out.

What counts as a row

Not every mention needs tracking. A row is any post, newsletter, deck slide or podcast answer that does one of these four things:

  1. Names a company or person who isn't you or your own business.
  2. Uses their numbers. Revenue, conversion rate, return rate, spend, headcount, even rounded.
  3. Quotes them, including a paraphrase close enough that they'd recognize the sentence.
  4. Describes them identifiably without naming them. "A 60-person pet brand in Austin that switched 3PLs in March" is a name in everything but spelling.

The fourth is the one founders miss. Anonymization only works if the reader who matters can't reverse it, and in a small category that reader usually can.

Most founders land at 15-40 rows once they look back over a year. That's an afternoon of work, not a project.

The five fields

1. Who granted it, by name and role. Not "the client." The actual person, their title, and whether they had the authority to say yes. This field alone would have saved our client. A marketing lead can reasonably approve a quote. She probably can't approve publishing the company's conversion rate, and nobody asked.

2. What exactly was approved. Permissions are narrower than founders remember, so break it into the four parts: name, logo, numbers, quote. "Yes, you can mention us" is permission to name. It is not permission to publish their CVR. When we go back through client archives, the most common gap is a post that had permission to name a company and then used its numbers.

3. Where the approval lives. A link to the email, the doc comment, the signed case study release. Not a Slack DM. Slack workspaces get archived, DMs belong to people, and contractors leave. If the only record of consent is in a thread you won't be able to open next year, you don't have a record.

4. The condition it depends on. Almost every permission quietly depends on something staying true: "while they're a client," "until they announce the raise," "as long as it's anonymized to the category," "this quarter only, before the retail launch." Write the condition down, because the condition is what expires.

5. Where it's published. Every surface the claim now lives on: the post, the newsletter, the About section, the sales deck, the podcast episode. If you run a claim register this is the same column, and for the same reason. Revoking a permission means finding every copy, and you can't find copies you never listed.

Permissions expire on events, not dates

This is the part that surprises founders. Almost nobody's permission comes with an end date. It ends when something happens:

  • The client churns. A former client doesn't want their results in a vendor's archive, especially if they're now working with a competitor of yours.
  • The approver leaves. Consent was a relationship with a person, and the person is gone. Their successor never agreed to anything.
  • The company is acquired or raises. New owners, new comms policy, and suddenly the 2024 revenue figure you published is a number their board didn't approve.
  • A dispute starts. A post that was a warm case study in April reads very differently in September if you're arguing about an invoice.
  • Your own employee leaves. "Our ops lead found this" was a nice credit while she worked for you. It becomes an awkward one if she's now job-hunting and the post makes her previous role sound smaller than it was.

So we don't review the register on a calendar. We check it when one of those events happens. Clients tell us when an account churns, when a key contact leaves, or when a supplier relationship goes bad. That takes five minutes against the register instead of an unbounded search through two years of posts.

What to do when a row goes stale

Default to editing, not deleting. On LinkedIn, removing the name and numbers while keeping the mechanism usually preserves 80% of the post's value. "A supplement brand cut returns from 11% to 7%" becomes "a supplement brand we worked with cut returns by roughly a third." The lesson stays, and the part they own goes.

When someone asks, act within 24 hours and don't argue. Even if you're certain you had permission. Being right about a Slack message from 2025 is worth nothing next to being the founder who made a former client chase them. How you handle a revocation request travels further than the post ever did.

Re-confirm before reusing. The riskiest moment is not the original post. It's the re-run, the deck slide or the podcast answer eighteen months later, when the founder repeats a result from memory under permission that lapsed a year ago. Before any rewrite of a proven post, check the row.

How we set it up with clients

Three rules, all introduced in the first month, because retrofitting consent onto an archive is much harder than capturing it as you go:

  • Ask in the same thread as the draft. Send the actual paragraph, not "mind if we mention you?" People approve what they read, not what they imagine. It also puts the approval next to the exact wording.
  • Default to a count, not a name. "Across the four supplement brands we onboarded this year" is often stronger than one named example, needs no permission, and can't expire. Save names for the stories where the name does real work.
  • The founder owns the register, not the writer. We maintain the log, but consent comes from the founder's relationships. We can draft the request. We can't be the one who knows the approver left in January.

FAQ

Isn't this what the disclosure ladder already covers? No. The disclosure ladder decides how much of your own business you reveal. The permission register tracks consent for other people's information. You can get your own disclosure exactly right and still publish a client's numbers you had no right to.

What about customer reviews and DMs? A public review is quotable, but naming the reviewer usually isn't worth it. Private DMs and emails from customers need a row like anything else. Screenshots of private messages, even cropped, are the single most common thing we ask founders to take down.

Do I need written permission for a positive mention? For naming a company in a flattering context, usually not. Once you add numbers or a quote, get it in writing. The test is simple: would they be surprised to see this? If yes, ask.

We have two years of posts and no register. Where do we start? Not with the archive. Start with every new post this week, then run one pass over the posts that name a client and use their numbers. That's typically a dozen rows, and it's where the risk sits.

Content that names real businesses is the content that works for ecommerce founders. The register doesn't make you more cautious. It makes you able to be specific without carrying a quiet liability in your archive. If you want a content system built around the material only you have access to, talk to us.

Ready to turn your LinkedIn into a revenue channel?

We write operator-level content for e-commerce founders. No fluff. No generic posts. Just content that drives pipeline.

Book a Strategy Call