DrawDogChain of custody for creative work

Notes

How to prove to a client you actually made the work

Five kinds of evidence that a piece was made by hand, what each one actually proves, where each one can be faked, and how to send them before anyone asks.

September 2, 20266 min readDrawDog

Three years ago nobody asked. You sent the file, they paid the invoice, and the only question about process was whether you could turn the revisions around by Friday. Now a good chunk of art directors have been burned at least once by a "concept artist" whose portfolio was a Midjourney feed, and the question has changed. It is rarely asked out loud. It sits underneath the brief, in the slightly-too-careful wording of "we're looking for a really hand-crafted feel," and it decides whether you get the second job.

You can't argue your way out of that suspicion. You can only show your work. Here is what showing it actually means, evidence by evidence, including the part most advice skips: where each kind of proof can be faked, and therefore how much weight a sceptical client will really give it.

The layered source file

The classic. Send the PSD, the CLIP file, the Procreate document with its 140 layers, and the client can open it and see the sketch under the lines under the flats under the rendering. It's tangible. Art directors who came up through studios trust it instinctively because it's the thing they used to hand each other.

What it proves: that the file was assembled in layers, in an editing app, by someone who knew what they were doing.

Where it fails: a layered file can be built after the fact. Generate an image, drop it in as a base, trace the lines onto a layer above, block the colours onto another, hide the original. Twenty minutes of work and you have a "process file" that opens beautifully. Any client who has thought about this for more than a minute knows it, which is why the source file alone has quietly stopped being enough. Send it anyway. It's still the most natural thing to hand over, and it takes you zero extra effort.

Work-in-progress shots

Four or five screenshots or photos taken along the way: the thumbnail, the rough, the mid-render with half a face still flat, the finished piece. Cheap to make, and clients love them because they tell a story.

What it proves: that intermediate states existed at some point.

Where it fails: intermediate states can be reverse-engineered. Take the finished image, paint out detail, blur, desaturate, save as "rough". It's harder than the layer trick and produces slightly wrong-looking roughs to a trained eye, but it works well enough on a phone screen. The stronger version is WIP shots that carry their own timestamps: an Instagram story from three days before delivery, a message thread with the client where you shared the rough on Tuesday. The timestamps are the proof, not the pictures.

The timelapse

Procreate records one by default. Clip Studio and Photoshop can with a little setup. A four-hour session collapses into forty seconds of the piece appearing out of nothing, and it is far and away the most persuasive thing you can put in front of a doubtful client, because it looks like watching a person work.

What it proves: that a sequence of strokes was made, in that order, in that app.

Where it fails: a timelapse can be replayed. Put a generated image on a hidden reference layer, trace over it stroke by stroke on the visible layers, export the recording, delete the reference. The result is a genuine recording of a hand tracing a machine's output. Nothing in the video reveals the reference layer. This is the retype attack, and every kind of process evidence is vulnerable to it, because the person really did do the work. They just did it as a copy.

That's worth sitting with for a second. There is no evidence of process that a sufficiently motivated person can't manufacture by doing the process. The honest goal isn't to make faking impossible. It's to make faking cost more than the job pays.

Version history

Dropbox, iCloud, and Google Drive keep old versions of files. Figma and Adobe's cloud documents keep them with named checkpoints. Most people never look at this panel, which is exactly why it's decent evidence: it accumulates without anyone thinking about it.

What it proves: that the file changed over a span of real time, in steps, with sizes and dates recorded by a third party who has no reason to lie for you.

Where it fails: it's coarse. Dropbox keeps a version per save, not per stroke, and if you work for six hours and save twice, you have two data points. It also lives in a service the client has to trust and often can't see directly, so you end up sending screenshots of the version panel, which loops back to the WIP-shot problem. Still, of the things you already have, this is the one that's hardest to fake convincingly, because faking it means faking the cloud provider's records.

A process record

This is the newer category, and it's the one DrawDog sits in, so read this section as coming from a company with a product to sell. A process record is a small app that watches your project folder while you work, notes each time the file changes and how big it got, notes which application was in front, and at the end signs the whole log and gets it timestamped by a public authority. The client gets a link. They can drop the file you sent onto it and confirm it's the exact file the record describes.

What it proves: that a file grew in a particular pattern over a particular span of time, while particular apps were open, and that this record hasn't been edited since. Because a third party timestamped it, "when" isn't your word either.

Where it fails: same retype attack as everything else. Trace a generated image inside a watched folder and the record shows a real, organic-looking process, because one happened. What it does add over the other four is that it's honest about the gap. A decent record says on its face what it can't see, marks time in a browser as unattributed rather than innocent, and refuses to call a session "certified" if it didn't see enough. That refusal is the point. A proof that can only ever say yes isn't a proof.

Send it before they ask

Whatever mix of the above you use, the timing matters more than the format. Evidence that arrives after a client raises the question reads as defensive, however good it is. Evidence that arrives with the delivery, unprompted, reads as professionalism, and it quietly answers the question before it's asked.

So the delivery email gets a second paragraph. Something like: "Source file and a short timelapse are in the folder too, in case anyone on your side wants to see how it came together." One sentence. It costs nothing, it pre-empts the awkward call, and it marks you as the person who understood what clients are worried about this year without being asked. The illustrators who do this consistently are going to keep getting the second job. The ones waiting to be asked are going to keep having the conversation covered in the next piece, and it's not a fun one.

If you want the process-record version of this, here's what one looks like, including the part where it declines to certify a session it didn't see enough of.