How to work through it

01

Identify every input and authority

Start with the project brief and assign immutable identifiers to source assets, reference crops, prompt documents, style notes, and policy approvals. For each item, record origin, rights holder, license or permission, permitted transformation, geographic or channel limits, expiration, and responsible person. Do not collapse a mood board into one unlabeled upload: every reference needs a traceable decision. Verify that the authorized cloud account is suitable for the data classification before transfer. A social post is not authority for assets, privacy, service terms, or product capability.

02

Connect prompts, settings, and jobs

Store prompt versions as text with timestamps and editors rather than screenshots alone. Link each submitted job to the exact prompt, input versions, controls actually selected, account or workspace, operator, submission time, and available service event ID. If the interface omits a field, mark it unavailable instead of reconstructing it from memory. Preserve change reasons between attempts so reviewers can explain why an output differs. The record should distinguish creative revision, source substitution, setting change, service retry, and unknown variation.

03

Register outputs and downstream use

Assign each returned file an asset ID and retain its original bytes, checksum when appropriate, measured properties, thumbnail, linked job, and review disposition. When an editor crops, composites, retimes, or combines it, create a derivative record instead of overwriting origin. Link final use approval to the precise derivative in the released master. Document deletion or retention actions for cloud inputs and outputs according to policy. This chain proves what your team recorded; it does not certify vendor security, ownership, availability, output quality, or reproducibility beyond the observed job.