Creative operations guide for D2C brands
Add AI Provenance to Every Ecommerce Asset Handoff
An AI-generated ad asset labeling workflow should treat provenance as structured handoff data, not as a filename, watermark, or publishing toggle. Classify each asset component, retain its source materials, verify metadata in the delivery file, decide disclosure requirements by destination, and record what the publisher actually submitted.
Direct answer
The practical workflow
Use four internal provenance categories: human-made, AI-assisted, substantially AI-edited, and AI-generated. Apply them separately to images, backgrounds, video, voices, music, copy, product titles, and descriptions. At intake, record the AI tool or feature, source files, synthetic elements, metadata status, rights documentation, intended channels, disclosure decision, reviewer, and approval state. Before publication, inspect the final exported file rather than trusting the editable master. Create a separate disclosure decision for every asset, destination, and relevant geography. After publishing, save the platform asset ID, disclosure state, submitted feed data, publisher, timestamp, and any rejection or remediation notes. This makes provenance durable enough to survive creator, agency, editor, ecommerce, and media-buyer handoffs.
01
1. Why provenance has to survive the full handoff
A label attached only at the end of production is too fragile for a multi-person ecommerce workflow.
A typical D2C asset can pass from a founder to a freelance creator, designer, editor, agency, ecommerce manager, and paid-media buyer. Each person may create a new file, change the format, remove metadata, or publish to a destination with different disclosure controls. If the only provenance record is _AI in a filename or a message in a project thread, the publisher may not know what was generated, what was merely enhanced, or which source materials support the classification.
Platform requirements also concern different parts of the handoff. Google Merchant Center directs merchants to retain embedded IPTC DigitalSourceType metadata for images created with generative AI. It also provides structured handling for AI-generated product titles and descriptions. TikTok's advertising policy, meanwhile, requires an AIGC label or clear disclosure for completely generated or significantly AI-edited ads.
The operational response is to make provenance a record that follows the asset. That record should describe the master, its ingredients, each relevant component, the delivery rendition, the applicable destination decision, and the final publication state. A visible disclosure may be one output of the record, but it is not the record itself.
02
2. Adopt a four-category house taxonomy
Use a simple internal vocabulary, then retain more detailed component-level facts underneath it.
These categories are operational definitions for your team. They are not claims that every platform, metadata standard, or jurisdiction uses the same thresholds. The objective is consistent routing: two reviewers looking at the same production history should usually assign the same internal category.
Human-made: The component was captured or created without generative AI. Conventional editing can remain in this category when it does not introduce generated content. Record important editing steps even when no AI disclosure review is expected.
AI-assisted: AI supported ideation or performed a minor enhancement without generating or materially changing the represented subject. Examples can include denoising, sharpening, or background removal. TikTok lists lighting adjustments, background removal, and denoising as examples of insignificant edits, but that platform-specific treatment should not be generalized into a universal exemption.
Substantially AI-edited: Real or human-created source material remains, but generative AI materially changes what a viewer sees or hears. Examples include making a person appear to perform an action they did not perform, cloning speech, or using generative inpainting to add a material product-use scene. Route this category to disclosure review by default.
AI-generated: A trained model generated the primary image, video, audio, or text component. This includes a generated lifestyle image even when a real packshot is composited into it. It can also include a generated product title while the accompanying product photograph remains human-made.
The IPTC Digital Source Type vocabulary offers more precise values, including concepts for algorithmically enhanced media, trained-algorithmic media, and composites involving synthetic content. Use those values where a destination or metadata process requires them; do not force the four-category house taxonomy to replace the underlying standard.
03
3. Classify components, not only the campaign
A single campaign-level AI flag hides the distinctions a publisher needs.
A video may contain human-shot footage, a substantially altered background, an AI-generated voice, licensed music, and human-written captions. A product listing may pair a real image with a generated title. Recording only AI-assisted campaign does not reveal which platform rule applies to which field.
Create a component record for the visual subject, background or environment, spoken voice, music and sound, on-screen copy, product title, product description, and any testimonial or endorsement. If a component contains multiple treatments, record those details rather than overwriting them with a single broad label.
For routing, use the highest relevant category as the asset-level status. For example, an ad with human-shot footage and a cloned voice can be routed as substantially AI-edited while its component record still says the footage is human-made. This preserves nuance without allowing a material synthetic element to disappear from review.
- List every publishable component in the intake form.
- Assign one of the four house categories to each component.
- Describe the generated or modified element in plain language.
- Set the asset-level routing category to the highest material component category.
- Keep the component classifications attached to every later version.
04
4. Make provenance and disclosure separate decisions
Provenance explains how an asset was made; disclosure records what a particular destination requires you to do about it.
Do not use one checkbox called AI. It conflates production history, internal policy, platform requirements, geography, and publication status. Instead, store provenance once and create disclosure decisions for each asset × destination × geography combination.
For TikTok paid ads, completely generated media and real media significantly modified by AI require an AIGC label or clear disclosure under the cited policy. TikTok says undisclosed AIGC may be rejected or restricted. Its Ads Manager disclaimer documentation describes an AI-generated-content disclaimer for in-feed ads. Record whether the platform control was required, selected, and visible after publication.
For Google Merchant Center, the workflow is different. Generative-AI images should preserve the appropriate embedded IPTC DigitalSourceType. AI-generated titles and descriptions should use the relevant structured title or description handling with digital_source_type set to trained_algorithmic_media, according to Merchant Center's AI-generated content guidance.
Do not burn one universal watermark into every master. Merchant Center's product-image guidance restricts promotional overlays and watermarks. Maintain a clean master, preserve required embedded metadata, and generate destination-specific renditions or disclosures.
- Choose the destination and target geography.
- Compare the component record with that destination's current policy.
- Record
required,not required, orescalate—never leave the decision implicit. - Specify the method: metadata, feed attribute, platform toggle, caption, watermark, sticker, or another approved treatment.
- Record the policy URL and review date because platform instructions can change.
05
5. Build a minimum viable asset-intake record
Require enough information to reconstruct what happened without turning intake into an unusable questionnaire.
The creator or agency should submit the editable master, final flattened export, original photographs or footage, audio, product renders, and other source ingredients. Ask for the tool, model or feature when known, generation or edit date, prompt or concise prompt summary, and a description of synthetic elements. If people, voices, trademarks, creator content, music, or third-party materials appear, attach the applicable permission or rights status.
C2PA calls the source assets used to create a composed asset its ingredients. Its Content Credentials explainer describes how provenance can represent an asset history and the ingredients used to produce it. C2PA can provide a richer, cryptographically verifiable record, but your intake workflow should still expose the critical facts to reviewers who do not inspect a manifest.
Use controlled values where consistency matters. For metadata status, useful values include not_applicable, present_unverified, verified_in_master, verified_in_delivery_file, externally_linked_manifest, missing, stripped_during_export, and stripped_after_upload. Free-text notes can explain exceptions.
- Record
asset_id,asset_version, andparent_asset_id. - Record
asset_type, asset-level provenance, and component provenance. - Record the AI tool, model or feature, date, and human oversight.
- Link source files, editable masters, prompts or prompt summaries, and rights evidence.
- Record metadata standard, status, validation date, and validator.
- List target channels and geographies.
- Record the disclosure requirement, method, policy basis, reviewer, review date, and approval status.
- After publishing, add platform IDs, disclosure evidence, publisher, timestamp, and remediation notes.
06
6. Validate metadata in the file that will actually ship
Metadata present in the master does not prove that it survives in a resized, flattened, or uploaded rendition.
For a Merchant Center image created with generative AI, inspect the submitted image for its embedded DigitalSourceType. Confirm that the value fits the image's actual production history, preserve the tagged original, and record who performed the check. A filename such as hero_AI_v4.jpg is not a substitute for embedded metadata.
Run validation after any operation that creates a new file: flattening, resizing, transcoding, localization, agency transfer, ecommerce upload, CDN transformation, or platform ingestion. If a process strips the metadata, mark the rendition as failed rather than silently inheriting the master's verified status.
C2PA Content Credentials can record origins, edits, software agents, and ingredients. The C2PA technical specification is useful when your tools support it. Treat C2PA and required IPTC fields as complementary where appropriate: one does not excuse you from checking the specific field or submission method required by the destination.
Keep master storage and delivery validation connected. ATIYO's approach to uploading and storing assets in the Vault can support the source-file side of this process, while the team still needs to inspect the external delivery file and platform submission.
- Hash or uniquely identify the approved master.
- Export the destination-specific rendition.
- Inspect the rendition's embedded metadata.
- Compare the rendition with the approved visual and source record.
- Upload it to the destination.
- Where practical, retrieve or inspect the delivered version again.
- Record the result against that exact version—not against the campaign generally.
07
7. Use explicit human review gates
AI disclosure does not replace creative, claims, rights, or publishing review.
First, creative review should confirm that the export matches the brief, brand direction, and real product. Generated scenes can accidentally alter package text, product proportions, colors, included accessories, or expected use. A brand reference should therefore be available to reviewers; teams using ATIYO can keep that direction connected through the Brand Bible workflow.
Second, provenance review should compare the assigned category with the source files and tool record. Third, claims review should inspect whether the generated scene implies unsupported performance, results, product size, endorsements, or availability. TikTok's policy separately addresses misleading claims and mismatches between an ad and its landing page; an AI label does not make a misleading representation acceptable.
Fourth, identity and rights review should check likeness, voice, creator, music, trademarks, and source-material permissions. Fifth, platform review should select the required metadata, feed attribute, label, or disclaimer. Sixth, geography review should flag destinations requiring additional handling. Finally, the publisher should confirm that the live platform configuration matches the approved record.
Assign named owners. A practical division is creator for intake completeness, creative lead for fidelity, compliance or designated policy reviewer for disclosure, and publisher for platform evidence. Small founder-led teams may combine roles, but each gate should still have a named person and date.
- Reject incomplete source or tool records before creative approval.
- Require a factual-product check against current product materials.
- Require rights escalation when a real person's likeness or voice is involved.
- Approve disclosure by destination, not globally.
- Require the publisher to return platform evidence after launch.
08
8. Worked example: real packshot in an AI lifestyle scene
Treat the product, generated environment, copy, and publishing renditions as separate components.
Suppose a skincare brand supplies a human-shot packshot. A designer places it in a generated bathroom scene, uses generative fill to create reflections, writes the headline manually, and removes minor dust from the original product photograph with an automated retouching feature.
The product packshot can be recorded as human-made, with the dust cleanup noted as AI-assisted. The bathroom and reflections are AI-generated. The composite asset should route at the highest material category: AI-generated or substantially AI-edited, depending on how the final composition was produced and how the applicable standard describes it. The headline remains human-made.
The intake record links the packshot, editable composition, flattened master, tool and feature, prompt summary, and product reference. A reviewer checks that the generated reflection does not change the label, cap, color, scale, or amount of product shown. Another reviewer determines the destination treatment.
For a TikTok paid-ad rendition, the record may say disclosure required, with the approved AIGC label or disclaimer method. For a Merchant Center rendition, the record focuses on preserving the appropriate IPTC DigitalSourceType in the submitted image. The team should not assume that a disclosure sticker burned into the TikTok export belongs on the Merchant Center product image.
After publication, the publisher records the TikTok creative ID and selected disclaimer state. For Merchant Center, the publisher records the submitted file or URL, feed handling, and metadata validation result. Both records point back to the same master but retain different destination decisions.
09
9. Audit the live publication, not just the approval
Approval proves intent; publication evidence shows what was actually shipped.
Save the platform asset or creative ID, campaign and ad ID where applicable, disclosure-toggle state, screenshot of any visible disclosure, feed payload or structured attribute, submitted file hash or URL, publisher, and timestamp. Record rejection, restriction, resubmission, or remediation notes as new events rather than overwriting the original decision.
For TikTok Spark Ads, keep commercial-content disclosure and AI disclosure as separate checks. TikTok provides a distinct commercial content disclosure setting for content promoting a brand, product, or service. One disclosure should not be treated as proof that the other requirement was addressed.
Schedule lightweight audits after major export-pipeline changes, new agency onboarding, localization, or policy updates. Sample live assets and compare them with their approved record. The goal is to detect systemic problems—for example, a transcoder stripping metadata or publishers repeatedly missing a destination field—rather than merely blaming individual operators.
- Confirm the live creative matches the approved rendition.
- Confirm required disclosure controls were selected.
- Capture visible or platform-level evidence.
- Check the delivered file or feed field when applicable.
- Record rejection and remediation history.
- Feed any recurring failure back into the intake checklist or brief.
10
10. Put the workflow into a creative operating system
The record should live beside the brief, asset versions, approvals, and learnings rather than in a disconnected spreadsheet.
A workable system connects the roadmap item, creative brief, brand context, source ingredients, master, renditions, reviews, publication records, and later learning. That lets a new editor understand why an asset was classified a certain way and helps a publisher find the correct version without searching through chat threads.
ATIYO is a Django/Postgres creative-strategy operating system for founder-led ecommerce brands, creators, and dropshippers. It organizes roadmaps, briefs, brand context, assets, iterations, and reusable learnings. Its Brain is bring-your-own-key through OpenRouter. Teams can use ATIYO to preserve the creative context around a provenance workflow, while external metadata inspection and platform configuration remain separate operational tasks.
ATIYO does not connect to ad accounts, buy media, calculate ROAS, or automatically know performance. Media performance remains in the ad platform. ATIYO preserves the creative context and learnings behind each asset. If a result or policy outcome matters to future creative decisions, a user must record it.
The broader creative operations software approach is useful when provenance is one part of a repeatable brief-to-publication process. The product should not be treated as a platform-policy enforcement engine. A named reviewer and publisher remain responsible for checking current requirements and the live submission.
11
11. Copyable handoff template
Use this compact record as a starting point and expand it only when your risk, channels, or production methods require more detail.
Keep controlled values in dropdowns and attach free-text notes only where context is necessary. Make the creator complete production-history fields, the reviewer complete policy fields, and the publisher complete live-submission fields. That ownership prevents one person from guessing at every stage.
```text Asset ID / version: Parent asset ID: Asset type: Master location: Delivery-file location: Asset-level provenance: Component provenance: - Product or primary subject: - Background/environment: - Video manipulation: - Voice: - Music/sound: - On-screen copy: - Product title/description: AI tool, model, or feature: Generation/edit date: Prompt or prompt summary: Synthetic elements: Human oversight: Source ingredients: Rights/likeness status: Metadata standard/value: Metadata status: Validated file/version: Validator/date: Destination/geography: Disclosure required: required / not required / escalate Disclosure method: Policy basis and review date: Reviewer/date: Approval status: Platform asset/creative ID: Disclosure state after publication: Published file URL/hash or feed evidence: Publisher/timestamp: Rejection or remediation notes: ```
Frequently asked questions
Questions about this workflow
Is every use of AI subject to the same disclosure requirement?
No. Platforms distinguish between different uses and may apply different thresholds. TikTok, for example, distinguishes completely generated or significantly modified content from minor changes such as denoising or background removal. Record the actual production history first, then make a destination-specific disclosure decision.
Can we label an entire campaign as AI-assisted?
You can use a campaign-level status for routing, but it should not replace component records. A campaign can contain a generated title, human-made packshot, synthetic voice, and substantially edited video. Those components can trigger different metadata or disclosure treatments.
Is `_AI` in the filename enough?
No. A filename can help humans search, but it does not replace embedded metadata, feed attributes, platform labels, source documentation, or a review record. It can also be changed or lost during handoff.
Should we add a visible AI watermark to every asset?
Not automatically. Disclosure methods vary by destination, and Merchant Center product-image guidance restricts promotional overlays and watermarks. Keep a clean master and create destination-specific treatments based on current requirements.
What if metadata exists in the editable master?
Inspect the final delivery file as well. Exporting, resizing, flattening, transcoding, uploading, and other transformations can create a new rendition. Record metadata verification against the exact file that will be submitted.
Does an AI label make a generated product claim acceptable?
No. Disclosure and truthfulness are separate reviews. A labeled asset can still misrepresent product size, appearance, performance, endorsements, availability, or the relationship between the ad and landing page.
Can ATIYO determine whether a platform requires disclosure?
ATIYO can preserve the brief, asset context, review decision, iterations, and recorded learnings. It is not a platform-policy enforcement service and does not inspect or configure ad accounts. Your reviewer should consult current platform guidance, and your publisher should record the live configuration.
Does ATIYO report whether AI-labeled ads perform better?
No. Media performance remains in the ad platform. ATIYO preserves the creative context and learnings behind each asset, and users can record relevant outcomes for later creative work.
Primary and official sources
Sources used in this guide
External product facts were checked against the organizations’ own documentation. Features can change; confirm current details before making a purchase or campaign decision.
- Google Merchant Center Help — AI-generated content Consulted for generative-AI image metadata and structured title and description requirements.
- TikTok Advertising Policies — Misleading and false content Consulted for AIGC disclosure thresholds, examples of significant and insignificant edits, and related misleading-content rules.
- TikTok Ads Manager — About ad disclaimers Consulted for the AI-generated-content disclaimer available for in-feed ads.
- Google Merchant Center Help — Image link Consulted for product-image requirements concerning overlays and watermarks.
- IPTC — Digital Source Type vocabulary Consulted for standardized concepts describing human, algorithmically enhanced, synthetic, and composite media.
- C2PA Technical Specification 2.4 Consulted for Content Credentials capabilities, including provenance assertions and ingredients.
- C2PA Content Credentials Explainer Consulted for the explanation of ingredients and asset provenance history.
- TikTok — Commercial Content Disclosure setting Consulted to distinguish commercial-content disclosure from AI-content disclosure.
Move the plan out of scattered sheets
Run the roadmap, briefs, assets, and learnings in ATIYO.
ATIYO keeps the brand context and production decisions connected. It does not buy media, connect to ad accounts, or invent performance results.