What Legal Permissions Do I Need Before Publishing a Customer Testimonial? Complete Guide
Contents
- The permission people forget is not the quote
- What you actually need permission for
- The cleanest version of consent is boring
- If sales collected it on a call, do not wing the follow-up
- Bigger companies have a second approver, and it is usually not the buyer
- If they change jobs, the permission does not automatically travel with them
- Approval emails are useful. Release forms are harder to argue with
- Don’t ask for the quote and ignore the rest
- International customers change the rules faster than most teams expect
- The practical answer for B2B SaaS teams
- What to do next
#The permission people forget is not the quote
A customer saying, “This saved us hours,” is not the same thing as having the right to publish it.
That’s the mistake that causes the most pain in a B2B SaaS customer quote approval process. Teams get the quote, paste it into a landing page, then legal, procurement, or the customer’s comms team asks the obvious question: who approved this, exactly, and for what use?
If you want to avoid takedowns, awkward escalations, and last-minute rewrites, treat testimonial permission as a small rights package, not a single yes. The words matter, but so do the name, title, company, logo, headshot, recording, screenshot, and where the quote will appear.
Key takeaway: if you cannot explain, in one sentence, what the customer agreed to, where it will appear, and whether their company is named, you do not have clean testimonial consent yet.
#What you actually need permission for
At minimum, you need permission to use the testimonial itself, plus any identifying details attached to it. In practice, that usually means:
- the quote or paraphrase
- the customer’s name
- their job title
- their company name
- the company logo
- a headshot
- any recording of the call
- screenshots of their product use, dashboard, or results
- case study details that reveal business information
The one that most often triggers a takedown is the logo, followed closely by the company name when the buyer is in a regulated or conservative industry. A lot of people will tolerate a quote being used. They get much less comfortable when their brand mark is on your homepage or their employer is named in an ad.
That is why testimonial rights are broader than “can we use this quote?” They are really about publicity rights, copyright in the recording or transcript, privacy, and, in some cases, employer approval.
If you are also building trust content around case studies, this is the same reason What Should I Include in a Case Study? Trust Checklist matters. The story is not complete until the permissions are.
#The cleanest version of consent is boring
A testimonial release form is usually the cleanest option because it spells out the scope in one place. A simple approval email can work, but it survives legal review less often because it is usually vague, scattered across a thread, and missing the parts people care about later.
Here is the practical difference in a B2B SaaS customer quote approval process:
| Permission format | What it usually covers | How it holds up in review |
|---|---|---|
| Approval email | “Yes, you can use this quote” | Fine for low-risk website use, often weak if the customer is large, regulated, or the use is paid media |
| Testimonial release form | Quote, name, title, company, logo, image, recording, channels, duration | Much more likely to survive legal, procurement, and brand review |
If you are publishing on a website and the customer is small, an approval email plus a clear reply can be enough in practice. If you are using the testimonial in ads, on a homepage, in a PR release, or with a recognisable logo, get the release form signed.
That is the part teams skip because it feels slower than just sending the quote for a thumbs-up. It is slower. It is also the reason you do not spend the next month chasing down a “please remove our logo” email.
#If sales collected it on a call, do not wing the follow-up
Sales teams often capture the best line on a call. That is normal. The mistake is turning that verbal praise into published copy without converting the moment into written consent.
The cleanest move is simple:
- Pull the exact quote from the call transcript or notes.
- Send a short email with the quote in context.
- Ask for written approval of the quote and the specific uses.
- If the use is public, paid, or branded, attach a testimonial release form.
A message like this is enough:
Thanks for the call, and for sharing this feedback. We’d love to use the quote below on our website and in sales materials. Please reply with “approved” if you’re happy for us to publish it, and let us know whether we can include your name, title, company, and logo.
That is usually better than asking them to rewrite it. You are not asking for more work. You are asking them to confirm what they already said.
If you want to make this less manual, Customer Story Collection is built for exactly this kind of handoff. It gives customers one link, captures the story in a guided conversation, and turns it into polished testimonial material without the back-and-forth that kills momentum. For busy founders and customer success teams, that saves a lot of chasing.
#Bigger companies have a second approver, and it is usually not the buyer
This is where the B2B SaaS customer quote approval process gets messy. The person who loves your product is often not the person allowed to approve public statements.
At larger companies, the chain usually looks like this:
- the user or champion approves the substance
- marketing or comms approves the wording and brand use
- legal or privacy reviews anything public
- procurement may care if the testimonial sits inside a broader commercial agreement
Do not assume the champion’s enthusiasm is enough. If they say, “Sure, no problem,” but the company later objects to the logo or title, you will lose the argument.
The safest path is to ask for two things separately:
- approval from the individual for the quote and their personal attribution
- confirmation that they have authority, or internal clearance, to let you use the company name, logo, and role
If they cannot approve that themselves, ask them to forward the draft to the right person. That is not being difficult. It is how you avoid publishing something that gets pulled after launch.
#If they change jobs, the permission does not automatically travel with them
This comes up more than people expect. A customer approves a quote while they are at Company A, then leaves two months later. Can you keep using the testimonial?
Usually, yes, if the permission was granted for the testimonial and the use was not tied to their employment status in a way that makes the context misleading. But you should check the original approval language.
The real issue is not whether the quote still exists. It is whether the attribution is still accurate. If the testimonial says, “As Head of Operations at Company A, I used this tool to cut reporting time,” and they are no longer there, that may still be usable if it reflects their experience at the time. But if you keep implying they currently endorse you in that role, that is where it gets shaky.
In a clean B2B SaaS customer quote approval process, I would do this:
- keep the original permission on file
- update the attribution if the person asks
- remove the company logo if the company no longer wants to be associated
- re-confirm use if the testimonial is being repurposed into a new campaign, ad, or case study
If the quote is strong and evergreen, keep it. Just do not pretend the same approval covers every future use forever. That is where testimonial compliance gets sloppy.
#Approval emails are useful. Release forms are harder to argue with
Teams often ask whether they really need a testimonial release form or whether an email is enough. The honest answer is that an approval email is often enough until it is not.
An email thread can survive if:
- the use is low risk
- the customer is small
- the quote is anonymous or lightly attributed
- the channel is a website or sales deck, not paid media
A release form is the better bet if:
- the customer is enterprise or government
- the testimonial will appear in ads
- the logo, headshot, or recording is included
- the customer is in a regulated sector
- the testimonial may be translated, edited, or republished later
That is why legal teams prefer the form. It is clearer on rights, duration, channels, and revocation. It leaves fewer gaps for someone to argue about later.
If your team is trying to build trust without sounding like you are bragging, How Do I Write Trust-Building Content Without Bragging? is worth a look. Permissions and tone are linked more tightly than most teams realise. The more credible the story, the less you need to oversell it.
#Don’t ask for the quote and ignore the rest
The most common failure mode is not the quote. It is the extras.
Teams get written approval for the words, then forget to ask about:
- the company logo
- the headshot
- the job title
- the recording
- screenshots from the product
- the customer’s name in paid ads
- the case study itself if it includes internal metrics or implementation detail
The logo is the one that most often causes a takedown. A customer may be happy to be quoted. They may not want their brand mark sitting next to your pricing page, especially if their legal team never saw it.
Paid ads are the other trap. A testimonial on your website is one thing. The same quote in a LinkedIn ad is another. That is where testimonial disclosure and consent need to be explicit, because the customer is no longer just being cited, they are being used to persuade strangers at scale.
If you are building a trust-first content system, How do you recover when reviews are positive overall but the newest reviews mention the exact objections hurting conversion? goes into the same problem from the other side. The point is not to collect praise. The point is to use it in a way that can survive scrutiny.
#International customers change the rules faster than most teams expect
If you work with customers outside Australia, the permission step that changes most is how you handle personal data and marketing consent.
In plain English, the biggest shift is this: some jurisdictions care not just that the customer approved the quote, but that you have a lawful basis to store, process, and publish their personal information. That can include their name, title, photo, voice, and any identifiable details in the testimonial.
What teams usually miss until launch day:
- consent wording that is fine in one country but not another
- rights to withdraw consent
- whether the testimonial can be transferred across borders
- whether the customer’s employer has separate approval requirements
- whether the ad platform use needs a different disclosure than the website use
If you are publishing globally, the safest move is to separate the permissions by use:
- website
- sales deck
- social post
- paid ad
- case study
- recording or clip
- logo and brand assets
That way, if one use gets blocked, you do not lose the whole testimonial.
#The practical answer for B2B SaaS teams
If you want a process that actually holds up, use this order:
- Capture the quote.
- Ask for written approval of the exact wording.
- Ask separately for name, title, company, logo, headshot, and recording rights.
- Clarify the channels, website, sales deck, social, ads, case study.
- For enterprise or international customers, route it through the right internal approver.
- Store the approval where your team can find it later.
That is the B2B SaaS customer quote approval process in real life. It is not glamorous. It is also the difference between a quote you can use once and a testimonial asset you can keep using safely.
#What to do next
Pull your last three testimonials and check them line by line. If you cannot find a written yes for the quote, the attribution, the logo, and the channel it appears on, fix that before you publish another one.
If you want the faster path, use Customer Story Collection to collect the story and permission in one flow, instead of stitching it together from call notes and email replies. It is a cleaner way to turn praise into something you can actually publish.



