Consider a paragraph any consultant could write, invented for this article but shaped like a thousand real ones:
“A retail client of mine — one of the largest in their country — spent eighteen months on a replatforming effort that stalled. When their CTO left last spring, the new leadership asked us to assess what went wrong. The answer was painful: the vendor they’d chosen over our objections had never run at their scale.”
No names. Fully anonymized, by the standard most writers apply. Now count what it discloses: the industry, the approximate size, the country framing, the project type and its duration, the timing of an executive departure, the fact that an assessment happened, its conclusion, and the existence of a disagreement about a vendor. Any employee of that client recognizes the company by the second clause. Any competitor can shortlist candidates from public CTO-departure news. The vendor recognizes themselves, and now knows the writer called their capability into question in public.
Removing the names removed nothing that identifies and nothing that harms. The scenario is the fingerprint. Specifics identify in combination long before any name appears, and the more interesting the story, the more identifying its shape, because what makes a story interesting is exactly its specificity.
I write about my own work under real constraints: engagements I do not discuss, conversations that stay in rooms, an archive of published material that names some relationships and deliberately never names others. What follows is the discipline I actually use. Five tests, run in order, on any draft that touches real parties. They replace both of the standard non-answers: “change the names” (which fails as shown above) and “when in doubt, cut everything” (which fails differently, by starving your writing of the lived material that makes it worth reading).
Test one: precedent
Have I already published this kind of fact about this party, on a surface I author?
Your own published record is the one boundary you can consult without judgment calls. If your bio has named a company as your employer for years, restating that relationship is not a new disclosure. You made that decision when you published the bio, and made it deliberately. If you have never named a client on any page you author, a draft that names them is a new decision that deserves to be made as one, not smuggled in by narrative momentum at midnight because the paragraph needed an example.
Two subtleties make this test sharper than it looks. Precedent covers the kind of fact, not the party: an employer named on your resume is precedent for the relationship (role, era, public work), not for anything that happened inside. And precedent is about your publications. That a fact about the party is public somewhere on the internet does not mean you have published it.
Test two: provenance
Where did I learn this?
Not “is this true,” not “is this public somewhere,” but where did I get it? If the answer is a private room (a client engagement, a board conversation, a confidence, a document under NDA), the fact is tainted for your use regardless of its truth and regardless of whether some version of it is publicly known. You learned it wearing a hat that came with obligations.
Provenance is the test that catches the most honest writers, because honest writers confuse “true and verifiable” with “publishable by me.” A fact can be entirely public and still not yours to state, because your statement adds what the public record lacks: confirmation from someone positioned to know. “It was in the trade press” is how writers end up confirming, under their own byline, stories they were never supposed to corroborate. When you write about parties whose rooms you have been in, you are never just a writer reporting; you are a source corroborating.
Test three: negativity
Would the party read this as anything other than positive or neutral?
Not “is it fair,” not “is it true,” not “could I defend it.” Would they, reading it with their name-detector on high alert, feel anything but fine? Any doubt fails the test. Criticism of identifiable parties is a different genre with different rules; journalism has standards and counsel for it. The writing this discipline covers (professional essays, lessons from practice, war stories) earns nothing from a negative example that a synthetic one could not teach, and risks relationships, reputation, and sometimes contracts on the difference.
The invented paragraph above fails this test twice over. The client’s project “stalled”; the vendor “had never run at their scale.” Note that it fails for the vendor, a party the writer probably never considered a subject at all. Run the test for every party the story touches, not just the one it is about.
Test four: identification
Could an outsider, an insider, or a motivated adversary narrow this to the real party?
This is the test that formalizes the fingerprint problem, and the three-reader framing is what gives it teeth. The outsider has public information and a search engine. The insider (an employee, a former colleague, a competitor who was in the deal) has context you cannot see from your desk, and will recognize combinations that look generic to you. The adversary is looking for the identification, because it is useful to them: as ammunition, as evidence, as pressure.
“A major metropolitan newspaper where I ran engineering” survives the outsider for about one search. I can write that description only because the relationship it resolves to is already all over my published biography; it passes test one, which is exactly the point. Identifying descriptions are names. Govern them identically.
If a story must be told and its shape identifies, the honest options are transformation or permission. Transformation: change industry, scale, stakes, and vocabulary together until the real party is genuinely unrecoverable, and say you did, because disguised examples presented as literal reporting cost you the credibility the story was meant to buy. Permission: ask the party, the one move that converts a risk into a relationship. Half-measures, dropping the name while keeping the scenario, are the specific thing this article exists to end.
Test five: aggregation
Do individually safe facts combine into a disclosure none of them makes alone?
The subtlest failure, because every sentence passes review and the paragraph still leaks. Watch it happen across three innocuous sentences, invented like the opener:
Your bio, published years ago, names you as an advisor to a payments company. A post last winter mentioned spending the spring embedded with a client in Northern Europe. Today’s draft observes that “an acquisition I watched up close fell through this spring.”
No sentence names anything, and each passes the first four tests alone. Together they date, place, and connect a failed acquisition to an identifiable company, and hand an insider the one fact that was never public: that you were in the room. Aggregation is why running tests sentence-by-sentence is not enough. You judge the combination, and you judge it across your whole archive, not just the draft in hand. You cannot assume this post’s readers skipped your last three; the person who reads all four is exactly the insider or adversary from test four. Serial disclosure is still disclosure. It is just disclosure on layaway.
The discipline in practice
Five tests, in order, escalating from mechanical to judgment: precedent (consult your published record), provenance (trace your source), negativity (read as the named party), identification (read as three hostile readers), aggregation (judge the combination). When any test is uncertain, the answer is not “probably fine.” The answer is ask (the party, or yourself in a calmer hour) or transform until the test passes cleanly. Uncertainty resolving to “publish” is how careful writers accumulate a public record they would not choose deliberately.
Two closing notes on what this discipline is for, because both get misread.
It is not a muzzle. It is the opposite: a decision procedure is what lets you publish near the boundary with confidence instead of avoiding the whole territory out of vague dread. The writers who share nothing from practice are not being careful; they are being uncalibrated, and their writing pays for it in vagueness. Knowing precisely which facts are yours to state is what makes the rest of the page free.
And it is not an AI topic, though AI raises its stakes. If you use an AI assistant that has read your private material (your email, your client work, your drafts), it holds facts you never published and will volunteer them fluently, in your voice, with perfect confidence. The tests do not change; what changes is that provenance now has to be asked of a collaborator with a perfect memory of every private room you have let it into. I have built mechanical enforcement for exactly that problem on the engineering side of this practice, and it is open source. But the pencil version, these five questions asked before you hit publish, is where all of it starts.
What you may publish is governed by what you have already published and where you learned the rest, never by which names appear.