every model spec’d & versioned · harness ✓ greenchangelog →

Writing · Toolkits

Attribution Audit Worksheet

Where the badge needs to appear, in what form. The audit takes an hour and prevents most attribution failures.

By Worthune Staff · 2026-08-14

Attribution failures are rarely intentional. They happen because nobody walked the specific surfaces where the badge belongs.

Callers using a free-tier verified-math vendor typically owe some form of attribution back to the vendor. The specific requirements vary by vendor and by integration pattern; on Worthune’s free tier, embedded calculators must keep the built-in badge and API and MCP results shown to end users must carry a visible Powered by Worthune with a link. Internal tools and evaluation use require nothing.[1] This worksheet is the audit a caller can run to confirm every surface that owes attribution is displaying it correctly.

Before the audit

The audit

The remediation, when a surface fails

Common patterns that cause failures

A specific set of patterns causes most attribution failures. A design-system update that reflowed the calculator page and dropped the badge into a hidden overflow area. A performance optimization that inlined the calculator’s HTML and stripped the badge markup. A caller-built wrapper around the API that was implemented before the attribution requirements were reviewed. An assistant integration that was launched with a prompt template that did not include the vendor. Each of these is a plausible engineering decision that had an unintended attribution consequence, and each is worth checking during the audit.

The audit for callers on paid tiers

Callers on a paid tier that removes attribution requirements still benefit from the audit, but for a different reason. The audit becomes a confirmation that no residual free-tier attribution is still present in ways the caller no longer wants. Paid-tier callers with a mix of surfaces — some upgraded to paid, some still on free — particularly benefit, because the boundary between the two is a place where surfaces sometimes end up in the wrong bucket.

What the audit does not do

The audit does not verify that the attribution is legally sufficient in every jurisdiction the caller operates in. Attribution is a commercial-terms compliance question, and jurisdictions with specific advertising or disclosure rules may have additional requirements the vendor’s attribution alone does not satisfy. The audit is the specific attribution audit, not a general compliance audit.

Attribution failures are not usually deliberate. They are surfaces the last design change forgot about.

A note on attribution economics

Some callers view attribution as friction and periodically re-evaluate whether to move to a paid tier that removes it. This is a legitimate business decision, and the piece Powered-by Attribution vs. White-Label (/writing/attribution-vs-white-label) develops the tradeoff in detail. The audit worksheet is about compliance with whatever tier the caller is currently on; the tier choice itself is a different question and is worth revisiting annually.

Three surfaces the audit most often misses

The first is the archival surface. A history view that redisplays a stored envelope is arguably still an API result shown to an end user. The pricing page does not address archival display separately; the conservative posture is to keep attribution there, and the definitive answer is a question for the vendor, not an inference. Audit passes that focus on live surfaces routinely miss this one.

The second is the exported artifact. A caller that lets users download a PDF or share a link to a computed scenario is producing an end-user-visible artifact. The pricing page does not address exports separately; the conservative default is to carry attribution into the exported artifact, and the definitive answer is a vendor question. Audit passes that focus on in-app surfaces routinely miss the export path.

The third is the third-party embedding. A caller whose calculator or article is picked up by another site — a partner, a syndication feed, an aggregator — is delivering the vendor’s output through a channel the caller may not fully control. Attribution requirements do not obviously stop at the caller’s own domain. If a syndication partner strips the badge, the caller should raise it — with the partner and, if unresolved, with the vendor — rather than assume the downstream copy is someone else’s problem. Audit passes that focus on the caller’s own surfaces routinely miss what happens downstream.

The audit as a habit

The audit takes about an hour once the inventory is built and less each subsequent time. Teams that run it quarterly rather than annually catch drift closer to when it happens. The engineering cost is negligible; the reputational cost of a vendor discovering unattributed use before the caller does is nontrivial. A quarterly cadence is not overkill; it is the cadence at which drift is visible before it accumulates.

Documenting each audit

Each audit produces a small artifact: the inventory as of the audit date, the state of each surface, and any remediation applied. The artifact is stored where a future auditor — the caller’s own risk team, the vendor’s compliance function, or an external reviewer — can retrieve it. Callers who maintain the artifact year over year develop a durable record. The record is small; its value compounds because the record itself becomes the answer to any future question about when a specific surface first received attribution or when a specific remediation happened.

The audit and the vendor relationship

Vendors typically prefer to hear about attribution issues from the caller before they hear about them from anywhere else. A caller who runs a quarterly audit, finds a lapse, remediates it promptly, and mentions it in the next vendor conversation is a caller the vendor extends more trust to than a caller who was never audited and gets notified about a lapse discovered externally. The audit is not only a compliance discipline; it is a relationship-management discipline. Callers who treat it that way find the vendor more flexible on adjacent asks. Callers who ignore it find the vendor less flexible over time, which is a preventable cost.

The audit is also a way to catch drift that would otherwise trigger a vendor-initiated conversation the caller would rather have on their own terms. A caller who discovers a lapse in their own audit can address it silently. A caller whose lapse is discovered by the vendor is now in a conversation the vendor initiated, which is a materially harder conversation to have. The hour per quarter that the audit costs is small relative to the alternative.

Sources

  1. [1] Worthune pricing page (attribution language). https://worthune.com/pricing
  2. [2] Powered-by Attribution vs. White-Label: A Cost Tradeoff. https://worthune.com/writing/attribution-vs-white-label