
A clearly hypothetical web-studio moment: a client approves the final site and replies, “Looks great.” The team now has three possible next steps. It could request a public review, ask for permission to use the comment as a testimonial, or discuss a portfolio case study. Those are different artifacts with different permissions and review paths.
A client compliment becomes trustworthy public proof only after the studio separates the review request, testimonial permission, and portfolio rights into distinct human-approved steps.
Short answer: An AI agent for reviews and reputation in a web design shop can prepare neutral review requests after a staff-approved project milestone, track the request state, and route complaints or testimonial questions to a person. It should not turn a private email into public praise, write a client’s review, choose only clients expected to be positive, offer a reward, or publish any response. The studio still decides who is eligible under a consistent rule, confirms the correct contact and destination, secures separate permission for testimonials or portfolio use, and authorizes every public reply.
Public reviews, testimonials, and portfolio proof are not interchangeable
A public review is the client’s evaluation on a review platform. A testimonial is an advertising message selected or presented by the business. A portfolio case study can add project details, screenshots, process notes, or outcomes. Moving from one category to another can change the permission, evidence, rights, confidentiality, and approval questions.
The FTC’s staff guidance draws a specific distinction between consumer reviews and testimonials. It also says that advertising agencies, public relations firms, review brokers, and reputation-management companies are not immune from the Consumer Reviews and Testimonials Rule when their conduct falls within it.[2]
For a web design and development shop, the practical lesson is simple: keep separate records for separate uses.
- Review request: Ask for an honest account of a genuine experience through a verified destination.
- Testimonial request: Ask the client whether exact approved wording may be used in named public placements.
- Portfolio request: Identify the project details, visuals, marks, results, and channels the client may authorize.
- Private feedback: Keep service-recovery discussion separate from access to a public review path.
A friendly email does not silently become a marketing license.
Why review provenance matters now
In May 2026, the FTC and Illinois announced a lawsuit alleging that a company created fake local-business profiles and used fabricated five-star reviews to lift their ratings. The allegations are not a final finding, but the action is a current reminder that fabricated review activity is enforcement territory.[1]
Google Maps policy also requires reviews to reflect genuine experience. It prohibits paid reviews, incentives for posting or changing reviews, discouraging negative reviews, and selectively soliciting positive reviews.[3]
That does not mean a web studio must turn every project record into a request. It means any exclusion should follow a documented operational rule, not a prediction about praise. A wrong contact, opt-out, duplicate request, disputed project state, unresolved confidentiality question, or missing permission can be a valid stop condition. “This client will probably leave five stars” is not one.
What the workflow should record
A review workflow needs less data than many teams assume. Start with a narrow, staff-approved record:
- Project state: The authorized person marked the agreed request milestone complete.
- Contact authority: The intended recipient and permitted communication route are current.
- Request class: The step is a public review request, testimonial-permission request, portfolio-permission request, or private follow-up.
- Approved wording: The message asks for an honest account without suggesting a rating or supplying praise.
- Destination: The review link or permission route is verified before use.
- Stop state: Missing context, complaint, confidentiality concern, dispute, opt-out, or rights question goes to a person.
- Administrative history: Prepared, approved, sent, stopped, replied, and closed remain distinct.
This is operational bookkeeping, not a judgment about project quality or client sentiment.
Where KIGWI’s Reviews & Reputation AI Agent fits
KIGWI USA lists a Reviews & Reputation Specialist among its marketing and growth agents.[4] For a web design and development shop, a defensible configuration stays inside the administrative lane.
Under an owner-approved workflow, the agent can:
- identify project records that have reached the approved request milestone
- check for missing fields, duplicate requests, opt-outs, and named stop conditions
- prepare neutral review-request copy for staff approval
- keep testimonial and portfolio-permission requests in separate queues
- record the administrative state without copying unnecessary client or project data
- route complaints, sensitive replies, rights questions, and public-response drafts to the authorized person
The agent should not:
- decide that a project was successful
- select only clients predicted to be happy
- write or edit the client’s review
- publish a testimonial from a private message
- approve screenshots, logos, code, project results, or client names for portfolio use
- answer a complaint, promise a remedy, or publish a public response without approval
- perform code, security, privacy, accessibility, or legal review
Human authority is the point of the design, not a patch added later.
Use a refusal rule before using automation
A useful workflow says when it will stop. For this use case, stop when:
- the project state is unclear or disputed
- the intended recipient or communication permission is uncertain
- a request has already been sent
- the client has opted out
- the reply contains a complaint, threat, demand, or confidential detail
- testimonial wording changes the client’s meaning
- portfolio use would expose a name, logo, screenshot, design, code, metric, or unpublished work without exact permission
- the destination link or account is unverified
A person then chooses the next step. No automatic retry, public reply, suppression, or quiet conversion of private praise into public proof.
A practical first setup
Start with one completed-project queue and synthetic test records. Do not connect live client data until the workflow, permissions, destination, and owners are verified.
Write down:
- the exact milestone that makes a project eligible for review consideration
- the neutral request wording
- every hold and stop condition
- the verified review destination
- the owner for complaints and public replies
- the separate permission path for testimonials and portfolio assets
- the minimum record needed to prevent duplicates and explain what happened
Then test ordinary, duplicate, opted-out, disputed, confidential, and complaint scenarios. The workflow is ready only when each exception stops in the right place and the responsible person can see why.
Frequently asked questions
Can a web design shop ask only clients it expects to be positive?
That is a bad rule. FTC staff says asking only customers expected to leave positive reviews could violate the FTC Act, and Google Maps policy prohibits selectively soliciting positive reviews.[2][3] Use a consistent eligibility rule based on genuine experience and a verified project state, then document valid stops such as opt-outs, duplicates, or unclear contact authority.
Is a private “looks great” email already a testimonial?
Not for KIGWI workflow purposes. Treat private praise as private correspondence until the client authorizes exact public wording, placement, identity treatment, and any related project assets. A testimonial also creates advertising claims, so the studio must preserve the client’s meaning and avoid adding unsupported results, credentials, or typicality implications.
Can the AI agent write a review for the client?
No. The client’s review should reflect the client’s genuine experience in the client’s own words. The agent can prepare the studio’s neutral request, insert a verified destination, and track the administrative state. It should not draft praise, choose a star rating, create an identity, or tell the client what specific claim to include.
Can a studio reuse a public review in its portfolio?
Do not assume so. A portfolio placement changes the context and may add a client name, logo, screenshot, project detail, or implied endorsement. KIGWI treats that as a separate rights and approval decision. The studio should confirm the exact quotation, asset, placement, channel, and duration before republishing anything.
What should happen when a request uncovers a complaint?
Stop routine automation and route the message to the authorized person. That person decides how to address the service issue, what project facts may be discussed, and whether any public response is appropriate. The complaint should not be hidden, pressured, or used to remove the client’s access to an honest review path.
Keep each kind of proof in its own lane
Reviews, testimonials, and portfolio stories can all support trust, but only when their origin and permission are clear. The clean workflow is deliberately boring: verified milestone, neutral request, separate permission paths, named stop conditions, and human review where judgment or public claims begin.
Ask KIGWI USA about a bounded Reviews & Reputation workflow for your web design and development shop: https://kigwi.com/contact/
Sources
[1] https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-illinois-take-action-stop-deceptive-conduct-company-created-thousands-business-listings-fake [2] https://www.ftc.gov/business-guidance/resources/consumer-reviews-testimonials-rule-questions-answers [3] https://support.google.com/contributionpolicy/answer/7400114?hl=en [4] https://kigwi.com/solutions