1. Preserve the source
Ask where the image came from and obtain the earliest available file. A screenshot or social-media download may already have lost provenance data. Preserve the original before converting or editing it.
2. Validate Content Credentials
Check whether a C2PA manifest exists, whether it remains bound to the file, whether the signature is valid, and whether the signer is trusted under the validator’s policy. Read the actions and digital source type rather than stopping at the badge.
3. Inspect metadata and workflows
Look for generator names, software fields, prompts, seeds, model identifiers, ComfyUI graphs, and export history. Treat filenames as weak hints and embedded workflow data as stronger file-specific evidence.
4. Match proprietary and visual checks
If the claim concerns SynthID or another named watermark, use the compatible provider verifier. If using a visual classifier, record the tool, version, confidence, and limitations. Do not combine unlike scores as if they were independent proof.
5. Check context and reverse-search
Find the earliest publication, creator account, project history, and related versions. Context can expose contradictions that a file-only tool cannot see, while a plausible context cannot repair invalid cryptographic evidence.
6. Report the narrow conclusion
State exactly what was found: “valid credential naming generator X,” “ComfyUI workflow embedded,” “no supported metadata,” or “classifier estimated Y.” Preserve uncertainty and avoid replacing it with a definitive label.