The Xanadu standard
The AI Content Supply Chain
The enterprise operating model for AI-generated content, with Canva and Claude as the reference implementation.
This document defines an operating model for organisations adopting AI-generated content at scale. It is written for the people accountable for the outcome: COOs, CMOs, CIOs and transformation leads. The structure is vendor-neutral. The reference implementation is the Canva and Claude stack, because that stack is currently the most complete publicly available example of the model working end to end. Where something does not work yet, this document says so.
Section 1
The bottleneck has moved
For most of the last twenty years, the constraint on enterprise content was production. Making things was slow and expensive, so demand was rationed by budget and headcount. Every process, approval chain and team structure in a modern marketing or operations function was built on that assumption.
The assumption no longer holds. Generation is now effectively free. A competent operator with a frontier model and a design platform can produce in an afternoon what a team used to produce in a month. Demand, which was always latent, is now unbounded. Every department that ever wanted a deck, a report, a one-pager or a campaign can now have one.
The result is not a productivity dividend. It is a queue that has moved downstream. The constraint is no longer making things. It is governing, approving, distributing and measuring them.
This shows up operationally, not philosophically. A marketing team generates forty campaign variants and ships three, because review capacity did not scale with generation capacity. A regional office produces performance reports nobody has reconciled to source data. A brand team discovers, in a customer meeting, a customer-facing deck that no designer ever touched. None of these are tool failures. They are operating model failures.
The demand side is not a forecast. In the UAE alone, over 54 million designs were created on Canva in 2025, and roughly one in eight UAE internet users is on the platform. In February 2026, the Dubai Chamber of Digital Economy signed an agreement with Canva at the World Governments Summit, in the presence of the Minister of State for Artificial Intelligence, to establish Canva’s regional headquarters in Dubai and support 250,000 SMEs over five years (World Governments Summit). Canva built the demand. The open question for every enterprise is whether it has an operating model for absorbing what its people now produce.
That operating model is the AI content supply chain. The rest of this document defines it.
Section 2
The reference architecture
An AI content supply chain has four tiers. The names are vendor-neutral. The tiers exist whichever stack you run.
Tier 1. Systems of record. Finance, ERP, CRM, operations platforms, communications tools. This is where the truth lives, and nothing downstream can be better than what this tier holds. If the CRM is dirty, the supply chain produces well-designed artefacts about dirty data, faster than ever before.
Tier 2. The reasoning layer. A model that reads across the systems of record, decides what matters, and drafts the answer. In practice today this is a frontier model working through connectors: pull the pipeline, notice the pattern, draft the narrative.
Tier 3. The connective layer. Identity, permissions, orchestration and approval routing. This tier decides which account the agent acts as, what it is allowed to read, what happens between draft and shipped, and what gets recorded along the way. It is the least discussed tier in the market and the most consequential, because it is where every failure described in this document either gets caught or gets through. It is also where most of the implementation work sits.
Tier 4. The output layer. The artefacts themselves: decks, reports, one-pagers, campaign assets, produced on brand and in a form a human will actually use. Output that is technically correct but visually wrong does not get used, which makes brand infrastructure a supply chain component, not a cosmetic one.
The reference implementation: Canva and Claude
The clearest end-to-end example of this architecture in production is the integration Canva and Anthropic have built over a two-year collaboration. The Canva MCP for Claude launched in July 2025, and in January 2026 it expanded to on-brand generation with Brand Kits applied in the flow of a conversation (Canva Newsroom). Claude Design launched on 16 April 2026, powered by Claude Opus 4.7 and using Canva’s Design Engine (TNW). The Canva AI Connector, powered by the Canva MCP Server, works with both Claude and ChatGPT (Canva).
On the same day as Claude Design, Canva announced Canva AI 2.0 at Canva Create: conversational design, agentic orchestration, object-level intelligence and a Memory Library, built on MCP and launching with connectors for Slack, Gmail, Google Drive, Notion and Zoom, plus Scheduling for recurring autonomous tasks (CMSWire, BigGo). It launched as a research preview, with general availability rolling out progressively; check availability for your tenancy before you plan a rollout on it.
The May 2026 integration of the Canva Design Engine into Claude for Small Business shows all four tiers in a single motion: the workflow runs via Claude Cowork, pulls CRM sales data, and connects QuickBooks, PayPal, HubSpot and DocuSign (Canva Newsroom, DesignRush). Systems of record in, reasoning across them, orchestration in the middle, on-brand output at the end. That is the supply chain, shipped as product.
In June 2026, Canva extended the output layer into distribution and measurement with Canva Grow 2.0, launched at Cannes Lions: ad generation, publishing to Meta, TikTok and LinkedIn, performance feedback and automated creative refresh in a single workflow (Canva Newsroom). It is assembled from a year of acquisitions, including Ortto for marketing automation, MagicBrief for turning performance data back into creative direction, Doohly for digital out-of-home and SimTheory for agent management (SMBtech). AI Ad Tagging is available on Canva Business and Canva Enterprise, with market availability expanding progressively after launch (Business Wire), so confirm availability for your tenancy before planning against it.
Three things follow. First, the pattern is not vendor-specific. Adobe expanded its Firefly AI Assistant across Premiere, Photoshop, Illustrator, InDesign and Frame.io in June 2026 and extended it into ChatGPT, Claude and Copilot (Adobe). The architecture holds; the implementation changes. Second, multi-vendor is the normal end state. Canva itself runs a deliberately multi-vendor internal AI toolbox, with Claude as a go-to tool (Anthropic). Your operating model has to survive that reality rather than assume a single-vendor world. Third, vendors expand across tiers. Canva enters this document as the output layer and Grow 2.0 extends it into orchestration and campaign-level measurement. That is the expected direction of travel for every vendor in this stack, and it is why the tiers are worth holding separate from the products that currently occupy them. When evaluating any vendor, the useful question is not which tier they belong to. It is which tiers they now cover, and which ones you remain responsible for yourself.
Section 3
The five control points
The four tiers describe what the stack is. The control points describe where the enterprise keeps its hands on it. There are five. Each has a specific, predictable failure mode when it is absent, and each can be tested with one question to your own team.
Identity and access
What it is. Knowing which account every agent and every generation is acting as. Personal versus corporate. Named human versus service identity. And the shadow account problem: the tools entered most organisations through individuals, not procurement, so work product is routinely being created under accounts the organisation does not own and cannot see.
The failure mode. Corporate content accumulates in personal accounts. When people leave, the content, the templates and sometimes the customer-facing assets leave with them. Eventually procurement or security runs an audit and discovers a population of unmanaged accounts doing company work, at which point the conversation is remedial rather than strategic.
The question to ask
If we listed every account that generated content on our behalf this week, how many would we recognise?
Data boundaries
What it is. An explicit statement of what the reasoning layer can read, what it must never read, and what is permitted to leave the tenancy. Connectors make this concrete: every connector grant is a data boundary decision, whether or not anyone treated it as one.
The failure mode. Scope granted once and never reviewed. A drive connector authorised for a campaign folder in March quietly covers the whole shared drive by September because someone reorganised the folders. The quarterly board deck gets drafted from a directory that also contained the M&A model. Nobody decided that. Nobody decided anything, which is the point.
The question to ask
For each connector currently live, who approved its scope, and when was that scope last reviewed?
Brand guardrails
What it is. The mechanism by which brand rules survive generation at volume: brand kits, locked templates, protected elements, and a clear rule for which artefact classes must be built from governed components. At human production speed, brand was enforced by designers being in the loop. At generation speed, it has to be enforced by infrastructure.
The failure mode. Brand drift at volume. Not one bad deck but a thousand nearly-right artefacts, each slightly off in colour, type or tone, produced faster than any brand team can correct them. The brand does not break in one incident. It erodes in ten thousand small ones.
The question to ask
What percentage of generated output ships without a designer touching it, and have we actually looked at what that output looks like?
Human approval gates
What it is. An explicit decision about what ships without review, what does not, and who owns the decision. The point is not to review everything. Reviewing everything rebuilds the bottleneck the supply chain exists to remove. The point is that the unreviewed classes are chosen, on record, by someone accountable.
The failure mode. One of two symmetrical failures. Either everything queues for human review and the organisation has recreated its old constraint with extra software, or nothing does and the first serious customer-facing error becomes the moment governance gets designed, in a hurry, by the people angriest about the error.
The question to ask
Can anyone in this room name the classes of content that ship unreviewed, and who signed that off?
Audit and telemetry
What it is. A record of what was generated, by whom, from what source data, through which route, and whether anyone actually used it. Usage matters as much as provenance: a supply chain that cannot distinguish artefacts that got used from artefacts that got generated cannot make a return-on-effort argument to anyone.
One distinction to hold. Campaign performance telemetry and generation telemetry are not the same thing. Tools in the output layer increasingly report how an artefact performed once published, which is useful and closes part of the return-on-effort argument. It is not a tenancy-wide record of what was generated, by whom, from which source, and whether it was used at all. The second is what an audit requires, and it remains an admin and partner-tier capability rather than an end-user one. Where the first is presented internally as the second, the gap stays open and nobody notices until it matters.
The failure mode. Two flavours. Day to day, the ROI story runs on anecdote, which means renewal and expansion decisions run on anecdote too. In an incident, nobody can reconstruct how an artefact came to exist, which turns a contained problem into a trust problem.
The question to ask
If a generated artefact caused a problem tomorrow, how long would it take us to establish its full provenance?
Section 4
The maturity scale
Organisations do not move from ungoverned to governed in one step. They move through five recognisable levels.
The scale maps to the four dimensions measured in the AI Readiness Assessment: Leadership, People and skills, Process and workflow, and Governance and data.
| Level | Leadership | People and skills | Process and workflow | Governance and data |
|---|---|---|---|---|
| 1 · Ad hoc | Unaware or indifferent | Self-taught individuals | None; personal habits | Personal accounts, no visibility |
| 2 · Adopted | Curious, no owner | Pockets of capability | Informal, per team | A licence exists; a model does not |
| 3 · Standardised | Named executive owner | Trained on the standard stack | Repeatable top workflows | Corporate tenancy default; brand kits live |
| 4 · Governed | Budgeted capability with targets | Role-based skill paths | Explicit approval gates per content class | All five control points implemented |
| 5 · Agentic | Reviews telemetry, not anecdote | Supervise agents, not just prompts | Exception-based; humans handle escalations | Autonomous generation inside guardrails, measured |
Scroll the table sideways to see every dimension.
Level 1: Ad hoc. Individuals use the tools on personal accounts. Leadership either does not know or treats it as a curiosity. Skills are self-taught and uneven. There is no process: output is shipped or abandoned at the discretion of whoever made it. The organisation could not produce a list of its own accounts.
Level 2: Adopted. Teams use the tools openly and a corporate licence exists somewhere. Leadership is interested but nobody owns the outcome. Some individuals are genuinely skilled; most are not. Process is informal and varies by team. Governance amounts to having bought seats, which is a procurement event, not an operating model.
Level 3: Standardised. There is a named executive owner. The corporate tenancy is the default, brand kits and governed templates exist, and training exists for the standard stack. The highest-volume workflows are repeatable rather than reinvented per person. Data boundaries are defined for the main connectors. This is the first level at which the organisation could answer the five questions in Section 3 without an awkward silence.
Level 4: Governed. Leadership treats the content supply chain as an operating capability with a budget and targets, not a tool rollout. Skills are developed along role-based paths: what a brand manager needs differs from what an analyst needs. Approval gates are explicit per content class and on record. All five control points are implemented and auditable.
Level 5: Agentic. Scheduled and autonomous generation runs inside the guardrails: recurring reports, background research, campaign refreshes that execute without a human initiating each one. Leadership reviews telemetry rather than anecdotes. The human role shifts from producing content to supervising the system that produces it, handling what the approval gates escalate. Return is measured against source data, not asserted.
How the assessment bands map to the scale
The AI Readiness Assessment returns one of four bands. They map onto the five levels as follows:
- Experimentingcorresponds to Level 1, Ad hoc
- Emergingcorresponds to Level 2, Adopted
- Scalingcorresponds to Level 3, Standardised
- Embeddedspans Level 4, Governed, and Level 5, Agentic
The top band covers two levels deliberately. A nine-question self-serve diagnostic can reliably establish that AI is embedded in how an organisation works. It cannot establish whether that embedding is governed, audited and measured, or simply widespread. That distinction is the difference between Level 4 and Level 5, and it is not something any questionnaire resolves. It takes a proper look at the control points, the telemetry and the approval architecture.
Most organisations, honestly assessed, sit at Level 2 while describing themselves as further along. The distance from Level 2 to Level 4 is not primarily a tooling problem. The tooling largely exists. It is an operating model problem, which is why it does not solve itself with another licence purchase, and why closing it is the substance of a structured AI transformation programme rather than a procurement exercise.
Section 5
The workflow taxonomy
The supply chain carries categories of work, not one-off requests. Eight categories cover most of what enterprises actually run through it.
Examples below are drawn from three verticals where the pattern is furthest along: real estate, higher education, and QSR and franchise operations.
Reporting and performance packs
Recurring artefacts built from operational data. A weekly sales performance deck from the CRM; an enrolment funnel summary for a faculty board; a franchisee performance scorecard from POS data.
Sales and proposal collateral
Buyer-facing material assembled from governed components. Property listing brochures and investor one-pagers; course prospectuses and partnership proposals; franchise development pitch packs.
Campaign and social content at volume
The highest-volume category and the one where brand guardrails earn their keep. Project launch campaigns across portals and social; open day and clearing campaigns; limited-time offer creative across every store format. As of mid-2026 this is also the first category in the reference stack with a native path from generation through publishing to performance feedback, which changes the volume calculation: variants can be judged on results rather than simply produced.
Data-to-design
Structured data rendered directly into visual artefacts. Pipeline reviews generated from CRM extracts; admissions dashboards turned into governor-ready summaries; store league tables turned into regional review packs.
Internal communications and enablement
Content for your own people. Agent onboarding and compliance refreshers; staff policy updates and teaching resources; crew training materials and operations bulletins.
Localisation and multi-market adaptation
One governed master, many compliant variants. English and Arabic listing sets; international student variants of recruitment material; menu and pricing boards adapted per territory.
Event and launch collateral
Time-boxed, high-visibility, brand-critical. Handover ceremonies and sales gallery material; graduation and open day kits; new store opening packages.
Scheduled and autonomous generation
Any of the above, running on a schedule inside the guardrails rather than on request. A weekly market snapshot that publishes itself for review; term-cycle recruitment content; recurring offer refreshes. This category is what Level 5 of the maturity scale looks like in practice, and it is the category most dependent on the five control points being real.
Use the taxonomy as an audit rather than a menu. Score each category on three axes: how much volume it carries, how much brand risk it exposes, and how much human review burden it creates today. The categories that score high on all three are where a supply chain earns its keep first, and they are almost never the categories a team would have nominated from instinct.
Section 6
The build ledger
A standard that ignores what the tools cannot do yet is marketing. This ledger records what Xanadu validates in daily production use of the reference stack, tagged honestly. It is updated as the stack changes. Current as of July 2026.
Validated
Works on publicly available functionality now
- The Canva MCP and AI Connector operating inside Claude: conversational generation of Canva designs from a Claude session.
- Claude Design output transferring into Canva as editable designs, not flat images.
- Canva connectors into Slack, Gmail, Google Drive, Notion, Zoom and HubSpot for pulling source material into generation.
- Canva Code 2.0 with HTML import as a publish path for interactive artefacts.
- Scheduled background generation tasks via Canva AI 2.0’s Scheduling capability, noting the research preview status above.
Gap
Not currently reliable for this purpose; needs a workaround
- Programmatic brand kit application. Canva’s January 2026 release applies Brand Kits in the flow of an interactive Claude conversation, and that works. Unattended, API-driven generation is a different matter: in our production use, brand fidelity for programmatic calls still requires baking hex codes and font names directly into the generation prompt. Interactive on-brand generation and programmatic on-brand generation are not yet the same capability, and rollout plans should treat them separately.
- Multi-page carousels in a single generation call. Generate-design produces single artefacts; multi-page sequences require multiple calls and assembly.
- Fully unattended merge operations. Merging designs requires explicit confirmation, so it cannot run inside an autonomous pipeline without a human step.
- Layout control. The generator makes its own layout choices. Treat every generated artefact as a strong draft, not a finished piece. Workflows that assume zero-touch finals will disappoint; workflows that assume a fast draft plus targeted edits perform well.
- Targeted text edits. Find-and-replace against specific strings is materially more reliable than broad text replacement for programmatic corrections.
Needs privileged access
Requires partner-tier or admin-tier capability
- Organisation-wide usage telemetry: who generated what, from what, and whether it was used, across the whole tenancy. This is the backbone of control point five and it is an admin and partner capability, not an end-user one.
- Admin-tier governance controls and brand template APIs at Enterprise scope: locked elements, org-wide template enforcement, and programmatic template management.
Not yet assessed
Shipped by the vendor, not yet in our production use, therefore not rated here
- Canva Grow 2.0 (June 2026). Ad generation, publishing and performance optimisation in one workflow. Not yet in our production use, and market availability was still expanding at launch. It will be rated here once we have run it end to end on a live account. Listed rather than omitted so the omission is not mistaken for an assessment.
The gaps are not a reason to wait. They are a reason to design the operating model around what is true, and to revise it as the vendors close them, which on current release cadence they are doing quarterly.
Section 7
What this standard does not solve
This standard defines the operating model for AI-generated content. It deliberately does not cover several adjacent problems. Legal review of claims made in generated content remains a legal function; the supply chain routes artefacts to it, it does not replace it. Questions of model training data and IP provenance sit with the vendors and their terms, not with the operating model. Data quality in the systems of record is a prerequisite, not a deliverable: the supply chain will faithfully amplify whatever the CRM contains. Organisational change management, incentive design and the politics of who loses a bottleneck they used to own are real work and out of scope here. And this standard does not select vendors for you. The reference implementation is the stack we run and recommend; Claude is our chosen and recommended platform, and the architecture holds regardless of which stack you implement it on.
Naming the boundaries is the point. A standard that claims to solve everything solves nothing.
Section 8
Where to start
Every organisation reading this is already somewhere on the maturity scale, whether or not anyone has looked. The five questions in Section 3 will tell you roughly where in one meeting. The AI Readiness Assessment will tell you precisely, in nine questions and about three minutes, scored across the same four dimensions this standard is built on, with an honest read on the fastest next step for your organisation.
If the answer is that the distance you need to close is an operating model problem rather than a tooling one, that is what our AI transformation practice exists to do.
Where does your organisation actually sit?
Nine questions, about three minutes, scored across the same four dimensions this standard is built on.
Questions
Frequently asked questions
What is an AI content supply chain?
The operating model an organisation uses to govern, approve, distribute and measure AI-generated content. It has four tiers (systems of record, a reasoning layer, a connective layer, an output layer) and five enterprise control points: identity, data boundaries, brand guardrails, approval gates, and audit.
Is the Canva and Claude integration ready for enterprise use?
The core integration is in production: the Canva MCP for Claude shipped in July 2025, on-brand generation with Brand Kits followed in January 2026, and Claude Design launched in April 2026. Enterprise readiness depends less on the integration and more on your operating model around it, which is what this standard defines.
How do we keep AI-generated content on brand at volume?
Through infrastructure rather than review: brand kits, locked templates and governed components, plus an explicit rule for which content classes must be built from them. Interactive on-brand generation works today; fully programmatic brand application still needs workarounds, as recorded in the build ledger above.
What should ship without human review?
That is a decision, not a default. Classify your content, decide per class, and put a name against the decision. Internal, low-risk, data-derived artefacts are the usual starting point for unreviewed shipping. Customer-facing and regulated content keeps a gate.
How do we measure the ROI of AI-generated content?
Through telemetry, not anecdote: what was generated, from what source, by whom, and whether it was used. Usage is the number that matters. If your stack cannot yet report it, that gap belongs on your roadmap before any expansion decision.