What decision should onboarding settle before any access is granted?
The onboarding decision is whether this provider is ready to perform a specific live duty under the business’s controls. It is not whether the sales call felt organized or whether a portfolio looked polished. Write the first assignment as one customer decision, such as helping homeowners request an estimate for a current service, with a named audience, approved offer, source facts, proof, destination, profiles, deliverables, review owner, response boundary, and review date.
Separate duties that can be accepted independently. Research, planning, writing, design, approval coordination, scheduling, publishing, comment moderation, direct-message handling, reporting, and paid media require different information and permissions. A provider can be ready to create drafts but not ready to send replies or manage ads. The onboarding record should show which duty is proposed, what evidence unlocks it, who approves it, and what would return it to a safer stage.
How does the four-gate 30-day acceptance plan work?
Gate one is control: confirm business ownership, recovery, named users, contract scope, source owners, and stop authority before production. Gate two is a dry run: create one complete post package and one simulated exception without publishing. Gate three is limited live release: publish a small approved batch to the named profiles while monitoring links, status, corrections, and customer handoffs. Gate four is acceptance: reconcile what happened, export the record, test removal, and decide whether each duty should expand, remain narrow, return to dry run, or stop.
Time is not the acceptance criterion. A provider does not pass because two weeks elapsed, and a late approval does not automatically prove provider failure. Each gate needs observable evidence. Record the asset version, source, approver, platform role, scheduled time, live URL or platform identifier, exception outcome, report, owner workload, and unresolved risk. A thirty-day window is useful because it can contain a full operating cycle, but the business should extend or narrow the test when volume, seasonality, regulation, or buying cycles make the evidence incomplete.
What belongs in the onboarding source-of-truth pack?
Give the manager a controlled operating pack rather than an unstructured drive dump. Include current services or products, prices or quote rules, locations, hours, availability, offer terms, credentials, approved claims, customer questions, brand rules, accessible logos, usable media, proof permissions, destinations, campaign dates, exclusions, and the person authorized to update each fact. Mark volatile information with a recheck date and distinguish public source material from internal or restricted records.
Add a negative brief: claims the business will not make, outdated offers, images that cannot be used, customers who withdrew permission, services outside the campaign, restricted audiences, and topics that require qualified review. The manager should demonstrate that missing or conflicting facts create a visible pause rather than a guess. FTC guidance requires truthful, non-deceptive advertising and an appropriate basis for objective claims, so onboarding must establish where substantiation lives before the calendar creates pressure to publish.
Which people must own approval, corrections, and sensitive handoff?
Name one factual approver, a backup, a publishing stop owner, and the people who receive sensitive conversations. Define which decisions belong to marketing and which remain with operations, customer service, sales, legal, clinical, financial, or another qualified role. Routine public facts can use an approved answer library; custom prices, refunds, disputes, threats, private customer details, regulated advice, employment issues, media requests, emergencies, and crisis statements should move to the named internal path.
Define the review object and deadline. Approval should cover the visual, on-image text, caption, disclosure, accessibility text, CTA, destination, profile, scheduled time, and any response prompt as one versioned package. Silence should not count as approval. If a material fact, image, claim, disclosure, destination, or schedule changes, the item returns to review. Give the manager an emergency pause channel, but reserve irreversible account, financial, customer, or legal decisions for specifically authorized people.
What platform access should a social media manager receive first?
Keep the business’s primary ownership, recovery methods, billing, domains, analytics properties, and administrator management outside the routine provider role. Use the platform’s named access model instead of sharing a primary password. Meta distinguishes full-control and task capabilities; LinkedIn separates super admin, content admin, analyst, and paid-media roles; TikTok Business Center separates member and asset permissions; Google lets owners add managers without sharing credentials. Match the role to the accepted duty rather than to the provider’s preferred convenience.
Create an access register with person, organization, platform, asset, role, purpose, grantor, approval date, review date, and removal trigger. Start content production without inbox, lead, advertising, finance, or administrator access unless the first assignment requires it and the corresponding controls have passed. Test that the business can remove the person and connected application before the first live release. Also inventory schedulers, design tools, link shorteners, media libraries, analytics, automation, and subcontractor access because the platform role is only one part of the real permission surface.
How should the dry run test the whole workflow?
Use one representative assignment, not an easy generic greeting. Ask the manager to turn current source material into a finished post, request a missing fact, route a deliberately sensitive comment, schedule to a non-live review state, show the publication check, and prepare the reporting record. Inspect the creative and the operating behavior: whether the provider preserves source meaning, flags uncertainty, follows the approval state, uses the correct destination, and can explain who owns the next action.
Include one correction drill. Change a material date, price, availability detail, image permission, or landing-page destination after the draft is prepared. The manager should locate every affected version, return the package to review, update scheduled copies, preserve the incident note, and confirm no stale version remains queued. This test is more informative than asking whether the provider has a quality process because it shows how the process behaves when ordinary small-business facts change.
What must pass before the first live batch?
Require a complete approved package, a verified destination, appropriate platform role, named publication monitor, correction window, and sensitive-message handoff. Limit the first release to a few posts, one audience, one active offer or customer question, and one or two profiles. Avoid combining a new provider, new ad account, new automation, untested landing page, broad inbox authority, and a major launch in the same experiment because a failure would be hard to diagnose or contain.
Set stop conditions before scheduling. Pause for unsupported claims, expired terms, missing permission, wrong location, inaccessible destination, unexplained role escalation, unapproved subcontractor access, material creative changes after approval, or unclear customer handoff. A safe stop is evidence that the onboarding control worked, not a missed productivity target. Resume only after the named owner resolves the cause and the exact revised package returns to approval.
How should a worked local-business onboarding unfold?
Consider a hypothetical plumbing company onboarding a manager for maintenance-plan content. During days one through five, the owner retains all account ownership, the office manager supplies current service-area and booking facts, and the provider receives a controlled photo set with recorded permission. The first assignment is four posts that explain plan fit and lead to a tested estimate form. Message handling, paid ads, and after-hours monitoring are explicitly outside the initial scope.
The dry run catches an old service-area statement and a job photo whose property number is visible. The provider pauses, requests a corrected source, and uses a reviewed crop. The first two posts then publish under limited content access; the office manager handles a custom-pricing message through the handoff rule. At the acceptance review, the team verifies live versions, destinations, source records, owner review time, one qualified estimate request, no unsupported attribution, successful export, and tested role removal. The result supports continuing content and publishing, not automatically adding inbox or advertising authority.
What evidence should the manager deliver at the acceptance review?
Reconcile the complete cycle: planned assets, sources requested, facts supplied, drafts, revisions, approvals, scheduled records, publication identifiers, failures, corrections, customer handoffs, performance exports, and owner decisions. The report should distinguish work delivered from platform attention and qualified customer action. Google requires Business Profile third parties to preserve client ownership, communicate changes, provide accessible performance information, obtain consent for management, and support an orderly termination path.
Measure retained owner work as well as provider output. Record time spent gathering inputs, correcting facts, reviewing creative, repairing links, handling escalations, and interpreting reports. A manager who produces eight posts but creates several hours of avoidable rework may not have passed the operating test. A manager who correctly pauses two items and publishes six supported assets may be the stronger choice. End with one decision per duty: expand, continue, repair, or remove.
Which onboarding failures require a pause or reset?
Stop expansion when the provider requests primary ownership without a task-level reason, shares credentials, adds people or applications without approval, publishes outside the approved version, cannot locate the claim source, hides an error, treats sensitive messages as generic engagement, mixes ad spend or finance access into a content role, or withholds reports and transferable assets. Also pause when the business supplies conflicting facts, misses every review window, lacks a response owner, or asks the provider to publish a claim nobody can substantiate.
Choose the smallest corrective action. A missing source owner may require a new internal handoff, not a new agency. A failed correction drill may return publishing to dry run while design continues. A role-control failure may require immediate access removal even if the creative is strong. For legal, tax, employment, privacy, healthcare, financial, or other regulated questions, use qualified advice for the business’s specific facts; a marketing onboarding checklist cannot determine those obligations.
What should be preserved for offboarding on day one?
Onboarding should create the exit record before the relationship becomes difficult. Store the contract scope, source inventory, access register, connected applications, transferable file terms, licenses, approval history, scheduled work, reporting exports, open conversations, campaign identifiers, retention rules, and removal steps in locations the business controls. Verify which editable files and licensed components transfer, and never let the provider’s private dashboard become the only copy of business evidence.
Run a tabletop exit at the acceptance review. Confirm the business can pause future posts, remove the provider and its applications, recover approved assets and captions, export reports, locate unresolved customer handoffs, and identify any data that must be returned or deleted. Google requires Business Profile clients to retain ownership or co-ownership and describes a termination path for regaining exclusive control. A provider that can leave cleanly is easier to trust with a carefully expanded scope.
What does current guidance change about this plan?
We reviewed current first-party platform role and asset-permission documentation from Meta, LinkedIn, TikTok, and Google, Google's third-party management obligations, and FTC advertising substantiation guidance. We synthesized those sources into four progressive onboarding gates that accept creation, publishing, response, reporting, and account duties independently instead of treating one contract or elapsed time as blanket approval.
Platform roles should follow accepted duties
Meta distinguishes full-control and task capabilities, LinkedIn separates super admin, content admin, analyst, and paid-media roles, TikTok Business Center assigns member and asset permissions, and Google supports separate owners and managers without shared passwords.
How to apply itKeep business ownership and recovery outside the routine provider role, record the exact asset and purpose for every grant, and unlock each live duty only after its corresponding dry run and removal test pass.
Review Meta: About Facebook Page accessAccount security includes an inventory and removal path
Google advises businesses to limit Business Profile access to essential owners and managers, retain access when adding a third party, remove people who no longer need it, and use individual accounts plus stronger sign-in protection.
How to apply itInventory people, roles, connected applications, schedulers, analytics, media libraries, and subcontractors before release, then prove the business can remove them without losing approved content or records.
Review Google Business Profile: Protect your profileConsent, transparency, reporting, and termination belong in onboarding
Google's Business Profile third-party policies require informed client control, communication of changes, consent for management, accessible performance information, ownership continuity, fee transparency, and a practical path to disassociate the provider at termination.
How to apply itBuild the exit record, reporting access, change notice, and role-removal test during the first month rather than waiting until cancellation or a dispute exposes the missing controls.
Review Google Business Profile: Third-party policiesThe source pack must establish claim support before production
FTC small-business guidance states that advertising must be truthful and non-deceptive and that objective claims require an appropriate evidentiary basis before they run.
How to apply itGive every price, service, credential, result, testimonial, image, offer condition, and destination a current owner or source, and make missing or conflicting evidence trigger a visible pause in the dry run.
Review FTC: Advertising FAQs for small businessCreation, publishing, messages, ads, analytics, and finance are separate acceptance lanes
First-party LinkedIn and TikTok documentation shows that content, analytics, paid media, asset assignment, settings, and finance can use different roles or permission levels rather than one universal manager grant.
How to apply itAccept each lane from task evidence, keep inbox, lead, advertising, finance, and administrator access outside a content-only pilot, and expand only the duty that passes its correction, reporting, export, and removal checks.
Review LinkedIn: Page admin rolesWhich useful examples can you adapt?
These are not fake captions to copy word for word. Use them as structure, then replace the proof, timing, and CTA with real business details.
For a DIY-versus-service decision, compare the next campaign, available source files, editing time, required formats, deadline, and ownership after delivery.
Replace every detail with the current business facts, then keep only the evidence needed to choose the smallest path that gets the campaign published.
Current offers and job photos exist, but source details and estimate handoff change weekly.
Begin with controlled content and publishing, test one changed fact, and keep custom quotes with the office team.
Educational content is useful, but privacy, claims, and patient questions require qualified control.
Keep the provider in an approved public-source lane until information, reviewer, access, and escalation obligations are resolved.
Which authoritative sources should the practice review?
Use these sources as a starting point, then follow the laws, professional rules, and qualified advice that apply to the practice and its location.
- Meta: About Facebook Page access Meta's current explanation of full-control, partial-control, task, content, message, advertising, and insight permissions for Pages.
- LinkedIn: Page admin roles LinkedIn's first-party definitions for super admin, content admin, analyst, and paid-media responsibilities.
- TikTok Business Center: Account and asset permissions TikTok's first-party description of Business Center member roles and account- or asset-level access controls.
- Google Business Profile: Owners and managers Google's role-based access guidance for managing posts and reviews without sharing a password.
- Google Business Profile: Protect your profile Google's first-party security guidance for retaining owner access, limiting permissions, removing former workers, and using 2-Step Verification.
- Google Business Profile: Third-party policies Google's requirements for provider transparency, client ownership, management fees, reporting access, consent, termination, account security, and realistic claims.
- FTC: Advertising FAQs for small business FTC guidance on truthful advertising, objective claims, disclosures, and the evidence businesses should keep.