Key takeaways
- A working policy fits on 1-2 pages: brand voice, who can post without approval and who needs it, account access rules, and the crisis escalation path.
- Approval rules should be tiered by risk, not blanket — a routine reply needs less oversight than a scheduled campaign post.
- Account access (who has login credentials, how access is revoked when someone leaves) belongs in the policy, not left as an informal habit.
Social media policy template: the sections a policy needs
- Brand voice — 3-5 adjectives describing the tone, plus one or two example posts that show it done well
- Posting approval rules — which content types need sign-off before publishing, and from whom (see the tiered approach below)
- Response guidelines — how to handle comments, DMs and reviews, including when to escalate rather than reply directly
- Account access — who holds login credentials or is added as a SkedCast team member, and the process for revoking access when someone leaves
- Crisis escalation — a pointer to the separate crisis communication plan template for anything beyond a routine response
Tiering approval by risk
Routine, low-risk content (a scheduled post following an established pillar) can go out with light or no review from an experienced team member. Higher-risk content — anything mentioning a competitor, a sensitive topic, pricing, or a legal claim — should require sign-off from a named approver before it publishes. SkedCast's approval workflow can enforce this distinction directly rather than relying on everyone remembering the rule.
Revoking access cleanly
When someone leaves the team, their account access should be removed the same day, not "eventually" — this is one of the most commonly skipped policy items. Keep a simple log of who currently has access to which accounts so a departure has a clear checklist to work from.
FAQ
- How long should a social media policy be?
- 1-2 pages is a reasonable target — long enough to cover the sections above, short enough that people actually read and remember it.
- Does every post need approval?
- No — tiering by risk (routine posts lightly reviewed, higher-risk content requiring sign-off) keeps the process fast without removing oversight where it matters.
- What happens when a team member leaves?
- Their account access should be revoked the same day; the policy should name who is responsible for doing this and keep a log of current access.
- How does this relate to the crisis communication plan?
- This policy covers everyday operation; the crisis plan template is specifically the escalation path for something going wrong publicly — link the two together.