Social media policy template for small teams

A copy-and-fill social media policy template covering approvals, personal accounts, community management, crisis response, disclosure and account security.

Last updated: August 22, 2026

Why every team needs a social media policy

A social media policy sounds like a document that exists to stop people doing things. The good ones do the opposite. They tell everyone what they are allowed to do, so employees stop hesitating, the person running the accounts stops guessing, and nobody has to invent a rule at eleven at night while a comment thread goes sideways.

Most small teams do not have one until something goes wrong: an intern replies with a joke that reads badly out of context, a salesperson shares a customer name that was not public, or an off-hand political post gets attached to the company logo. None of those are malicious. They happen because nobody wrote down what good looks like.

This is a template you can copy, fill in and adopt in an afternoon. It works for a five-person startup and scales to an agency running accounts for other people's brands. Take what fits, delete what does not, and keep it short enough that people actually read it.

Before you write: three decisions

Get these settled first, because every clause below depends on them.

  • Who speaks for the brand? Name the accountable person, not the department. Someone should own the accounts, the calendar and the response queue.
  • How much freedom do employees have to post about work? Ranging from "only the official account posts" to "everyone is encouraged to share and tag us". Most healthy teams sit in the middle: employees are encouraged, with clear boundaries.
  • What is genuinely confidential? Unreleased products, customer names, revenue numbers, security details, hiring decisions, legal matters. Be specific, because "use good judgment" means different things to different people.

The template

Copy everything below into your own document and replace the bracketed parts.

1. Purpose and scope

This policy applies to everyone at [Company] — employees, contractors, interns and anyone posting on our behalf. It covers our official brand accounts and any personal posting where you identify yourself as connected to [Company].

It exists to protect our customers, our colleagues and our brand, and to give you confidence about what you can share.

2. Who can post on official accounts

The following people are authorised to publish on [Company] accounts: [names or roles].

All other requests go through [named owner or shared inbox]. Nobody posts from a brand account without approval, including "quick" replies and stories.

Account credentials are stored in [password manager] and are never shared over chat or email. Access is reviewed [quarterly] and removed on the day someone leaves the team.

3. What we publish

Our accounts exist to [state your purpose in one line, for example: help small business owners market themselves with less effort].

Content should be:

  • Useful, accurate and something we would stand behind publicly.
  • Consistent with our brand voice guide, including tone, spelling and emoji use.
  • Checked for facts, names, prices and dates before it goes out.
  • Accessible: alt text on images, captions on video, no essential information conveyed by colour alone.

Content should never include:

  • Unreleased products, features, pricing or launch dates that have not been publicly announced.
  • Customer names, logos, screenshots or quotes without written permission.
  • Colleagues' images or personal details without their consent.
  • Anyone else's copyrighted work, including music, photography, fonts and article text.
  • Claims about results, health, earnings or performance we cannot evidence.
  • Content generated by AI tools that has not been reviewed and edited by a human.

4. Approvals

  • Routine posts matching the approved content calendar: published by the authorised owner, no extra approval needed.
  • Anything involving a customer, partner, price, claim, or legal or regulatory topic: approved by [role] before publishing.
  • Paid promotion, partnerships and sponsored content: approved by [role], and always disclosed clearly using the platform's own disclosure tool as well as plain language such as "paid partnership" or "ad".
  • Crisis or sensitive-moment posts: see section 7.

5. Personal accounts

You are welcome, and encouraged, to talk about your work. A few boundaries make that safe for everyone.

  • If you post about [Company], make your connection clear. A line in your bio is enough.
  • Speak for yourself. Where a post could be read as an official position, add something like "views are my own".
  • Do not share anything covered by section 3 as confidential, including internal screenshots, dashboards, roadmaps and customer conversations.
  • Do not respond to complaints, journalists or public criticism about [Company] on your personal account. Forward it to [named owner].
  • Do not use company accounts, logos or assets on personal profiles without permission.
  • What you post outside work is your business. We only get involved when a post is unlawful, harasses a colleague or customer, or is presented as coming from [Company].

6. Engaging with people

Community management is where reputation is actually built, so give it the same care as publishing.

  • Aim to respond to questions within [one working day], and to complaints within [four working hours] during business hours.
  • Answer as a person, not a script. Use the person's name where you have it.
  • Never argue publicly. Acknowledge, take it to a direct message or email, and resolve it there.
  • Never share personal data in a public reply, including order numbers, emails, addresses and account details.
  • Correct factual errors in our own posts openly rather than quietly deleting, unless the post breaches this policy or the law.
  • Hide or remove comments only when they contain hate speech, harassment, personal data, spam or explicit content. Disagreement is not a reason to delete.
  • Block only for repeated abuse or spam, and log it in [location].

7. When something goes wrong

Speed and honesty beat cleverness. If a post causes a problem, or a wider issue makes our scheduled content inappropriate:

  • Immediately pause all scheduled posts. Whoever notices first can and should do this.
  • Tell [named owner] straight away, even outside working hours, using [channel].
  • Do not delete, edit or reply until [named owner] has seen it, unless the content is illegal or exposes someone's personal data.
  • [Named owner] decides the response: correct, apologise, clarify or stay quiet.
  • Only [named spokesperson] speaks to press or on the record.
  • Screenshot everything before making changes, for the record.
  • Within a week, write a short note on what happened and what we changed, and update this policy if needed.

8. Advertising and regulated claims

  • Any gifted product, affiliate link or paid arrangement must be disclosed, whether the post comes from us or a creator we work with.
  • Testimonials must be real, verifiable and typical of what customers experience.
  • Follow the platform rules and the advertising rules in every market where we run ads.
  • Contests and giveaways need visible terms: eligibility, dates, how winners are picked, and the fact the platform is not a sponsor.

9. Security

  • Two-factor authentication is required on every account, personal and brand, that can access our profiles.
  • Use a business manager or equivalent so accounts are owned by [Company], not an individual.
  • Grant the minimum access someone needs, and remove it the day their role changes.
  • Never approve a login request you did not initiate.
  • Treat unexpected DMs about copyright strikes, verification or brand deals as phishing until proven otherwise. Report them to [named owner] rather than clicking.

10. Acknowledgement

Everyone reads this at onboarding and confirms it annually. Questions go to [named owner]. This policy was last reviewed on [date] and is reviewed every [six months].

Making the policy stick

A policy nobody reads is worse than none, because it creates the illusion of protection. Three things make it real.

Keep it to two pages. If it runs longer, move detail into the brand voice guide or a separate security document and link to them.

Build it into the workflow rather than a folder. The approval rules should be visible where posts are drafted and scheduled. If your team plans content in one place, the rules for who approves what, which claims need checking and how fast to reply belong right there beside the calendar. Managing your calendar, approvals and publishing together in BrandFleet makes the policy something people follow by default rather than something they have to remember.

Review it after every incident and every platform change. New platforms, new formats and new disclosure rules arrive constantly. A policy written three years ago says nothing useful about AI-generated content or short-form video, and people notice when a document is out of date.

A short version for very small teams

If ten sections feel heavy for a team of four, this is the minimum viable policy:

  • [Name] owns the accounts. Nothing goes out without their sign-off.
  • Never post unreleased products, customer names or anything we cannot evidence.
  • Disclose anything paid or gifted.
  • Complaints get acknowledged within a day and moved to email.
  • If something blows up, pause everything and tell [name] immediately.
  • Two-factor authentication on everything, credentials in the password manager.

Print it, pin it, and expand it when the team grows.

Ready to put the rules where the work happens? Start with BrandFleet and keep your calendar, approvals and publishing in one place.

Run every brand from one studio

BrandFleet generates on-brand content, schedules it, and publishes it everywhere — for every brand you manage.

Start free