StrategySocial Media PolicyTeam Workflow

How to Write a Social Media Policy (With Examples)

A practical guide to writing a social media policy for your business: what employees can and cannot post, approval workflows, compliance, and copy-ready examples.

Dan — Founder, SocialKit6 min read

A social media policy is a written document that sets the rules for how your company and its employees represent the brand on social platforms — what they can post, what they cannot, who approves it, and what happens when something goes wrong. It is a governance document, not a to-do list. Where a standard operating procedure tells your team how to schedule a post, a policy defines the guardrails everyone posts inside of.

If you manage more than one person touching your brand accounts, you need one. Here is exactly what goes in it, plus copy-ready examples you can adapt today.

Policy vs. procedure: don't confuse the two

This is the mistake most businesses make. They write a "social media policy" that is actually a workflow checklist ("log in, draft the caption, schedule for 9am"). That is a social media SOP — useful, but a different document.

  • A policy answers what is allowed and who decides. It governs behavior, risk, and approval authority. It changes rarely.
  • A procedure (SOP) answers how the work gets done, step by step. It changes often as tools and cadence evolve.

Keep them separate. Your policy protects the brand; your SOP runs the day. When you conflate them, the important governance rules get buried under operational trivia and nobody reads it.

Who your policy needs to cover

A common assumption is that a social media policy only applies to the two or three people with the account passwords. In practice it needs to cover three distinct groups, and each gets different rules:

  1. Official brand voice — the people posting as the company. Highest scrutiny, tightest approval.
  2. Employee advocates — team members who share company content or talk about work on their personal accounts. This is where employee advocacy on social media lives, and it needs clear, encouraging-but-bounded rules so people amplify the brand without creating liability.
  3. Everyone else — staff who never post for work but whose personal posts could still reflect on the company. They need a short "personal use" section, not the full rulebook.

Name these groups explicitly at the top of the document. A rule that makes sense for the brand account (never post without approval) would kill employee advocacy if applied to everyone.

The core sections every policy needs

Here is the skeleton. You can lift these headings directly.

1. Purpose and scope

Two or three sentences. Who this applies to, which accounts it covers (brand-owned handles across every platform you're on), and why it exists. Be plain:

This policy applies to all employees and contractors of [Company]. It governs conduct on official [Company] accounts on Instagram, LinkedIn, Facebook, TikTok, X, YouTube, and any other brand-operated channel, as well as personal social media use that references the company.

2. Roles and responsibilities

State who owns what. This is the backbone of a policy for a multi-person team. Define at minimum:

  • Who can post to brand accounts (by role, not by name — names change).
  • Who approves content before it goes live, and for which content types.
  • Who owns crisis response and can pause or pull scheduled content.
  • Who holds the credentials and manages access.

3. What employees can and can't post

The heart of the document. Split it into clear "green light" and "red light" lists so there's no ambiguity.

Encouraged / allowed:

  • Sharing published company content, blog posts, and launches.
  • Celebrating team wins and milestones.
  • Honest, respectful engagement with your community and customers.
  • Posting expertise and thought leadership tied to your industry.

Prohibited:

  • Sharing confidential, unreleased, or financial information.
  • Disparaging customers, competitors, or colleagues.
  • Speaking on behalf of the company without authorization.
  • Posting discriminatory, harassing, or hateful content.
  • Sharing customer data, DMs, or private conversations publicly.
  • Undisclosed paid or sponsored content (a legal requirement in most markets).

Give real examples for the gray areas. "Don't share confidential info" is abstract; "don't post photos of a client's office, unreleased product, or internal dashboards" is enforceable.

4. Brand voice and conduct standards

Point to your voice guidelines rather than restating them — but do reference them. Consistency in tone is part of governance, and a shared brand voice definition keeps five different people sounding like one company. Include the non-negotiables: how you handle criticism (respond, don't delete legitimate complaints), grammar and accuracy standards, and how personal opinions are flagged ("views are my own" disclaimers for employee accounts).

5. Approval workflow

Spell out the sign-off chain. This is where a policy earns its keep for teams. A workable model:

  • Standard content (evergreen posts, curated shares): one reviewer, or scheduled directly by trusted roles.
  • Campaign or launch content: reviewed by the marketing lead before scheduling.
  • Sensitive topics (anything legal, political, financial, or crisis-adjacent): escalated to leadership.

Tie approval to content risk, not to every single post — or you'll create a bottleneck that guarantees nobody follows the policy. Role-based approvals matter here: in a shared calendar, you can route drafts to the right approver instead of trading screenshots over Slack. Tools like SocialKit let you schedule and customize content across all 11 platforms from one calendar with approval steps built in, so the "who signed off on this" question has a real answer instead of a guess.

Cover the requirements that carry actual liability:

  • Disclosure: sponsored, affiliate, and gifted content must be clearly marked (#ad, #sponsored) per advertising-standards rules in your region.
  • Copyright and music: only use licensed images, fonts, and audio.
  • Data and privacy: no sharing of personal customer data; follow your privacy obligations.
  • Regulated industries: finance, health, and legal have extra rules — reference them explicitly if they apply to you.

7. Security

Password management, two-factor authentication on every account, no shared logins in plain text, and an offboarding step to revoke access when someone leaves. Most brand-account disasters are access failures, not content failures.

8. Crisis and escalation

Define what counts as a crisis, who gets notified, and the first response ("acknowledge, pause scheduled posts, escalate"). This should hand off directly to your full social media crisis management plan rather than trying to contain everything in the policy. The policy's job is only to say who pulls the trigger and how fast.

9. Consequences

State plainly what happens when the policy is violated — from coaching to disciplinary action for serious breaches. A policy with no teeth is a suggestion. Keep it proportionate and tied to your existing HR process.

A short example policy you can adapt

Here's a compressed version showing the tone to aim for:

[Company] Social Media Policy

Purpose: This policy protects our brand and our people by setting clear rules for social media use on company accounts and in personal posts that reference [Company].

Who can post: Only the marketing team may post to official accounts. All campaign content is approved by the Marketing Lead before scheduling.

You may: Share our published content, celebrate wins, and engage respectfully with our community.

You may not: Share confidential or unreleased information, disparage anyone, post undisclosed paid content, or speak for the company without authorization.

Personal accounts: You're encouraged to share and talk about your work. Add "views are my own," never share confidential information, and don't present personal opinions as company positions.

If something goes wrong: Notify [role] immediately, pause any scheduled posts, and do not respond publicly until the team aligns.

That's a real, usable starting point. Expand each section to fit your risk profile.

Rollout: a policy nobody reads doesn't count

Writing it is half the work. To make it stick:

  • Keep it short. Two to four pages. If it reads like a legal contract, it dies in a folder.
  • Onboard with it. New hires acknowledge it on day one.
  • Review it quarterly. Platforms change rules; so should you.
  • Make the safe path the easy path. When posting correctly — through an approval queue, on cadence — is easier than posting rogue, compliance takes care of itself.

That last point is the real lever. Governance fails when following the rules is harder than breaking them. Run your brand accounts through one shared, role-based calendar and the policy stops being a document people ignore and becomes the way the work actually happens.

If you're standing up a multi-person posting workflow, you can try SocialKit free for 7 days and route every draft through the right approver across all your platforms before it goes live — the policy, enforced by the tool instead of by hope.

Key terms in this guide