This is a starting point, not legal advice, and a lawyer in your jurisdiction should review anything binding before you put it in a handbook.
A social media policy answers two questions: what employees may say about the company on their own accounts, and who may say anything at all on the company’s accounts. Most policies fail because they only answer the first, or because they read as a list of prohibitions nobody remembers.
The full template is below, inline and ungated.
The template
# Social Media Policy: [COMPANY NAME]
**Version:** [X.X]
**Effective:** [DATE]
**Owner:** [ROLE, e.g. Head of Marketing]
**Applies to:** [Employees, contractors, interns, agency partners]
**Review date:** [DATE]
---
## 1. Purpose
This policy explains how [COMPANY NAME] uses social media and what we ask of
people who work here. It covers company accounts and, where work is involved,
personal accounts. It is not intended to restrict lawful discussion of pay,
working conditions or terms of employment.
## 2. Scope
| Situation | Covered? |
|---|---|
| Posting from an official [COMPANY] account | Yes |
| Posting about [COMPANY] from a personal account | Yes |
| Personal posts unrelated to work | No |
| Posting on behalf of a client | Yes |
| Employee advocacy or referral programmes | Yes |
---
## 3. Company accounts
**Approved accounts.** Only accounts listed in [LOCATION OF THE ACCOUNT
REGISTER] are official. Creating a new account representing [COMPANY] requires
approval from [ROLE].
**Who may publish.** [ROLES]. Publishing access is granted and removed by
[ROLE], and reviewed [CADENCE].
**Access rules.**
- Access is granted through [COMPANY]'s business manager or admin console, never
by sharing a personal login.
- Two-factor authentication is required on every account.
- Access is revoked on the last working day when someone leaves.
**Approval.** Posts are approved by [ROLE] before publishing, except
[EXCEPTIONS, e.g. routine replies].
**Brand voice.** Follow [LINK TO BRAND GUIDELINES].
---
## 4. Personal accounts
You are free to have and use personal accounts. When work comes up:
**Do**
- Make it clear you speak for yourself, not [COMPANY]. A line such as "views my
own" in your bio helps but does not by itself cover a specific post.
- Disclose your employment when you post about [COMPANY]'s products, or about a
competitor. Disclosure rules apply to employees, not just influencers.
- Correct your own factual mistakes openly rather than deleting quietly.
**Do not**
- Share anything confidential (see section 5).
- Speak on behalf of [COMPANY] unless authorised by [ROLE].
- Respond to press, analyst or regulator enquiries. Forward them to [ROLE].
- Post about a live incident, outage, legal matter or acquisition.
- Post customer names, images or data without written permission.
- Harass, discriminate or abuse. This applies at all times.
**Grey areas.** If you are unsure whether a post is fine, ask [ROLE] before
posting. Nobody is penalised for asking.
---
## 5. Confidential information
Do not post any of the following, including in replies, screenshots, video
backgrounds or livestreams:
| Category | Examples |
|---|---|
| Financial | Unpublished revenue, forecasts, funding |
| Product | Unreleased features, roadmaps, internal screenshots |
| Customer | Names, logos, data, contract terms |
| People | Colleagues' personal details, salaries, disciplinary matters |
| Legal | Disputes, investigations, contracts |
| Security | Credentials, internal URLs, architecture, incident detail |
If in doubt, treat it as confidential.
---
## 6. Employee advocacy
Sharing [COMPANY] content is welcome and never required. If we ask you to share
something:
- Sharing is voluntary and has no bearing on performance reviews.
- Add your own words rather than copying supplied text word for word.
- Disclose that you work here.
- Suggested content lives at [LOCATION].
---
## 7. Responding to negative comments
| Situation | What to do |
|---|---|
| A factual complaint | [ROLE] replies within [TIMEFRAME], offers a channel to resolve |
| A factual error about us | [ROLE] corrects politely, once |
| Abuse or spam | Hide or delete per section 8, do not engage |
| Anything legal, safety or press related | Do not reply. Escalate immediately |
Employees should not defend the company in comment threads on their own
initiative. Forward it instead.
---
## 8. Moderation
We hide or delete comments that are [illegal, abusive, discriminatory, spam,
or disclose personal data]. We do not delete criticism.
Deletions are logged in [LOCATION] with the reason.
---
## 9. Escalation
| Severity | Example | Contact | Response time |
|---|---|---|---|
| 1 | Account compromised, offensive post published | [NAME], [PHONE] | Immediate |
| 2 | Viral complaint, press enquiry, legal threat | [NAME], [EMAIL] | [N] hours |
| 3 | Repeated negative comments, minor error | [ROLE] | [N] working day(s) |
Out of hours contact: [NAME], [PHONE].
**If you post something you should not have:** tell [ROLE] straight away. Do not
delete it first. Early reporting is treated as cooperation.
---
## 10. Personal use at work
[STATE YOUR ACTUAL RULE. For example: personal social media use during working
hours is fine in moderation, provided it does not interfere with your work.]
---
## 11. Legal and regulatory
- Follow disclosure and advertising rules in every market we operate in.
- Follow each platform's own terms.
- Do not use copyrighted images, music or fonts without a licence.
- Do not make claims about our products that are not approved by [ROLE].
- [ADD ANY SECTOR RULES: financial promotions, health claims, alcohol, etc.]
---
## 12. Breaches
Breaches are handled under [COMPANY]'s disciplinary procedure. Serious breaches,
including disclosure of confidential information or harassment, may be treated
as gross misconduct.
---
## 13. Acknowledgement
I have read and understood the [COMPANY NAME] Social Media Policy.
Name: ____________________ Signature: ____________________ Date: __________
How to adapt each part
Section 2, scope. Contractors and agencies are the most commonly missed group and often have the most account access. Name them explicitly.
Section 3, access. The single most valuable clause here is the ban on shared personal logins. Accounts held in someone’s personal Facebook account is the reason companies lose their pages when that person leaves. The access review cadence is what catches it.
Section 4, personal accounts. Keep this permissive. A policy that reads as a gag order gets ignored entirely, and in many jurisdictions it is unenforceable where it touches discussion of pay and working conditions, which is why the purpose section says so directly.
Section 5, confidential information. The categories table is more useful than a paragraph, because people check tables. The “video backgrounds and livestreams” phrasing is deliberate: a whiteboard behind someone on a call is a real leak route.
Section 7 and 9. The escalation table needs actual names and actual phone numbers, filled in and kept current. A policy with “[ROLE]” left unreplaced in an incident is a policy that fails at the only moment it mattered.
Section 10. Write the rule you actually apply. A rule everyone breaks devalues the whole document.
Section 11. Add your sector’s rules. Financial services, healthcare and alcohol brands all have specific requirements that a generic template cannot cover, and this is where your lawyer’s review matters most.
What most people get wrong
Writing a list of prohibitions with no escalation path. People need to know who to call at 11pm, not just what they may not say. Section 9 is the most-used part of a good policy.
Restricting lawful speech. Blanket bans on discussing the company are frequently unenforceable and always corrosive. Aim at confidentiality and misrepresentation, not criticism.
Never removing access. The offboarding line in section 3 is the clause most often written and least often executed. Tie it to your leaver checklist or it will not happen.
Leaving it unsigned. The acknowledgement in section 13 is what makes the policy usable in a disciplinary process.
Writing it once. Platforms, and the company’s own accounts, change. The review date exists for that reason. Pair the review with a social media audit, which surfaces the account and access facts sections 3 and 9 depend on.
Confusing this with brand guidelines. A policy governs conduct and risk. Tone, visuals and formatting belong in brand guidelines, and section 3 should link to them rather than restate them.
Making the access rules real
Sections 3 and 9 assume you can answer “who can publish to which account” instantly. Most teams cannot, because access is spread across each platform’s own admin console.
Publishing through one tool makes that answerable: roles decide who can publish, approvals put a named reviewer in front of anything going live, and platform access sits in the company’s connection rather than in an individual’s browser session. It does not replace the policy, but it is the difference between a policy that is written and one that is enforced.
The short version
Thirteen sections. Be permissive about personal accounts and strict about confidentiality and access. Ban shared personal logins. Put real names and phone numbers in the escalation table. State that reporting your own mistake early is treated as cooperation. Get it signed, set a review date, and have a lawyer read it before it becomes binding.