The hard part of social media work as a virtual assistant is not the posting. It is that every account you touch belongs to somebody else. You need enough access to do the job, no more than that, and a way to hand it all back on a week’s notice without anything breaking. Get that part right and the rest of the work is ordinary.
This is a guide to the access and handoff side, which is the part nobody writes about, rather than to caption writing.
How do you get access without sharing passwords?
Ask for a connection, not a login. Every major network supports delegated access: the owner keeps the account and grants a role or an app connection on top of it.
| Network | The right way in | What you should never accept |
|---|---|---|
| Facebook and Instagram | A role on the Page or Business asset, granted from the client’s Business Manager | The client’s personal Facebook password |
| A Page admin role on the company page | Access to the client’s personal profile login | |
| YouTube | A channel permission via the Brand Account, or Google delegation | Signing into the client’s Google account |
| A business account role | A shared password | |
| X, Bluesky, Threads, Mastodon | A scheduler connection authorised by the owner | A password, unless the network genuinely has no other route |
Two rules follow from that table. First, if the only way in is the client’s password, that is a fact about the network, not permission to make it your default. Write it down in the agreement and turn on the client’s two-factor with the client’s own device, not yours. Second, whoever holds the Business Manager holds everything downstream. If a client’s Page lives inside an agency’s Business Manager that predates you, expect a slow untangling later.
Do the connecting yourself while screen-sharing with the client. It takes fifteen minutes once and saves the three-day email thread where they try to find the right settings screen.
Why do approvals matter more when you are not the brand?
Because a mistake costs you the client rather than costing you a Tuesday.
An in-house social manager who posts something clumsy has a manager, a context and a history to fall back on. A contractor who posts something clumsy has an invoice and a signature. Approvals are not bureaucracy in that position. They are the record that says the client saw this wording and said yes.
What that looks like in practice:
- Everything you write for a client goes into a queue that cannot publish itself until somebody on their side approves it.
- A rejection comes back with a reason attached, in writing, in the same system. Verbal feedback in a call disappears.
- You stop asking for approval on the recurring, boring posts once a pattern is established, and keep asking on anything with a claim, a price, a date or a person in it.
The last point matters, because an approval step that covers everything gets rubber-stamped within a month and then protects nobody. Approve the risky category, not the whole calendar.
If you work with several clients, keep each client’s accounts grouped separately so you cannot open the wrong calendar. This is the same problem agencies have, and the agency workflow guide covers the grouping side in more detail.
What happens when a client leaves?
Plan the exit at the start, when everyone is friendly, rather than during the awkward final week.
A clean handoff has four parts:
- Remove your access, and confirm it is gone. Ask the client to check their own Business Manager and Page roles afterwards. Your word that you removed yourself is not the same as them seeing it.
- Hand over the scheduled queue. Anything you have queued past the last day of the engagement either gets cancelled or gets transferred. A post that fires two weeks after the contract ended is a bad last impression and occasionally a real problem.
- Hand over the media. Photos, graphics and video you produced for them. Agree upfront whether the source files come with it, because that is a genuine dispute in a surprising number of engagements.
- Hand over the calendar and the notes. What was scheduled, what performed, what the client vetoed and why. This is the part clients remember you for.
The single most common failure is the queued post that fires after the relationship ends. Before your final week, list everything scheduled beyond the end date and go through it with the client line by line.
Keep your own work in an account you control, and connect the client’s channels to it. Then leaving means disconnecting channels rather than surrendering your workspace. If the client insists that the scheduling account be theirs, that is a reasonable request, but it means you are a user inside their tool and you should price accordingly.
What should be in the agreement?
Short list, and it makes the rest of the job calmer:
- Which accounts you have access to, and at what role.
- Who approves what, and how long they have to do it before a post slips.
- What happens to scheduled posts when the engagement ends.
- Whether you or the client owns the media you produce.
- Whether you are permitted to reply to comments and DMs, or only to publish.
That last one gets skipped constantly. Replying is a different risk from posting, and plenty of clients want you doing one and not the other.
The short version
- Get delegated access through roles and connections, never a password, unless the network leaves no other option.
- Put an approval step in front of anything with a claim, a price, a date or a person in it.
- Group each client’s channels separately so the wrong calendar cannot be opened.
- Before an engagement ends, clear or transfer everything queued past the last day.
- Write the exit into the agreement while everyone still likes each other.
Scheduling several clients from one place
This is the practical shape of the work: one workspace you own, each client’s channels connected to it and kept in their own group, posts that wait for that client’s approval before they can publish, and a disconnect at the end rather than a handover of your whole account.
BulkPublish does that. Channels group per client, posts and media carry labels so the calendar filters down to one client at a time, and a post held for approval cannot reach the queue until it has one. Approvals are on the approvals page if you want the detail, and the pricing page lists how many channels each plan connects, which is usually the number that decides how many clients you can carry.
Two free tools worth keeping in a tab: the LinkedIn character counter for checking a client’s post before it goes for approval, and the social media holiday calendar for filling the predictable weeks without asking the client for ideas.