← Back to Blog

Social Media Guidelines for Small Business: The One-Page Document You Can Adopt Today

Social media guidelines for a small business are one page that says who may post, what needs approval before it publishes, what never goes out, what tone the business speaks in, how replies are handled, what record is kept, who owns the logins, and when the page is reviewed.
You can copy the table below, fill in three names and adopt it today.
The reason to write it down is not the day everything goes well; it is the day a staff member posts a customer's name, a price that changed last month, or a claim about results, and nobody can say whether that was allowed.
Software with an approval step enforces the two lines that matter most, who posts and who approves, without anyone having to remember them.

Why one page

Length is what kills a guidelines document.
A ten-page policy borrowed from a corporate template gets signed once and read never.
A small business needs the opposite: a page short enough to sit in the shared drive, be read in five minutes, and be pointed at when a question comes up.

The page does three jobs.
It tells a new employee what they are allowed to do on the business accounts before they touch them.
It gives the person who approves posts a fixed list to check against, so approval is a read, not a debate.
And it gives you something to point at when a post goes wrong, so the fix is to the page and not to the person.

Everything below is written for a business of one to twenty people with one owner who is accountable for what the accounts say.
If you have a marketing department, you already have a longer document, and this page is the summary that should sit on top of it.

The guidelines, as a table you can copy

Copy the table, replace the bracketed items, and save it where the team can find it.
Every row is one rule and one owner.

RuleWhat it saysOwner
Who may postOnly [name] and [name] publish to the business accounts. Everyone else sends ideas, photos and corrections to them.[Owner]
What needs approvalEvery post is read by [approver] before it publishes. Nothing goes out unread, including reposts, stories and replies that make a claim.[Approver]
What never goes outA customer's or client's name, photo, address, property or situation without written permission. A health, legal or financial claim about results. A price, hour or offer that can change. Anything about a specific person without their permission. Anything your trade's regulator restricts.[Approver]
ToneWe write the way [name] talks to a customer in person: plain words, first person, no hype, no exclamation marks, no jokes at anyone's expense. We say what we do, not that we are the best.[Owner]
Replies[Name] answers comments and messages within one business day. Complaints get a short public reply and a move to private. We never argue, never delete a critical comment that is civil, and never reply to a customer's situation in public.[Name]
Corrections and takedownsA post that breaks a rule comes down the same day, with a short correction if it was seen. [Approver] notes what happened in the record.[Approver]
The recordEvery published post is kept with its date, channel, the approver's name and the source of any fact in it. Screenshots or an export are enough.[Approver]
LoginsBusiness accounts belong to the business. Logins live in [password manager], two people hold access, and access is removed the day someone leaves.[Owner]
Personal accountsStaff may say where they work. They do not speak for the business, share customer information, or post anything the never list covers, on any account.[Owner]
Review dateThis page is reviewed on [date, six months out] and any time a post has to come down.[Owner]

Ten rows.
If you fill the brackets with the same name in every row, that is fine; the page is still doing its job, because the next hire will read the names before they read anything else.

The rows, explained once

Who may post

Name the people, not the roles.
"The marketing team" is nobody in a business of eight.
Two names is the right number: one to post and one to cover a week of holiday.
Everyone else feeds them, and the feed matters, because the best photo of the month is usually on a technician's phone.

What needs approval

The plain rule is that everything is read before it publishes.
Some businesses soften this to "everything except reposts of our own earlier posts," which is reasonable.
What does not work is "use your judgment," because judgment is what the page exists to replace.
The approval workflow page has the template for how the read happens and how to keep it from stalling the week.

What never goes out

This is the row that earns the page.
Write it as a list and treat it as a hard stop, not a judgment call.

Customer details are first because they are the easiest rule to break without meaning to.
A before-and-after photo, a thank-you message pasted into a post, a "congratulations to the Smiths on their new home" with the house behind them: each one is a person's information published without their permission.
Get written permission, a text message is enough, and file it with the record.

Health, legal and financial claims are second because they are the hardest to take back once they are published.
"Our treatment cures," "you will win your case," "you will save thousands": each one is a claim about a result you do not control.
Describe the service and let the reader draw the conclusion.

Perishable facts are third.
A price, an opening hour, a staff name or an offer that ends on Friday will be wrong eventually, and the post will still be up.
Point to the website for anything that changes, and keep the website current.

Anything about a specific person without permission is fourth.
That covers a competitor, a public figure, a former employee and a customer who left a bad review.
Nothing the business posts about a named person is worth the reply it will get.

Your trade's rules are fifth, and you fill this in.
Real estate has fair housing language.
Financial services have advice and testimonial rules.
Clinics have patient privacy.
Contractors have licence display rules in some states.
Write the one that applies to you into the row in your own words.

Tone

One sentence is enough, and the best one describes a person: "we write the way Maria talks to a customer at the counter."
Add the three things you never do.
Three that hold up well: no hype, no exclamation marks and no jokes at anyone's expense.
The content quality checklist turns the tone line into checks a reader can apply to a draft.

Replies

Set the clock, one business day, and set the move: a short public reply, then private.
The rule against deleting civil criticism matters more than it looks.
A deleted comment gets screenshotted and reposted; an answered one gets forgotten.
The rule against discussing a customer's situation in public is the never list applied to replies, and it is easy to break with good intentions.

The record

Keep every published post, with its date, its channel, who approved it and where the facts came from.
This sounds like bureaucracy until the first time someone asks "did we ever say that," and you can answer in a minute.
A monthly export from the scheduling tool, or a folder of screenshots, is the whole system.

Logins

Accounts belong to the business.
That means the email on the account is a business address, the password lives in a manager two people can open, and access is removed on someone's last day.
An account nobody can open is an account that goes quiet, and that is what happens when the login leaves with the person who held it.

Review date

Six months out, and any time a post comes down.
The review is ten minutes.
Read the page, change the names that changed, add the channel you started, and move the date.

What stays with you whatever tool you use

No software and no service takes these off your plate, and any page that says otherwise is selling.
Fair housing language, medical and legal claims, financial advice rules, and anything perishable such as prices and hours are yours to check, because you know the rule for your trade and the tool does not.
Permission to use a customer's face, name or situation is yours to obtain and file.
The guidelines put these checks in the never row so that whoever approves a post reads them every time, but the approver is a person on your side of the table.

How software with an approval step enforces the page

Two rows of the table depend on people remembering them: who may post, and what needs approval.
Software that publishes only after a named person approves turns both rows into mechanics.
Nobody can post around the approver, because the approver is the publish button.

Boomp is that kind of software.
It reads your public website, writes social media posts about your business from what the site says, makes the images, and adds carousels and short videos on paid plans.
Nothing it writes publishes until it is approved.

The approval step maps onto the guidelines this way.

Guideline rowWho enforces itCore, $39 a monthDone-for-you, $275 a month
Who may postThe software; only the approver's yes publishesYouBoomp's founder
What needs approvalThe software; every post waits for a readYou approve each post in the app, about ten minutes a weekKathleen approves every post; you never open the app
What never goes outThe approver, reading against your listYouKathleen approves every post; your trade's rules stay your check
ToneThe approver; the software writes from your site's own wordsYouKathleen
RepliesYou; no Boomp plan replies to comments or messagesYouYou
The recordYou; an export or a folder of screenshots is the whole systemYouYou

Two limits worth stating plainly.
The software writes from what your public website says, so a claim on your website will be a claim in a draft, and the approver's read against the never list is still the last check.
And no Boomp plan replies to comments, runs ads, shoots photos or holds strategy calls, so the replies row stays with you on every plan.

Here is what an approved post looks like when it comes out of that process.
The customer is a listing agent on the West Michigan lakeshore, shown without her name, and the caption is hers as published.


Two similar houses side by side, one freshly kept and one tired, both for sale.

"Ever wonder why two nearly identical Saugatuck homes sell for wildly different prices?
Same square footage, same bedrooms, same street.
One sells in a week over asking; the other sits for two months."
Excerpt, the first three sentences of the post.
Published August 2, 2026.
Published through Boomp from the agent’s own website.
Shown without the agent’s name.

Read it against the never row.
No client is named.
No price is quoted.
No result is promised.
Nothing about a specific person.
That is what the approval read is for, and the post passed it.

Adopting the page in one sitting

  1. Copy the first table into a document and fill the brackets, with your own name if in doubt.
  2. Write your trade's rule into the never row in one sentence.
  3. Send the page to everyone who has ever posted for the business and ask for one reply: read it.
  4. Move the logins to a password manager two people can open.
  5. Put the review date in your calendar.
  6. Decide who the approver is and pick the tool that makes them the publish button.

The strategy page covers the six decisions that sit above the guidelines: which channels, how often, what about.
The guidelines run underneath whatever you decide there.

The three doors at Boomp

Every Boomp plan starts the same way: the software reads your website and writes posts about your business.
The price follows who does the approving.

- Packs, $9 a month.
Ten finished posts with images, by email link.
You read them against your page and publish the ones that pass.
Nothing is connected or scheduled.
- Core, $39 a month.
Twenty posts, one carousel and one video, published to your connected channels after you approve each one in the app.
You are the approver the guidelines name.
- Done for you, $275 a month.
The same content, with Boomp's founder approving every post.
You never open the app.
It is not an agency: no ads, no replies, no photo shoots, no strategy calls.

No contract on any of the three; plans and prices has the full comparison, including Pro and Max for businesses that need more than Core.

Before any of them, the free door: ten finished posts made from your own website, with images, a carousel and a short video, before any email, account or card, so you can read them against your new page before you pay anyone anything.

Frequently asked questions

What should social media guidelines for a small business include?

Eight things, and they fit on one page: who may post, what must be approved before it publishes, what never goes out, the tone the business speaks in, how replies are handled, what record is kept of each post, who owns the logins, and a date when the page is reviewed. Anything longer than a page gets filed and forgotten. Anything shorter than these eight leaves a gap that a wrong post finds first.

What is the difference between social media guidelines and a social media policy?

Mostly the audience. A policy is usually an HR document about what employees may say about the business on their own accounts, and it carries consequences. Guidelines describe how the business's own accounts are run: who posts, what is approved, what is off limits. A small business needs the guidelines first, because the business accounts publish every week and personal accounts mostly do not. A short line about personal accounts can sit inside the guidelines.

What should a small business never post on social media?

Five categories cover most of the trouble: anything that identifies a customer or client without written permission, health or legal claims about results, prices or hours that change, anything about a specific person without their permission, and anything a regulator in your trade restricts, such as fair housing language in real estate or advice language in financial services. Write the five into the guidelines as a short list and treat the list as a hard stop, not a judgment call.

Who should approve social media posts in a small business?

One named person, and the owner is the default in a business with fewer than ten people. The approver reads every post before it publishes and checks it against the never-post list, the tone line and the facts on the website. If the owner is also the writer, a second reader is still worth having for anything that names a price, a person or a result. The name goes in the guidelines so nobody has to ask.

How often should social media guidelines be reviewed?

Put a review date on the page, six months from the day you adopt it, and add a second trigger: any time a post has to be taken down. The review is a ten-minute read to check that the names, the never-post list and the reply rule still match how the business works. If a staff member, a channel or a rule has changed, update that line and move the date; otherwise the page stands as it is.

How does software enforce social media guidelines?

Software with an approval step enforces the guidelines mechanically. Nothing publishes until the named approver has read it, so the who-may-post line and the approval line hold without anyone remembering them. Boomp works this way: it writes posts from your public website, and on Core you approve each one in the app before it publishes. On done-for-you, Boomp's founder approves every post and you never open the app.

Try it with your business

Get a finished post, carousel, or short video from your website. Keep the file and copy the caption. Your first sample needs no email, account, or card.

Rather not do this yourself? Start with what done-for-you social media should handle or alternatives to hiring a social media manager.

Save this to Pinterest

Social Media Guidelines for Small Business: The One-Page Document You Can Adopt Today
KC

Written by Kathleen Celmins

Founder of Boomp. Helping local businesses stay visible on social media without doing the work themselves.