
Rules and ethics
Part of Is a social media approval workflow for UK agencies necessary?
Is a social media approval workflow for UK agencies necessary?
UK agencies need a social media approval workflow to record client sign-off, meet ASA and UK GDPR duties, and stop rework before scheduled posts go live.
What to take away
- Yes, for most UK agencies, because client sign-off is a compliance record as well as a creative decision.
- ASA rules make the advertiser responsible for claims, so agencies need evidence of who approved the final wording.
- UK GDPR requires a lawful basis and accountability for personal data used in targeting or replies.
- Approval should match riska light check for a generic post, a documented two-stage sign-off for regulated claims.
Why approval is not the same as scheduling
Scheduling tools answer when and where a post appears. Approval answers who accepted the content, the claim and the audience. UK agencies often treat the scheduler as the record, then discover it stores only a timestamp. That gap matters when a client disputes a post or a regulator asks for evidence.
Scheduling vs approval
Scheduling
- Question answered
- When and where
- Record kept
- Timestamp only
- Version control
- Not covered
- Dispute value
- Weak
Approval
- Question answered
- Who accepted
- Record kept
- Sign-off evidence
- Version control
- Lapses on change
- Dispute value
- Defensible
A client may approve a draft on Monday and see a changed image on Wednesday. Version control is therefore part of approval. The approver should see the final creative, caption, landing page and paid targeting. If any of those change, the approval should lapse.
The UK rules that shape client sign-off
The CAP Code applies to marketing communications in paid and organic social media where they fall within its scope. The ASA's advertising codes page sets out the rules and the responsibility of advertisers. Agencies should keep a record that the client approved claims, prices and comparisons before release.
UK GDPR sets duties for personal data processed in scheduling, targeting and replies. The ICO's UK GDPR guidance hub explains lawful basis, consent and accountability. An approval workflow should show which basis covered each audience and message.
The Data Protection Act 2018 sits alongside UK GDPR and covers law enforcement and other processing. For agency work, the practical point is accountability: document decisions, not just outcomes.
A five-step approval workflow for UK agencies
Use this sequence for each campaign or always-on content stream.
Five-step approval workflow
- Classify post by risk, channel, data use
- Build approval pack with final assets
- Route to named client and agency approvers
- Capture decision, version hash and timezone
- Lock approved version into scheduler
A five-step approval workflow
- Classify the post by risk, channel and data use. Record whether it contains claims, prices, competitions or personal data.
- Build the approval pack. Include the final caption, image or video, landing page, targeting notes and expiry date.
- Route to named approvers. Use one client owner and one agency owner, with a deputy for holiday cover.
- Capture the decision. Record approve, approve with edits, or reject, plus the version hash and timezone.
- Lock the release. Move only the approved version into the scheduler. If an edit is needed, return to step 2.
Where agencies lose time and money
Slow approval usually comes from missing information, not stubborn clients. If the approver sees a caption without the image, the decision stalls. A single approval pack with a deadline removes most of that friction.
Agency managers also underestimate the cost of rework. A post rescheduled twice can consume account management time, design time and media time. The internal article on Costing social scheduling beyond the supplier charge explains how to include labour and exit costs.
How to fit approval to client risk
Not every post needs a formal committee. Match the route to the risk. A generic brand post may need one agency check and a client notification. A financial promotion, health claim or competition needs documented client sign-off. A paid campaign using personal data needs a named data contact.
Keep the model under review. If a client's sector changes or a campaign uses new data, move it up a tier. The social scheduling plan template includes fields for rights, timezone and stop rules, which makes the tier decision easier to record.
Common questions
Does every social media post need client approval?
No. Low-risk posts can follow a notification route if the client has agreed that in the contract. Regulated claims, prices and personal data use should always have documented approval.
Who owns approval in a UK agency?
The agency owns the process, but the client owns the decision on its brand and claims. Name one client approver and one deputy. The agency account lead should own the internal route and the record.
How long should approval take?
Set a service level in the contract, such as two working days for standard posts. High-risk campaigns need longer. If the client misses the deadline, the scheduler should hold the post, not release it.
What evidence should agencies keep?
Keep the approved version, the approver name, the date and timezone, and any conditions. For personal data, keep the lawful basis and the client instruction. Retention should follow the agency's data policy and the client contract.



