Named people
Give each operator an individual identity and only the client, brand and task access they need.
A shared password turns one account into an invisible group identity. It weakens attribution, offboarding and incident response. Agencies and multi-brand teams should use platform roles, delegated consent and scoped tool access wherever providers support them, with a documented fallback for the combinations that do not.
Provider role models and consent screens change. Verify current platform documentation and account eligibility. This guide is an operational baseline, not a claim that every provider offers equivalent delegation.
Give each operator an individual identity and only the client, brand and task access they need.
Connect approved software through provider consent instead of handing the primary account password to the tool.
Know who can remove a person, revoke a token and protect scheduled work when access changes.
List account owners, administrators, employees, contractors, agencies, connected applications, recovery addresses, devices and automation tokens. Record the purpose, approver, last use and removal owner for each. Unknown access is a finding even when it appears legitimate.
Separate provider roles from permissions inside your social tool. A person may have access to a brand workspace without permission to publish, and a tool may have a provider token even after a former user leaves. Review both layers together and include recovery methods in the inventory.
Prefer an individual provider identity added through the platform business or channel role model. Use OAuth or the provider consent mechanism for connected software. Ask for the narrowest permissions compatible with the approved workflow. Do not send passwords through chat, documents, email or project-management fields.
Confirm the destination identity during consent. Brand names can be similar and operators can control several accounts. Store the provider account identifier, visible name, workspace owner and granted scopes. Before the first post, have a second person verify that the destination matches the client agreement.
Define who can view, create, edit, approve, schedule, publish, connect accounts, export data and manage billing. Apply access per brand rather than giving a contractor portfolio-wide visibility. Sensitive actions such as token management and publication should require stronger authority than viewing a calendar.
Avoid permanent administrator access for routine work. Use time-bounded access for launches or temporary specialists where the provider permits it. Preserve historical attribution after a person is removed, but prevent their sessions and credentials from authorising new actions.
Onboarding requires an owner request, role approval, individual account, multi-factor authentication where supported, training and a test of the exact workflow. Never copy a predecessor’s credentials. Record the systems and brands granted so offboarding has a complete checklist.
Offboarding removes workspace membership, provider roles, active sessions, recovery methods and personal tokens. Reassign scheduled work and approvals before removal. If a client relationship ends, export agreed records, disconnect the account, revoke consent and confirm what evidence must be retained.
Some legacy or unsupported path may still tempt a team to share credentials. Treat that as a visible exception with owner, reason, limited duration and migration plan. Use an approved password manager if no delegated path exists, never a reusable message or spreadsheet, and rotate after the exception ends.
For suspicious access, freeze publishing, preserve relevant logs, revoke sessions and tokens, rotate recovery factors when necessary and contact the provider. Then reconcile recent remote posts and scheduled intentions. Document what happened without exposing the secret in the incident record.
The security reference explains modern OAuth guidance. Provider help pages define current account and third-party connection controls.
Prefer provider roles and delegated consent. If no supported path exists, document a temporary exception and use an approved secret manager with a migration plan.
OAuth delegates the scopes the user approves. The tool can act within those scopes, so ownership, storage, review and revocation still matter.
Remove tool and provider roles, revoke personal tokens and sessions, reassign scheduled work and preserve past attribution.
Review on a regular risk-based cadence and immediately after staffing, client, ownership or provider-security changes.
Validate the workflow, permissions and evidence before expanding the scope.
Create a Cascads workspace