Write the Social Policy Staff Can Actually Follow.
Most staff social policies only list what is banned. How to write one that reduces risk and still lets your team post about work.
Most staff social media policies are written as a ban list.
They tell people what they must never post and stop there, which reads as a warning rather than a permission.
A policy staff can actually follow does three things. It says plainly what people may post about work, it names the small number of genuine red lines, and it tells them who to ask when something sits between the two.
That order matters. Written the other way round, the only safe reading is to post nothing about work at all, and that is exactly what most teams do.
The legal side points the same way. Rules that are vague are the hardest to enforce, and rules nobody was clearly told about are harder still.
Why a ban list produces silence
A prohibition-only policy asks staff to make a judgement they have no information to make. They know what is forbidden and nothing about what is welcome, so the risk-free option is to say nothing.
Silence looks like compliance. It is really the policy failing at the one job it shares with marketing, which is getting the company talked about by the people who know it best.
The ban list rarely removes much risk either. The posts that cause real damage are almost never written by someone weighing up a handbook. They are written in temper, at speed, or by someone who genuinely did not know a client name was confidential.
The contradiction most brands walk into
Then the growth plan arrives. Someone decides the company needs employee advocacy, or a founder-led social strategy, and asks staff to start posting about their work.
Those people open the handbook and find a document telling them not to mention the employer, not to discuss projects and not to speak for the company. The advocacy push stalls, and it gets blamed on culture.
It is not culture. It is two documents giving opposite instructions, and the older one is the one attached to the disciplinary procedure.
Start with what people may post
Write the permission section first, and make it concrete. Vague encouragement gets read as a trap.
Worth naming explicitly:
- That they work here, and what they do.
- Company posts, campaigns and public announcements, reshared or quoted.
- Their own view on their craft, their industry and how they approach the work.
- Photos from the office, events and team days, subject to the confidentiality rules below.
- Open roles, with a link to the listing.
That list takes ten minutes to write and removes most of the hesitation in one go.
The short list of genuine red lines
Red lines should be short enough to remember without opening a document. Most organisations need something close to this:
- Confidential information: unreleased work, client and customer data, financials, anything covered by an NDA.
- Speaking for the company: only named people do that, and everyone else makes clear they are speaking for themselves.
- Harassment, discrimination and abuse: the conduct standards that apply in the office apply online, including in DMs and group chats.
- Material you do not own: photos, music and copy belonging to someone else.
- People and premises: no colleague, customer or visitor in a photo without their agreement, and no secure areas.
Five rules are memorable. Twenty is a document nobody finishes.
Vague rules are unenforceable rules
“Do not bring the company into disrepute” appears in almost every handbook and does the least work of any line in it. It is a judgement rather than a rule, and it gets made after the fact.
The Acas Code of Practice on disciplinary and grievance procedures expects rules and procedures to be set down in writing, to be specific and clear, and to be findable by the people they apply to. A tribunal can adjust an award by up to 25 per cent where an employer unreasonably fails to comply with the Code.
So specificity is not pedantry. It is the difference between a rule you can act on and one that collapses the moment it is challenged. Have HR or an employment adviser check the final wording. The operational half is what NBK works on, not the legal drafting.
Personal accounts, work accounts, and where the line sits
A personal account belongs to the person. A blanket ban on lawful private expression outside working hours is not a rule an employer can reasonably impose, and attempting it is how a policy loses credibility with the people it governs.
What an employer can act on is narrower and clearer: conduct that breaches confidentiality, that harasses or discriminates against a colleague, or that causes real harm to the business.
Say that in the policy in plain words. People trust a document that admits its own limits far more than one claiming authority over their weekend.
Two things are worth settling in writing while you are there. Who owns a work-related account and the following built on it during employment, and the fact that a “views are my own” line in a bio does not put a post outside the conduct rules.
Say who to ask, and answer the same day
Every policy produces edge cases. The thing that decides whether yours works is who a member of staff asks at four on a Friday, and how long they wait.
Name a person and a channel. Not “the marketing team”. A name, with a named backup.
Then commit to a response time and hold to it. A question that takes four days to answer teaches the whole team that asking is not worth it, and the next borderline post either goes out unasked or does not go out at all.
This is the part a document cannot carry alone. It needs a short session where people can ask the awkward questions out loud, which is why team training shifts behaviour more reliably than another policy revision.
Link it to the disciplinary procedure, and apply it consistently
A policy with no stated consequence is guidance. A policy that jumps to dismissal for any breach is one nobody believes.
State that breaches may lead to disciplinary action up to and including dismissal, and that the normal procedure applies: the allegation put in writing, the evidence shared, a hearing, a right of appeal.
Consistency is where employers lose. Where similar conduct has gone unremarked before, coming down hard on one person reads as disproportionate rather than principled.
Under the unfair dismissal test in the Employment Rights Act 1996, an employer has to show a potentially fair reason and that dismissal was reasonable in the circumstances. Ad hoc enforcement fails the second half of that far more often than the first.
Reputational harm has to be evidenced
“It made us look bad” is a feeling, not a finding. Where reputational harm is the reason for acting, an employer should be able to point to evidence of actual or reasonably foreseeable damage rather than speculative concern.
That has a practical consequence most teams miss. Screenshots, timestamps, visible reach, complaints received, client emails and the sequence of who saw what and when are all far easier to capture in the first hour than the first week.
Whoever runs the social accounts usually sees it first, so they are the person who needs to know what to record. Deleting the post is the instinct, and deleting first destroys the record.
How to roll it out so people actually know it
A policy buried in a handbook nobody opened is close to worthless, and the fact people were never properly told is exactly what makes it hard to rely on later.
- Send the policy on its own, not inside a sixty page handbook update.
- Record an acknowledgement that each person has read it, and keep it on file.
- Run one short live session per team, using real examples from your own industry.
- Repeat it at induction, so new starters get it in week one rather than never.
- Review it once a year, and whenever a platform change makes part of it wrong.
What good looks like
A member of staff reads the policy once and knows what they can post without asking anyone. That is the whole test.
Brand posts still go through a proper process, because the brand account carries a different level of risk, and that is what a good approval process is for. Personal posts about work do not need an approval queue, and putting them in one is how advocacy quietly dies.
Questions arrive occasionally and get answered the same day. Enforcement is rare, and when it happens nobody is surprised by it.
Meanwhile the company shows up in feeds it does not own, in the words of the people who actually do the work.
How NBK thinks about staff social policy
NBK treats this as an operations question rather than a legal one. The wording is for HR and an employment adviser. What decides whether the policy works is the system around it.
That means the permission list gets as much thought as the ban list, the named owner has the capacity to answer, the training happens more than once, and the document is reviewed on a schedule instead of after an incident.
A policy is a workflow with a cover page. Judged that way, most fail at the same three points: nobody knows what is allowed, nobody knows who to ask, and nobody has looked at it in three years.
Next step
If your team is posting regularly but still feels stuck, NBK can help find the constraint in the system. Often it is not the content at all. It is a document written entirely in the language of risk that quietly told forty people to say nothing.
The NBK Social briefing
Social media news and analysis from NBK Social, by email.