On this page
The access problem comes first
Every agency eventually has the same painful conversation: a client relationship ends, and nobody is entirely sure what access was granted, to whom, on which tools, using whose login. Solving this before it happens is the single highest-value operational decision in agency social work, and it costs nothing except discipline.
- Never accept client passwords. Ever. It is a terms violation, it makes offboarding impossible to verify, and it puts the liability squarely on you.
- Connect through official OAuth from the client’s own account, so the client can see and revoke your access from their settings.
- Maintain a written register of which tools hold which permissions for which client, reviewed quarterly.
- Document the offboarding sequence and run it the day a contract ends, not when someone remembers.
- Re-audit connected apps after any staff departure, because access follows people more often than anyone plans.
The revocability of an OAuth connection is what makes clean offboarding possible at all, and it is one of the concrete practical differences between official and credential-based tooling. The permission model is explained in Instagram OAuth permissions for DM automation.
Standardising without making every client sound the same
Agencies get efficiency from repeatable process and get fired for delivering visibly identical work. The resolution is to standardise the structure and vary the substance: same rule architecture, same review cadence, same measurement — entirely different words.
- A standard rule taxonomy every client gets: lead magnet, pricing enquiry, booking intent, out-of-hours, negative-sentiment exclusion.
- A copy brief per client capturing voice, banned phrases, and claims that require legal review.
- Trigger words chosen per brand rather than reused across the roster, so a leaked playbook is not a competitive giveaway.
- A shared QA checklist applied identically, because process consistency is invisible to clients and valuable to you.
The negative-sentiment exclusion should be non-negotiable across every account you manage. One automated discount offer sent to a client’s publicly complaining customer is a screenshot that ends a relationship. The reasoning is in the Meta-safe comment-to-DM guide.
A repeatable client onboarding sequence
- Confirm the account is professional and the message-access setting is enabled — before you promise a launch date.
- Connect via OAuth in a session with the client present, so they understand what they granted.
- Audit their existing connected apps and remove anything abandoned; this alone is often worth the first month’s fee.
- Collect the copy brief, the banned-claims list, and the escalation contact for out-of-hours incidents.
- Build and test one rule on one post from a second account before anything touches live creative.
- Agree the reporting cadence and the specific metrics up front, in writing.
- Set the review date for the first rule audit at onboarding rather than promising to remember.
Step one prevents the most common launch delay in this category. The connection prerequisites fail silently and take days to diagnose if you discover them the afternoon before a campaign — the diagnostic order is in the OAuth permissions guide.
Incident response across a portfolio
With one account, an incident is an inconvenience. With twenty, it is a Saturday. The scenarios are predictable enough to write runbooks for, and the agencies that do are visibly calmer than the ones improvising.
- A client post goes viral overnight and the automation queue backs up — who is paged, and what gets throttled?
- A client account gets restricted — what do you stop, what do you tell them, and in what order?
- A rule fires on the wrong audience — how fast can you pause it, and from a phone?
- A platform change breaks event delivery across every account simultaneously — this happens, and the answer is a vendor with a track record.
- A staff member leaves mid-campaign — whose rules were they, and who owns them now?
Capacity behaviour during a spike, and which ceiling you hit first across many accounts, is covered in Instagram API rate limits explained.
Reporting that renews contracts
Clients do not renew because comment volume rose. They renew because they can see revenue, or a credible proxy for it, attributable to what you did. That requires instrumentation decided at onboarding, because attribution cannot be reconstructed retroactively.
- Distinct UTM parameters per rule per client, agreed before launch.
- Unique discount codes where the client sells products, which removes attribution disputes entirely.
- Report triggered conversations, reply rate, human-handoff rate, and downstream outcome — in that order of increasing importance.
- Include what you switched off and why; pruning underperforming rules is visible work that clients rarely see otherwise.
- Show response-time improvement, which is the easiest win to demonstrate and the one clients feel.
Response time is the underrated line in an agency report because it maps directly to money the client was previously losing. The arithmetic is in what missed Instagram messages cost, and the fuller metric set in Instagram DM automation metrics and ROI.
Pricing the service and the tooling underneath
Agencies get squeezed when their cost model and their revenue model have different shapes. If you bill a flat retainer per client and your tooling charges per contact, a client’s viral month costs you money — and it is the client you would most like to keep happy.
- Prefer per-account or flat tooling pricing, which maps cleanly onto per-client retainers.
- If you must use contact-based tooling, build a volume clause into the client agreement.
- Price setup separately from management; the initial build is genuine work and clients understand that.
- Charge for the audit. Reviewing and pruning rules quarterly is where the ongoing value is, and unbilled work gets deprioritised.
- Negotiate multi-account arrangements explicitly rather than stacking single-account subscriptions.
The mechanics of each pricing model and what it punishes are covered in Instagram DM automation pricing explained.
What to require from tooling
Agency requirements diverge from single-brand ones in ways vendor comparison pages rarely capture. These are the questions worth asking before a roster-wide rollout.
- Aggregate visibility across accounts with per-account drill-down, in one view.
- Role-based access so a junior can edit copy without holding the connection.
- Per-account exports, because clients will ask for their data at some point.
- Alerting on connection expiry — across twenty accounts, silent token expiry is a certainty rather than a risk.
- A clear answer on who is accountable if a client account is restricted while using the product.
SocialAutoDM’s standard plan covers a single connected account — an Instagram account or a Facebook Page — so agency rosters are handled as an enterprise arrangement — multiple accounts, custom workflows, and a named contact — through sales. The general evaluation criteria, useful whichever vendor you land on, are in the buyer’s guide.
Frequently asked questions
Should agencies ask clients for their Instagram passwords?
How do rate limits work across many client accounts?
What happens to automations when a client leaves?
Can we white-label this for clients?
Put this into practice with SocialAutoDM
Keyword rules, instant replies and DMs on Instagram and Facebook — on Meta’s official APIs.