Short answer: keep each client's accounts, files and approvals separate, and make the separation physical where you can: group each client's accounts on their own phone or phones, name devices by client, and keep a per-client log of what was posted. Clients should own their accounts; the agency gets access, not ownership. Get written approval for what goes out.
Principles
| Principle | In practice |
|---|---|
| Clients own their accounts | Accounts registered to client email; agency is added or given credentials under a written agreement |
| One client never sees another | Separate folders, calendars and devices |
| Every post is approved | Written sign-off per batch |
| Every post is recorded | Per-client log: time, account, status |
| Access ends cleanly | Offboarding checklist when a client leaves |
Phones per client
On phones, account switching happens inside the apps, so several accounts share a device. Grouping by client keeps mistakes contained.
| Client size (example) | Accounts | Phones (assumption) |
|---|---|---|
| Small SaaS | 2–3 (brand, founder) | 1 dedicated phone, or a shared phone if you accept the risk |
| Mid-size | 4–8 | 1 dedicated phone |
| Large | 9–16 | 2 dedicated phones |
These are operational choices, not platform rules. A dedicated phone per client makes offboarding simple: sign out and reassign one device. Hardware choices are covered in best iPhone for a phone farm and USB hubs.
Naming and records
- Devices: "Client A – Phone 1", "Client B – Phone 1".
- Files:
clientA_2026-09-18_demo-invoices_tiktok.mp4. - Links: a per-client UTM sheet, with
utm_campaignset per client program; see UTM links. - Log: every post with account, platform, time and outcome.
Access and security
- Two-factor authentication on every client account, with recovery methods the client controls.
- Credentials in a password manager with per-client vaults.
- Staff access limited to the clients they work on.
- On offboarding: sign out of every app on the client's phones, remove saved credentials, return or delete files as agreed, and confirm in writing.
Reporting to clients
A simple monthly client report covers what was planned, what was posted (with confirmed status), what was not and why, and the signals you agreed on, such as tagged link clicks and follows. Keep the per-client log as the source, so the report can be rebuilt from records rather than memory. Share problems early; a client who hears about a failed post from you trusts the rest of the report.
Approvals and content rules
Send each client a batch with captions and times; post only what they approve. Use only content the client owns or has permission to use. Do not offer clients fake engagement such as bought likes or follows. For team workflow, adapt the social team SOP.
Running client posting with Farmero
Farmero runs from a Mac and drives iPhones you own, up to eight accounts per iPhone. Before posting or warming, it reads the profile header on screen to prove it is on the right account, which matters most when a mistake would put one client's clip on another client's profile. Each post is checked on the profile and reported as posted, uncertain or refused, which gives you a per-client record. Optional per-phone proxies are in Settings. The Agency plan covers 60 iPhones, 480 accounts and 10 Macs at $349 a month. Automating these apps may breach their terms, and nobody can promise an account will never be restricted; tell clients that plainly. See running several phones and pricing.
FAQ
Should an agency own client social accounts?
No. The client should own them, with the agency given access under a written agreement.
Can two clients share one phone?
It is possible, but a dedicated phone per client is cleaner for access and offboarding.
How do we prove to a client that posts went out?
Keep a per-client log with the time, account and confirmed status of each post.
What happens when a client leaves?
Sign out of their accounts on every device, remove stored credentials, and confirm in writing.
