SEO agency onboarding checklist: make the first 30 days usable
Set up account ownership, measurement, business context, content workflows, technical delivery, approvals and the first roadmap without turning onboarding into a password-collection exercise.
Onboarding is complete when the team can make and ship a decision—not when every login works
Access without conversion definitions, product context, implementation owners, expert review, and approval times produces faster confusion. Treat the first month as the construction of an operating system: who knows, who decides, who changes, who validates, and how the evidence is preserved.
First-month sequence
What each onboarding stage must unlock
Create the operating frame
Name the sponsor and day-to-day owner, define goals and conversions, create the access register, agree the responsibility map, and schedule decision-makers.
Open the right doors
Grant named, scoped access; explain the business, customers, platform, content standards, release calendar, approval routes, and known constraints.
Establish what is true
Validate tracking, approve a dated baseline, inventory content and systems, separate business from search competitors, and open the issue register.
Turn discovery into delivery
Agree the first 90-day roadmap, reporting format, content workflow, change control, acceptance tests, risks, dependencies, and next decisions.
Interactive first-month template
SEO agency onboarding checklist
Check an item only when the access, definition, owner, or decision is usable—not merely requested in an email.
Access model
Keep ownership with the client and grant only the role the task needs
Use individual accounts, MFA where available, and an access register. The precise permission depends on the work; discovery should not silently become permanent administrator access.
| System | Durable client control | Agency access | Exit check |
|---|---|---|---|
| Search Console | Client remains a verified owner | Named full or restricted user based on the task | Remove agency users and review unused ownership tokens |
| Google Analytics | Client controls the account and property administrators | Viewer, Analyst, Editor, or other minimum role at the required level | Remove users or groups and retain definitions, annotations, and exports |
| Google Tag Manager | At least two active administrators inside the client organisation | Read, Edit, Approve, or Publish only where required | Remove direct and inherited access; export the current container version |
| Business Profile | Business retains primary ownership | Individual manager or owner only when the task needs it | Remove the agency user and confirm the business still controls the profile |
| CMS and code | Client controls administrator, repository, hosting, and recovery access | Named draft, edit, deploy, or read role with MFA where available | Deactivate accounts, keys, tokens, SSH access, and active sessions |
| CRM and lead data | Client controls the system, field permissions, retention, and lawful use | Restricted reports, masked fields, aggregated exports, or scoped user access | Remove access and confirm treatment of downloaded or cached data |
Do not send a spreadsheet of shared passwords. Named accounts and platform roles preserve accountability, allow minimum access, and make revocation possible without changing every credential.
Kickoff agenda
Use the first meeting to expose decisions and dependencies
Business
Which product, market, customer, conversion, and commercial constraint is the programme meant to influence?
Customer
What language, objections, evaluation criteria, evidence, and sales feedback should guide discovery and content?
Measurement
Which systems define a conversion, qualification, sale, value, and reporting period—and where is the data weak?
Platform
Which stack, release, security, migration, performance, or vendor constraints affect implementation?
Content
Who supplies expertise, sources, brand rules, legal review, media, publishing, and refresh decisions?
Delivery
Who prioritises, creates, approves, implements, validates, and escalates each workstream?
Next ten business days
Which access grants, interviews, exports, audits, and decisions will happen next, with an owner and date?
Day-30 handoff
What should exist by the end of onboarding
A large or technically complex site may still be under analysis. These records should nevertheless be usable enough to govern what happens next.
Access register
Systems, client owner, agency user, permission, purpose, grant date, review date, and removal process.
Measurement baseline
Dated source data, conversion definitions, filters, known gaps, seasonality, and data-quality limits.
Issue and opportunity register
Evidence, affected scope, impact, confidence, effort, owner, dependency, status, and validation.
First 90-day roadmap
A feasible sequence matched to development, content, approval, analytics, and authority capacity.
Content and authority plan
Priority audiences, topics, pages, sources, experts, production ownership, promotion, and policy boundaries.
Reporting pack
Metric glossary, business outcomes, leading indicators, shipped work, blockers, insight, and decisions.
Governance records
Responsibility map, approval targets, communication rhythm, change control, risk log, and escalation path.
Primary platform guidance
Named roles make onboarding and offboarding safer
Google’s current documentation separates owners and users in Search Console, allows Analytics access at account or property level with specific permissions, and supports Tag Manager permissions from read through publish. Tag Manager explicitly recommends that someone inside the organisation manage the account rather than an external agency. Business Profile supports owners and managers without password sharing and advises businesses to retain access when adding third parties.
SEO agency onboarding FAQs
How long should SEO agency onboarding take?
Basic access and operating decisions should usually be resolved early, while a complex audit or enterprise baseline may take longer than a month. The first 30 days should still produce usable ownership, measurement, issue, roadmap, and governance records rather than an indefinite discovery phase.
What access does an SEO agency need?
Access depends on the contracted task. Discovery often starts with read-only Search Console, Analytics, CMS, crawler, and reporting access. Editing, publishing, deployment, DNS, or administrator rights should be added only for named work with appropriate approval, logging, and removal controls.
Should we share passwords with an SEO agency?
Prefer individual user accounts, role-based permissions, MFA, and an access register. Shared passwords weaken accountability and make offboarding harder. Platforms such as Search Console, Analytics, Tag Manager, and Business Profile support named users and roles.
What should happen in an SEO kickoff meeting?
The kickoff should confirm the business decision, conversion definitions, customer and product context, platform constraints, delivery roles, approval routes, communication rhythm, immediate access blockers, and the next ten business days of work.
What if the client cannot provide every onboarding input?
Mark the gap, owner, consequence, workaround, and due date. The agency should not invent business truth or hide the limitation. Some work can proceed using documented assumptions, but the roadmap and reporting must show where confidence is reduced.
Who should own analytics and Search Console after onboarding?
The client should retain durable account and property control. The agency should receive named, task-appropriate access that can be reviewed and removed without losing the company’s history, configuration, or ability to manage other users.
Start onboarding with a settled scope and an evidence-tested agency
The first month cannot repair a vague proposal. Confirm responsibilities, investigate red flags, and preserve access ownership before delivery begins.