How to manage Google My Business: control roles, data, and reviews
Managing Google My Business—now Google Business Profile—means maintaining an accurate public representation and replying from authorized accounts. It includes ownership, roles, changes, hours, photos, reviews, and incidents, not just editing fields. A good process reduces errors and protects the business, but it cannot set local rankings.
Quick answer
Use the correct Business Profile, keep ownership in a company-controlled account, and give each collaborator the minimum role needed. Assign owners for information, hours, photos, questions, and reviews; log changes and incidents in Search and Maps. For multiple locations, keep data separated by profile and do not merge profile metrics with website metrics.
Five layers of management
A healthy profile needs access and content controls. If one person can edit everything with no record, the issue is operational governance, not SEO.
| Layer | Control question | Recommended practice |
|---|---|---|
| Ownership | Does the company control the owner account and have a recovery path? | Use a company email, secure recovery, and a register of owners and managers. |
| Permissions | Can each person do only what their role requires? | Separate ownership, local management, review support, and support escalation; remove access when roles change. |
| Data | Does the profile reflect the current name, contact, location, category, and hours? | Review edits against an internal source and check the public result. |
| Experience | Can customers find, contact, and understand the service without contradictions? | Test links, phone, special hours, photos, and questions on mobile. |
| Reputation | Are reviews handled with context, privacy, and consistent judgment? | Centralize work if useful, but preserve human review and real publishing permissions. |
| Incidents | What happens when Google rejects an edit, suspends a profile, or a duplicate appears? | Define escalation, evidence, owner, and timeframe; never create parallel profiles as a shortcut. |
How to build a management system
Consistent management depends more on boundaries and owners than on editing many times a day.
Inventory accounts and profiles
List every location, URL, owner account, managers, verification state, and critical data. A visible inventory exposes personal access, duplicate locations, and sites without an owner.
Define roles and approvals
Agree who can edit information, reply, change links, or ask for help. In regulated sectors, add review before publishing a reply that could reveal sensitive details.
Set a cadence
Review data and hours whenever they change and schedule checks for links, photos, questions, and reviews. Keep it realistic; an impossible checklist creates false confidence.
Log changes and incidents
Keep date, field, old value, new value, reason, user, and verification. If Google rejects an edit or a profile changes unexpectedly, the record speeds diagnosis.
Separate data and decisions
Keep profile actions, website organic queries, published replies, and commercial outcomes distinct. Improve one operation without attributing everything to one edit.
Daily management checklist
Turn management into a small sustainable routine. The aim is to catch risk before it affects a customer.
Secure access. The company can recover the owner account and no shared password is required.
Minimum roles. Each collaborator has the necessary permission and an offboarding process exists.
Current data. Name, contact, category, location, and hours match real operations.
Contextual replies. Replies protect privacy, offer a next step, and do not rely on an empty template.
Changes verified. The team checks the public profile rather than assuming Google published the edit.
Escalable incidents. Duplicates, suspension, or rejection have evidence and an owner without parallel listings.
Operational governance metrics
Management can be measured without turning a dashboard into a ranking promise.
| Metric | Proper use |
|---|---|
| Active access | Measure exposure and review whether each person still needs the role. |
| Rejected edits | Find data or policy issues; approval does not prove a ranking improvement. |
| Reply time | Manage service capacity, not a promised local position. |
| Location coverage | Show whether each site has a profile, owner, and reviewed data. |
| Open incidents | Prioritize duplicates, suspension, broken links, and wrong hours by customer impact. |
| Commercial outcomes | Connect calls, forms, or sales to source and location; state what cannot be attributed. |
Scenarios and decisions
Use this matrix to adapt the guide to a real situation. Each row separates the observable problem from the safer action, so the team does not turn a hypothesis into a promise.
| Situation | What may be happening | Recommended decision |
|---|---|---|
| Ownership | Managing a listing means keeping public information correct and replies inside a process. | Assign an operating owner per location and a review date instead of vague responsibility. |
| Permissions | Editing and replying should not depend on sharing personal passwords. | Use official roles, review access, and remove accounts no longer working with the business. |
| Information | Hours, services, phone, and address change with the operation. | Record the change in a master source and check the public view afterwards. |
| Reviews | A reply should be useful, respectful, and cautious with customer information. | Escalate sensitive cases and do not turn a public reply into a private argument. |
| Multiple sites | An aggregate board can hide a location without an owner or with stale data. | Filter by location, state, and owner before claiming the network is covered. |
| Incidents | Rejected changes, suspended profiles, and wrong data require different diagnoses. | Keep operational evidence and follow official help rather than duplicating profiles. |
| Control | Operational success is traceable correct work, not a claim about local position. | Measure coverage, response time, and errors separately from Search Console impressions. |
| Access audit | A person who can view a profile may not have the same capabilities as an owner or manager. | Map the required action to the minimum appropriate role and review access after staff changes. |
| Shared workflow | A password shared across a team makes it difficult to know who changed a public field. | Use the supported account and permission model, with named owners for material changes. |
| Duplicate location | A move, rebrand, or second site can make an old profile look like a new one. | Reconcile existing listings before creating another profile and keep location identifiers in the operating record. |
| Review queue | A profile can receive feedback while the team is changing hours, phone numbers, or services. | Separate urgent customer replies from profile maintenance and assign an owner to each queue. |
| Change review | A saved edit is not proof that the public listing now shows the intended value. | Reopen the visible profile after important updates and record the result and date. |
| Recovery | Loss of access can stop replies and updates even when the public profile remains visible. | Maintain a documented recovery contact and escalation path without storing credentials in editorial content. |
Frequently asked questions
Is management only editing fields?
No. It includes ownership, roles, changes, hours, photos, reviews, incidents, and public verification.
Should I share the password with an agency?
No. Grant the needed Google role and keep company ownership.
Does every location need an owner?
Yes, even when one person coordinates several. The owner needs profile, operations, and escalation context.
How do I control unexpected changes?
Log old value, new value, user, date, and public verification to distinguish internal edits from external changes.
Can I automate everything?
Do not enable writes without authorization, limits, retries, auditability, and policy review. Google actions need context.
What if a profile is suspended?
Read the reason, gather evidence, and use the official appeal process; do not create a duplicate shortcut.
What does Repliq add?
It can organize a review queue and help draft replies, but profile authority, permission, and publication remain with Google.
Next step
Start with the inventory and remove access or profiles the business cannot control. Then create a review queue with location and owner. Repliq can organize work and help draft replies, but Google's account and permissions remain authoritative.