Playbooks · 5 min read
Handing an Instagram Inbox to a VA Without Handing Over Everything
On this page
Written for both sides of the arrangement: the person about to hand an inbox over, and the assistant about to be handed one.
This is not the argument about whether to hire a VA or automate instead — that comparison exists separately and it is a false choice in most cases anyway. The two go together. What follows is how to set it up so it survives the assistant leaving.
Rule one, and it is not negotiable: a seat, never the password
The default arrangement in this industry is that the client sends the Instagram login over WhatsApp. Do not do this, in either direction.
Sharing account credentials is against Instagram's terms. It also means the client cannot revoke access without changing a password and breaking every other thing that used it, and it means every action taken is indistinguishable from the owner's own.
The correct shape is boring. The owner connects the Instagram account themselves — an OAuth handshake with Meta, on their own screen, granting a specific set of permissions. The assistant gets a seat in the workspace. When the engagement ends, the seat is removed and the connection is untouched.

What a seat actually gives access to
Every direct message the account has received. Addresses, phone numbers, complaints, order details, occasionally things a customer would be alarmed to learn a third party read.
Both sides should say this out loud once, at the start. The client should know what they are granting rather than discovering it later. The assistant should know they are handling somebody else's customers' private correspondence and behave accordingly — no screenshots into a portfolio, no examples in a pitch deck, no exports to a personal laptop that the client did not ask for. Leads export as a CSV, and where that file goes is a policy question, not a technical one.
An inbox is not a marketing asset you were lent. It is other people's private messages, and they did not agree to you.
What a VA can do freely
Most of the work, in fact. None of these reach a customer without a further step:
- Build automations. Triggers, keywords, negative keywords, drafts of both replies. This is the bulk of the job and it is entirely safe.
- Test on myself. Runs the complete pipeline — match, the ten checks, reply generation, send — and delivers to the tester's own account. Nothing public happens.
- Triage the inbox. Reading, sorting, answering the ordinary questions by hand.
- Keep the records. Annotating lead rows with what somebody wanted. This is where a good assistant quietly creates most of the value, and nobody ever asks for it.
- Read Activity daily. Connection health, blocked replies and their reasons. Nothing alerts anybody here, so this is the entire monitoring function.

What requires the owner
Going live is the line. Test on myself changes nothing publicly; Go live puts a template under a real post where real customers and competitors read it. Make that a named decision by the person whose business it is, even when the VA wrote every word of it.
And the templates that make promises — price, delivery times, availability, anything with a rupee figure or a date in it — should be approved rather than drafted-and-shipped. Not because assistants are careless, but because they do not always know what changed in the business last Tuesday.
The voice problem, which is specific
Voice DNA is built from replies the account owner actually wrote. If the assistant writes every reply from day one, the profile is learning the assistant, and the account gradually stops sounding like the person the customers think they are talking to.
The fix takes an hour of the owner's time and is worth insisting on: the owner answers twenty or thirty messages themselves, in their own register, Hinglish and all, before handing over. That set is the reference everything else is written towards. What the voice profile is built from is the longer version.
Three things a VA should never be asked to automate
Draft it, do not ship it
Why
There is a fourth, softer one: never automate a reply the assistant would not be comfortable defending to the client's customer in person. It is a good filter and it catches most of what the first three miss.
One mechanic every VA needs explaining
Takeover. The moment a human replies by hand in a thread, automation stands down there permanently.
That is usually what you want, and it has a consequence assistants get caught by. If you type a quick "checking, one sec" into a conversation, nothing automated will ever answer that thread again. The follow-up is now yours, by hand, and the twenty-four hour DM window is running from the customer's last message rather than from your holding note. So a fast, empty reply is not a safe placeholder here — it is a commitment with a deadline attached.
The handover document
Two pages, written once, and it makes the whole arrangement survivable: who owns the reply set, who presses Go live, which questions escalate to the owner and how, where the lead CSV is allowed to go, and where the kill switch is so that whoever notices a problem at 9pm can stop all sending without finding anybody.
If several people share the inbox rather than one assistant, the coordination problem changes shape. And if the assistant is inside an agency running this for several clients at once, that has its own set of things that break.


