Tutorial · 6 min read

The UGC Build Sheet: Fields, Order, and What to Switch Off

The PostEngage teamEngineering and support ·

The argument for asking properly before you repost somebody's photograph is made in full elsewhere, and it is the post to read first. A tag is not permission, consent has to cover where and for how long and whether paid advertising is included, and the ask belongs in a fixed template because the wording is the record.

This is the other half: the sheet you work from when you sit down to build it. Fields, order, settings, and the two things that have to be switched off.

Step zero, which is not in the builder

The caption line.

"Tag us and comment SHARE if we can repost" is what turns a passive tag into a comment you may legitimately answer. Nothing here writes captions, publishes posts, or reads your feed. If that line is not in the post, the automation sits there matching a word nobody has been told to type, and every other decision on this sheet is irrelevant.

It is also the moment you set the expectation. People who type the word have opted in before you have sent anything, which is a much better starting position than asking a stranger cold.

The trigger

  1. One word, narrow. SHARE, or whatever you actually asked for. Not a list of five. This reply should only reach people who opted in by typing, and a broad trigger sends a consent request to somebody who was asking about shipping.
  2. Not a word already in your comments. LOVE, LINK and INFO are in half of everybody's comment section. The word has to fire on intent, not on enthusiasm.
  3. Know what matching does. It folds case, punctuation and Latin accents, so Share, share. and SHARE are one word. It does not fold Indic vowel signs — दाम and दम are two different words to the matcher. And it matches whole words, so share will not catch sharing. If you want both, write both.
  4. Any-of, not all-of. People type one word. Requiring two is a trigger that never fires.
The builder with a post selected, the trigger keywords listed, and the public and private replies written out.
Both replies come from one trigger. The private half carries the ask; the public half is read by everyone else in the comments and should never contain the permission wording.

The two replies

Public. Short, warm, content-free. "Sent you a message." It is read by everybody scrolling, so it must not contain the consent request itself — a permission asked in public is a permission asked in front of an audience, and it invites people to answer in public where the wording gets lost.

Private. The full ask, unchanged, every time. Where the photograph will appear, for how long, and whether paid advertising is included. Then a request that they reply yes.

That reply does two things at once: it is the consent, and it restarts the twenty-four hour DM window, which you will need if anything has to be sorted out. Ask for it explicitly.

The negative keywords

Two groups, and the second one is the one people forget.

Withdrawal. remove, removed, take down, delete, hata do, unauthorised, permission. Anybody changing their mind reaches a person immediately, and no template goes anywhere near it.

Complaints wearing UGC clothes. Somebody posting a photograph of your product because it arrived broken has also tagged you, and may well type the word. broken, damaged, refund, return, worst, late. A consent request landing under a complaint is a screenshot.

Advanced, setting by setting

Specific posts. On for anything campaign-shaped. An account-wide UGC trigger will fire under your customer-service posts and your sale posts, which is not where you want to be asking for photographs.

First-time senders only — off. This is the counterintuitive one. Your best UGC comes from repeat customers, who have written to you before. Filtering them out is exactly backwards.

Quiet hours. On. A consent request at 3am reads as automated even when the wording is perfect, and the wording is the whole point here.

Rate budget. On, especially for a hashtag campaign. A comment stays answerable for seven days counted from each comment, so a cap turns a spike into a queue rather than losing anything.

Test on yourself, then go live

The button runs the whole pipeline — every check in order, the real reply, delivered to your own account.

Read the delivered message rather than the checklist. What you are checking is not whether the plumbing works but whether the permission sentence is exactly the sentence you want on the record. It is much easier to notice a missing clause about paid advertising when you are reading it as a message than when you are reading it in a text field.

A test run showing each check that passed and the reply exactly as the recipient would receive it.
The checks passing tells you it will send. Only the delivered message tells you what it will say, and here the wording is the entire deliverable.

Then go live on one campaign and read what got blocked after a week.

Retirement, and the record

A hashtag campaign is a temporary structure. Give the automation a switch-off date the day you create it, in the same list as taking the banner off the site. A consent request for a campaign that ended in March, sent in September, is confusing at best.

The record it leaves is thin and you should know its limits before you rely on it: a handle, the post the message came from, the exact words they typed, and a timestamp. Leads export as CSV. There is no rights-management feature, no consent ledger, no image recognition — nothing here reads photographs — and no tracking of where a picture was used afterwards.

So the sheet automates one step of a real process: asking clearly, in the same words, quickly. Crediting people properly, taking things down promptly when somebody changes their mind, and keeping track of what you have used remain manual, and that is what makes the automated half acceptable.

Cost, and the limits

Templated replies are free and unlimited, so this entire build spends nothing however many people type the word. Free tier is 100 credits with no card; packs start at ₹499.

Official Graph API only. Seven days to answer a comment, counted per comment; twenty-four hours inside a DM thread, restarted only by their next message — so there is no follow-up chase, and somebody who did not reply has given you their answer. It cannot message anyone who has not written to you first, so you cannot ask permission from somebody whose post you merely liked. Takeover stands the automation down the moment you reply by hand.

If story mentions are where your tags actually arrive, be precise about what produces an event before designing around them. For the related ask with its own ethics, testimonial collection covers gating.

One email when we publish.

No drip sequence, no “quick question” follow-up. Unsubscribe is one click and we honour it immediately.

Try it on your own posts

Free forever. Three minutes to set up.

Start free