An agency manages social accounts for eleven clients. Everything about the arrangement is ordinary. Each client granted access in writing; each account belongs to a real business, and nothing is automated beyond scheduling and reporting.
On a Tuesday afternoon, four of them ask for verification at the same time, and two get restricted. Nothing changed on the agency’s side that morning, which is exactly the point.
Worth saying at the start: this is about accounts you have been given access to. Nothing below helps with fake accounts or with getting around a ban, and neither should it.
The pattern a platform actually sees:
From inside the agency, eleven clients are eleven separate relationships with contracts, invoices, and different people on the other end of each one.
From the platform’s side, eleven unrelated businesses are being operated by a small number of machines in one building, at the same time, in the same rhythm, from the same address. That shape is indistinguishable from a bulk operation running fake pages, and the classifier making the decision has never seen your contracts and has no mechanism for reading them.
The trigger is rarely one account doing something wrong. It is the correlation between accounts that were supposed to look unrelated. This is why the restrictions arrive in clusters, and why the agency’s first instinct, which is to audit what the flagged account posted that week, usually finds nothing.
What gets checked besides the login?
The address and its reputation, including the network block it belongs to and that block’s history. Traffic from a hosting provider is trivially identifiable and carries very different weight to traffic from a residential or mobile network.
Browser and device fingerprint. Canvas and font rendering, installed plugins, screen dimensions, colour depth, timezone, language list, hardware concurrency, audio stack quirks. Individually meaningless. Collectively close to unique, stable for months, and identical across every tab on the same machine no matter how many windows you open.
Storage overlap. Cookies, local storage, service worker caches and identifiers that survive considerably longer than most people assume, including across what feels like a clean logout.
Timing and rhythm. Eleven accounts that post within the same ninety-second window every morning share an operator, and that pattern persists even when everything else has been separated properly. Automation makes this worse precisely because it is reliable.
Recovery and contact details. Shared phone numbers or recovery emails across accounts are one of the strongest correlation signals available, and one of the easiest to create accidentally when an agency sets up two-factor authentication for a client using its own number.
The restriction ladder:
Platforms rarely go straight to a ban, and understanding the sequence is what turns a crisis into a maintenance task.
It usually begins with a soft checkpoint. A verification prompt, a request to confirm a code, an unusual login notice. Most agencies clear it in thirty seconds and think nothing more about it. That is the cheapest warning you will ever get, and it is the moment to look at the setup.
Next come action blocks. Following stops working, or commenting, or messaging, usually for hours rather than days, and usually on the specific behaviour that triggered the score.
Then feature restrictions with a duration attached, then a temporary suspension with an appeal route, and only then anything permanent. By the time an account reaches the later stages, it has generally been through the earlier ones repeatedly, and somebody has been clicking through the prompts without reading them.
Why the obvious fixes make it worse
A consumer VPN. One shared exit address used by thousands of strangers, sitting in a range every large platform already scores badly because of what the other thousands have been doing with it. The office address was at least boring. This one has a history, and none of it is yours.
Private browsing windows. They clear cookies. The fingerprint is unchanged, which is the part actually doing the correlation, so the accounts remain visibly related.
One browser profile per client on the same machine. Genuinely better for storage separation and no help at all on address or fingerprint. Two of the three main signals still match perfectly.
Datacenter addresses. The right instinct with the wrong tool for consumer platforms. They are excellent for collecting public data and immediately recognisable to a service that expects a person holding a phone.
What does a clean setup look like?
The goal is not to hide. It is to stop accidentally telling a platform that eleven businesses are one business.
That means one consistent connection per client account, held stable over time. Consistency matters far more than novelty here, and it is the part most people get backwards. An account that has always been managed from Manchester should keep being managed from Manchester. Rotating an established account through a new city every session manufactures exactly the anomaly you were trying to avoid, and does it on a schedule.
Carrier addresses hold up best for this, for a structural reason rather than a clever one. Mobile networks put large numbers of real subscribers behind each address, so a platform cannot treat a mobile range harshly without catching ordinary users in volume, and so it does not. Running a client account through a 5g mobile proxy places it in the same category as everyone posting from a phone on the train, which is the category these platforms were built to serve in the first place.
Pair each connection with its own browser profile and keep the pairing fixed for the life of the account. The connection and the fingerprint have to travel together. Separate one and not the other, and you have solved half the problem while leaving the half that does the correlating fully intact.
Onboarding a new client account:
The first fortnight decides how much trouble an account gives you for the next year, and almost nobody treats it that way.
Take access through the platform’s own business tools wherever they exist. Business manager-style delegation is visible to the platform as a legitimate agency relationship, which is information working in your favour rather than against it. Sharing a password is the opposite: it looks like an account takeover, because mechanically it is one.
Introduce the new connection gradually rather than switching an account from its owner’s home city to your setup overnight. A location that moves five hundred kilometres and stays there is a much smaller signal than one that moves every day, but it is still a signal, and there is no reason to spend it in week one.
Keep the client’s own access working. An owner who still logs in occasionally from their own phone is evidence of a normal business relationship. Agencies that lock the owner out remove the most useful legitimacy signal the account has.
The part that has nothing to do with connections:
Plenty of flagged accounts have a technically clean setup and get caught on behaviour anyway.
Identical copy posted across unrelated brands. Eleven accounts following the same twenty profiles within a week of each other. Engagement bursts at machine-regular intervals. Bios and link structures built from one template with the business name swapped. Profile photos uploaded in the same session with sequential filenames.
A platform looking for coordinated inauthentic activity will find all of that regardless of where the requests originated, and frankly it should.
When one does get caught?
Stop posting from that account immediately and leave it alone for a day. Continuing to push against a restriction is the single most reliable way to escalate it.
Have the client submit the appeal rather than the agency where the platform allows a choice. The owner appealing for their own business is a different conversation than a third party appealing on their behalf.
Fix the correlation before restoring normal activity, because an account that comes back into the same setup that got it flagged will be flagged again, usually faster the second time.
And write down what the setup was on the day it happened. Agencies seldom do this, which is why the same incident gets diagnosed from scratch every six months.
A short checklist:
One connection per client, stable over months rather than sessions. One browser profile per client, permanently paired to that connection. Delegated access through the platform’s own business tools instead of shared passwords. Separate recovery details per account. Different posting times across accounts, even by a few minutes. Original copy per brand, which you are presumably being paid for anyway. And written authorisation on file for every account, which will matter far more on the day something goes wrong than any of the technical work above.


