A good SEO onboarding process should leave you with six things by the end of the first 30 days:
- verified access without surrendering ownership;
- one agreed version of the business, market and offer;
- a dated target-versus-actual baseline;
- named decision, implementation and approval owners;
- a prioritized backlog tied to commercial priorities and dependencies; and
- at least one meaningful improvement shipped and verified, or a named production blocker with an owner and date.
Month one succeeds when the provider can work safely, measure honestly and move the first useful change through your real production system. A clear kickoff and a strong diagnosis support that outcome; they are not the outcome by themselves.
If you are still comparing providers, begin with the five tests for choosing an SEO agency. If the provider is already selected, agree on what the SEO retainer includes before access and production work begin.
Before day one: carry the commercial promise into delivery
The handover should happen before kickoff.
Record:
- signed scope and exclusions;
- commercial goals and the evidence behind them;
- claims made during the sales process;
- markets, offers and customers in scope;
- known website, analytics and reputation risks;
- named provider and client leads;
- invoicing and contract contacts;
- access required and why;
- the first decision that must be made; and
- unresolved assumptions.
The delivery team should inherit every material promise, assumption and qualification made during the sale. If the proposed result or timeframe has not been verified, label it as an assumption and resolve it in the first planning cycle.
Build an access and ownership map
The client should own primary accounts wherever possible. Give the provider the least privilege needed to perform the agreed work.
| Surface | Typical access | What to verify |
|---|---|---|
| Website or CMS | Editor, admin or deployment path appropriate to scope | Login works; draft and publish permissions are understood |
| Code repository | Read, branch or merge access | Production branch, review process, environments and rollback |
| Google Search Console | Full or restricted user as required | Correct property, history, sitemap and ownership |
| Google Analytics | Viewer, analyst or editor as required | Correct property, events, conversions, filters and time zone |
| Tag manager | Read or publish access | Container, environments, consent and release permissions |
| Google Business Profile | Manager access where local work is in scope | Correct locations, roles, categories and change controls |
| CRM and call tracking | Read or reporting access | Source fields, qualification, duplicates and privacy boundaries |
| CDN, hosting and logs | Bounded technical access | Production controls, security, retention and incident owner |
| SEO and reporting tools | Client-owned seat or documented provider access | Data source, limits, export and ownership after exit |
Use proper account invitations and a secure credential process for the few systems that cannot support roles. Your business should retain primary ownership wherever the platform allows it.
“Access requested” is not access. The onboarding ledger should show requested, granted, tested, insufficient or blocked.
Establish the commercial truth
The provider needs more than a keyword list.
Define:
- what you sell;
- who buys it;
- where you can fulfill;
- which sales or transactions are valuable;
- margin and capacity context;
- qualification and disqualification;
- real competitors, including non-search alternatives;
- compliance or claims boundaries;
- seasonality and business changes;
- customer objections;
- the buying path from discovery to revenue; and
- what must never be published.
Then write the engagement job in one line:
Improve valuable discovery and conversion for [offer] in [market], measured through [source-backed search evidence] and [commercial outcome], within [material boundary].
That line stops a provider from celebrating traffic the business never wanted.
Freeze a baseline before changing the site
A baseline needs a date, source, definition and limitation.
| Layer | Useful evidence | Common trap |
|---|---|---|
| Availability | Crawl, render, indexation, canonicals, sitemaps, profiles | Treating a crawler score as Google’s index |
| Discovery | Queries, pages, markets and devices in Search Console | Reporting privacy-suppressed rows as complete demand |
| Visibility | Rank sets, local packs, search features and answer panels | Mixing unlike surfaces into one score |
| Visits | Landing pages, channels and linked visits | Assuming every “organic” session is valuable |
| Conversion | Calls, forms, purchases, bookings and demos | Counting spam, duplicates or broken events |
| Qualification | CRM stages, fit, revenue and gross profit | Treating all leads as equal |
| Delivery | Live changes, release dates and verified URLs | Confusing recommendations with implementation |
Google says Search Console and Google Analytics measure different parts of the journey and will not exactly match. Onboarding should reconcile definitions, not force the tools into a fake single truth.
Where data is unavailable, write “unavailable” and name the fix. Do not backfill zeroes.
Preserve the history before changing it
A new agency should not erase the scene before it understands it.
Capture:
- current rankings and Search Console exports;
- analytics and conversion definitions;
- redirect, canonical and sitemap state;
- content and URL inventories;
- recent releases and migrations;
- manual actions and security issues;
- backlink and digital PR records;
- Business Profile history and ownership;
- previous strategies, audits and unresolved tickets;
- contracts covering content, links or tools; and
- known experiments.
If a previous provider controlled the accounts, obtain the handover before removing access. If suspicious tactics are present, preserve evidence and contain the risk before making claims about cause.
Name the people who make the work real
The first month should settle:
| Decision | Owner | Deadline or cadence |
|---|---|---|
| Commercial priority | Executive sponsor | At kickoff and when scope changes |
| Search strategy | Senior search lead | Ongoing |
| Facts and claims | Subject-matter owner | Per page or asset |
| Editorial approval | Brand or marketing owner | Agreed service level |
| Development | Named technical owner | Sprint or release cadence |
| Legal/compliance | Named reviewer where required | Before publication |
| Production approval | Explicit approver | Per release class |
| Measurement | Analytics owner | Baseline and event changes |
| Escalation | One provider and one client lead | When blocked or at risk |
Every material decision needs a named person and a usable deadline. “The client will implement” becomes useful only when the responsible team, handover format and release window are explicit.
Turn the diagnosis into a release queue
The first diagnosis should rank opportunities and defects by the value of resolving them.
Score work by:
- commercial impact;
- confidence in the cause or opportunity;
- effort;
- dependency;
- reversibility;
- risk; and
- time to obtain useful evidence.
Each accepted item should state:
- affected pages or systems;
- target versus actual;
- proposed change;
- owner;
- dependency;
- acceptance test;
- rollback where relevant; and
- expected evidence.
That gives the business a release queue, not an agency’s raw findings.
The first 30 days, week by week
The sequence changes with access and risk. The required end states do not.
| Period | Provider must establish | Client must provide or decide | Proof |
|---|---|---|---|
| Before kickoff | Scope handover, access request, known risks | Owners, availability, existing material | Handover record and access map |
| Week 1 | Fit, business truth, tested access, baseline plan | Offer, market, customer, claims and approval context | One-line job, role map and verified access state |
| Week 2 | Measurement baseline, site/market diagnosis, inherited risk | Data definitions and production constraints | Dated baseline and evidence-backed findings |
| Week 3 | Prioritized backlog, first release ready, decision log | Priority and implementation decisions | Accepted tickets or briefs with tests |
| Week 4 | First meaningful improvement shipped or formally blocked | Approval and production support | Live readback, source diff, tracking check and next queue |
An enterprise site may spend more of month one on governance and a local business more on profile, service-page and tracking foundations. The provider still has to show the same chain from evidence to decision to implementation.
What should ship in month one?
The first release should be high-confidence, useful and proportionate to risk.
Examples:
- repair a broken conversion event;
- remove an accidental
noindex; - correct a canonical or redirect defect;
- fix an important title and search snippet;
- strengthen a high-value service page;
- restore a broken internal path;
- correct material Business Profile facts;
- publish a verified company-fact or proof block; or
- convert a finding into an approved development ticket in the next real sprint.
Do not force a visible change for theatre. A risky migration, disputed claim or unclear traffic drop needs evidence before action.
The month-one control pack
At the 30-day review, you should receive:
- scope and commercial job;
- access and ownership map;
- baseline with source limitations;
- material risks and inherited issues;
- prioritized backlog;
- shipped-change ledger;
- open blockers, owners and dates;
- reporting definitions;
- the next 60-day release plan; and
- decisions required from leadership.
The review should end with agreed decisions, owners and release dates.
What healthy onboarding looks like
- Your business retains primary account and asset ownership.
- Sales, scope and delivery assumptions are reconciled before work begins.
- Intake covers the offer, customer, market, claims and commercial result.
- Tool exports support the diagnosis rather than becoming the strategy.
- Content and page work have clear route, proof and approval decisions.
- Search metrics connect to valuable customer actions.
- Implementation, approval and measurement owners are named.
- Access and live changes have a visible ledger.
- Previous work is preserved until its purpose and risk are understood.
- AI-visibility observations record the prompt, surface, date and source.
- Unavailable evidence remains explicitly unavailable.
- Month one produces a verified release or a dated, owned production dependency.
- The roadmap reflects the actual website and market.
FAQ
What is SEO onboarding?
SEO onboarding is the controlled transfer from a signed scope into an operating system that can diagnose, prioritize, implement and measure search work safely.
What should be completed in the first 30 days?
Tested access, business and market truth, a dated baseline, owner and approval maps, inherited-risk preservation, a prioritized backlog and the first verified improvement or named production blocker.
Which accounts should an SEO agency access?
Only the systems required by scope. Common examples include the website, repository, Search Console, analytics, tag manager, Business Profile, CRM and reporting tools. The client should retain primary ownership.
Should the agency make changes in the first month?
Usually, yes: one useful, high-confidence change should reach production. The exception is when access, risk, evidence or approvals make an immediate release irresponsible; that blocker should be explicit.
Do Search Console and Google Analytics numbers have to match?
No. They measure different parts of the journey and use different processing and attribution rules. The provider should explain definitions and discrepancies rather than forcing a false reconciliation.
What if the previous SEO agency owns our accounts?
Recover client ownership and export material evidence before removing access. Record content, links, profiles, tools, redirects, analytics and open work so the handover does not destroy history.
How do we know onboarding was good?
You can name the commercial job, see the baseline and risks, identify every important owner, inspect what shipped and understand exactly what happens next.
The first month should leave you ready to move
By day 30, you should be able to see the market, the baseline, the owners, the first release and the next decision. Use that foundation to begin a useful SEO operating relationship, not an extended setup phase.