Who should approve review replies in a multi-location business?
When one business has several locations, review replies can become a governance problem before they become a writing problem.
A branch manager may know what actually happened. A central marketing or operations team may be responsible for brand consistency. A legal or clinical lead may need to review sensitive allegations. If every reply waits for head office, customers may get slow, generic responses. If every branch publishes independently, one public reply can create a promise or disclosure the wider business did not intend.
Google does not tell multi-location businesses how to design this internal approval process.
Google’s published rules are simpler: Business Profile owners and managers can help manage profiles and respond to reviews, replies are public, and the replies themselves must follow Google’s content policies. Google also recommends professional, concise replies and warns businesses not to expose private information in negative-review responses.
The approval structure is therefore a business decision.
Short answer
Use a two-level rule.
Let the branch publish routine replies itself when the response is factual, low-risk and stays within an agreed public boundary.
Require central approval when the reply could create a broader commitment, expose sensitive information, affect more than one location or introduce legal, safety, regulatory or reputational risk.
The useful question is not “Who is senior enough to answer?”
It is:
What kind of reply can safely be published by the person closest to the customer, and what kind of reply needs a second set of eyes before it becomes a public statement from the business?
What does Google actually allow owners and managers to do?
Google Business Profile Help says a profile can have owners and managers.
Google says owners have full control of the profile. Managers have most of the same day-to-day capabilities, although they cannot perform some owner-only actions such as adding or removing users or removing the profile.
Google’s help documentation specifically notes that owners and managers can help with daily operations, including replying to reviews.
Google also recommends that each person use their own Google Account rather than sharing a password.
For a multi-location business, Google also provides business groups so multiple administrators can manage sets of profiles.
None of those features decide who should approve a reply inside your organisation.
Access is not the same as approval authority.
A person may technically be able to press “Reply” while still being outside your internal approval boundary for that kind of message.
Why should some replies stay local?
The local team often has the best factual context.
They may know:
- whether the customer visited that branch;
- whether the issue was already resolved;
- whether a queue, outage or staff absence affected service;
- whether the branch hours or booking process changed;
- which contact route the customer should use next.
For a simple review such as “Great service, thank you,” requiring central approval can add little value.
For a straightforward complaint, a trained local manager may also be able to acknowledge the issue without making a legal conclusion or disclosing private details.
Local ownership can make replies faster and more specific.
But that only works if the branch knows the boundary.
Which replies can a branch usually handle?
A practical branch-level category can include replies that are:
- routine;
- factually straightforward;
- limited to that location;
- free of private customer details;
- free of legal or regulatory claims;
- free of compensation promises outside existing authority;
- free of accusations against the reviewer;
- consistent with existing public policy.
Examples might include:
- thanking a customer for positive feedback;
- acknowledging a delay;
- clarifying publicly posted opening hours;
- inviting the reviewer to use an existing customer-service contact route;
- stating that the branch is looking into a service issue;
- correcting a simple factual misunderstanding without publishing personal data.
This is a practical governance recommendation, not a Google rule.
Which replies should go to central approval?
Escalate before publishing when the reply includes or responds to something that could affect the wider company.
Typical escalation triggers include:
1. Legal threats or allegations
If a reviewer alleges fraud, discrimination, negligence, harassment, theft or another serious legal issue, the branch should not improvise a public legal response.
2. Privacy-sensitive information
Google recommends protecting privacy and avoiding disclosure of a reviewer’s private information.
If the only way to “prove” the branch’s position would be to reveal booking details, medical information, payment information, private correspondence or other personal data, move the detailed discussion to a private channel.
3. Safety, health or regulatory claims
A reply about a safety incident, clinical complaint, food-safety issue or regulated service may need review by the person responsible for that area.
4. Compensation or refund promises
A branch should not create a public financial promise beyond its actual authority.
If compensation is already approved under the company’s rules, the branch can follow that rule. If not, escalate.
5. Allegations involving several locations or the whole brand
A review may be posted on one branch but describe a central booking system, loyalty programme, delivery platform or company-wide policy.
That reply can affect every location.
6. Media, influencer or high-visibility incidents
The risk is not the reviewer’s follower count by itself. The issue is whether the response may become a wider public statement.
7. Disputed facts with no clear local record
If the branch cannot establish what happened, it should not publish certainty it does not have.
Should head office approve every negative review reply?
Usually, no.
Negative sentiment by itself is a poor escalation rule.
If every negative review requires head-office approval, the system can become slow and defensive. A one-star rating does not automatically mean the case is legally or reputationally complex.
A better trigger is the content and risk of the reply, not the star rating.
A routine complaint about waiting time may be handled locally.
A five-star review that mentions confidential information or an improper promise may still need intervention.
Do not build the workflow around “positive versus negative.”
Build it around what the business is about to publish.
What should the branch be allowed to say without approval?
The business should define a small public boundary rather than a long script library.
A branch can usually be allowed to:
- acknowledge the customer’s experience;
- apologise when appropriate;
- state a confirmed local fact;
- explain a known limitation;
- invite the customer to continue privately through an approved contact route;
- say that the issue is being reviewed.
A branch should not be expected to invent:
- legal conclusions;
- refund terms;
- medical explanations;
- disciplinary outcomes;
- policy exceptions;
- promises about platform removal;
- statements about another branch it does not control.
This keeps local replies useful without turning a branch manager into the final authority for every public issue.
How quickly should central approval happen?
There is no Google rule that says a business must answer within a particular number of hours.
So do not invent a platform deadline.
Internally, a multi-location business should choose a review process that is fast enough to avoid obvious bottlenecks.
The practical test is simple:
Can the branch tell whether it may publish now or must escalate, and can the approver make a decision without starting the investigation from zero?
If escalation means forwarding an unclear screenshot to a central inbox with no context, the workflow will stay slow.
A useful escalation package can contain:
- the review link;
- the location;
- the proposed factual response;
- the reason for escalation;
- the confirmed facts already known;
- any public-information boundary that matters.
That is operational guidance, not a Google requirement.
Who should be the central approver?
The role matters more than the job title.
A central approver should have authority to decide what the business may publicly say about the issue.
Depending on the company, that could be:
- a central reputation or customer-experience lead;
- an operations manager;
- a clinical or compliance lead;
- a legal reviewer for defined high-risk cases;
- a brand lead where the reply affects wider positioning.
One person does not need to approve every category.
A multi-location business can define different escalation owners for different risks.
The important point is that the branch knows where a reply goes before it publishes.
What does the customer see when different people reply?
Google publishes the response as a reply from the business.
The customer is not given your internal approval history.
That is another reason to define responsibility clearly: even if the reply was written by one employee, reviewed by another and published by a manager, it appears publicly as the business speaking.
Internal accountability matters because the public reply represents the location and brand.
Should every location use identical replies?
No.
Google itself advises businesses to keep replies relevant and to avoid using the same generic “thank you” for everyone.
Multi-location consistency should mean consistent boundaries, not identical wording.
For example, every branch can follow the same rule on:
- privacy;
- escalation;
- compensation authority;
- prohibited claims;
- private follow-up.
But the reply can still refer to what happened at that specific location.
What if a branch publishes the wrong reply?
First decide whether the problem is factual, privacy-related, tone-related or authority-related.
Google Business Profile Help allows businesses to edit or delete their review replies.
Correct the public reply when needed.
Then fix the approval boundary that allowed the mistake.
Do not solve every error by moving all replies to head office. That can replace one problem with a slow central bottleneck.
The better question is:
What type of reply was this, and should the branch have known to escalate it?
A practical approval rule
A branch can publish directly when all of these are true:
- the facts are clear;
- the issue belongs to that location;
- no private information is needed;
- no legal, safety or regulatory interpretation is required;
- no new compensation or policy exception is being promised;
- the reply stays within an agreed public boundary.
Escalate before publishing when any of those conditions is not true.
This is not a Google-mandated workflow. It is a practical way to use Google’s access model without confusing technical permission with organisational authority.
What should a multi-location owner check?
Ask six questions:
- Who currently has owner or manager access to each profile?
- Which routine reply categories can a trained branch manager publish without approval?
- Which issues must be escalated before publication?
- Who owns each escalation category?
- What facts must the branch provide to the approver?
- Can an incorrect reply be identified and corrected quickly?
If those answers differ unpredictably from branch to branch, the business does not just have a reply-writing problem. It has an approval problem.
Discuss your locations with Madloba Consult
FAQ
Can a Google Business Profile manager reply to reviews?
Yes. Google says owners and managers can help with daily Business Profile operations, including replying to reviews. Managers have most of the same day-to-day profile capabilities as owners, although some account-control actions remain owner-only.
Does Google require head-office approval before a branch replies?
No official Google source reviewed for this article sets a head-office approval rule for multi-location review replies. That is an internal business-governance decision.
Should every negative review go to head office?
Not necessarily. Escalation should depend on the content and risk of the proposed reply, not simply whether the review is negative.
Which replies should normally be escalated?
Replies involving legal allegations, privacy-sensitive information, safety or regulated matters, company-wide policies, unapproved compensation promises or unclear facts are strong candidates for central review.
Can a business edit a published review reply?
Yes. Google Business Profile Help provides options to edit or delete a business reply to a review.
Should branches share one Google password?
No. Google recommends giving each user their own Google Account and using Business Profile owner or manager access rather than sharing passwords.