Two step review approvals mean an initial draft, written by a person or by AI, followed by a separate approver who checks and publishes the reply. The reliable way to run this is risk-based routing: let routine positive reviews auto-approve while low-star, flagged, or privacy-sensitive reviews wait for a manual sign-off from someone with verified Business Profile access. Keep an audit trail of every draft and decision, and start there before adding automation.
TL;DR:
- Automated drafting speeds up reply creation but manual sign-off is essential for reviews flagged as sensitive, low-star, or policy-violation risks.
- Routing rules based on star rating, keywords, and manual overrides help prioritize reviews needing human approval within set SLAs.
- Only verified Business Profile owners or managers can publish replies, with role separation starting at the profile level due to Google's access controls.
- Moderation usually takes minutes but can extend up to 30 days, so approval workflows must account for varying publication timing.
- Audit logs must record draft versions, approver identities, timestamps, and reply states to ensure compliance and facilitate review process improvements.
Table of Contents
- Why two step approvals matter for multi-location and agency teams
- Design the workflow: roles, routing rules, SLAs and exceptions
- Technical constraints: verification, access roles and moderation timing
- Content and compliance best practices for approvers
- Operational playbook: templates, audit records, reporting and iteration
- A working note on rolling this out slowly
- How Local Review Reply supports two step approval workflows
- Primary Google docs and product workflow resources
- Sources
- FAQ
Why two step approvals matter for multi-location and agency teams
A single unreviewed reply can undo weeks of good reputation work. When one person drafts and publishes without a second check, tone slips, facts get misstated, and franchise locations end up sounding like different businesses. Multi-location operators and agencies feel this fastest because they manage dozens or hundreds of profiles with different staff, different local context, and no shared style memory.
The policy risk is just as real. Google can limit or suspend account privileges when replies include harmful, deceptive, or otherwise policy-violating content, so a reply written in frustration or containing another customer's personal details is not just a bad look, it is a compliance problem.
Volume adds pressure on top of both risks:
- A single reviewer covering many locations cannot read every draft carefully under time pressure.
- Remote or seasonal staff often draft replies without full visibility into brand tone or local circumstances.
- Franchises need consistency across locations that legally operate as separate businesses.
Pro Tip: Give every location one named approver, even if that person also drafts replies elsewhere; a shared inbox with no owner is how sensitive reviews slip through unapproved.
Design the workflow: roles, routing rules, SLAs and exceptions
A workable two step approval system rests on three decisions: who drafts, who approves, and what triggers manual review instead of auto-approval.
- Define the role matrix. Preparers (staff, agency account managers, or AI drafting tools) can write and submit replies but never publish directly. Approvers need verified owner or manager access on the Business Profile, since that access level determines what a person can actually do with a reply.
- Set routing rules. Route by star rating (4 and 5 stars can often auto-approve if the draft passes basic checks), by keyword flags (mentions of injury, legal threats, discrimination, or illegal activity always go to manual review), and by manual override (any staff member can flag a review for human eyes regardless of rating).
- Assign SLA bands. A practical structure: draft within 4 hours of the review posting, approval within 24 hours for standard cases, and a 2 hour emergency path for anything with public relations or legal exposure. Agencies managing SLAs across many client accounts can adapt staged approval timelines to fit contractual response commitments.
- Build the exception path. When a review contains false claims, threats, or content that should be reported rather than answered, route it to whoever owns Google's removal request process instead of drafting a public reply at all.
Pro Tip: Write your routing rules down as a simple table, not tribal knowledge; new approvers should be able to follow it without asking what counts as "sensitive."
Legal or privacy-adjacent reviews deserve their own escalation lane, separate from the standard approval queue, so a defamation claim or a data-privacy complaint never waits behind routine drafts.

Technical constraints: verification, access roles and moderation timing
Google's own infrastructure sets hard limits on what a two step workflow can do. Replies are only possible on verified Business Profile locations, and availability can vary by country or business category. Owners and managers have different levels of control, and only an owner can change who else has owner or manager status, which is why role separation has to start at the profile level, not just inside your internal tool.
Applications that draft or publish replies programmatically use OAuth authorization through Google's updateReply endpoint, which requires specific scopes and only works against verified locations. That authorization lets software act on the business's behalf, but the business itself remains accountable for what gets published, not the tool.
Once a reply is submitted, Google moderates it before it appears publicly. The reply state moves through PENDING, APPROVED, or REJECTED, and moderation typically takes minutes and usually under 10, though edge cases can take up to 30 days. That variability matters for SLA design: a fast internal approval does not guarantee fast publication.
For audit purposes, preserve these fields for every reply:
- Location ID and review ID, so any draft maps back to the exact profile and review.
- Draft text and final published text, if they differ.
- Approver identity and decision timestamp.
- Google's reply state and publication outcome.
Content and compliance best practices for approvers
Approvers are the last line of defense before a reply goes public, so their checklist should be short enough to actually use every time. Google's own guidance favors professional, personalized replies over generic thank-you messages, and steers businesses away from promotional language or content that reads as an attack on the reviewer.
Google states that account privileges can be limited or suspended for harmful or policy-violating contributions, which means a single careless reply carries more than reputational risk. It can affect the whole profile's standing.
Before publishing, an approver should check for:
- Any personal information about the reviewer or a third party, which should never appear in a public reply.
- Personal attacks or defensive language, even when the review itself is unfair.
- Promotional phrases, discount codes, or calls to visit again in ways that read as advertising.
- Complex disputes that need a phone call or email instead of a public back-and-forth.
- Content that should be reported to Google for removal rather than answered at all.
When a review makes a legal threat, alleges illegal activity, or clearly violates Google's content rules, the right move is often to flag it for removal through Google's own process rather than reply publicly, since a public response can sometimes validate a claim you have not verified.
Operational playbook: templates, audit records, reporting and iteration
Once roles and routing are set, the day-to-day system runs on templates, records, and a small set of numbers worth watching.
- Build a template taxonomy. Keep three tiers: fully standardized replies for simple five-star reviews, lightly personalized templates for four-star reviews with minor complaints, and fully custom drafts for anything one star or lower. Reusable reply templates speed up drafting without making every response sound identical.
- Log the minimum audit fields. For every draft and decision, store the location ID, review ID, draft version, approver name, timestamp, and final publication result. These are the same fields Google's API exposes, so your internal log should mirror them exactly.
- Track three metrics. Time-to-approval tells you where bottlenecks form. Rejection rate by approver tells you where drafting quality needs work. Publish success rate tells you whether Google's own moderation is creating delays worth planning around.
- Pilot before rolling out. Test the routing rules on a small set of locations, watch rejection reasons for a defined period, then adjust thresholds before expanding to the full portfolio.
A working note on rolling this out slowly
Most teams over-engineer the routing rules before they have watched a single week of real approvals. Start narrower than feels necessary: a handful of locations, one clear SLA, and a habit of writing down why a draft got rejected instead of just fixing it and moving on. The rejection reasons are the actual training data for your approval process.
Pilot checklist: verify your locations, define who drafts and who approves, write routing rules for star rating and flagged keywords, set SLA targets for each stage, then review the metrics after a defined test window before expanding further.
— Ryan
How Local Review Reply supports two step approval workflows
Local Review Reply builds the pieces this article describes into one system: AI drafts a personalized reply, sensitive or low-star reviews route to a manual approval step, and every draft and decision is logged with an audit trail. Role management lets you control who drafts and who has final publish authority across locations, which matters most for franchises and agencies juggling dozens of profiles.

Automation speeds up drafting, but human approval stays essential for the reviews that carry real risk, which is exactly where the platform's approval controls are designed to sit.
- AI drafting for routine replies, freeing approvers to focus on flagged cases.
- Manual approval gates for low-star or sensitive reviews before anything publishes.
- Role and permission controls so preparers and approvers stay separate.
- Audit logs covering drafts, approvers, and publication outcomes.
| Workflow piece | What it needs | Where it lives in the product |
|---|---|---|
| Drafting | Fast, on-brand first pass | AI-generated reply drafts |
| Approval gate | Manual review for sensitive cases | Approval controls for low-star reviews |
| Access control | Separate preparer and approver permissions | Role management |
| Recordkeeping | Draft, approver, and outcome history | Audit logging |
Plans range from a free tier for basic use up to paid subscriptions with various features, including options for larger multi-location needs. Check the pricing page or explore the feature overview to see which tier fits your location count and reply volume.
Primary Google docs and product workflow resources
- Owners & managers guidance for role separation.
- Review management and reply states from Google.
- updateReply API reference for technical constraints.
- Content policy rules for approvers to follow.
Sources
- Manage your Business Profile owners & managers - Google Business Profile Help
- Manage customer reviews - Google Business Profile Help
- Accounts.locations.reviews.updateReply - Google My Business API
- Prohibited & restricted content - Google Business Profile Help
FAQ
What is a two step review approval workflow?
It is a process where one person or an AI tool drafts a reply to a customer review, and a separate approver checks and publishes it rather than letting the draft go live automatically. The approver typically needs verified owner or manager access on the Business Profile to complete the publish step.
Who can approve and publish Google review replies?
Only users with verified owner or manager status on a Business Profile can publish replies, and only an owner can grant or change that access for others. Apps using the updateReply API still require the underlying account to hold verified access.
How long does Google take to moderate a review reply?
Google's own guidance says moderation usually takes minutes, often under 10, though it notes that some reviews can take up to 30 days in edge cases. Reply states move through PENDING, APPROVED, or REJECTED during this process.
Which reviews should always require manual approval?
Reviews mentioning privacy details, injury, legal threats, or claims of illegal activity should always route to manual approval rather than auto-approval, since these carry higher policy and legal exposure. Routine positive reviews with no flagged language are the safer candidates for lighter, faster approval paths.
Does Local Review Reply support manual approval for sensitive reviews?
Yes, Local Review Reply includes approval controls that route low-star and sensitive reviews to manual sign-off before publishing, while AI handles drafting to speed up the process. Plans and features are listed on the pricing page.
