Maintenance
Part of Online identity and self-presentation: a practical guide
A practical online identity and self-presentation checklist
Online identity checklist: review purpose, audience, names, images, credentials, disclosures, privacy, security, impersonation, recovery, and search results.
What to take away
- Review one named profile or identity decision at a stated date.
- Separate accurate selectivity from a material false claim.
- Verify roles and credentials through the relevant official source.
- Assume posts can move beyond their intended audience.
- Stop unexpected requests for money, access, codes, or sensitive data until independently confirmed.
Use this checklist before launching a profile, accepting a collaboration, publishing a biography, or trusting an account for a consequential action. Mark each item Pass, Review, Stop, or Not applicable and record the evidence.
1. Purpose and scope
- The account has a clear personal, professional, creative, community, or service purpose.
- The public name fits the purpose and applicable rules.
- The profile does not imply a broader role than intended.
- The owner knows which account is being reviewed.
- The review date and next trigger are recorded.
Review if: one account is expected to serve incompatible audiences without a boundary plan. Separate purpose accounts are one of the six approaches compared for exactly that situation.
2. Audience map
- Intended audiences are listed.
- Plausible unwanted audiences are considered.
- Public, followers-only, group, and direct-message surfaces are distinguished.
- Tagging, resharing, search, and screenshot exposure are considered.
- High-risk details are kept away from broad audiences.
Yale's guidance on professional online identity advises reviewing privacy settings, public search results, and the possibility that viewers capture and spread posts beyond their intended audience. Apply it as career guidance, not as a universal employment rule. Reach is not only a settings question; how feeds select and rank decides which of those audiences a post actually reaches.
3. Names, images, and biography
- Display name, handle, and photograph do not impersonate another person or organization.
- A stage name or pseudonym does not create a false regulated credential.
- Biography claims are current and dated where needed.
- Profile images do not expose another person without permission.
- Synthetic or materially edited identity media is disclosed when context requires it.
Stop if: a copied photo, logo, seal, or lookalike handle creates a false affiliation.
Where the edited media is a joke image, the meme publishing checklist handles consent, sources, and labeling.
4. Roles and credentials
- Current employment is checked through an official directory or independent contact.
- Licenses are checked in the relevant registry.
- Degrees, publications, awards, and memberships are stated precisely.
- Former roles are not written as current.
- A badge is interpreted under the platform's current definition.
Record unsupported claims as self-asserted rather than confirmed.
5. Authorship and portfolio
- Work samples link to originals or documented records.
- Team contributions and commissioned work are attributed accurately.
- Reposted work is not presented as owned.
- Dates and project status are clear.
- Confidential or client material is published only with authority.
6. Commercial and relationship disclosures
- Paid endorsements, free products, affiliate links, and employment ties are disclosed clearly.
- Fundraising recipients and payment destinations are verified.
- Personal relationships that materially affect a recommendation are stated.
- Testimonials do not imply typical results without support.
- Contact information leads to the intended person or organization.
For creator accounts, the audience-and-creator checklist carries the fuller disclosure and paid-access items.
7. Unexpected messages
- The sender's account and request are separated from the familiar name or logo.
- Urgency, secrecy, threats, prizes, and unusual payment methods are treated as warning signs.
- Links and phone numbers in the message are not used for verification.
- The person or business is contacted through a known or independently found channel.
- Codes, passwords, recovery links, and identity documents remain private.
The FTC's description of business impersonator scams warns that a message can look as if it came from a familiar business while directing the recipient to send money or personal information. A familiar profile appearance is not enough to authenticate a request.
8. Privacy and data exposure
- Home address, routine, live travel, private contact data, and document numbers are absent unless required.
- Photo backgrounds and metadata were checked.
- Visible friends, groups, likes, and location tags fit the intended boundary.
- Old posts and public replies were reviewed.
- Data collected for identity checks has a retention and deletion plan.
9. Account security and recovery
- Password is unique and stored safely.
- A suitable second factor or passkey is enabled where available.
- Recovery email and phone are current and protected.
- Active sessions and connected applications are reviewed.
- Backup codes are stored away from the account.
- A trusted recovery process exists for an organizational profile.
10. Public-view test
- The signed-out profile was reviewed.
- Search results and cached snippets were checked.
- Links resolve to the intended domains.
- A second reader described the role and claims they inferred.
- Overbroad or outdated wording was corrected.
Decision record
| Result | Meaning | Action |
|---|---|---|
| Pass | Material claims and controls fit the purpose | Publish or proceed within scope |
| Review | Evidence or audience boundary remains uncertain | Narrow claim or gather proof |
| Stop | Impersonation, fraud, unsafe exposure, or account compromise | Preserve evidence and use the proper response route |
Common questions
Must a personal profile list a legal name?
Not unless law, contract, service rules, or the transaction requires it. Do not falsely imply someone else's identity.
Is deleting a post enough to remove it?
No. Copies, screenshots, archives, and search snippets may remain. Correct material falsehoods through appropriate channels.
How often should a profile be reviewed?
Review after role, relationship, security, or audience changes and on a regular schedule suited to the profile's risk.
Can one source verify every claim?
No. Match each role, credential, authorship, affiliation, or identity claim to the source that can support it.
When should a reviewer stop investigating?
Stop when the decision has sufficient evidence or must be declined. Do not collect unrelated private facts.