“Automation” covers two very different things: software that publishes what you wrote, and software that pretends to be you. LinkedIn’s rules treat them completely differently, and the difference matters more when the account you are risking belongs to a client.
Scheduling a post you wrote and having a bot spray two hundred connection requests both get called automation, and the second one is why the first one has a bad reputation. LinkedIn does not draw the line at software. It draws it at two things: whether the software is reaching LinkedIn through a route LinkedIn sanctions, and whether the activity it produces is authentic.
That distinction is not a matter of interpretation. LinkedIn publishes it, and the wording is unusually specific about which behaviours are prohibited.
Summarised from LinkedIn’s User Agreement (effective 3 November 2025), its Professional Community Policies, and its help article on prohibited software and extensions, all read on 19 August 2026. Policies change and this page is not legal advice — check the current wording before you build a process on it.
Sorted from the things nobody should worry about to the things that end accounts.
Risk ratings are our reading of the published rules, not LinkedIn’s. They reflect both what the policy says and how visible each behaviour is in practice.
People imagine a ban. What usually happens first is quieter and harder to notice: content gets less distribution, a post is labelled or removed, and the account keeps working. By the time someone is locked out, there is normally a history behind it.
That quietness is the real problem for an agency. An account that has been throttled looks exactly like an account whose content is not landing, and you will spend two months rewriting hooks before anyone considers that the tool sitting in the browser might be the cause. There is an appeals process, and it is worth using, but the cheaper move is not to end up there.
The second risk is one nobody plans for. LinkedIn says prohibited tools may stop working without notice, and they periodically do. If your entire client delivery runs through an extension, the day it breaks is the day none of your clients get posted for — and you will be explaining a compliance decision you made on their behalf without telling them.
Four rules. They cost you nothing except the tactics you should not have been using.
The account holder authorises access themselves and can withdraw it whenever they like. This survives them turning on two-factor, survives them leaving the company, and means a breach at your end does not become a breach at theirs.
If a tool needs a browser extension to post, it is driving the account rather than talking to LinkedIn. That is the distinction the rules are built around, and it is the one that decides whether the account is at risk.
Comments and likes should come from a person who read the thing. Automating them is prohibited, and it also produces the flat, generic replies that damage the account’s reputation with the only audience that matters.
Which account, who authorised it, who approves posts, and how it ends. This protects the client, and on the day someone asks how their profile came to be publishing, it is the difference between a short answer and a long one.
We publish through LinkedIn’s official interface, never ask for a password and ship no browser extension. It rules out some tactics, and that is the point.
Fourteen days, no card, no extension and no password. Every account is connected by the person who owns it, and they can disconnect it whenever they choose.
Per connected account. Teammates are free.