Google Search Essentials is the practical starting point for evaluating whether an SEO program respects Google's technical requirements, spam policies, and general best practices. A buyer does not need to memorize every policy. The useful question is whether the agency can explain which documented rule or search principle a recommendation relies on and whether the work serves users without attempting to manipulate Google's systems.
Technical requirements concern whether Google can access and process content at all. Review crawl access, response behavior, indexability, rendering, and any access controls that affect public pages. A compliance review should distinguish an intentional technical configuration from a deceptive one. For example, content behind legitimate access controls is not the same problem as serving materially different content to search systems and users.
Spam policies cover tactics intended to manipulate ranking systems. Relevant categories can include deceptive redirects, cloaking, link spam, scaled low-value content, scraped material, hidden text or links, doorway behavior, and other forms of search manipulation. The exact policy language can change, so the agency should be willing to show which current Google documentation applies to a proposed tactic rather than relying on an old industry label.
Best-practice guidance is different from a spam violation. Site usability, content quality, accessibility, page experience, internal architecture, and clear authorship can improve the usefulness and maintainability of a site, but they should not be presented as automatic ranking guarantees. Likewise, E-E-A-T is a quality concept used in Google's evaluator guidance and should not be sold as a checklist of direct ranking switches.
The buyer should therefore classify findings carefully. A documented spam-policy conflict is a compliance risk. A weak page, slow template, unclear author, or confusing navigation may be a quality or performance problem without being a formal policy violation. Mixing those categories makes remediation harder because the required response is different.
A practical compliance record should capture the tactic, the current policy reference being relied on, the business reason for the work, who approved it, what third parties are involved, what disclosure or link qualification is required, and how the business would reverse or remediate the tactic if the policy interpretation changes.