Moderation
Part of Handling community conflict and incidents
Reviewing a serious incident with the moderation team
Review a serious moderation incident with a factual timeline, decision checks and improvement actions with owners.
Once immediate risk is stabilised and urgent handoffs have owners, review the serious community incident with the people who must learn from it. Reconstruct what the team knew and did, identify response gaps and assign changes that can be checked. Keep private case material within the necessary group.
Set the purpose and access
Name a review lead and the decisions the meeting must make. The team may need to ask whether a report reached the right person, whether exposed information was contained promptly, or whether a member received an accurate update. Include the moderators involved and the relevant privacy, security, support or business owner. Where practical, use someone other than the original decision-maker to lead a review of a contested decision.
Keep sensitive posts in a restricted case record, not a broad meeting invitation. A personal-information incident may also need a separate privacy or legal assessment. Agree which team owns each conclusion; a moderation debrief does not replace that assessment.
Reconstruct a factual timeline
Start with observable events: when content or a report appeared, when someone saw it, what members could access, what action followed and when another owner accepted the case. Add member and staff communications. Mark gaps as unknown rather than filling them from memory.
| Field | Question to answer |
|---|---|
| Signal | What first indicated a problem, and who received it? |
| Exposure | What was accessible, and for how long as far as the team knows? |
| Decision | What was authorised, by whom and with what information? |
| Handoff | Which owner accepted the next task? |
| Outcome | What is confirmed, and what remains unknown? |
Use the timeline to examine decisions, not to score staff members. Delay may reveal an unclear escalation route or missing permission. Early removal may still leave copies beyond the team’s control.
Examine the response against its job
At each decision point, ask what the team knew then, what options it had and what the member needed. Check whether the conduct rule was applied consistently, the action reduced risk, notices protected private details and any underlying customer issue reached an owner. Compare the response with the tools and coverage the team actually had.
Invite differing interpretations. If moderators applied a rule differently, record the ambiguity. If a reporter or affected member received no update, find where the handoff stopped. Separate a preventable process gap from an outcome the team could not know or control.
Assign changes that can be checked
Record each change, owner and verification point. “Improve training” is too vague. “Add a privacy contact and backup to the incident roster, then ask the next scheduled moderator to locate both routes” gives the team something it can check. A clearer report category, restricted evidence location or revised notice may also help, if adopted and verified.
The OAIC’s data-breach guidance includes review and prevention among the response stages for personal-information breaches. That principle may help the team examine a wider community incident, but the relevant privacy owner must make any regulatory assessment.
Close the loop
Record decisions, action owners, due dates and who will confirm completion. Tell affected members about a meaningful process change when appropriate, without exposing another person’s case. Recheck a changed routine with a fictional scenario before relying on it. The meeting ends before the improvement work does.



