Before calling a conversation a crisis, collect the original claim, its source and timestamps, the number of distinct reports, the affected product or service, and any immediate risk. Keep verified facts separate from allegations. Send a credible urgent-risk signal to the responsible team while verification continues; a complete social report must not become a condition for getting help.
Social media issue triage has two decisions: who needs to investigate, and what the brand can responsibly say in public. Those decisions can happen at different times. The procedure below is an editorial recommendation for brand teams, not a platform rule or a substitute for an existing emergency plan.
Start with the claim behind the alert
A negative-sentiment spike gives you a reason to inspect the posts. It does not establish what happened. Sprout Social's listening examples recommend monitoring topic and sentiment changes, then examining the messages behind them.
Write the allegation in one neutral sentence. Include what supposedly happened, where, and when. Avoid adding intent, blame or scale that the source does not establish. For example, a hypothetical post about a failed checkout supports recording a reported checkout failure. It does not yet support recording a site-wide outage.
Give each material claim its own evidence status:
- Observed: the post exists and you have read its full context.
- Corroborated: a separate source or operational record supports a specified part of the claim.
- Unresolved: a necessary fact remains missing or conflicting.
- Contradicted: identified evidence conflicts with a specified part of the claim.
These are working labels for the triage record. A genuine post can contain a mistaken claim. A missing post can leave a claim unresolved.
Trace the original before counting the copies
Open the source URL. Read the thread, linked material and any visible correction. If an alert contains only a screenshot, locate the underlying post before treating the screenshot as an authenticated record.
The European Journalism Centre's verification handbook sets out checks for provenance, uploader, creation date and location. Apply those checks to the allegation, with these additions for a brand handoff:
- Record the earliest version you can locate. Describe it as the earliest located version unless you establish that it is the original.
- Separate the post's publication time from the claimed event time. Include time zones and your capture time.
- Check whether the image or video appeared earlier in another context. An upload date alone does not establish when the scene occurred.
- Identify what the author claims to know firsthand. Repeating another person's account is a different evidence type.
- Ask the relevant internal owner to check operational records through approved channels. Record which details those records support or contradict.
If you contact the author, ask narrow questions about the event. Use an approved private support channel for order details or other sensitive information. Do not request those details in a public reply.
Keep the original URL alongside any permitted capture. Preserving evidence when a post may disappear covers the record needed for a later review.
Separate spread from independent evidence
Group reposts, copied captions and repeated screenshots by their underlying source. Retain them as evidence of spread, but count independent incident reports separately. Different accounts repeating the same screenshot have not independently confirmed its contents.
A quote-post needs inspection. It may repeat the claim, dispute it, or add a separate firsthand experience. Count what it contributes rather than assigning every quote-post the same role. Use a repeatable rule for removing duplicates from a listening sample.
Record your search boundaries beside the count. For X, native search documentation describes Top and Latest views, location and account filters, and safe-search settings that can exclude sensitive content or muted and blocked accounts. Record the settings used. A search result count without those details is hard to compare later.
Access also limits the record. X's protected-post documentation says protected posts are searchable on X by their author and followers. Treat inaccessible material as a coverage gap. Do not bypass access controls to complete a triage form.
A convenience set of public posts cannot establish how common an experience is among all customers. In its 2019 study of U.S. Twitter users, Pew used a probability-based panel and weighting, and found differences between users and the broader population. That historical study is a methodological warning, not a description of today's X audience.
Report the number of distinct reports found within your declared search. Leave total affected customers unknown until suitable operational evidence supports an estimate.
Use a triage form that preserves uncertainty
Copy this structure into the incident record. Fill missing fields with a specific unknown and a named person responsible for checking it.
| Field | What to record |
|---|---|
| Claim | One neutral sentence for each allegation |
| Source | Original URL, account, firsthand or relayed account, full context |
| Time | Claimed event time, publication time, capture time, time zones |
| Evidence status | Supported facts, unresolved details, contradictions and supporting links |
| Duplication | Raw items reviewed, source groups, distinct incident reports |
| Coverage | Platforms, query, time window, filters, languages, access gaps |
| Scope | Product, location, service or customer group supported by evidence |
| Immediate risk | Possible ongoing harm, affected activity, reason delay matters |
| Owner | Person accepting the handoff and the decision they need to make |
| Next review | Exact review time and the new evidence that would change the decision |
If the batch is too large to review fully, record how you selected items and how many you read. Do not present labels from that subset as a complete account of the batch. Check uncertain language, sarcasm and quoted allegations before assigning meaning.
Follow the escalation decision tree
The WHO Regional Office for Europe's toolkit overview separates detection, verification, risk assessment, response design and outreach. Its setting is public-health emergencies. The brand workflow below adapts that separation; the thresholds are recommendations for teams to agree in advance.
- Could delay allow serious harm? If yes, or if you cannot safely rule it out, send the source and uncertainty to the designated safety, security or incident owner now. Continue verification in parallel. The handoff does not confirm the allegation.
- Is there a supported operational problem? If yes, route it to the responsible service or product owner. Ask them to establish scope and containment needs. Communications can prepare while those checks continue.
- Are distinct reports increasing or reaching new affected groups? If yes, request a cross-team review. Show the source groups and comparable time windows. Separate additional witnesses from additional copies.
- Is the record still one unresolved claim with no identified urgent risk? Assign an investigator and a review time. Continue ordinary support where appropriate. Reopen escalation when new evidence changes risk or scope.
Your incident lead should decide whether to activate the crisis plan under your organization's criteria. Do not invent a universal mention threshold that lets a serious low-volume report fall through.
Hypothetical triage example
Suppose an alert about checkout failures yields this fully reviewed batch from one declared source set and time window. All numbers are hypothetical.
| Classification | Items |
|---|---|
| One original firsthand report | 1 |
| Reposts of that report with no new experience | 12 |
| A second firsthand report | 1 |
| Unrelated uses of the brand name | 6 |
| Total reviewed | 20 |
The handoff records two distinct firsthand reports and twelve additional copies. It does not claim fourteen affected customers. The checkout owner checks whether the reports share a payment method, region or failure time. The social team records the outcome of that check before widening the stated scope.
While the owner investigates, avoid quote-posting an unverified allegation to the brand's larger audience. If a public update is necessary, state the confirmed problem, the action underway and when the next update will appear. Keep unsupported causes and personal details out of it.
Open the next alert with the triage form, assign its risk owner, and set the next review time before forwarding it.



