Most things that get escalated as crises aren't crises. And over-reacting to a complaint — a defensive reply, a deleted comment, a statement nobody asked for — is one of the more reliable ways to manufacture the thing you were trying to avoid.
Triage before response
The first decision is what you're actually dealing with, and it determines everything after. Four tiers cover nearly all of it.
| Tier | What it looks like | Response |
|---|---|---|
| 1. Service issue | One unhappy customer, contained | Reply helpfully, move to a private channel, resolve |
| 2. Escalating complaint | Spreading to people with no direct involvement | Public acknowledgement, visible fix, monitor |
| 3. Genuine failure | You did something wrong and it's demonstrable | Named apology, stated change, senior involvement |
| 4. Coordinated or malicious | Brigading, impersonation, fabricated material | Verify first, document, platform reports, minimal public engagement |
Three questions separate the tiers reliably: Is it spreading beyond the people directly involved? Did we actually do something wrong? Does it threaten something material — safety, legality, a significant relationship?
Tier one dressed as tier three is the most common error. A single angry post answered with a formal corporate statement signals that something serious happened, and invites everyone to find out what.
The core discipline Match the response to the tier. Over-response converts complaints into crises; under-response converts failures into scandals.
Acknowledge fast, resolve properly
These are different obligations and conflating them causes most bad responses.
The standard advice is to respond within an hour. What that should mean is acknowledge within an hour — because a fast reply containing the wrong position is considerably worse than a slower one containing the right position.
The first public statement frames everything after it. If it minimises something that turns out to be serious, every subsequent correction reads as a retreat. If it accepts blame for something you didn't do, you've created a fact. Both are very hard to walk back.
So the acknowledgement should do one job: demonstrate you're aware and taking it seriously, without committing to a position on facts you haven't established. "We've seen this and we're looking into it — we'll come back today" costs nothing and buys the hours you need.
What that requires is someone authorised to send it, which brings us to the practical failure mode.
The 11pm Saturday problem
Incidents don't respect office hours, and the breakdown is almost never a lack of knowledge. It's authority.
The person watching the accounts sees it, knows roughly what should be said, and can't approve anything. They message a manager who's asleep. Three hours pass. By Monday the silence has become the story.
The fix is pre-authorisation, agreed while nothing is happening:
- Two or three holding statements, written and signed off in advance, that a named person may publish without further approval.
- A documented escalation contact with an actual phone number, not a role title or a shared inbox.
- An explicit threshold for what triggers waking someone up — usually tier three and above.
- Access that works. Whoever is on call needs credentials that function on their phone at midnight.
That's an hour of work, done once, and it's the difference between a three-hour gap and a three-minute one.
Guidelines are the prevention half
Published community guidelines get treated as legal boilerplate. Used properly they prevent most escalation, because they convert a contested judgement call into a stated policy applied consistently.
The thing to understand: unenforced guidelines are worse than none. Selective enforcement is itself a grievance, and a well-documented one — people notice which comments get removed and which don't, and inconsistency reads as bias whether or not it is.
Good guidelines are short, specific and behavioural rather than tonal. Not "be respectful" — which is unenforceable and argued about endlessly — but concrete statements about what gets removed and what happens next.
DemandBird
B2B social media scheduling and management platform with content repurposing, analytics and client reporting.
Best for: B2B teams & agencies scheduling multi-platform social content
The deletion line, decided in advance
The most consequential moderation decision, and the one most teams make ad hoc under pressure.
Never delete for criticism. Deleting critical comments is among the most reliable ways to turn a complaint into a genuine crisis, because the deletion becomes a second and considerably worse story. Screenshots exist. Someone always has one.
Do delete content that harms other people. Illegal material, harassment or abuse directed at other community members, doxxing, threats, spam. You have an obligation to the people in your community, and leaving abuse visible to protect an appearance of openness fails them.
That distinction — remove what harms others, never what criticises you — is the line, and it should be written into your published guidelines with examples, so that when you apply it you're pointing at a rule rather than making a judgement in public.
State the consequence ladder too: comment removed, warning, temporary restriction, ban. Predictability defuses far more than severity does.
Verify before you respond
A step that has become materially more important and is frequently skipped under time pressure.
Fabricated screenshots, doctored images and synthetic audio or video are now trivial to produce, which means a viral accusation supported by "evidence" warrants verification before any substantive response. Apologising for something that didn't happen is its own crisis, and it's a harder one to unwind than the original accusation would have been.
Practical checks: does the account making the claim have any history? Can you locate the original interaction in your own systems — the order, the ticket, the conversation? Does the artefact match your actual interface, templates and wording? Is the amplification pattern consistent with organic spread, or does it look coordinated?
None of this means treating complainants as suspects. Most complaints are real, and defaulting to suspicion is its own failure. It means that the holding statement exists precisely so you can check before committing — and this is the environment described in the state of AI-generated media, where synthetic material is cheap and verification is the scarce step.
The pile-on dynamic
Social escalation is self-amplifying in a way other channels aren't, because your response becomes content. Every reply is a new surface, a new screenshot, a new thing to quote.
Which produces a counterintuitive rule: once your position is stated clearly, stop replying publicly. Continued public back-and-forth extends the story rather than resolving it, and each additional reply gives the pile-on fresh material.
Move to direct messages or email with the people genuinely affected. Answer new substantive questions once, in one place, rather than individually in fifty threads. Let the statement stand.
This is hard to do because silence feels like losing, particularly to whoever is watching internally. But arguing publicly with a crowd has no winning condition — the crowd has more time than you do, and the argument is the content it runs on.
Look after the person doing this
Worth its own section because it's routinely omitted and it matters.
During a pile-on, someone is reading every message. That person absorbs hundreds of hostile comments, often personally directed, frequently alone, and usually while junior to everyone else involved in the decisions.
Practical protections: rotate the role so nobody sits in it for days; have someone else present, even remotely, so it isn't done in isolation; make clear that abuse of staff is a removal reason under your guidelines and enforce it; and debrief afterwards, separately from the performance post-mortem, because those are different conversations.
Beyond being the right thing, it's operationally sound — judgement degrades under sustained hostility, and the person making minute-by-minute decisions during an incident is exactly the person you need thinking clearly.
What actually ends it
Not a statement. A demonstrable change.
Apologies that express regret about how people felt tend to prolong escalation, because they avoid the substance and everyone can tell. The version that closes things has three parts: name what happened, accept responsibility without conditions, and state what will be different, specifically.
Then do the thing. The follow-through is what converts the incident from a reputational event into evidence that you respond properly when something goes wrong — which is worth more than never having had the incident, and considerably more than a well-crafted statement. That's the durable version of what brand trust is actually made of.
One caution about apologising for things you didn't do, purely to make it stop. It usually doesn't, it creates a documented admission, and it's unfair to whoever inside the organisation is being blamed for it.
Afterwards
The part that determines whether the next one goes better.
- Write the timeline while it's fresh. What happened, when, who decided what. Memory reshapes this within a week.
- Separate the two post-mortems. What caused the underlying problem is one conversation; how the response performed is another. Merging them means the operational lessons get lost in the blame.
- Update the guidelines and the holding statements based on what you actually needed and didn't have.
- Check whether the complaint was legitimate and common. Incidents frequently surface an issue many people had and few voiced — the same material that drives objection-led content, as covered in building content around objections.
- Review your dormant accounts. Old profiles nobody monitors are where incidents go unnoticed for days, which is one reason they belong in a social audit.
Point four is the one with commercial upside. A crisis is expensive, and the least wasteful thing to do with it is extract the information it contains about what your customers actually experience.
What prevention actually looks like
Less dramatic than response and considerably more effective.
Answer complaints when they're small. Most escalations began as an unanswered message. Response time on ordinary enquiries is crisis prevention, and it's the cheapest form of it available.
Have a community that will speak for you. An established community with genuine goodwill provides context and counterweight during an incident in a way no statement can — which is part of the return on building an engaged community that never appears in engagement reporting.
Brief the people who post on your behalf. Employees advocating for the brand are an asset and an exposure simultaneously, and they need to know what to do when something goes wrong — including that they aren't obliged to defend the company personally, which is the duty-of-care side of employee advocacy.
Run one rehearsal a year. An hour, a hypothetical, everyone in a room. You'll discover that nobody knows who has out-of-hours access before you discover it at 11pm.
If your accounts are effectively unmonitored outside working hours and nobody has agreed what happens when something breaks, that gap is the whole risk — and it's where a social media partner with monitoring coverage is worth more than any amount of documentation.
The short version
Triage before you respond, because over-reacting to a complaint is one of the more reliable ways to manufacture a crisis. Acknowledge fast and resolve properly — they're separate obligations, and the first public statement frames everything after it. Pre-authorise holding statements and a named contact with a real phone number, since the out-of-hours failure is almost always authority rather than knowledge. Never delete criticism, always remove what harms other people, and publish that line in advance. Once your position is stated, stop replying publicly — every reply is fresh material for a pile-on. And look after whoever is reading all of it.
Would anyone know what to do if it happened tonight?
We set up guidelines, monitoring and response plans before you need them rather than during.
Explore Social Media Marketing →Frequently asked questions
What actually counts as a social media crisis?
Far less than teams assume. A useful test is whether the situation is spreading beyond the people directly involved, whether it concerns something your organisation genuinely did wrong, and whether it threatens something material such as safety, legality or a significant commercial relationship. One angry customer is a service issue. A complaint gaining traction among people with no direct involvement is escalating. Treating every negative comment as a crisis produces over-reaction, and over-reaction is itself frequently what turns a complaint into one.
Should you delete negative comments on social media?
Not for being negative, and deleting criticism is among the most reliable ways to convert a complaint into a genuine crisis, because the deletion becomes a second and more serious story. There are legitimate reasons to remove content — illegal material, harassment of other community members, doxxing, spam and off-topic disruption — and those reasons should be written into published guidelines before you need them. The distinction that matters is removing content that harms other people, never content that criticises you.
How quickly should you respond to a social media crisis?
Acknowledge quickly, resolve properly — they are different obligations and conflating them causes most bad responses. A fast reply containing the wrong position is considerably worse than a slower one containing the right one, because the first public statement frames everything that follows and is very difficult to walk back. A brief acknowledgement that you are aware and looking into it buys the hours needed to establish facts, and it satisfies the reasonable expectation that you are paying attention.
Who should be able to approve a crisis response out of hours?
Someone reachable, which is usually the practical failure rather than any lack of knowledge. Incidents rarely occur during office hours, and the common breakdown is that the person watching the accounts cannot approve a response and cannot reach anyone who can. The fix is pre-authorisation: a small set of holding statements agreed in advance that a named person may publish without further approval, plus a documented escalation contact with an actual phone number rather than a role title.
What actually ends a social media crisis?
A demonstrable change rather than a statement. Apologies that express regret for how people felt tend to prolong escalation because they avoid the substance; apologies that name what happened, accept responsibility and state what will be different generally close it. The other thing that helps is stopping the public back-and-forth once the position is stated, because in a pile-on every reply becomes a new surface to attack and continued engagement extends the story rather than resolving it.