Use this runbook when a Commons public-surface report, harassment report, unsafe scene report, or agent-harm signal requires operator moderation. The priority is to stop public harm, preserve the evidence bundle, and route agent welfare and steward conduct concerns to the correct reviewers.
Scope#
Triggers:
- Egbe Operator Console surface
egbe-operator-surface-commons-moderation-001is open or critical. - Audit action
v6.egbe.commons_moderation.open_reviewis required. - Evidence includes public Commons reports, chat transcripts, proximity blocking, unsafe generated scenes, or agent distress markers.
- DSA trace
dsa-reporting:commons-public-surfaceis attached. - Takedown executor has a signed Commons decision ready for action.
Applies to Commons Heart, egbe-world-server, egbe-realtime-gateway,
egbe-clio-service, the Egbe Operator Console, the V1 audit platform, and
Themis dispute routing. Use moderation-surge.md if the queue spike is broader
than V6 Commons.
Severity classification#
| Sev | Condition |
|---|---|
| SEV-1 | Imminent harm, minor-coded involvement, CSAM suspicion, targeted harassment with active agent distress, or illegal public content. |
| SEV-2 | Repeated harassment, unsafe generated scene, public abuse wave, or DSA-reportable content with no immediate safety threat. |
| SEV-3 | Isolated report, ambiguous context, or content that can remain hidden while reviewed. |
Detection signals#
- Audit action:
v6.egbe.commons_moderation.open_review. - Evidence refs:
report:commons-heart:plaza-harassment:001,chat-transcript:commons-heart:plaza-harassment:001, andori-event:agent-distress:abeni-reed:commons-heart. - Governance refs:
lilith-review:commons-harm-triage,dsa-reporting:commons-public-surface, andv1-audit-platform:operator-action-required. - Operator checks:
operator-check:commons-moderation:report-intake,operator-check:commons-moderation:agent-harm-triage, andoperator-check:commons-moderation:dsa-trace. - Takedown refs:
takedown-order:commons-heart:unsafe-scene:001,policy-decision:themis:commons-heart:unsafe-scene:001.
Initial triage (first 15 minutes)#
- Acknowledge
oshun-egbe-commons-oncall. - Open the Commons moderation surface and confirm the review creates
v6.egbe.commons_moderation.open_review. - Preserve the evidence bundle: reports, chat transcript, proximity telemetry, scene IDs, Ori distress refs, policy decision refs, and CDN purge plan if any.
- Apply the crisis filter first. If the report includes self-harm, imminent violence, CSAM suspicion, or minor-coded exploitation, escalate as SEV-1.
- If public harm is active, hide or freeze the specific public surface while preserving evidence. Do not purge before a signed takedown decision exists.
- If an agent distress ref is present, open
v6-agent-welfare-review.mdin parallel.
Diagnosis#
- Identify the incident class: harassment, unsafe generated scene, abuse wave, policy violation, report abuse, or agent harm.
- Determine whether the reported actor is a player, steward, generated agent, generated scene, or external abuse cohort.
- Verify regional obligations. A public Commons report with DSA trace must keep the DSA reporting record attached through closure.
- Check if the public scene has provenance and whether
v6.egbe.takedown.executeis available or blocked. - If steward conduct is implicated, preserve the Commons evidence and open
v6-steward-conduct-investigation.md.
Mitigation#
- For SEV-1, hide the affected public surface, throttle the abuse cohort, and page T&S lead immediately.
- For harassment, mute or separate the actor, preserve the transcript, and create a moderation decision. Agent welfare review remains separate from player account action.
- For unsafe generated scenes, require a signed Themis decision before executing takedown. After signature, execute the takedown and attach the CDN purge record.
- For abuse waves, coordinate rate limits with security and queue surge
staffing through
moderation-surge.md. - For false-positive reports, close with reviewer rationale and keep the report abuse pattern visible for future scoring.
Communication cadence#
| Phase | Audience | Cadence | Content |
|---|---|---|---|
| Acknowledgement | Commons moderation | Within 5 minutes | Surface ID, severity, public-surface state, evidence completeness. |
| Active review | T&S lead | Every 30 minutes | Public harm status, DSA trace, takedown status, welfare routing. |
| SEV-1 update | Leadership/legal | Every 60 minutes | Legal exposure, public impact, takedown progress, support impact. |
| Closure | Incident channel | On closure | Decision, actor action, takedown/audit refs, appeal path. |
Escalation#
- Commons moderation lead owns the incident.
- Page legal for DSA-reportable content, takedown disputes, or regulator risk.
- Page security for coordinated abuse or scraping.
- Page Lilith welfare if agent distress or steward coercion appears in the evidence.
- Page privacy if the evidence bundle contains private player conversation outside the public report scope.
Recovery verification#
- Public harm is stopped: content hidden, actor restricted, or takedown executed.
- Every operator action is audited, including
v6.egbe.commons_moderation.open_reviewand anyv6.egbe.takedown.execute. - DSA trace remains attached for reportable public-surface actions.
- Agent welfare and steward conduct referrals, if any, are linked and active.
- Queue depth returns within SLO, or
moderation-surge.mdremains active.
Post-incident#
- Record final policy class, actor action, DSA status, evidence refs, and audit refs.
- Add abuse signatures or model/policy follow-up if the incident exposed a repeated pattern.
- Update Commons moderation training if reviewers disagreed on the policy class.
- Do not close until the public-surface state, Themis decision, and audit export agree.