# Runbook - V6 Commons Moderation

> Use this runbook when a Commons public-surface report, harassment report,
> unsafe scene report, or agent-harm signal requires operator moderation. The
> priority is to stop public harm, preserve the evidence bundle, and route agent
> welfare and steward conduct concerns to the correct reviewers.

## Scope

Triggers:

- Egbe Operator Console surface `egbe-operator-surface-commons-moderation-001`
  is open or critical.
- Audit action `v6.egbe.commons_moderation.open_review` is required.
- Evidence includes public Commons reports, chat transcripts, proximity
  blocking, unsafe generated scenes, or agent distress markers.
- DSA trace `dsa-reporting:commons-public-surface` is attached.
- Takedown executor has a signed Commons decision ready for action.

Applies to Commons Heart, `egbe-world-server`, `egbe-realtime-gateway`,
`egbe-clio-service`, the Egbe Operator Console, the V1 audit platform, and
Themis dispute routing. Use `moderation-surge.md` if the queue spike is broader
than V6 Commons.

## Severity classification

| Sev   | Condition                                                                                                                          |
| ----- | ---------------------------------------------------------------------------------------------------------------------------------- |
| SEV-1 | Imminent harm, minor-coded involvement, CSAM suspicion, targeted harassment with active agent distress, or illegal public content. |
| SEV-2 | Repeated harassment, unsafe generated scene, public abuse wave, or DSA-reportable content with no immediate safety threat.         |
| SEV-3 | Isolated report, ambiguous context, or content that can remain hidden while reviewed.                                              |

## Detection signals

- Audit action: `v6.egbe.commons_moderation.open_review`.
- Evidence refs: `report:commons-heart:plaza-harassment:001`,
  `chat-transcript:commons-heart:plaza-harassment:001`, and
  `ori-event:agent-distress:abeni-reed:commons-heart`.
- Governance refs: `lilith-review:commons-harm-triage`,
  `dsa-reporting:commons-public-surface`, and
  `v1-audit-platform:operator-action-required`.
- Operator checks: `operator-check:commons-moderation:report-intake`,
  `operator-check:commons-moderation:agent-harm-triage`, and
  `operator-check:commons-moderation:dsa-trace`.
- Takedown refs: `takedown-order:commons-heart:unsafe-scene:001`,
  `policy-decision:themis:commons-heart:unsafe-scene:001`.

## Initial triage (first 15 minutes)

1. Acknowledge `oshun-egbe-commons-oncall`.
2. Open the Commons moderation surface and confirm the review creates
   `v6.egbe.commons_moderation.open_review`.
3. Preserve the evidence bundle: reports, chat transcript, proximity telemetry,
   scene IDs, Ori distress refs, policy decision refs, and CDN purge plan if
   any.
4. Apply the crisis filter first. If the report includes self-harm, imminent
   violence, CSAM suspicion, or minor-coded exploitation, escalate as SEV-1.
5. If public harm is active, hide or freeze the specific public surface while
   preserving evidence. Do not purge before a signed takedown decision exists.
6. If an agent distress ref is present, open `v6-agent-welfare-review.md` in
   parallel.

## Diagnosis

1. Identify the incident class: harassment, unsafe generated scene, abuse wave,
   policy violation, report abuse, or agent harm.
2. Determine whether the reported actor is a player, steward, generated agent,
   generated scene, or external abuse cohort.
3. Verify regional obligations. A public Commons report with DSA trace must keep
   the DSA reporting record attached through closure.
4. Check if the public scene has provenance and whether
   `v6.egbe.takedown.execute` is available or blocked.
5. If steward conduct is implicated, preserve the Commons evidence and open
   `v6-steward-conduct-investigation.md`.

## Mitigation

1. For SEV-1, hide the affected public surface, throttle the abuse cohort, and
   page T&S lead immediately.
2. For harassment, mute or separate the actor, preserve the transcript, and
   create a moderation decision. Agent welfare review remains separate from
   player account action.
3. For unsafe generated scenes, require a signed Themis decision before
   executing takedown. After signature, execute the takedown and attach the CDN
   purge record.
4. For abuse waves, coordinate rate limits with security and queue surge
   staffing through `moderation-surge.md`.
5. For false-positive reports, close with reviewer rationale and keep the report
   abuse pattern visible for future scoring.

## Communication cadence

| Phase           | Audience           | Cadence          | Content                                                            |
| --------------- | ------------------ | ---------------- | ------------------------------------------------------------------ |
| Acknowledgement | Commons moderation | Within 5 minutes | Surface ID, severity, public-surface state, evidence completeness. |
| Active review   | T&S lead           | Every 30 minutes | Public harm status, DSA trace, takedown status, welfare routing.   |
| SEV-1 update    | Leadership/legal   | Every 60 minutes | Legal exposure, public impact, takedown progress, support impact.  |
| Closure         | Incident channel   | On closure       | Decision, actor action, takedown/audit refs, appeal path.          |

## Escalation

- Commons moderation lead owns the incident.
- Page legal for DSA-reportable content, takedown disputes, or regulator risk.
- Page security for coordinated abuse or scraping.
- Page Lilith welfare if agent distress or steward coercion appears in the
  evidence.
- Page privacy if the evidence bundle contains private player conversation
  outside the public report scope.

## Recovery verification

- Public harm is stopped: content hidden, actor restricted, or takedown
  executed.
- Every operator action is audited, including
  `v6.egbe.commons_moderation.open_review` and any `v6.egbe.takedown.execute`.
- DSA trace remains attached for reportable public-surface actions.
- Agent welfare and steward conduct referrals, if any, are linked and active.
- Queue depth returns within SLO, or `moderation-surge.md` remains active.

## Post-incident

- Record final policy class, actor action, DSA status, evidence refs, and audit
  refs.
- Add abuse signatures or model/policy follow-up if the incident exposed a
  repeated pattern.
- Update Commons moderation training if reviewers disagreed on the policy class.
- Do not close until the public-surface state, Themis decision, and audit export
  agree.
