Protecting staff from online abuse: a duty of care checklist for the people who read your comments
Someone in your office, your council or your club opens the page every morning and reads everything that arrived overnight: the threats, the slurs, the pile-ons, and somewhere among them the resident asking about a bus route. Reading abuse all day is a work health and safety hazard like any other, and Australian employers have a duty to manage it. This guide is a practical checklist: name the hazard, cut the exposure, give people a process, keep the record off their shoulders, and look after them afterwards.
7-day free trial on every plan · hosted in Australia · cancel anytime

Before you read on. Clarify is software, not a lawyer or a workplace safety consultant, and this checklist is general information, not legal or WHS advice. Your obligations depend on your state or territory and your organisation; check them with your regulator or an adviser. Where this guide describes Clarify reducing what staff read, remember that the AI can miss a threat or misjudge a comment, so a person still has to read on a bad day, and the welfare steps here are what a person does, not what software does.
The part of the job nobody applied for
- It is usually one person. The most junior staffer, the comms officer, the club volunteer with the login. They read all of it so nobody else has to.
- It is after hours. The worst comments arrive at night and at weekends, and the person with the phone reads them in bed.
- It is personal. The abuse is aimed at the MP or the mayor, but the staffer reads a threat against their boss's children and carries it home.
- Nobody has agreed what to do. So the staffer decides alone, every time, whether this one is serious.
The checklist
Name it as a hazard
Write "exposure to abusive and threatening content while moderating the page" into your risk register or WHS assessment, next to lone work and aggressive customers. Once it is named, it has an owner and gets reviewed. Most offices skip this step because the work is invisible; the staffer never says how bad it is.
Cut the exposure
Nobody needs to read every comment raw. Triage so staff work from a sorted stream with threats and genuine questions on top and the rest below. Auto-hide the categories where there is nothing to decide (slurs, spam) so the clear-cut cases never reach a person. Put moderation on a rota so the same person does not carry every bad night, and set hours after which alerts go to a duty phone, not to everyone.
Give them a process
One page, agreed in advance: what counts as a threat, who they tell, how they capture it, when they call police, and when they stop and hand over. The decision about whether a threat is real should never sit with one person at 11pm. The guide to reporting a threatening comment in Australia is a starting point for that page.
Keep the record off their shoulders
A staffer who has to remember every threat, keep the screenshots and reconstruct the timeline for police is carrying the case personally. A system that records each threat with its account, post and time, groups repeat offenders and builds the report means the record exists whether or not they are at work, and whether or not they are coping.
Debrief and support
After a bad week, say so out loud, rotate them off the page, and make the employee assistance program a normal thing to use rather than a sign of weakness. Ask what they read. Managers who never look at the comments do not know what they are asking of the person who does.
What the law expects
Work health and safety law across Australia requires an employer to manage psychosocial hazards, the aspects of work that can cause psychological harm, with the same seriousness as physical ones: identify them, assess the risk, control it so far as is reasonably practicable, and review the controls. Repeated exposure to abusive and threatening material is squarely a psychosocial hazard, and so is being the only person responsible for deciding whether a threat is real. The practical standard is the same as for any hazard: could you show a regulator what you did about it?
This guide is not legal advice. The regulator in your state or territory publishes guidance on psychosocial hazards, and Safe Work Australia's model code of practice on managing psychosocial hazards at work is the common reference.

What this looks like with Clarify
Clarify exists because of this job. It reads every comment on the connected pages first and sorts it, so the person on duty works from a prioritised stream rather than the raw feed. Opt-in auto-hide removes the categories you choose at high confidence the moment they land, reversibly, so nobody has to read the slurs to hide them. Alerts are per person, so the duty officer takes the email alerts and everyone else sees the bell. Every threat is logged with its evidence and grouped by account, and a case report can be generated by whoever is on shift, not only by the person who read the comment. The social media threat monitoring page describes the whole of that, and the morning brief ends with one genuinely kind comment from a real supporter, because the people doing this work deserve it.
Frequently asked questions
Is reading abusive social media comments a work health and safety issue?
Yes. Australian work health and safety law treats psychosocial hazards, the parts of a job that can cause psychological harm, as hazards an employer must identify, assess and control like any other. Repeated exposure to abusive and threatening content while moderating a public page is a recognised example, and so is leaving one person to decide alone whether a threat is real.
Can we just turn off comments to protect staff?
A council, an MP or a public body usually cannot, because the page is a public forum, and for everyone else it hands the abusers their win. The alternatives that work are triage so staff read a sorted stream rather than the raw feed, auto-hiding the categories with nothing to decide (slurs and spam), a rota so one person does not carry every bad night, and a written process for threats.
What should a staff member do the moment they see a threat?
Capture it before doing anything else: the comment text, the account, the post URL and the time, or confirm the system has recorded it. Tell the person named in the process, do not reply, and if the threat names a person, a place, a time or a weapon, call 000 without waiting for anyone's approval. Then hide the comment with the platform's hide rather than deleting it.
Does using AI to moderate comments take the human out of the job?
No. It changes what the human reads first. Clarify classifies every comment and puts threats and genuine questions at the top, so a staffer still reviews the threats and still approves every reply and every hide except the opt-in auto-hide categories they have chosen. The abuse they no longer read is the abuse that was never going to need a decision.
Who is responsible for the welfare of a volunteer who moderates a club's page?
In most Australian jurisdictions, work health and safety duties extend to volunteers in an organisation that also has paid staff, and a club that has none still owes a duty of care. Practically, the same checklist applies: name the hazard, cut exposure, give the volunteer a process and a person to call, and keep the record in a system rather than on their phone.
Read how it works, step by step
- Auto-hiding commentsAuto-hide lets Clarify hide the worst comments for you, the moment they're found, so a slur or a spam link isn't sitting on your Page waiting for someone to…
- The Social StreamThe Social Stream is where most moderation happens. Every comment across your connected socials lands here, already sorted into a category by the AI.
- Alerts and the post re-open policyIn Settings > Alerts you choose how you personally hear about events. Each alert type has two toggles: In-app (the bell at the top of the screen) and Email.
- Team members and permissionsClarify workspaces are built for teams. The Owner controls who's in and what each person can do, so a volunteer can triage comments without being able to post…
- Post ModerationPost Moderation gives you a post-by-post way to clear your backlog, instead of wading through one giant list of comments.
Pricing
Triage, auto-hide, alerts and the threat log are in every plan; more team seats and the duty rota start on Pro. Prices in Australian dollars; every plan starts with a 7-day free trial, and paying yearly gives two months free.
More from Clarify
- Threat monitoring and reportingSocial media threat monitoring for Australian MPs, councils and public figures. Clarify watches your own pages for threats, preserves the evidence, and builds police and eSafety-ready reports.
- Replies in your voiceClarify drafts replies to the comments on your Facebook, Instagram, TikTok and Threads pages in your own voice, checks the facts on the web, and posts nothing until a person approves it.
- Comment moderationClarify sorts every comment on your pages as a threat, abuse, spam, misinformation, a question or fine, hides the clear-cut cases if you switch that on, and keeps every decision reversible.
- Media monitoringClarify watches Google News, GDELT and the outlets you add for mentions of you about once an hour, confirms each story is really about you, summarises it and scores its tone.
- Publishing with approvalsClarify schedules posts to Facebook, Instagram, TikTok and Threads from one calendar with your diary beside it, drafts them in your voice, and routes every post through an approval queue.
- MPs and candidatesSocial media threat monitoring and comment moderation for MPs, candidates and electorate offices. Clarify logs threats as evidence for police, hides abuse, and drafts replies staff approve.
- Councils and community groupsSocial media threat monitoring and comment moderation for local councils. Clarify keeps abuse and threats out of the feed with the evidence a police report needs, and drafts replies staff approve.
- Small businessClarify reads and sorts the comments on a small business's pages, drafts replies in the owner's voice, hides scams and spam, and schedules posts to every platform from one calendar.
- Sporting clubs, parties and peak bodiesClarify HQ lets a club, party or peak body see when one account is targeting several of its members across their own pages, and work referred cases together. Free for organisations.
- AthletesSocial media threat monitoring for athletes. Clarify reads the comments before they do, hides abuse the moment it lands, logs threats with evidence, and puts a real supporter in every morning brief.
- Creators and influencersClarify sorts a creator's Instagram, TikTok, Threads and Facebook comments, hides spam and abuse, mutes fake accounts, logs threats, and drafts replies to real questions in the creator's voice.
- Threatened on Facebook? How to report itSomeone threatened you on Facebook, Instagram or TikTok: when it is a police matter, how the eSafety Commissioner's adult cyber abuse scheme works, and what evidence to keep.
- Bot network detectionBot network detection by hand: the five signals that separate a bot network, troll farm or brigade from an organic backlash, what to record, and how to show the pattern to a platform or the police.
- Threat monitoring for a campaignHow a candidate's team sets up social media threat monitoring in a week, what to log from day one, and how to carry the evidence into the electorate office after polling day.
- Everything Clarify does, on one pageSocial media threat monitoring for Australian public pages: Clarify flags threats and coordinated accounts, keeps the evidence for police or eSafety, and drafts replies you approve.
