Reputation monitoring alerts: rules that work
A system that sends too many alerts gets muted within a week. How to write trigger, threshold, owner and message rules for reputation risk.
Short answer
An alert system for reputation risk rests on four decisions: what triggers an alert, above which threshold, who receives it, and what the recipient must do. Good alerts are few, and every one demands action. A bad alert system sends dozens of notifications a day, and within a week the team stops looking — so when a real risk arrives, nobody sees it.
What alerts are for, and what they are not
Alerts do not replace the daily check. The daily check looks at every new result; an alert separates only the cases that cannot wait until the next check. If ordinary complaints, questions and repeated news land in the alert list, that is not alerting but a second daily list. The question is simple: if this post waits until tomorrow morning's check, will the damage grow?
Four kinds of trigger
- Risk words: words such as safety, poisoning, fraud, theft, lawsuit or leak appearing with the brand name. This is the most precise trigger, because a single post is enough.
- Volume spike: mentions in the last 24 hours are sharply above a normal day. A normal day is your own baseline — for example, the average of the last four weeks.
- Source type: a negative piece about the brand on a news site or a large sector portal. A media story reaches a far wider audience than a forum post.
- Spread: the same topic appearing in several different sources within a short time. If a forum complaint is repeated on other sites, it is no longer a local problem.
How to choose thresholds
A fixed number (say, "50 mentions a day") does not work for volume spikes, because 50 may be normal on a campaign day while 15 is already unusual in a quiet week. A relative threshold is more reliable: two to three times a normal day plus at least a few negative posts. Combine the relative threshold with negative tone or a risk word, or a successful campaign will set off alerts too.
For the first month, run thresholds in log-only mode: no alert is sent, you simply record when one would have been. At the end of the month, check how many of those records were genuinely urgent, and adjust the threshold.
An escalation matrix
For each trigger, write down who receives it and how fast they react — in one table. A sample matrix:
- Level 1 — a single negative post with a risk word: the monitoring owner, review within 2 hours, passed to customer service if needed.
- Level 2 — a volume spike or a media story: the marketing/PR lead, assessment within 1 hour.
- Level 3 — safety, legal, or multi-source spread: leadership and legal, immediately; any public reply only with agreed wording.
- A deputy for every level: out-of-hours and holiday cover.
Alert fatigue
The most common failure is too many alerts. The symptoms: the team closes notifications unread, the alert channel gets muted, people say "another false alarm". The cure is not raising thresholds but sharpening triggers: which word brings wrong results, which source is noise, which alert never once led to action. Every month, tighten or delete at least one trigger.
What an alert message should contain
- What happened — one sentence: "a poisoning claim about our brand on portal X".
- Evidence — a link to the original post and a short quote.
- Context — how many posts and sources on this topic in the last 24 hours.
- Who is responsible, and by when.
- What not to do — for example, "do not reply publicly without agreed wording".
Illustrative example
This is an illustrative example. A restaurant chain has set "poisoning", "hospital" and "stomach" together with its brand name as level 3. On a Sunday evening a customer writes on a forum that they fell ill after eating at one branch. The person on duty sees it in the evening check and passes it to the operations director. The director agrees the public reply with a lawyer: regret, a contact channel, a promise to investigate — no admission of fault and no denial. At the same time an internal check starts at the branch. The next day no similar post appears elsewhere; the incident is downgraded to level 1.
How to test your alert system
- Review monthlyHow many alerts came in, how many led to action, how many were wrong.
- Look for missesFind cases that raised no alert but later turned out to matter, and note which trigger should have caught them.
- Measure reaction timeThe time from alert to the owner looking at it. If it misses the matrix target, the problem is the channel or the ownership.
- Change one thingAfter each review, change one trigger, one threshold or one owner.
Limitations
Alerts only see the sources you watch, and only when a search runs; closed groups and messages stay outside. A volume spike does not show its cause — it may be a campaign, news or a problem, and a person has to read and tell them apart. Alerts based on automatic tone labels can misjudge sarcasm. On legal or safety topics an alert is not a decision; it is a hand-off to the person who decides.
Setting it up with Vexvon Monitoring
In Vexvon Monitoring every result is marked with a priority by the AI: a public complaint or reputational risk that needs an answer today is "urgent", an unanswered question or a lead is "high", the rest "normal" or "low". There is no automatic notification feature: a search runs when the team starts it. So the alert logic is built as a workflow — for example, two searches a day, new results only, the "urgent" filter first, and the escalation matrix above. More on the Vexvon Monitoring page.
Next step
This week, write three things: ten risk words for your sector, the mention count of a normal day, and the owner of each level in a three-level escalation matrix. Alerts only make sense once these three documents exist. How to react to a single negative post is covered in detecting negative feedback early; other topics are in the brand monitoring section. To test it with your own risk words, get in touch.