Playbooks · 5 min read
When It Goes Wrong Publicly: The Kill Switch Comes First
The thing that turns a bad day into a bad week is not the original problem. It is the forty cheerful automated replies that went out underneath it while everyone was in a meeting deciding what to say.
Why the instinct to rewrite the template is wrong
Every operator's first reflex is to fix the reply. It feels responsible. It is the wrong order of operations for three reasons.
Editing takes minutes and sends keep happening while you edit. A template written inside the first hour of a crisis is written before anyone knows what is true. And a crisis changes what a keyword means — price under a post about a pricing error is not a pricing question any more, and no wording of the pricing reply is correct.
Turning it off costs you some slow replies. Leaving it on while you compose costs you a screenshot of your automation being upbeat about a problem you have not acknowledged.
The first ten minutes
- Kill switch on. It is the first check in the gate, before connection, before window, before anything. Nothing sends. Every attempt is still recorded as blocked, so you keep the record of what would have gone out.
- Check the DM inbox by eye, not by dashboard. You need to know whether this is twelve angry people or four hundred, and only reading it tells you that.
- Say something human, publicly, from the account. Even "we've seen this, we're looking into it, back within the hour". The gap between the incident and the first human word is the part people remember.
- Decide who is answering by hand, and tell them. One named person, not "the team".
- Do not turn anything back on yet. The pressure to restore normal service is the thing to resist.

Never automate a reply during a live complaint wave
This is the rule that gets broken with the best intentions. Complaints are pouring in, someone says "we should at least acknowledge everyone", and a holding-message automation goes up.
Do not do this.
A complaint wave is not a set of identical questions that happen to be angry. It is a set of different people with different losses, and an identical reply to all of them proves you did not read any of them. It is also the highest-screenshot-density moment your account will ever have. One templated "Thanks for reaching out! We appreciate your feedback 😊" under a genuine grievance is the image that outlives the incident.
During a complaint wave, a slow human reply beats a fast identical one by a margin that is not close.
There is a narrow exception, and it is narrow: a single public comment reply, written by a person, posted manually, saying what happened and where the update will be. That is not automation. That is you, typing.

The four shapes a crisis takes
They need different responses and people apply the same one to all four.
A product or service failure. Broken orders, an outage, a recall. Automation off entirely. Every reply by hand until the volume is genuinely repetitive and the facts have stopped moving — which is usually day two, not hour two.
A reply of yours that landed badly. Someone screenshots an automated message that was tone-deaf in context. Kill switch, then find the run in Activity and read exactly what was sent and to whom. Do not describe it from memory. Then apologise for the message, not for "any confusion caused".
Someone else's crisis in your comments. A news event, a controversy involving a collaborator. Your automation does not know the room has changed. Pause the automations attached to any post that is being commented on for reasons unrelated to the post.
A viral post that is not a crisis but behaves like one. Thousands of comments, most of them fine. Here you should not kill everything — you should let cooldown and rate_budget do their job, which is exactly what they are for. Watch Activity, spot-check the sends, and leave the throttles alone. Reading Activity as a diagnostic matters more in this shape than in any other.
Turning it back on
The restart is where people undo their own good work by restoring everything at once.
Before you restart
How to restart
The blocked list from the outage window deserves a specific pass. Those are people who asked and received silence. Most are fine. Some asked something time-sensitive and are now a day into believing you ignored them, and going back to those by hand is the highest-value hour in the whole recovery.
What to change afterwards
Not much, and specifically not "add a crisis automation". The reason this post has no crisis-template section is that the correct crisis behaviour is fewer automated messages, not better ones.
Two things are worth doing while the memory is fresh. Write down who is allowed to hit the kill switch — if that is one person and they are asleep, you do not have a kill switch, you have a bottleneck. And add the complaint vocabulary to your negative keywords permanently: refund, cancel, broken, worst, scam, galat, paisa wapas. Those words should never reach an automated reply on a normal Tuesday either.
Then read your own templates once, in the voice of your angriest customer. The ones that survive that reading are the ones you can leave running. For the wider set of habits that keep a setup from needing this post, the safety and refusal model is the place to start.


