Artificial Intelligence

Social Mention Spike: Telling a Viral Win from an Emerging Crisis

WebPro team 11 min read

Mentions have tripled in two hours and the alert stops there. Somebody has to decide quickly whether this is a campaign landing well or a problem that will matter by evening. Volume alone cannot distinguish them — which is why volume-only alerts produce either panic or complacency.

The alert that tells you nothing

Mentions have tripled in two hours. The alert says so and stops there. Somebody now has to decide, quickly, whether this is a campaign performing unusually well, a piece of coverage, a complaint gaining traction, or something that will be a problem by evening.

Volume alone cannot distinguish these, which is why volume-only alerts produce either panic or complacency depending on the temperament of whoever reads them. The same number of mentions can represent a product launch landing well or a service failure being discovered, and the response to each is entirely different.

What follows is a triage model for the first fifteen minutes after a spike: five signals to read, in order, and what each combination usually means. It is a diagnostic procedure rather than an alerting design — deciding what should notify you in the first place is a separate question.

Signal 1: what is the actual volume?

Before anything else, establish whether this is a real spike or a small baseline behaving normally.

  • Compare against your own recent baseline, not against a fixed threshold. A brand averaging ten mentions a day and one averaging ten thousand need completely different trigger levels.
  • Check the absolute number, not just the multiple. Tripling from four mentions to twelve is noise; tripling from four hundred is not.
  • Check whether the baseline itself has shifted — a campaign running in the background changes what normal looks like.
  • Look at the same period last week and last month. Weekly and seasonal patterns produce spikes that are entirely expected.
  • Rule out the technical explanations first: a query change, a newly added source, a deduplication failure, a platform restoring backlogged data. These account for a meaningful share of apparent spikes and cost nothing to check.
  • Check for a single source producing many posts — one account, a bot pattern, or syndicated content reposted widely.

Signal 2: how fast is it moving?

Velocity — the rate of change rather than the level — distinguishes the situations that need immediate attention from those that need a plan.

  • Accelerating volume is the signal that matters most. A spike that is still growing an hour in behaves very differently from one that has plateaued.
  • Decelerating spikes usually resolve themselves. Most viral moments, positive or negative, have a short half-life and intervening after the peak frequently extends the story rather than ending it.
  • Sustained elevation without a sharp peak is a different phenomenon — usually an ongoing issue being discovered gradually rather than a single event, and it is more likely to be a real operational problem.
  • Compare velocity across your competitive set. If the whole category is spiking, the cause is external and your response should reflect that.
  • Look at the time of day. A spike beginning in the evening may simply be when your audience is active.

A useful heuristic: level tells you how visible this is, velocity tells you how urgently to act. Both are needed and neither substitutes for the other.

Signal 3: what are people actually saying?

This is the step teams most often skip in favour of looking at the sentiment chart, and it is the one that determines the answer.

  1. 1

    Read the posts, starting with the earliest

    Twenty posts, oldest first. This takes five minutes and it establishes what started this, which the aggregate view cannot show. The origin usually explains everything that followed.

  2. 2

    Identify the originating post or event

    Most spikes trace to a single source: a review, a news item, a well-followed post, a customer's thread. Finding it tells you what you are actually dealing with.

  3. 3

    Check whether it is about you specifically

    Spikes frequently involve your brand being mentioned in a conversation about something else — an industry story, a competitor's problem, a comparison. The response differs entirely.

  4. 4

    Look for a factual claim you can verify

    If the spike concerns something specific — a fault, an outage, a policy — establishing whether it is true is more urgent than any communications decision.

  5. 5

    Use sentiment as a sorting aid, not as the answer

    Automated sentiment on a fast-moving spike is particularly unreliable, because novel language and sarcasm are both overrepresented. Use it to order what you read, with the usual caveats.

  6. 6

    Note the mix

    Many spikes are genuinely mixed — some praise, some criticism, some neutral discussion. Reporting a mixed spike as negative is a common error with real consequences for how the organisation reacts.

Reading the earliest twenty posts is the highest-value five minutes available in this whole process, and it is consistently skipped in favour of dashboards.

Signal 4: who is involved?

The identity of the participants changes both the trajectory and the appropriate response.

  • A single high-reach account can produce a spike that involves very few actual people. Check the distribution of authors before concluding anything about how widespread this is.
  • Journalists and media accounts participating suggests the story may move to other channels, which changes the timeline considerably.
  • Customers versus commentators: a spike composed of people who have used your product is a different problem from one composed of people reacting to a story about it.
  • Employees participating, in either direction, is worth knowing early.
  • Coordinated patterns — similar wording, similar timing, new accounts — indicate something other than organic reaction.
  • Competitors or their advocates participating changes what a response will look like.
  • Check whether the people involved are in markets where you operate. Spikes sometimes originate in regions where the brand name overlaps with something unrelated, which is a query precision problem rather than an event.

Author distribution is the most useful single check here. Many mentions from few people is a visibility event; few mentions from many people is the beginning of a broader reaction.

Signal 5: is it spreading beyond where it started?

Contained and spreading situations need different responses, and the distinction is observable.

  • Still on one platform, or appearing across several? Cross-platform movement is the clearest indicator that something will continue.
  • Has it reached channels with different audiences — professional networks, news, forums?
  • Is it being covered rather than discussed? A story about the conversation is a different phase from the conversation itself.
  • Is it reaching your support channels, or your phone lines? Operational systems frequently register a real problem before social volume does.
  • Are related searches increasing? People looking for information indicates something broader than a social reaction.
  • Has it crossed languages? This usually indicates genuine reach rather than a single community reacting.

Reading the combinations

The five signals together usually produce a clear reading. The common patterns:

  • High volume, decelerating, positive content, many distinct authors, single platform: a campaign or piece of content performing well. Amplify if useful, otherwise let it run.
  • Moderate volume, accelerating, negative content, growing author count, spreading across platforms: an emerging problem. This is the combination that warrants immediate escalation.
  • High volume, few authors, mixed content: a visibility event driven by one or two large accounts. Usually resolves quickly and rarely needs a response.
  • Sustained moderate elevation, negative, customers rather than commentators, visible in support channels: a genuine operational problem being discovered. Fix the problem; communications is secondary.
  • Volume spike, content not actually about you: you have been caught in someone else's story, or your query is matching something unrelated.
  • Coordinated pattern, new accounts, similar wording: treat differently from organic reaction and involve whoever handles that in your organisation.
  • Any combination including a verifiable factual claim about a fault or a safety matter: verification takes precedence over all of the above.

Write these readings down as a short reference before you need them. Triage under time pressure works considerably better from a prepared list than from first principles.

What to do in the first hour

A sequence that works regardless of which diagnosis emerges.

  1. 1

    Rule out your own systems

    Query changes, new sources, data backfill. Two minutes, and it prevents a significant share of false alarms.

  2. 2

    Read the earliest twenty posts

    Establish the origin. Five minutes.

  3. 3

    Check operational channels

    Support queue, call volume, error rates. If something is genuinely broken, this is where it shows.

  4. 4

    Classify and notify the right person

    Not everyone. The person who owns whichever category this falls into, with what you have established rather than with the alert.

  5. 5

    Decide whether to respond, and record the decision

    Deciding not to respond is a legitimate outcome and should be recorded as one, with the reasoning.

  6. 6

    Set a review point

    Check again at a defined interval rather than watching continuously. Continuous watching produces reactive decisions and exhausts the team.

The fifth step matters more than it appears. Many spikes are best left alone, and a team that has recorded 'we decided not to respond because it was decelerating and mixed' is in a much better position than one that simply did nothing.

Data and tooling requirements

Spike triage needs less tooling than it needs preparation.

  • Baseline data for comparison — at least several weeks of history per query, so 'unusual' has a definition.
  • Access to raw posts in chronological order. A platform that shows only aggregates makes the most important step impossible.
  • Author-level data, so the distribution can be checked.
  • A query change log, to rule out self-inflicted spikes.
  • Cross-platform view in one place.
  • Operational signals visible alongside — support volume, call volume — which usually means pulling two systems together rather than one platform providing everything, though a consolidated view removes part of that work.
  • A short written triage reference and a named owner per category.
  • A record of past spikes and how they were handled, which is the most useful reference the second time.

The historical record is worth keeping deliberately. Most organisations handle a handful of spikes a year and forget what they learned between them. Our automation services page covers connecting these signals into one view.

What the signals cannot tell you

Be clear about the limits when escalating.

  • Whether the underlying claim is true. That requires checking the facts, not reading more posts.
  • How this will develop. Spike trajectories are not reliably predictable and confident forecasts are usually wrong.
  • What people who are not posting think, which is most of your customers.
  • Whether a response will help or amplify. This is a judgement, and the evidence rarely settles it.
  • Anything about private conversations or channels you do not monitor.
  • Whether the coverage you can see is the whole picture — it is not, and coverage varies by platform.

Escalating with 'here is what we know, here is what we do not' is considerably more useful to a decision-maker than a confident narrative assembled from partial data.

Decision framework and next step

Four questions to answer before the next spike, not during it.

  1. 1

    What is your normal baseline, per query?

    Without this, every alert is uninterpretable.

  2. 2

    Can you read posts in chronological order?

    This is the single most important capability for triage.

  3. 3

    Who owns each category of spike?

    Product issue, service failure, campaign, media story, coordinated activity. Named people, decided in advance.

  4. 4

    Do you have a written triage reference?

    Working from a prepared list under time pressure is markedly better than working from first principles.

Establish baselines, ensure chronological access to raw posts, write the triage reference, and assign category owners before you need them. Which conditions should generate an alert at all is a separate design question, and building a full early-warning capability is a separate project again. Our AI solutions overview covers how these capabilities are staged.

Frequently asked questions

  1. 1

    How do you tell a viral win from an emerging crisis?

    By reading five signals rather than volume alone: the volume against your own baseline, the velocity and whether it is accelerating, what the earliest posts actually say, who is involved and how authors are distributed, and whether it is spreading across platforms and into operational channels.

  2. 2

    What should be checked first?

    Your own systems — a query change, a newly added source, a data backfill. A meaningful share of apparent spikes are self-inflicted and ruling that out takes two minutes.

  3. 3

    Why read the earliest posts rather than the dashboard?

    Because most spikes trace to a single originating post or event, and identifying it explains everything that followed. The aggregate view cannot show origin, and five minutes of chronological reading usually settles the diagnosis.

  4. 4

    Which combination warrants immediate escalation?

    Moderate but accelerating volume, negative content, a growing number of distinct authors, and spread across more than one platform — particularly if it is also visible in support or call volume.

  5. 5

    Is not responding a legitimate outcome?

    Frequently, yes. Most spikes decelerate quickly and intervening after the peak can extend the story. The decision not to respond should be recorded with its reasoning rather than simply not made.

Volume tells you how visible something is. Velocity, content, sources and spread tell you what it is — and only the combination supports a decision.

Let's talk about your project

Tell us what you want to build and we will work out the scope, timeline and approach together.