Back to Insights
Trust Operations

Why Manual Review Cannot Keep Pace With Coordinated Campaigns

Tom Garnett
Trust analyst working through a large queue of flagged accounts at a monitoring workstation

The Arithmetic Does Not Work

Start with a simple calculation. A skilled trust-desk analyst can thoroughly investigate one story, following the account network, checking posting patterns, reviewing content overlap, and reaching a confident conclusion, in roughly thirty to sixty minutes, assuming they have direct access to the relevant account data. Call it forty-five minutes on average for a story that requires meaningful investigation rather than an obvious pass or obvious fail.

Now consider the volume. A mid-sized newsroom or brand safety team may need to assess tens of stories per day that show potential manipulation indicators. A large brand during a PR crisis may see hundreds of suspicious content items surfacing within a matter of hours. Even the most optimistic analyst efficiency assumption runs out of runway quickly. At forty-five minutes per story, a single analyst can assess approximately ten stories in a working day. Ten stories per day, per analyst. The volume of suspicious content in an active campaign episode can exceed that in the first hour.

This arithmetic problem is the foundational reason why manual-only approaches to coordinated behaviour detection cannot scale. It is not a question of analyst capability or effort. It is a question of unit economics: the time required per investigation does not compress at the same rate as the volume of suspicious content expands.

How Campaigns Exploit This

The volume pressure is not accidental. Coordinated campaigns are frequently designed to generate enough activity to overwhelm any manual review process, whether the target is a platform moderator team or an organisational trust function. The logic is straightforward: if your team can investigate ten stories a day, a campaign that generates thirty suspicious signals simultaneously can be confident that two thirds of them will not be investigated in time to matter.

This is one reason why coordinated campaigns often include a significant proportion of lower-priority noise alongside the content they most want to spread. The noise is not the objective. It is operational cover: it consumes investigation capacity that would otherwise be directed at the higher-priority content. A well-resourced campaign operator understands that human review processes have a throughput limit and designs activity to exceed that limit intentionally.

Manual review under high volume pressure also degrades in quality as well as quantity. An analyst working through their twelfth suspicious account in a row is making different quality decisions than the analyst on their second or third of the day. Cognitive load and decision fatigue are real phenomena, and they affect the reliability of manual review in ways that a consistent automated scoring system does not experience. The cases that require the most careful judgment, the borderline ones where a coordinated campaign has invested in appearing credible, arrive at the point of highest analyst fatigue.

What Tooling Can and Cannot Do

The correct response to the arithmetic problem is not to try to hire enough analysts to close the gap. The economics do not work, and the talent is not available at the volume that would be required to match campaign volume with manual review capacity. The correct response is to change what analysts spend their time on.

Detection tooling that automates the structured parts of an investigation, retrieving account histories, measuring posting cadence, computing network clustering, comparing content templates, can reduce the per-story investigation time from forty-five minutes to something much shorter for the large proportion of stories where the signals are clear. A story where multiple automated signals all point in the same direction (thin accounts, coordinated timing, template content, network clustering) does not require a full analyst investigation to reach a confident conclusion. The structured analysis has done most of the work. An analyst reviewing the output needs minutes, not an hour.

This matters enormously for throughput. If tooling can handle the structured analysis layer and reduce analyst time per story to five to ten minutes for clear cases, the same analyst team that could handle ten stories per day manually can handle fifty to eighty stories per day with tooling support. That changes the arithmetic enough to be operationally meaningful in most campaign scenarios.

What tooling cannot do is replace the analyst judgment required for cases where signals are ambiguous or conflicting. The borderline cases, where the account profiles look mostly credible but something is slightly off, where the content template similarity is suggestive but not conclusive, or where the network structure is unusual but could have an innocent explanation, require the contextual knowledge and editorial judgment that experienced analysts bring and that automated systems cannot replicate reliably. The role of tooling is to clear the high-confidence cases efficiently so analyst attention is concentrated on the cases that genuinely require it.

The Triage Architecture

Effective trust-desk operations in well-resourced organisations tend to use a triage architecture rather than treating all suspicious stories as requiring the same depth of investigation. The first tier is rapid automated scoring: all suspicious stories receive an initial score based on fast-signal analysis within seconds. Stories with high-confidence clear signals in either direction (clearly coordinated or clearly clean) are triaged out of the manual review queue. Stories with ambiguous or conflicting signals, or that exceed a suspicion threshold without clear indicators, move to manual investigation.

The second tier is structured analyst review, supported by tooling that surfaces the relevant account and network data for a human to evaluate. The analyst is not starting from scratch: the tooling has already pulled together the relevant signals. The analyst's role is contextual judgment: does this pattern make sense given what I know about this topic area, this type of campaign, and the actors typically involved?

The third tier, reserved for high-confidence confirmed cases with significant scale or impact potential, involves cross-functional escalation: communications, legal, and potentially external partners who can assist with response.

This architecture does not eliminate the need for analysts. It changes what they do. The unit economics shift from one analyst per ten stories to one analyst handling a much larger volume at higher quality, because their time is directed to where human judgment actually adds value rather than being consumed by structured analysis that tooling handles more consistently.

The Honest Caveat About Automation

Automated detection tooling improves throughput but introduces its own failure modes. Systems tuned for high recall will generate false positives that consume analyst time in a different way. Systems tuned for high precision will miss campaigns that would have been caught by more sensitive detection. Keeping track of how the automated layer is performing in your specific deployment context, measuring false positive rates, reviewing cleared stories periodically to catch missed genuine cases, and recalibrating thresholds as the campaign landscape evolves, is ongoing operational work that cannot be set and forgotten.

The argument for tooling is not that it solves the scaling problem perfectly. It is that it makes the problem tractable in a way that manual review alone cannot. The alternative is a team that is perpetually under water during active campaign periods, making poor decisions under time pressure on the cases that matter most. That is the baseline cost of not having tooling, and it is worth measuring honestly against the cost and limitations of building or buying detection capability.