How safeguarding works,
and who can see what

Written for designated safeguarding leads. The oversight model is narrower than most people expect it to be, on purpose, and this is where the lines sit.

Socialheads governs one channel: the messages between your staff, and between your staff and the people they support. Oversight of that channel rests on three plain rules.

  • A young person can always raise a concern about a message, and it reaches a named safeguarding lead rather than the person who sent it.
  • Oversight above the conversation is signals and patterns. Reading a message you were not part of is a separate act with its own gate.
  • Every one of those acts is recorded with a name, a role, a time, and where it applies, a reason in someone's own words.

Put in one line: only the people in a conversation can read it, and any other access needs a recorded reason your service can see.

Can supervisors read messages?

No. Supervisors see signals and patterns, not transcripts. Reading message content is not something a job title grants, and where it happens it needs a recorded reason the organisation can see.

What a supervisor actually sees

Counts and trends for their service. How many people have nobody supporting them yet, what is stalling, what is waiting for the safeguarding lead. The line about flags reads "three flagged messages for the safeguarding lead to review", because that is whose job it is.

Why we drew it here

A supervisor who could read at will changes what a worker writes, and what a young person says. The line sits here so neither has to change.

What happens when a concern is raised

Three steps, and a fourth that is deliberately harder to reach.

The journey of a flagged message Step one, someone raises a concern: a young person always can, and whether staff flag in the app is the service's choice. Step two, a safeguarding lead reviews it, never the person who sent the message. Step three, the review itself is recorded: who looked, and when. What follows belongs to the service's own procedures. Reading what was written is a separate step: it has to be switched on for one named person, who types a reason first, and every administrator in the organisation is told. 1 Someone raises a concern A young person always can. Staff is your choice. 2 A safeguarding lead reviews it Never the person who sent the message 3 The review is recorded Who looked, and when. What follows is yours. Reading what was written Switched on for one named person, who types a reason. Every admin is told.

A young person can always raise one

For a young person, being in the conversation is the gate. They can raise a concern about any message, including one a worker sent them. That matters more than it first sounds. A young person can always raise a concern themselves, so they are never dependent on an adult noticing first. Before they send it they are told who will read it.

Whether staff also flag in the app is a setting your service chooses. A worker with a concern already has your safeguarding procedures to follow, and can export the message into them.

A lead cannot review a concern about their own message

If a lead sent the message, that flag is not theirs to see or to resolve. Their organisation's other safeguarding roles were told, so the concern still lands, just not with the person it is about.

The gate on reading content

Reading the content of a conversation you were not part of is a separate, deliberate step. We call it break-glass, because that is what it is like: you can do it when you need to, and everyone knows you did. It is short, it is loud, and it leaves a mark by design.

Before the option is even there, someone has to have been given access by name. Using it means writing down why, in their own words, and every admin in your organisation is told as it happens. Access closes on its own, and each look is recorded separately, so who looked, at what, when and why is answerable one look at a time.

The wording on screen before they do it says all of that plainly. Nobody arrives at this by accident, and nobody arrives at it quietly.

If your governance review wants this control by control, ask and we will send it the same day.

The audit trail, and what it actually holds

Entries are added, never edited

The trail can't be edited or deleted from the app, only added to. Reading the trail is itself an entry, so that is recorded too.

Every entry keeps the names and roles people held that day

A link to a staff record tells you what someone's name and role are today. A snapshot tells you what they were on the day, which is the fact a review, a complaint or an allegation actually needs.

Erasure reaches it carefully, not automatically

Contact details are redacted. The name and role attached to an action are kept where a retention duty, a safeguarding need or a legal hold applies, and disposed of with the record they belong to. An unconditional wipe would hollow out the safeguarding timeline at exactly the moment it matters most.

Oversight without surveillance

A young person who tells their worker something difficult has decided to trust one person. If a manager could read that quietly, they would not have told one person. They would have told a room, and most of them would have said nothing at all.

So the record is not there to watch anybody. It is there so that when something matters there is something to look at. Young people get their side of this written for them, not for you: what we tell a young person when they are invited, and who can see their information. In the product, they can see who supports them, and ask any organisation they are part of for a copy of what it holds about them.

The model has to survive one question: could you explain it to the young person it is about, in plain words, without them feeling watched?

Where Socialheads stops

  • It holds the record, and your case system holds the case. It holds what was said, the concerns raised on it, and what a lead decided about each one. It does not build chronologies, hold your case notes, or replace the system you keep those in. It gives you the record to attach.
  • People raise concerns and people review them. Nothing scans messages to decide what is worrying.
  • The judgements stay yours. Whether a record is sufficient, what to do about what it shows, and what to share with whom are decisions for your service.
  • The duty stays yours. Your organisation is the data controller and we act as your processor.

Straight answers

Can supervisors read messages?

No. A supervisor sees signals and patterns for their service, not transcripts. Reading a message you were not part of is a separate act that has to be granted to a named person, and doing it means writing down why, in your own words, where your organisation can see it.

Is Socialheads encrypted?

Yes. Connections are encrypted and personal data is encrypted field by field, including message content. Who may read a conversation is decided separately, by your organisation, and recorded: only the people in it, and any other access needs a reason your service can see. That separation is what lets a safeguarding lead review a flagged message at all.

Does flagging a message delete or hide it?

No. The message stays exactly where it is, readable by the people who could always read it, and nothing is acted on automatically. A flag opens a review for a named person to look at.

Who is told when someone opens protected content?

Every org admin in that organisation, as it happens, with a pointer to where the reason is recorded. It is never silent.

Can a young person raise a concern about a message a worker sent them?

Yes, always. A young person can raise a concern about any message in their conversation. It goes to the safeguarding leads in that organisation and never to the person who sent the message.

Does this make our service compliant?

No. Compliance stays with your organisation, because you are the data controller and we act as your processor. We are built so you can evidence what happened, and the duty stays yours.

Where this sits in the product

Most services start with the staff group, because that is where most of the day's messaging already happens. Messaging with the people you support is the second step, and it is where most of this page applies.

Core

From £3,000 a year

A safe alternative to WhatsApp for your staff team chats, owned by the service rather than by everyone's personal handset. Concerns can be raised on a staff message too.

Safeguarding Plus

From £7,500 a year

Adds messaging between your staff and the people you support, with the flag, review, break-glass and audit model set out on this page.

Plans and pricing sets out how your figure is worked out. Trust and security is the governance side of the same model.

Ask us to walk the model on real screens, with your own scenario, and tell us the timescale you are working to.

Top