Facebook's implementation of Safety Check is poor, inviting unnecessary worry about unaffected users who don't mark themselves as “safe”
Context & Ripple Effects
Safety Check began as a manually activated tool, but Facebook moved to algorithmically triggering it from post volume and third-party confirmations in 2016, and days before this piece added personalized tools including a fundraising option. Each expansion widens the pool of crises the feature fires for — and with it, the number of users silently swept into an affected zone.
Natasha Lomas's critique lands on the design gap that scaling created: the feature treats 'hasn't marked themselves safe' as legible information, when for most users silence just means they haven't opened the app. Two months later Facebook shipped a dedicated Safety Check tab listing global crises, an acknowledgment that discovery and status needed their own surface.
First-order effects
- Friends and family of users inside a triggered crisis radius get false alarms about people who are simply unaware or offline, converting a reassurance tool into a generator of duplicate worry.
- Facebook bears the support and reputational cost every time the feature misfires at scale, since the anxiety lands on the platform's own notification channels.
Second-order effects
- Adoption of the newly added fundraising option is hostage to trust in the surrounding tool — if marking feels unreliable, users are less likely to route charitable giving through it.
- The usability gap pushes Facebook toward structural fixes like the dedicated tab rather than incremental tweaks, shifting Safety Check from a push notification into a browsable product surface.
Third-order effects
- The episode fits the pattern BuzzFeed later described of Facebook taking a self-assured approach to safety features and then cleaning up its own mess — crisis tooling designed around what the company can measure (marks, triggers) rather than what absent data actually means.
- If silent-user ambiguity persists as triggering automates further, platforms face pressure to distinguish 'unconfirmed' from 'unsafe' by default, making absence-of-signal handling a core design requirement for any mass-notification system.
The trend: Crisis-response features are scaling from hand-triggered novelties into always-on infrastructure faster than their communication defaults mature, leaving platforms to retrofit meaning onto user silence.