Templates

Threat Made on Social Media: Parent Notification Templates

By the time a district hears about a threatening post, several hundred families have already seen a screenshot of it. The window between that and your first message is about ninety minutes, and what you send in it determines tomorrow's attendance.

Last reviewed 2026-08-04 ยท Kastr is pre-launch; we publish dated status rather than logos.

The ninety-minute window, minute by minute
ElapsedWhat is happening outsideWhat you do
0–15 minScreenshot spreads through student group chats; parents begin receiving itPreserve the original, notify [AGENCY], start the log. Do not message yet unless the threat names a time inside the hour.
15–40 minFirst parents call the front office; a parent Facebook group posts itBrief the front office with an exact script. Send the acknowledgement message — you are aware, it is with law enforcement, do not forward.
40–70 minLocal news picks it up; the screenshot mutates and gains details that were never in itSecond message with any credibility finding you have. Correct specific false details by naming them.
70–90 minFamilies are deciding about tomorrowSend the decision message: open or closed, what changes, and the attendance policy for families who keep children home.
Next morningAttendance dips 8–30% depending on what you sentMorning message from the building, not the district office. Presence is the message.

Ten templates by credibility finding

1. Unverified rumour circulating

We are aware of a message about [SCHOOL] circulating on social media. We reported it to [AGENCY] at [TIME] and they are investigating. We do not yet know whether it is credible. Please do not forward the screenshot — sharing it spreads it and makes the investigation harder. Everything we confirm will come from us at [CHANNEL]. Next update by [TIME].

2. Investigation underway, no finding yet

[AGENCY] is actively investigating the message about [SCHOOL]. They have not yet made a determination. [ANY VISIBLE MEASURE, EG ADDITIONAL OFFICERS ON SITE]. School is open and running normally. We will tell you the finding when we have it, including if the finding is that it was not credible.

3. Determined not credible

[AGENCY] has completed its investigation of the message about [SCHOOL] and determined that there is no credible threat to our students or staff. Specifically, they [WHAT THEY DID: identified the source, traced the account, confirmed the post originated outside the area]. School is open tomorrow on the normal schedule. [OFFICER OR ADMIN NAME] will be at the main entrance from [TIME] if you want to ask anything in person.

4. Credible, law enforcement action taken

[AGENCY] determined the message about [SCHOOL] to be credible and has taken action. We are not able to describe that action while the matter is active. [WHAT CHANGES AT SCHOOL]. School [IS OR IS NOT] in session on [DATE]. Counsellors will be available at [LOCATION].

5. Threat naming a specific date

The message circulating about [SCHOOL] names [DATE]. [AGENCY] is investigating and we are treating it seriously regardless of what we conclude about its origin. Here is what will be different on [DATE]: [SPECIFIC MEASURES]. School will be open. If you choose to keep your child home that day, the absence will be excused and there will be no penalty; tell [CONTACT].

6. Copycat chain message

A message naming several schools, including [SCHOOL], is circulating nationally. Versions of it have appeared in [N] states in the past week. [AGENCY] is aware. Chain messages of this kind spread because people forward them out of concern; the most useful thing you can do is not forward it.

7. Threat originating at another district

A threat directed at [OTHER DISTRICT] is circulating locally and some families have received it believing it concerns us. It does not name our schools. We are in contact with [OTHER DISTRICT] and with [AGENCY]. Our schools are open and operating normally.

8. Traced to an enrolled student

[AGENCY] has identified the person who made the post about [SCHOOL]. Because that person is a minor and a student, we are not able to say anything further about them, about consequences, or about what happens next. That is not us protecting anyone; it is the law. The matter is resolved from a safety standpoint and school is open normally.

9. Threat during a school break

We are aware of a message about [SCHOOL] circulating over the break. [AGENCY] is investigating. There are no students in the building. We will send an update before [RETURN DATE] regardless of the outcome, so you are not deciding on the morning.

10. Resolved with an arrest

[AGENCY] has made an arrest in connection with the threat against [SCHOOL]. Questions about the arrest go to [AGENCY PIO]; we are not able to comment on it. School is open on the normal schedule. Counsellors remain available at [LOCATION] for any student who wants to talk, and 988 is available to anyone in the US at any hour.

Writing the "not credible" paragraph

This is the paragraph districts get wrong most often, and it is worth six drafts. The failure mode is that a technically accurate reassurance still produces a fifteen per cent attendance dip the next day, because families read the hedge rather than the finding.

Six constructions, roughly in order of how well they land:

  • "We have no reason to believe there is a credible threat." Triple-hedged. Families hear "they don't know."
  • "The threat has been deemed not credible." Passive, no actor. Deemed by whom, on what basis.
  • "Law enforcement has determined the threat is not credible." Better — there is an actor and a finding.
  • "[AGENCY] investigated and determined there is no credible threat to our students." Better again — named agency, named subject.
  • "[AGENCY] traced the post to [SOURCE, NON-IDENTIFYING] and determined there is no credible threat." Now there is a mechanism, which is what turns a claim into something a parent can believe.
  • The above, plus what happens tomorrow and who will be standing at the door. The strongest version, because it converts reassurance into an observable fact the parent can verify at 8am.

Say what was done, not how confident you are. Confidence is unfalsifiable and reads as reassurance-seeking. A mechanism — the account was traced, the source was identified, the post originated in another state — is checkable, and it is what actually reduces the next-day dip. If you genuinely cannot describe the mechanism because the agency has asked you not to, say that instead: "There is more we know and cannot share yet" is more credible than a stronger adjective.

The next morning, and the parent who asks why you did not close

Morning message, sent at 6:45 from the building: "Good morning from [SCHOOL]. We are open and running the normal schedule. [PRINCIPAL] and [OFFICER] are at the main entrance and will be there through first period. [WHAT IS DIFFERENT TODAY]. If your child is anxious about coming in, call [NUMBER] and we will meet them at the door."

Reply to the parent asking why you did not close: "Thank you for writing — it is a fair question and several families have asked it. We close when the responding agency advises us to close or when we cannot operate safely. In this case [AGENCY] investigated and advised that [FINDING], and we put [MEASURES] in place. Closing also has a cost we weigh: it teaches that a post can shut a school, which is often what the post is for. That reasoning may not change your mind, and if you keep [STUDENT] home the absence is excused."

Do not name the platform in your public messages unless the agency asks you to. It adds nothing families need, and it points the next person at a venue.

Everything here should be reviewed once in advance by your counsel and the agency's public information officer, and everything about an identified student is governed by student privacy law and by your board policy rather than by what feels transparent. If students were frightened, the counselling route belongs in the message: your counsellors, your local crisis centre, and 988. Longer-term follow-up is on the post-crisis page.

Questions people actually ask

Should we message parents about a threat we have already determined is not credible?

Yes. Several hundred families have already seen the screenshot, and silence from the district leaves the screenshot as the only account. A message that names the agency, states the finding and describes the mechanism behind it is what reduces the next-day attendance dip.

What do we say when we cannot yet confirm whether a threat is credible?

Say exactly that. Acknowledge the post exists, say it has been reported to a named agency at a named time, say a determination has not been made, ask families not to forward it, and commit to a specific update time. Do not characterise the threat before the agency has.

How do we respond to a threat that names a specific date?

Treat it seriously regardless of the credibility finding, and say what will visibly be different on that date. Offer an excused absence with no penalty for families who choose to keep a child home, and say so in writing — families who feel forced to choose between safety and an attendance mark will resent both.

Do we name the platform the threat appeared on?

Generally no, unless the responding agency asks you to. Naming it adds nothing a family needs in order to act and effectively signposts a venue to the next person considering it.

One price. Every feature. Locked for three years.

$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.