Online safety education is heavily weighted towards configuration: making accounts private, restricting audiences, limiting who can contact you.
These are worth doing. They also address a specific threat — the unknown outsider — that accounts for a minority of documented harm to young people online.
Where harm actually comes from
Research on unwanted online experiences among young people consistently finds that a substantial majority involve people known to the subject: peers, classmates, current or former partners, and acquaintances.
Every one of these has already passed the privacy filter. They are inside the audience by design.
This is the structural limitation of configuration as a safety approach. Privacy settings are an access control system, and access control does not address misuse by people who have legitimate access.
The categories settings do not touch
Peer sharing. Content shared with a trusted audience being redistributed by a member of that audience. This is the mechanism in the large majority of image-based abuse cases involving young people.
Partner coercion. Pressure to share passwords, to grant location access, to accept monitoring. Surveys of adolescent relationships find these behaviours reported at substantial rates and frequently not recognised as abusive by either party.
Account compromise through known people. Password sharing within relationships and friendship groups is common, and the access frequently outlives the relationship.
Group dynamics. Exclusion, targeted group chats, and coordinated behaviour by peers. No setting addresses being talked about.
What a safety plan actually contains
The distinction is between configuration and planning. A plan addresses what happens when something occurs, not only how to reduce the chance of it occurring.
Account recovery. Recovery email and phone number that only she controls, two-factor authentication enabled, and recovery codes stored somewhere accessible. This is the single most useful item and is rarely set up before it is needed.
An access audit. Which people and applications have access to which accounts. Old shared passwords, connected apps and remembered devices accumulate and are rarely reviewed.
An evidence routine. Decided in advance: what to screenshot, where it is stored, how it is labelled. Evidence collected in a panic is usually inadequate.
A named adult. Someone identified in advance as the person to contact. The research on disclosure is consistent that having a specific person identified beforehand substantially increases the chance of disclosure occurring.
Knowledge of the reporting routes. Which service handles what, and which specialist organisations exist. Discovering this during a crisis is slow.
The location aggregation problem
This deserves separate treatment because it is the risk least well addressed by settings and least intuitive.
Location is rarely disclosed directly. It is reconstructed from accumulated detail: the school uniform in a photograph, the route mentioned in a caption, the shop in the background, the timing of posts, the tagged friends.
No individual item is a disclosure. The aggregate is.
Metadata compounds it. Images can carry location data, and while most major platforms strip it on upload, direct file sharing frequently does not.
The practical implication is that teaching a rule about not posting location is insufficient, and demonstrating how aggregation works is considerably more effective — most people find the demonstration startling in a way the rule does not achieve.
The persistence problem
The second thing configuration does not address is time.
Content shared with an appropriate audience today may be seen by a different audience later. Screenshots persist beyond deletion. Ephemeral content is not reliably ephemeral.
The useful framing is not that everything is permanent — an unhelpfully absolute claim that adolescents correctly identify as exaggerated — but that the audience is not fixed, and that a decision about who can see something is a decision about who can see it now.
What to do with a young person, concretely
Set up recovery properly, together, once. Two-factor authentication, recovery details she controls alone, codes stored somewhere she can reach.
Do an access audit, and repeat it after any relationship ends.
Demonstrate aggregation with her own posts. This is the single most effective teaching exercise in this area.
Name the adult, explicitly, and state what will and will not happen if she comes to them. The predictability is the point.
And be clear that settings are a first layer, not the plan. A young person who believes a private account has solved the problem is less prepared than one who knows what the private account does and does not do.