Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

An LLM can help moderate reviews without treating negativity as misconduct—but the safeguard is in how much authority the system gives it. In Corneliu Croitoru’s account of the travel site Back From My Trip, negative hotel and destination reviews are allowed; the model can approve text or send it for review, while a human administrator confirms or reverses an AI rejection. That is the text policy Croitoru describes, not an independently audited result.

What “bad reviews” means in this system

Here, “bad reviews” means negative travel reports and criticism, not fabricated or abusive reviews. Croitoru says the moderation prompt includes: “Negative reviews are ALWAYS allowed. A harsh critique of a hotel/destination is legitimate content.” The distinction is between an unfavorable opinion and other concerns, such as unsafe material or text that tries to manipulate the moderation process.

The account appears in Croitoru’s September 13, 2026 DEV Community post. The design and behavior described below are his account of his own system, not a separate evaluation of the live service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How text moderation works

Croitoru describes records moving among four states: pending, approved, needs_review and rejected. Public readers can see only approved records; authors can see their own submissions and their status or reason. The post says database row-level security enforces the public-access restriction.

The model can approve or escalate

For text, the model may approve ordinary content or route questionable material to a person. If it labels a submission for rejection, an administrator still gets the chance to confirm or reverse that decision. Croitoru summarizes the intended limit this way: “The model can flag. It cannot silence.”

Uncertainty and failures go to review

The described system retries transient moderation errors three times through a job queue. If the final attempt fails—or the moderation budget is exhausted—the submission goes to needs_review, rather than being approved by default. That is a fail-to-review policy: it avoids publishing content the system could not assess, while leaving a human decision available.

Checks around edits and status changes

The implementation account describes a database trigger that queues a row identifier, a worker limited by the author to 10 jobs a minute, and a moderation function that reads the text stored in the database and refuses callers without the service role. When text is edited, its moderation status resets to pending. A separate trigger is intended to prevent users from setting their own approval status.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Croitoru also says submissions that address the moderator, claim to be system or administrator instructions, demand a particular verdict, or resemble a prompt should be flagged for human review. This is a stated policy for escalation, not proof that prompt manipulation is impossible.

Why photos have a harsher rule

Images do not receive the same human-review safeguard in the described design. Croitoru says certain vision-model rejections—such as nudity, visible personal documents or identifiable children—lead to immediate file deletion, with no review queue or appeal. His stated reason is that the storage bucket is public: hiding a database row would not, by itself, prevent direct access to the image.

This choice trades the risk of retaining sensitive material for the risk of deleting an image that was mistakenly classified. Croitoru acknowledges that false-positive risk. It is his design decision for this site, not a general rule for moderation systems.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the account establishes—and what it does not

The post explains a moderation policy and describes technical safeguards intended to implement it. It does not report precision or recall, false-positive or false-negative rates, test-set results, costs, or comparative outcomes. It also does not name the LLM or vision-model provider. The stated three retries and 10-jobs-a-minute worker limit are implementation details reported by Croitoru, not measured performance results or general recommendations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The useful design distinction is reversibility: text rejection retains a human decision point, while selected image rejections can result in immediate, irreversible deletion. Croitoru’s broader lesson is: “When an LLM mistake cannot be undone, like silencing someone, give the model the power to escalate, never the power to decide.” His text workflow follows that principle more closely than the image policy, whose rationale depends on the risk he assigns to publicly accessible files.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.