Eight per-message grooming tactics, including reconnaissance, explained through a 100-turn predatory conversation.

If you've spent any time around online safety teams, you've heard "grooming detection" discussed as if it were a category, the same way "spam detection" is a category. A model returns 1 or 0, the platform takes action, life goes on.

That framing has been the limiting assumption of a generation of safety tools. And it's wrong in a way that matters: grooming is not a moment, it's a process. A predator targeting a 13-year-old doesn't send a single message you can flag. They send a hundred. Each one, in isolation, might look innocuous, sometimes deliberately so. The harm lives in the trajectory.

We've spent the last year working on this problem at Tuteliq. A few months ago our detect_grooming engine surfaced a tactic we hadn't explicitly trained against: meeting_request. It emerged from looking at real conversation patterns where the existing five tactics (flattery, secrecy_request, isolation, boundary_pushing, photo_request) would build up over twenty or thirty turns and then resolve into a sixth: can I come visit you?

Running a 100-turn red-team transcript through the same engine also surfaced gift_giving. It showed up around turn 35, framed as "i could send you that game skin you wanted, no big deal." The engine flagged it cleanly, scored it as part of the rising trajectory, and folded it into the final verdict alongside the other tactics.

The per-message taxonomy now has eight tactics. Reconnaissance is detected on the individual message carrying a probe about who supervises the child or when they are unobserved, including probes phrased as statements rather than questions. The distinction matters because the API's flags array can also contain values that are not tactics. sexual_content is a content category, while sexualization, grooming, and sextortion can arrive from coded-term matching.

The conversation, turn by turn

Here is what a 100-turn predatory conversation actually looks like when you score every message individually. The example is composite, assembled from patterns across many real cases, with details abstracted for safety. The scores are real outputs from our detection engine on this composite.

  • 🎨: Turn 1 · score 0.10: "i saw your dragon art post, that's seriously cool work." A compliment about art. Nothing to flag.
  • 💬: Turns 2–6 · 0.05–0.20: Small talk about interests, age, hobbies. Still nothing actionable.
  • ⭐: Turn 7 · 0.20 · flattery: "you draw better than most adults i know honestly." The engine starts tracking.
  • ✨: Turn 9 · 0.30 · flattery: "you seem really thoughtful for your age." The trajectory is rising.
  • 🔍: Turn 15 · 0.40 · reconnaissance: "do your parents check what you do online?" The model detects the message as probing who supervises the child and when they may be unobserved.
  • 🤫: Turn 17 · 0.50 · secrecy_request: "maybe just don't mention me to them." The trajectory crosses into actionable territory.
  • 📱: Turn 21 · 0.70 · isolation: "let's move to snapchat where messages disappear." Textbook platform-switching.
  • 📸: Turn 25 · 0.85 · photo_request: "you're really cute btw, can you send me a pic?" Now critical.
  • 🎁: Turn 35 · 0.88 · gift_giving: "i could buy you that game skin you wanted, my treat." Distinct legal and safety signal.
  • 🚪: Turn 48 · 0.91 · meeting_request: "i could come visit you sometime."
  • 🚨: Turn 100 · 0.99 · critical: Multiple message-level tactics combine across the conversation. The engine recommends immediate intervention.

The whole 100-turn transcript runs through the API in a single call (the documented per-call ceiling), and unlimited length is supported via continuation_token chunking.

The thing to notice is that none of the first ten messages would have been actionable in isolation. A keyword filter looking for "send pic" or "our secret" would have caught nothing. A single-message classifier would have spent the first half of the conversation returning 0.05s, 0.10s, 0.20s, well below any reasonable threshold, then suddenly returned 0.90 once the photo request landed. By that point, the child has been groomed for thirty turns.

The diagnostic information is in the pattern, not the moment. Eight per-message tactics build on each other in a recognisable order, while conversation analysis shows how they accumulate over time.

Grooming tactics

Tuteliq's grooming taxonomy has eight per-message tactics: Flattery, Secrecy request, Isolation, Boundary pushing, Photo request, Gift giving, Meeting request, and Reconnaissance.

1 | teal | Flattery | Signature
The opener. *"You're so mature for your age."* *"You draw better than adults."* The point isn't the compliment, it's establishing the predator as the only person who *truly sees* the child as special. This sets up every subsequent tactic by creating a relational bond that makes the child reluctant to break confidence.
===
Superlative language about the child's attributes (intelligence, maturity, talent, appearance) directed at someone the predator has just met or barely knows.
2 | blue | Secrecy_request | Signature
Once flattery has built rapport, secrecy keeps it from being interrupted. *"Don't tell your parents we talk."* *"It's our little secret."* This is the marker most people associate with grooming, but it's not the first one, and treating it as the trigger misses the build-up that made it possible.
===
Explicit or implicit requests to conceal the relationship from guardians, framed as protective ("they'd worry") or relational ("our thing").
3 | violet | Isolation | Signature
Secrecy keeps the relationship hidden. Isolation makes the predator the child's primary confidant. *"I get you in a way your friends don't."* *"Let's move to a platform where it's just us."* The platform-switching move is the most concrete isolation tactic.
===
Framing the predator as the unique confidant, plus proposals to move the conversation to unmonitored channels.
4 | amber | Boundary_pushing | Signature
Once the relationship is hidden and exclusive, the predator tests how far they can push. *"You're not a kid anymore."* *"It would be weird to other people but not to us."* Each push tests how much the child will accept before flagging concern.
===
Language that normalises asymmetries (age, role, type of conversation) the child would otherwise notice.
5 | red | Photo_request | Signature
The first concrete escalation toward physical content. Usually preceded by softening: *"just a normal one,"* *"nothing weird."* This is where the patterns become legible to single-message classifiers, but by this point the conversation has been groomed for many turns.
===
Explicit or implicit requests for images of the child, frequently with normalisation language.
6 | amber | Gift_giving | Signature
The newest tactic our engine surfaced. Predators offer something the child wants and can't easily get: a game skin, in-app currency, a gift card. *"I could buy you that skin."* *"My treat, no big deal."* It creates obligation and creates evidence the child can't show their parents, reinforcing the secrecy the predator already established.

In our 100-turn test, gift_giving appeared at turn 35, well after secrecy and isolation were locked in. That ordering matches what NGO partners describe: gifts work because the relationship is already exclusive enough that the child accepts them privately.
===
Offers of money, in-app items, merchandise, or experiences from an adult to a minor, small enough to feel normalised but specific enough to require identifying information (handle, account, address).
7 | red | Meeting_request | Signature
The endpoint of online grooming. *"I could come visit you sometime."* *"We should hang out."* This is the tactic our engine surfaced last year because we hadn't explicitly trained for it, but it kept appearing as the last move before either actual meeting or the predator going dark when the child resists.
===
Proposals to meet in person, often framed casually after a long arc of online intimacy.
8 | blue | Reconnaissance | Signature
Probing who supervises the child and when they are unobserved: oversight of their device or person, and the windows when they are alone. Detected on the individual message that carries the probe, in every supported language, including probes phrased as statements rather than questions.
===
Language that probes who is watching the child, and when nobody is.

The flags array in an API response can also contain values that are not tactics. sexual_content is a content category, and sexualization, grooming, and sextortion arrive from coded-term matching.

What this means for platforms

  • 🧩: Single-message classification is not enough: If detection runs per message and stops there, you'll miss the trajectory and intervene only at the late tactics, after most of the harm is done. Detection needs to be conversation-level, with state carrying across messages.
  • 🧭: The signal is the tactic sequence, not the score: The most useful thing for a safety team is the tactic ramp: flattery at turn 7, secrecy at 17, isolation at 21, photo at 25, gift at 35, meeting at 48. That's evidence. A single 0.99 is not.
  • 🎯: Intervention must match the tactic that fired: Flattery-only needs gentle monitoring. Secrecy needs context. A gift from an unverified adult is a legal signal worth surfacing. A photo_request needs immediate action. A meeting_request needs law enforcement notification and evidence preservation.

What we've learned about how to talk about this

A version of this post existed three months ago and we threw it out. It said "we detect grooming with 92% precision." That's a metric. It's not a story.

The thing that actually moves child-safety policy conversations forward is showing the anatomy of a real predatory arc: the slow tactical build-up, the way each tactic enables the next, and the way reconnaissance probes reveal supervision and access windows. Once you've seen one trajectory ramp from 0.10 to 0.99 across 100 turns, you understand viscerally why "is this single message grooming?" is the wrong question.

Grooming is the build-up, not the moment. Treat it that way in your detection. Treat it that way in your intervention. Treat it that way in how you talk about the problem.

---

If you work at a platform with minors in the user base and want to look at our tactic-level detection in action, the detect_grooming API reference documents the eight per-message tactics with example evidence text. The Composable safety primitives page covers how to combine grooming detection with vulnerability_exploitation and other endpoints to route to the right intervention.

If you're an NGO or researcher working on online child safety and want to talk about tactic taxonomies and what we're seeing in detection logs, reach out at hello@tuteliq.ai.

Get Started Free · Read Documentation · View Pricing