Up next on the roadmap - Wagtail Review
Published December 5, 2025
This video features Baptiste Mispelon and Ola Sendecka at DjangoCon US 2016 in Philadelphia, Pennsylvania, USA.
Stress Testing Your Code of Conduct in Production by Ola Sendecka & Baptiste Mispelon
The Django and Python communities have made codes of conducts a standard feature for many years now. But what exactly is a code of conduct? How does it work in practice? Why do we need them? What you should report? What are the consequences of having one?
We (Ola & Baptiste) have been working as CoC points of contacts at many conferences for the past few years: EuroPython 2014, DjangoCon Europe (2015 and 2016), and Django Under the Hood (2014, 2015). This has given us a unique insight into the inner workings and practical implications of codes of conducts and we want to share it with the Django community.
The talk will start with a brief history of codes of conducts. From then, we'll go over some of the challenges and pitfalls of implementing a CoC in our communities or events. After that, we'll show how CoC work in practice and answer some common questions about them. We will then briefly talk about how lessons learnt from CoC world can be applied successfully in your daily job to grow supportive and strong teams. Finally, we'll finish off by showing the new standardized CoC processes that we've been working on.
With this talk, we want to continue the process we've started of bringing CoC to the front of the stage, making them more transparent and less taboo. We believe that CoC are an essential part of any community and we'd like to share our vision for how we think ours should work.
A code of conduct is necessary wherever people interact, but publishing one is only the beginning: organizers must define explicit rules and boundaries for every physical and online space, provide accessible reporting channels, staff a dedicated response team, and prepare for safety issues. Drawing on mistakes from Django and Python events, the speakers explain how to receive a report, gather facts, respond as a team, speak privately with those involved, document the incident, follow up, and publish anonymized transparency reports. They argue that failures are inevitable, so communities should document and learn from them, and treat the code of conduct as one part of a broader effort to make events inclusive and welcoming.
Summarised automatically from the transcript.
Automatically transcribed, so expect mistakes in names and technical terms.
Speaker 1: Come on, no.
Speaker 2: Hello everyone, uh it's a really really great pleasure and an immense honor to be standing here today We both know it's been a very, very long day. It's very hot outside. It's very cold inside. There's been lots of amazing talks today, a lot to take in, so we're really, really glad that you decided to come to ours. So today we're going to be talking about code. About code of conduct. So the code of conduct, or we're probably gonna refer it. to it as COC from now on. It can be a quite a sensitive topic and personally I didn't feel like I could present this just just on my own. But luckily today I'm not alone on stage. I'm accompanied here by my good friend Ola. So Hola, she's a long long time member of the Django
Speaker 2: community. As was said before, she lives in London where she works for a company called Potato. But she's originally from Poland. You probably know her the most for co-founding the Django Girls Initiative, but she has many, many other talents. She's organized several DjangoCon, including one that was held in a circus tent in Poland. And she also has her own YouTube channel where she teaches programming to women.
Speaker 3: And I couldn't be do you hear me? Yeah. Okay, cool. And I couldn't be more grateful to have uh Batis of my co-present. He lives in Hungary, but he's originally from France and while working with him with various community projects I discovered that he has this gift that always put other people before himself. himself and it it is visible in everything he does in his contribution as a Django core developer uh in his uh skills and what he does as a conference organizers and also in his working with Django girls. And Batista is also the person you want to find if you want to translate something from English to English. emoji. And together we've been uh working as COC points of contacts at five major Python and Django conferences
Speaker 3: Over the last three years. And even though we don't consider ourselves experts, we hope that in our talk we'll answer at least some of the questions we might have regarding code of conduct. And at this point I want to stress out that even though things we will talk about in this talk are based on our conference and events experiences you can take the lessons we learn and apply them to your workplace or open source project or literally any you know any place where people meet and interact And this is because code of conduct and culture go together side by side and one is reflected in another.
Speaker 2: So I want to start by just explaining what we won't be talking about. So we're not here to discuss whether you're community, company, or project requires a code of conduct or not. There are many resources online, we don't really have the time for it. I think it's best summed up by this tweet from Lena Reinhardt. Let's let you read for a while. Basically, to sum it up, the moment you have humans interacting, you want to have a code of conduct. There's just no way around it. Also, we believe that the GIM community as a whole has kind of moved past this point where we're just arguing about whether we need one and we just accept as a fact that we our community actually needs one. So instead today, we'd rather focus on how you actually implement a good code of conduct in production, so to speak.
Speaker 2: We'd like to explain what it means in practice to have a code of conduct with some concrete examples that we've had over the years and some tips that we've learned along the way. But before we do that, we wanted to start with a bit of history of code of conduct inside our communities.
Speaker 3: And it's very hard to determine when first movements to implement code of conduct in tech industry started. And there is a lot of people who worked really hard to make code of conduct a standard and we are incredibly grateful for their work. And there are too many people to name them here, so we just want to say big thank you to all amazing people who Dedicated their time and effort to make code of conduct a thing. And really our community really stands on the shoulders of the giants. But going back to Django and Python community, we did some research and established that 2012 was a year when code of conduct started to be important topic. And Python US implemented one in March 2012, followed by DjangoCon
Speaker 3: Europe in Zurich in May And at the end of the year, on 21st of November, Python Software Foundation enforced conference organizers to have code of conduct At any event they want to sponsor.
Speaker 2: And similarly, on January 9th of the following year, the Django Software Foundation did exactly the same, and the board voted that they would only fund events that had a code of conduct. And later on, a few months later in April, the Python community adopted a code of conduct as a whole for the community for all its online spaces. And they were followed very soon after in July by the Django community who did exactly the same.
Speaker 3: And the important thing here is to realize that Django community started discussion about code of render quite early. At least this is what I feel And we improved immensely and code of conduct is present and visible not only at Django and Python conferences but also in online spaces where our community interacts. And we don't discuss uh if and why we need it, we discuss how to improve it. And the Django Code of Conduct was even showcased as a good example example of the community code of conduct by ADA initiative. And I think we should be really proud of Django community to for being really forward thinking and And striving to be nice and welcoming for place
Speaker 3: for everyone.
Speaker 2: But even though we find that uh COCs are kind of a standard uh in our communities, in practice it's not always so easy. You can just Put a piece of text on your website for your conference or your community and just be done with it. It's only when you deploy it to production that you start to interact with real users that you actually start to see edge cases and things that you hadn't thought about.
Speaker 3: And during last years when we served as members of various code of conduct response teams, we learned our share. And the response team is responsible for enforcing code of conduct. They receive the reports and are in charge of handling that. And believe me, we were far from being perfect. And we have a whole list of things that we wish we did better.
Speaker 2: And because we think that you can learn from our mistakes, we're just going to give you a few examples of the things that we wish we had known in advance. So for example, there was a conference where we had a Slack channel similar to what we have this year. Attendees could talk with each other and arrange dinners and stuff like that. And for us it was a big experiment. We didn't really think about it too much, didn't think about the consequences. And with hindsight, I think, even though it worked really, really well, we did a few mistakes. Like for example, one of them is that we never clarified from the start whether this was going to be like a one-time thing just for the duration of the conference or whether it was going to live forever after and if it was going to be moderated forever. We just created it and then we kind of let it on its own after the conference was over. Another problem we made was that we never set up explicit rules from the start. We just assumed people would behave and it would be fine.
Speaker 2: So we didn't say whether you could send private messages to people without being prompted, whether you could advertise, send job postings, like none of these things. And actually this ended up creating problems because two of the members, they understood these implicit rules differently, as it always happens. And this was a problem. And here you see that when we create a space for people to interact, whether it's a space in a physical world like here today or whether it's a space online where people go and talk to each other. You need always to set explicit rules and not rely on just an implicit understanding. And you also need to think clearly and in advance about the boundaries of this space you're creating. And I mean boundaries in terms of space, like where does the conference end and
Speaker 2: when does it start, but also in terms of time as in this online space is going to be available forever or just for a short time.
Speaker 3: At another event, there was another example of something we haven't thought through well enough. We decided to make code of conduct very visible. We put a lot of effort to create welcoming and safe space. We had like dedicated uh phone numbers uh for code of conduct we had posters reminding about code of conduct even like like lifts or elevators whatever is the right word in US, I don't know. We had posters reminding about code of conduct and uh yeah uh we emailed uh in every email to attack We reminded about that. And even though we put so much effort, we forgot something super crucial. And the thing was that we had no dedicated code of conduct email.
Speaker 3: So whenever you want to use an email you have to write to all organizers. So you either phoned one of the emergency numbers, which is not perfect if you are like me and you hate phoning uh strange uh people especially in foreign language um or you tried to find some people from response team and uh the people were all over the place
Speaker 2: Another mistake we made at the same conference had to do with social media. We were using Twitter and we had an official conference hashtag, which again was great because people could just go to one place and see everything that was happening. But but we weren't really monitoring it closely and we were also very quick to just re-broadcast like retweet and light things that we just saw without looking too much into them And again, social media is yet another space that you're creating that you need to have explicit rules for, but also you want to be able to monitor it. Like you want to have Someone who has the ability technically and time-wise to monitor and react when things happen on social media space.
Speaker 3: At another conference, uh we totally underestimated how much effort It is to handle code of conduct issues. And we had a small team, just two of us, and we also had other responsibilities. And we ended up just like dropping whatever we were doing for the conference because we had to deal with with code of conduct. And it is so much easier to have a bigger team and dedicated only to code of conduct and also it makes sure that you will not burning out on the way.
Speaker 2: Another thing we did wrong was that we had a conference party, so it was an after-hours event and we never really clarify whether this was an official party. That means whether the code of conduct applied to this. And this resulted in the fact that some people attended the party and they, let's say, they lost their sense of responsibility because they didn't really think that the code of conduct applied there. And we see this pattern yet again, like you have this space and it needs to have explicit rules because you can't rely on implicit rules and you need to know what is acceptable, what is not, what is the conference and what is not, and what are the rules for each space because each space may have may have slightly different rules.
Speaker 3: Uh we at one of the conferences we also had unwritten no comments only question uh policy, but we didn't communicate that clearly and that created very awkward moments um after some talks uh for speakers because uh our memcy interrupted uh some of the people making the comments. Um and when we realized that we made the policy more clear and announced that on stage, but we wish we were more clear at the very beginning. about that.
Speaker 2: And one last example of things that we wish we had done better was that there was a conference where we didn't have a dedicated just physical room to handle um code of conduct issues we had the organizers room which is great but then organizers who were not on the response team just kept popping in and out and interrupting and you don't want that that COC issues can be tricky, can be sensitive. You don't want to do them in a crowded hallway where people are passing by, but you also want to limit it to only the response team. You want to make sure that you have it doesn't have to be big, but a room, a space somewhere that can be closed and where you can handle code of connect issues
Speaker 3: As you can see, we are indeed far from being perfect. And all these things we just talked about happen even though we're like super dedicated to make it Right and we put a lot of effort to uh create a welcoming space. And dealing with code of conduct uh issues is hard and you will never have it 100% right and it's a living evolving process. And there will be always something that is unexpected that you are not prepared to So
Speaker 2: one of the most critical things you can do is just plan for failure because you will probably mess up and bad things will happen and some of them they just won't really be a big deal but some of them they might be. So you need to know how to handle failure like this. So one of the things you need to do is make sure you have a way to receive feedback, listen on it and act on it, and make sure you know how to apologize simply. You need to make sure you have a process for you when you make a mistake, you want to document this failure of organizer and analyze them later so that you can understand what went wrong and then correct so that you can improve. And also you want to be very public about this, I think, because holding up to your mistakes in public, it can be, trust me, a very humbling experience.
Speaker 2: But it sends a really really powerful message and a really positive message throughout your community that you really do care and these things do matter.
Speaker 3: And in a way some of code of conduct issues are not a big deal. If you made a mis uh if you made some joke that not native speaker could understand and made them feel awkward, for example. Well it's just a joke. It's not a big deal right uh you meant well it's just a mistake and in a way it's not a big deal from the offender point of view And when someone reports you, um except some really serious offenses. Code of conduct is not aimed to like make you feel unwelcome and you don't need to acquit and never speak to anyone in the community You are still a valuable member of the community. But at the same time, it is a big deal because the tiny little comment you just did might be a thousand
Speaker 3: one person just hurt and they might just quit after that. And there is a term for that, death by thousand cuts. So what matters from code of conduct response team point of view is objective outcome of your action. If your action excludes someone from our community, we will act and give you necessary feedback. So you will know better next time and you have a chance to improve. And we we believe that by handling the small things very seriously, we hope to build the trust so more people will fail off. Okay, uh to share their concerns and speak up if they need that.
Speaker 2: But what happens when someone speaks up? Concretely, what happens when someone files a code of conduct report? I think it's one of the things that can often seem very mysterious. It's scary. Sometimes even it feels taboo. And we wanted to kind of open this up and clarify what actually happens. And so we made up this kind of completely random example and simplify example to show you the process that we go through when we get a report. So say we're at a conference like this one and we get a report by email saying that Here's a tweet, someone's making fun from of a speaker who's on stage and they're using the conference hashtag. So how do we respond?
Speaker 3: So first thing To do is to let the reporter know that we received the report and we will take care of that. And this is important because it means that we take responsibility of the situation and we will take care of handling that and as an organizer you probably want to um do that on your own handle the the issue because uh otherwise people might try to find the the justice or or like do the public shaming and it might be very, very serious. And it is also crucial to let the reporter know that you you are uh uh dealing with this, um, to have a paper trail of what happened.
Speaker 2: Next up, we gather the response team so that we can talk about the incident. We can coordinate a response, assign tasks to everyone. And one of the benefits here of having a team is that for one, it's much, much easier to make hard decisions as a group as opposed to as an individual, which you might have to do. And the practical consequence of having a team is that you need to have a communication channel with this team and it needs to be private so that nobody else has access to it and it needs to be real time so that you can act quickly. So for example, we've used many times a private Slack channel and it just it works really well for that.
Speaker 3: At this point we take screenshots and try to gather as much information about the um incidents as possible. So we quickly determine that in uh the person making the tweet is in fact an attendee, they posted the photo of their batch uh earlier um and we can cross uh check it with the list of attendees. And gathering facts early means that you don't need to rely on your memory later and you can concentrate on other things.
Speaker 2: So we met with the response team and at the end of the meeting we've altogether decided about our next action. So in our case we'll be speaking with a person and asking them to delete the tweet. It's good here to have an idea before you go in the meeting with a person of how you're going to resolve the situation so that you can minimize the damage before.
Speaker 3: We find the offender during next break and ask them discreetly to join two of us in a private room. We found that two is an ideal number. You need more than one person. in but more than two is just too intimidating.
Speaker 2: So we're meeting with the person and the first thing we do is that we explain them that we had a report and what was reported. And then we ask them for their own point of view. It's very important to give both sides a chance to explain their point of view. You have to be neutral in the sense of letting everyone explain their point of view. It's also important to explain how and why what happened is a violation of the code of conduct. It's part of letting the person improve. So in our case, we explain them what happened and we inform them that it's a violation of the code of conduct and we ask them that they delete their tweet.
Speaker 3: We gather the team again to inform them of the outcome of the talk and we check that the tweet was indeed deleted. And it's important to make final decisions as a team and keep everyone in a loop. So
Speaker 2: one person on the response team immediately starts writing an incident report. That's a document where they establish a timeline of what happened, as detailed as possible. At least the facts, what we know exactly what happened, and also it's the people involved in the story. Writing the report immediately here is really really key because the more time will pass, you always think you'll have time later, but you probably won't. And also you'll tend to forget things, maybe you won't be able to take screenshots later on. So it's very key that you act on this immediately.
Speaker 3: Finally, we sent an email to the reporter explaining the actions we've taken and thanking them for reporting. Again, this establishes the paper. trail and let the reporter know that we actually took the action and builds trust. We also send an email to the offender repeating outcome of the talk and we let them know that the case is closed.
Speaker 2: So the clay the case is closed from the offender's point of view, but for us as organizers, as a response team, there's still a couple of things we need to do. One of them is that we forward the incident report to the Code of Conduct, the General Code of Conduct Committee And we also later after the conference publish a transparency report where we list all the events that happened during the conference and how we resolved them. But this list is completely anonymized The first step of forwarding the incident report to the Django Code of Conduct Committee is a way to have a kind of long-term memory of events, of what happens. It helps build , track repeated offense that may happen over several years, over several conferences. And the second step of having a transparency report is something that we do to demystify the code of connect process, to show exactly what happens
Speaker 2: so that people know things actually happen, but also show how we respond to them and see that sometimes it probably not a big deal and this really helps again build some trust with the community. At this point for us as well, we consider the case closed and we move on to the next event.
Speaker 3: And as you can see it's like So many steps for a very small thing. And the thing is, in real life, things can be more complex than that. The example here was very straightforward. The author identity was known and the person was cooperative. The damage was minimized by demitting the tweet. But things could go much more complicated very, very easily, and response team needs to make a call on the spot and sometimes judge what are the best actions to take. And when dealing with code of conduct issues, you have to be prepared to improvise.
Speaker 2: But every time you improvise there's always something that needs to be at your top priority is your attendees' safety. You have to know things in advance like maybe emergency numbers for your local area or make sure that there is security staff at your venue that can expel people if you need if you need to. Most likely you won't need that. But being prepared in advance just makes it so that when something happens that you didn't plan, which will happen, then it just really lowers the stress and lowers the amount of energy you need to spend to just respond to this. So we've seen with this process how you can implement the code of conduct in practice. But I want to stress that it's important To keep in mind that the code of conduct it's not there for its own sake. It's not a a tool of
Speaker 2: punishment or enforcing some vague values that we have. For us as organizers and as community members A code of conduct is one more tool in our tool belt that lets us create more inclusive events and more welcoming events. But it's not the only tool. You have many tools like making sure your venue is accessible, having free childcare for speakers, attendees, having gender neutral restrooms or food that caters to everyone's diets, you have like many, many other tools.
Speaker 3: So we've seen the code of conduct is now a standard thing in our community and we've shown you the examples that it is hard to get it right. And we realize that the hardest and most stressful thing for us is in the whole process is when we need to improvise and we don't know what's the next step. And this is why we started to document our process into a step-by-step manual that takes out a lot of improvisation and guesswork. It also takes uh takes some of the emotional factor out of the And we are proud to announce that we are releasing our nodes and our process online. So the whole Django community and not only Django community can use and and improve them.
Speaker 3: And it is joint work with Ola Sitalska who is sitting there. And you should go and follow her if you don't do that Yes.
Speaker 2: So this handbook it's a collection of practical steps that you can take to improve your code of conduct process It shows a process a bit like we did before but much much more in depth. It talks about some of the do's and don'ts and it also has some things like templates for emails and reports that you can just reuse and fill as you need The repository is very new. It's still quite work in progress, but we think it's already good enough for public consumption. We're also really, really interested in getting feedback on it. and hear the ideas of the community and take pull requests for anyone who wants to improve. And if you'll get the sprints, we'll also be there as well. And so if you're interested you can come talk to us.
Speaker 3: Okay Okay, I see we are kind of over time, so let's let's recap. We've shown you a bit of a history of Django Community Implemented Code of Code. that one and we also show you the mistakes we've made when we serve as um in various response teams and how hard it's to remember about everything and uh if you don't have step by step install instructions.
Speaker 2: Then we showed you what happens practically when you receive a report and what steps we take to resolve it. So this is our formal process that we're trying to Stick to and document so that it could be reused by other communities out there.
Speaker 3: And we do all work in in the open because we believe that code of conduct is not only a problem of a response team It's also not a problem of conference organizers, and it's not only a problem of DSF or PSF. And it's a problem of community as a whole And building safe and welcoming environment is extremely hard task. And even though we don't know yet how to do it right, we constantly try to push the limits and set higher and better standards every single year. And we want to believe that Django community will never stop pursuing being an inclusive and awesome community. We are so proud to be Part of. Thank you.
Set explicit rules instead of relying on assumptions, and define both the space’s scope and its duration—for example, whether a Slack channel continues after the conference and who moderates it.
Discussed at 7:55Create ways to receive and act on feedback, apologize clearly, document and analyze failures, and be open about mistakes so the community can see that they are taken seriously.
Discussed at 13:20The response team acknowledges the report, gathers facts, coordinates privately, speaks with the people involved, agrees on and carries out an appropriate response, documents the incident, and informs both the reporter and the subject. Afterwards, the incident is forwarded to the relevant committee and included anonymously in a transparency report.
Discussed at 16:19Two response-team members is presented as the ideal number: more than one provides support and accountability, while more than two can feel intimidating.
Discussed at 18:22Plan for improvisation while keeping attendee safety as the top priority. Know local emergency numbers, coordinate with venue security, and prepare resources in advance to reduce stress when an unplanned situation occurs.
Discussed at 21:55The handbook provides a detailed response process, guidance on what to do and avoid, and reusable templates for emails and incident reports. It is published openly so communities can use it, give feedback, and improve it.
Discussed at 24:06Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 14, 2026