← All posts
Liferay DXPKaleo WorkflowGeminiAIContent Moderation

A Human-in-the-Loop Content Moderation Agent Built on Liferay Workflow and Gemini

By LR Tools · August 23, 2026 · 3 min read

This is LR Tools’ rewrite of a post by Ankit Srivastava on Liferay.dev describing a proof-of-concept for smarter, faster content moderation built on tools already inside Liferay.

Intelligent content moderation with Liferay and Gemini AI

The human bottleneck

Any active online community faces the same tension: you want free-flowing discussion, but you also need to keep spam, toxicity, and bad-faith posts out. The traditional fix — a human moderator reading every comment before it goes live — doesn’t scale. It’s slow, expensive, and genuinely exhausting for whoever’s doing it.

A smart gatekeeper, not a replacement

The approach here pairs two things Liferay already has: the Kaleo Workflow engine, and Google’s Gemini 2.5 Flash as the reasoning layer. The explicit design goal is augmentation, not automation for its own sake — the AI shouldn’t be making moderation decisions instead of a human, it should make the human’s job faster. The target behavior for the agent breaks down into three things: read what a comment is actually trying to say, flag anything suspicious with a concrete reason attached, and — critically — tell the difference between a frustrated user and a genuinely toxic one.

The stack

Three pieces do the work: a Liferay workflow definition in XML lays out the state machine a submitted comment moves through on its way to “Approved”; Groovy scripting sits in the workflow as the integration layer that reaches out to external services; and the Gemini API does the actual sentiment and intent analysis.

The Liferay Kaleo Workflow definition routing comments through AI-assisted review before approval

The test that actually mattered: sarcasm

Testing against obvious spam is easy — the interesting test is sarcasm. The example used: a comment reading something like “Oh, perfect. I love it when the button deletes my data. Truly a 10/10 experience.” A naive keyword filter keys off “love” and “10/10” and waves it straight through. Gemini instead read the irony correctly, recognized the underlying complaint about a data-destroying bug, and flagged the comment for human review instead of auto-approving it — exactly the distinction a keyword-based filter can’t make.

What changes for the moderator

Instead of opening a bare, context-free submission, moderators now see an AI-authored annotation attached to flagged items — something like “AI Flagged: Potential hostile sarcasm directed at the author.” The system keeps the speed of automated triage, while the actual judgment call — the part that needs empathy and context — still rests with a person. That’s the human-in-the-loop model the whole design is built around.

Where this goes next

The current build is explicitly a proof of concept, relying on Liferay Workflow Scripting (Groovy) to bridge comments and the Gemini API. Two changes are already planned: routing the LLM configuration through Liferay AI Hub instead of hand-rolling REST calls and managing API keys inside Groovy scripts, for cleaner and more secure management of AI usage across the portal; and moving the moderation logic out of in-JVM scripting entirely into a Client Extension — a separate microservice, in whatever language fits, that should be more resilient, easier to unit test, and easier to upgrade than logic embedded in a workflow script.

The intent behind both changes is the same: keep the workflow low-code for whoever’s designing it, while making the system underneath it high-performance from an administrator’s point of view.

This article is LR Tools’ rewrite of the original post by Ankit Srivastava — read it on Liferay.dev for the author’s own framing.

This article is adapted from: Ankit Srivastava, Liferay.dev

More from the blog

Liferay DXPPostgreSQLDatabase Migration

Migrating Liferay to PostgreSQL: A More Reliable Alternative to Liferay's Beta Tool

August 23, 2026 · 3 min read

Liferay's own database migration tool is still Beta and unreliable in practice. Here's a third-party alternative, the exact 8-step migration procedure, and links to the tool and its docs.

Liferay DXPSecurityCVE

When a CVE Isn't a Liferay Vulnerability: Presence vs. Reachability

August 23, 2026 · 7 min read

A security scanner finding a CVE in a bundled library isn't proof that Liferay DXP is exploitable through it. Here's how Liferay's security team tells the difference — and why an unnecessary dependency upgrade isn't automatically the safer choice.

Liferay DXPFree TierLicensing

DXP Free Tier Licenses: Why the Product Version Doesn't Have to Match Your Runtime

August 23, 2026 · 3 min read

A DXP Free Tier activation key stamped with a quarterly release that hadn't shipped yet looked like a bug. It wasn't — here's what the product-version field in a Liferay license actually means, and why it isn't a strict compatibility gate.