A risk flag is a structured indicator in a tool-specific verification response that identifies a discrepancy, anomaly, or data point requiring attention. Risk flags from supported workflows are surfaced from source checks. Risk flags in the separate Evidence Pack export are fixture-derived samples and are not source findings.
What triggers a risk flag
Risk flags are raised when source data contains something that does not match an expected pattern, contradicts another source, or falls outside normal parameters. Examples include:
- An ABN that is registered but the GST registration has lapsed
- A trading name on an invoice that does not match the ABN holder on the ABR
- A supported professional-register record whose status needs human review
- A supported source that is unavailable or returns an incomplete response
What a risk flag contains
- Flag type: the category of discrepancy (for example, encumbrance, identity mismatch, status change)
- Severity: an indication of how significant the flag is, from informational to critical
- Source: which source check raised the flag
- Description: a plain-language explanation of what was found
- Timestamp: when the underlying source check ran
Why agents need this
Agents need structured risk indicators to decide what to do next. An agent that receives an unstructured narrative description of a source result has to parse it to extract actionable information. A structured risk flag tells the agent exactly what was found, how significant it is, and which source it came from, so the agent can route appropriately: continue, escalate to a human reviewer, or block the workflow.
Risk flags also give agents a way to explain their decisions. An agent escalating a transaction to a human reviewer can reference specific risk flags rather than summarising a narrative. Cited, not inferred.
How Hoist uses this
Risk flags appear in the documented field of a tool-specific verification response, such as risk_flags in an Evidence Card. Flags are structured so agents can filter, sort, and route on them without parsing free text. The separate Evidence Pack export includes fixture-derived sample flags for workflow testing. Available source-backed workflows generate flags only from checks that actually ran or explicit unavailability. Hoist PPSR preview and paid search are currently unavailable, so PPSR-shaped sample flags are fixture data, not a live result.
What Hoist does not infer
A risk flag is not a verdict. It does not mean a transaction is unsafe, fraudulent, or should be declined. An ABN with a lapsed GST registration may be operating a GST-exempt activity. Hoist surfaces the flag; the agent, the operator, and the human reviewer determine what it means for a given transaction. For flags that cannot be resolved from source data alone, the verification response may include a human review item.
Related terms
- Evidence Pack: the current owner-bound prelaunch sample export; its risk flags are fixture-derived workflow examples.
- Source check: the individual verification step that generates a source-backed risk flag.
- Human review item: an action required when a risk flag cannot be resolved from source data alone.
- PPSR: future Hoist contract whose preview and paid-search calls are currently unavailable; any current PPSR-shaped flag is sample/fixture data.
- NPII: AFSA's National Personal Insolvency Index, a separate person-insolvency register that is not currently enabled as a Hoist source.
- ABN: business identifier whose status can generate risk flags on mismatch or lapse.
- AFSA: the authority that would issue a certificate for a direct AFSA PPSR search.
