> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rescueconsole.com/llms.txt
> Use this file to discover all available pages before exploring further.

# File a flag

> Files a safety flag about a person or an animal. It is shared ACROSS organizations: once it is vetted, every other organization using RescueConsole can read it, including the narrative, the evidence references, the identifiers as they are kept, and your organization's name, contact email and contact phone.

A new flag is always **pending_review**, whatever you send. When its visibility is `network`, the people at every other organization who may review flags (**write** on Registry) are asked to: a notice on their bell and an email, saying the kind of flag, its severity and its subject type, never who it is about or what it says. They can open it to review it; no search returns it until two of them corroborate it and it becomes **active**. If you set `visibility` to `private`, no other organization is asked, or ever sees it.

The identifiers are what a search matches on, and they are kept masked. A microchip number, email address and phone number are kept only as a hash, so a search that already has one can match it, and the value itself is not stored. A date of birth is kept as its year plus a hash of the full date. An address is cut to its city, state or region, and country; the street lines and postal code are dropped. A name, an alias and an animal's description are kept as written and shown in full. An identifier that is not allowed for the subject type is refused, not ignored.

The API has no route to edit or withdraw a flag once it is filed. Needs **write** on Registry.



## OpenAPI

````yaml /api-reference/openapi.json post /api/registry/flags
openapi: 3.1.0
info:
  title: RescueConsole API
  version: '2026-09-19'
  description: >-
    Your own organization's records, from your own software. There is no
    sandbox: every request goes to your live organization.
servers:
  - url: https://{organization}.rescueconsole.com
    description: Your own organization's address, the one you sign in at.
    variables:
      organization:
        default: your-rescue
        description: >-
          The first part of the address you sign in at. A key only works at the
          address of the organization it was made in.
security:
  - apiKey: []
tags:
  - name: Animals
    description: The animals in your care, and the ones you have placed.
  - name: Animal notes
    description: Notes written on an animal's record.
  - name: Animal weights
    description: An animal's weight readings, one per weighing.
  - name: Animal medical records
    description: >-
      Vaccines, treatments, procedures, tests, exams and other medical records
      on one animal.
  - name: Animal placements
    description: The people an animal came from or has been placed with, over time.
  - name: Animal nutrition
    description: 'What an animal eats: its feeding list and its diet.'
  - name: Animal relationships
    description: Siblings, parents, offspring and bonded pairs.
  - name: Animal tags
    description: Your own short labels on an animal.
  - name: Breeds
    description: The breed or kind lists your intake form offers for each species.
  - name: Litters
    description: Litters, and the animals born into them.
  - name: Locations and housing
    description: >-
      The places animals are housed at each of your locations: campuses,
      buildings, rooms and cages, the tunnels that join cages into one space,
      and who is in each.
  - name: Foster homes
    description: >-
      The people who foster for you, what each home can take, and the animals
      offered to and placed with them.
  - name: Intakes
    description: >-
      How each animal arrived: the route in, who brought it, why it was given up
      and the state it came in.
  - name: Medical due
    description: >-
      Medical work that is outstanding across all your animals, and one medical
      record added to many animals at once.
  - name: Transports
    description: >-
      Transport runs: a chain of drives, each leg with its own driver, that
      moves animals from one place to another.
  - name: Animal calendar
    description: >-
      The dated things in animal care on one calendar: medical work due,
      adoptions, foster placements starting and ending, arrivals, and meet and
      greets.
  - name: Animal reports
    description: >-
      The operations report: intakes, outcomes, live release rate and the
      animals in your care, each figure with its own definition.
  - name: Adoption applications
    description: >-
      Applications to adopt or foster, from first draft to a decision, and the
      adoption contract signed on an approved one.
  - name: Adoptions
    description: >-
      Animals that went home, what each adopter owes and has paid, and closing
      or reversing the adoption.
  - name: Signed contracts
    description: >-
      Contracts signed on an adoption, a foster placement or an intake, each
      kept exactly as it read when it was signed.
  - name: Contract templates
    description: >-
      The contracts your organization has people sign, with the merge fields
      that fill them in.
  - name: Reconciliations
    description: >-
      A payment processor's settlement lines, matched against the adoption
      payments you recorded.
  - name: Animal custom fields
    description: >-
      The extra fields your organization adds to animals, housing units and
      adoption applications.
  - name: Age groups
    description: >-
      What counts as a baby, an adult or a senior, per species, which fee rules
      and discounts read.
  - name: Animal statuses
    description: >-
      Your organization's status vocabulary for animal records, and what kind of
      status each one is.
  - name: Application stages
    description: >-
      The steps an adoption or foster application moves through before it is
      decided, in your organization's words.
  - name: Behaviour attributes
    description: >-
      The catalogue of behavioural traits, and where a trait with each name may
      be shown beyond the record.
  - name: Cage card templates
    description: >-
      The layouts your organization prints for the kennel door: paper, fields,
      photo and QR code.
  - name: Adoption fee schedules
    description: >-
      The rules that suggest an animal's adoption fee, and the discounts laid
      over them.
  - name: Medical catalogue
    description: >-
      The diagnoses, tests, vaccines, treatments, procedures, conditions and
      medications your medical records pick from.
  - name: People
    description: >-
      The people your organization deals with: adopters, donors, volunteers,
      fosters and everybody else.
  - name: Person notes
    description: Notes written on a person's record.
  - name: Person contacts
    description: >-
      A person's phone numbers and email addresses, one of each kind marked
      primary.
  - name: Person addresses
    description: A person's addresses, one of them primary.
  - name: Person tags
    description: Free-text labels on a person, added and removed one at a time.
  - name: People duplicates
    description: People who look like the same person entered twice, and merging them.
  - name: People custom fields
    description: The fields a person's record carries beyond the standard ones.
  - name: Organizations
    description: >-
      The outside organizations your rescue deals with: veterinary practices,
      partner rescues, shelters, suppliers, employers and agencies.
  - name: Organization locations
    description: An organization's places, one of them the main one.
  - name: Affiliations
    description: >-
      Who works at, volunteers for or otherwise belongs to an organization, now
      or in the past.
  - name: Forms
    description: >-
      The forms your organization publishes, such as an adoption application or
      a volunteer sign-up, and the questions on them.
  - name: Submissions
    description: >-
      What people sent through your forms, and what your team does with each
      one.
  - name: Tasks
    description: >-
      To-dos, on a record or for the whole organization, narrowed to the records
      your key may read.
  - name: Calendar
    description: >-
      The dated work across your organization in one list, narrowed to the areas
      your key may read.
  - name: Activity
    description: >-
      What was created, changed and deleted in your organization, narrowed to
      the areas your key may read.
  - name: Shift schedules
    description: >-
      Schedules: the occasions shifts are grouped under, such as an adoption day
      or Saturday kennel cover.
  - name: Shift windows
    description: >-
      Shifts: a stretch of time at a place, with the volunteer roles it needs
      and how many of each (the address calls a shift a window).
  - name: Shift bookings
    description: >-
      Sign-ups: a person taking a role on a shift, giving it up, and the hours
      they worked.
  - name: Volunteers
    description: >-
      The people who volunteer: where each stands, what they have done, and
      where they would rather work.
  - name: Volunteer roles
    description: >-
      The jobs a volunteer can sign up for, such as Dog walker or Adoption
      counselor.
  - name: Volunteer qualifications
    description: 'Approvals: who may take which role, and at which location.'
  - name: Shift policies
    description: The rules you set for sign-ups and cancellations.
  - name: Shift calendar
    description: Schedules and shifts as calendar items for a date range.
  - name: Shift custom fields
    description: Your own fields on schedules, shifts and sign-ups.
  - name: Events
    description: >-
      The occasions your rescue hosts: adoption days, fundraisers, clinics and
      the rest.
  - name: Events calendar
    description: Your events between two days, as calendar entries.
  - name: Campaigns
    description: >-
      Appeals you raise money for, each with its goal and what it has raised so
      far.
  - name: Donations
    description: 'Gifts of money: how much, from whom, and what they were given to.'
  - name: Donors
    description: The people who have given, with what each has given in all.
  - name: Wish list
    description: The things your rescue needs, and the deliveries that met them.
  - name: Fundraising custom fields
    description: Your organization's own fields on donations and campaigns.
  - name: Message templates
    description: >-
      Saved wording your organization sends again and again, with merge fields
      filled from your records.
  - name: Sending
    description: >-
      Everything here sends real email from your organization, and none of it
      can be unsent.
  - name: Message log
    description: >-
      The email your organization has sent or tried to send, and what became of
      each message.
  - name: Conversations
    description: >-
      The email conversations in your organization's inboxes, and the records
      each one is about.
  - name: Inboxes
    description: >-
      The addresses your organization receives email at, and who may read each
      one.
  - name: Contact preferences
    description: >-
      Whether a person has asked not to be emailed, altogether or about one kind
      of message.
  - name: Suppressions
    description: >-
      Addresses no email goes to, because mail to them bounced or their owner
      asked not to be written to.
  - name: Sender and deliverability
    description: Who your organization's email goes out as, and how much of it arrives.
  - name: Registry flags
    description: >-
      Safety flags your organization files about a person or an animal, which
      other organizations using RescueConsole can see once the flag is vetted
      and shared.
  - name: Registry reviews
    description: >-
      Another organization's vote on a flag it did not file, which decides
      whether the flag becomes active or disputed.
  - name: Registry search
    description: >-
      The lookup by microchip number that anybody may make, with or without a
      key.
paths:
  /api/registry/flags:
    post:
      tags:
        - Registry flags
      summary: File a flag
      description: >-
        Files a safety flag about a person or an animal. It is shared ACROSS
        organizations: once it is vetted, every other organization using
        RescueConsole can read it, including the narrative, the evidence
        references, the identifiers as they are kept, and your organization's
        name, contact email and contact phone.


        A new flag is always **pending_review**, whatever you send. When its
        visibility is `network`, the people at every other organization who may
        review flags (**write** on Registry) are asked to: a notice on their
        bell and an email, saying the kind of flag, its severity and its subject
        type, never who it is about or what it says. They can open it to review
        it; no search returns it until two of them corroborate it and it becomes
        **active**. If you set `visibility` to `private`, no other organization
        is asked, or ever sees it.


        The identifiers are what a search matches on, and they are kept masked.
        A microchip number, email address and phone number are kept only as a
        hash, so a search that already has one can match it, and the value
        itself is not stored. A date of birth is kept as its year plus a hash of
        the full date. An address is cut to its city, state or region, and
        country; the street lines and postal code are dropped. A name, an alias
        and an animal's description are kept as written and shown in full. An
        identifier that is not allowed for the subject type is refused, not
        ignored.


        The API has no route to edit or withdraw a flag once it is filed. Needs
        **write** on Registry.
      operationId: createRegistryFlag
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RegistryFlagCreate'
            example:
              subject_type: person
              flag_type: falsified_application
              severity: moderate
              visibility: network
              narrative: >-
                Applied to adopt from Contoso twice in March 2026 under two
                different names. Both applications gave the same reference phone
                number, and the landlord named on the first said they had never
                rented to the applicant.
              identifiers:
                name:
                  first: Jordan
                  last: Ellis
                email: jordan.ellis@example.org
                phone: 207-555-0100
                phone_country: '1'
                address:
                  line1: 12 Elm Street
                  city: Portland
                  administrative_area: ME
                  postal_code: '04101'
                  country: US
                date_of_birth: '1987-03-04'
              evidence_refs:
                - Application 2026-0311, Contoso adoption files
      responses:
        '201':
          description: The flag, as it was filed, with its identifiers masked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RegistryFlag'
        '400':
          $ref: '#/components/responses/Problem'
        '401':
          $ref: '#/components/responses/Problem'
        '403':
          $ref: '#/components/responses/Problem'
components:
  schemas:
    RegistryFlagCreate:
      type: object
      required:
        - subject_type
        - flag_type
        - severity
        - narrative
        - identifiers
      properties:
        subject_type:
          $ref: '#/components/schemas/RegistrySubjectType'
        flag_type:
          $ref: '#/components/schemas/RegistryFlagType'
        severity:
          $ref: '#/components/schemas/RegistrySeverity'
        visibility:
          allOf:
            - $ref: '#/components/schemas/RegistryVisibility'
          default: network
        narrative:
          type: string
          minLength: 1
          description: >-
            Why the flag was raised. Required, and shown in full to every
            organization that can see the flag.
        identifiers:
          $ref: '#/components/schemas/RegistryIdentifiersInput'
        evidence_refs:
          type: array
          description: >-
            References to your evidence, kept as you send them and shown to
            every organization that can see the flag.
          items: {}
    RegistryFlag:
      type: object
      required:
        - id
        - originating_tenant_id
        - subject_type
        - identifiers
        - flag_type
        - severity
        - status
        - visibility
        - narrative
        - evidence_refs
        - moderation_metadata
        - created_at
        - updated_at
      properties:
        id:
          type: string
        originating_tenant_id:
          type: string
          description: The ID of the organization that filed it.
        subject_type:
          $ref: '#/components/schemas/RegistrySubjectType'
        identifiers:
          $ref: '#/components/schemas/RegistryIdentifiers'
        flag_type:
          $ref: '#/components/schemas/RegistryFlagType'
        severity:
          $ref: '#/components/schemas/RegistrySeverity'
        status:
          $ref: '#/components/schemas/RegistryFlagStatus'
        visibility:
          $ref: '#/components/schemas/RegistryVisibility'
        narrative:
          type: string
        evidence_refs:
          type: array
          items: {}
        moderation_metadata:
          $ref: '#/components/schemas/RegistryModeration'
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    RegistrySubjectType:
      type: string
      description: Whether the flag is about a person or an animal.
      enum:
        - person
        - animal
    RegistryFlagType:
      type: string
      enum:
        - animal_abuse
        - neglect
        - fraud
        - abandonment
        - falsified_application
        - other
    RegistrySeverity:
      type: string
      enum:
        - advisory
        - moderate
        - severe
    RegistryVisibility:
      type: string
      description: >-
        network: other organizations can see it once it is active. private: only
        your organization ever sees it.
      enum:
        - network
        - private
    RegistryIdentifiersInput:
      type: object
      description: >-
        What the flag can be found by. At least one key. A person may carry
        name, name_alias, email, phone, phone_country, address, date_of_birth
        and microchip_number. An animal may carry microchip_number, animal_name,
        species, breed, color, sex and name_alias. Any other key is refused.
        After masking at least one searchable value must be left: a street
        address alone is refused.
      minProperties: 1
      additionalProperties: false
      properties:
        name:
          type: object
          description: >-
            A person's name in parts, kept and shown in full. Each part is cut
            to 80 characters. Unless you send name_alias, the alias is made from
            the first and last names.
          additionalProperties: false
          properties:
            prefix:
              type:
                - string
                - 'null'
            first:
              type:
                - string
                - 'null'
            last:
              type:
                - string
                - 'null'
            suffix:
              type:
                - string
                - 'null'
        name_alias:
          type: string
          description: A name the subject is known by, kept and shown in full.
        email:
          type: string
          description: >-
            Kept only as a hash. Punctuation counts: j.smith@example.org and
            jsmith@example.org are different addresses.
        phone:
          type: string
          description: >-
            Kept only as a hash of its digits, so any spelling of the same
            number matches.
        phone_country:
          type: string
          description: >-
            The calling code for the phone, such as 1. With it, the phone is
            also matched in its international form, and the calling code is kept
            and shown. A value that is not one to three digits is ignored.
        address:
          type: object
          description: >-
            Only city, administrative_area and country are kept and shown.
            line1, line2 and postal_code are accepted and dropped. Any other key
            is refused.
          additionalProperties: false
          properties:
            line1:
              type:
                - string
                - 'null'
            line2:
              type:
                - string
                - 'null'
            city:
              type:
                - string
                - 'null'
            administrative_area:
              type:
                - string
                - 'null'
              description: The state, province or region.
            postal_code:
              type:
                - string
                - 'null'
            country:
              type:
                - string
                - 'null'
        date_of_birth:
          type: string
          format: date
          description: >-
            YYYY-MM-DD, and no other spelling. The year is kept and shown; the
            full date is kept only as a hash.
        microchip_number:
          type: string
          description: Kept only as a hash. Spaces and punctuation do not matter.
        animal_name:
          type: string
          description: Kept and shown in full, cut to 80 characters.
        species:
          type: string
          description: Free text, kept and shown in full, cut to 80 characters.
        breed:
          type: string
          description: Kept and shown in full, cut to 80 characters.
        color:
          type: string
          description: Kept and shown in full, cut to 80 characters.
        sex:
          type: string
          description: Kept and shown in full, cut to 80 characters.
    RegistryIdentifiers:
      type: object
      description: >-
        The identifiers as they are kept. Only the keys the flag was filed with
        are present.
      additionalProperties: true
      properties:
        microchip_hash:
          type: string
          description: A hash of the chip number. The number itself is not kept.
        email_hash:
          type: string
          description: A hash of the email address. The address itself is not kept.
        phone_hash:
          type: string
          description: A hash of the phone number. The number itself is not kept.
        phone_hash_national:
          type: string
          description: >-
            A hash of the phone's digits without the calling code, present when
            a calling code was given.
        phone_country:
          type: string
          description: The phone's calling code, digits only.
        name_parts:
          type: object
          properties:
            prefix:
              type: string
            first:
              type: string
            last:
              type: string
            suffix:
              type: string
        name_alias:
          type: string
        animal_name:
          type: string
        species:
          type: string
        breed:
          type: string
        color:
          type: string
        sex:
          type: string
        address_area:
          type: object
          description: The area, never the street.
          properties:
            city:
              type: string
            administrative_area:
              type: string
            country:
              type: string
        dob_year:
          type: string
          description: The year of birth, such as 1987.
        dob_hash:
          type: string
          description: A hash of the full date of birth. The date itself is not kept.
    RegistryFlagStatus:
      type: string
      description: >-
        pending_review until two other organizations corroborate it (then
        active), or two dispute it (then disputed). Nothing sets revoked at
        present.
      enum:
        - pending_review
        - active
        - disputed
        - revoked
    RegistryModeration:
      type: object
      description: The tally of other organizations' reviews.
      properties:
        corroborations:
          type: integer
        disputes:
          type: integer
        insufficient_evidence:
          type: integer
        corroborating_tenant_ids:
          type: array
          description: The IDs of the organizations that corroborated it.
          items:
            type: string
        disputing_tenant_ids:
          type: array
          description: The IDs of the organizations that disputed it.
          items:
            type: string
  responses:
    Problem:
      description: What is wrong, in one sentence you can show to a person.
      content:
        application/json:
          schema:
            type: object
            required:
              - error
            properties:
              error:
                type: string
          example:
            error: house_trained must be 1, 0 or null (not assessed)
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: An API key from Settings, API keys. It starts with rc_live_.

````