See a guest's history before it repeats.
When a booking arrives, and again when the guest checks in, your team sees whether that guest already has a record. It never blocks the booking. It just means no one is caught off guard.
Redflag is an optional add-on for CheckinGuest. It cannot work without it, since the confirmed match depends on the passport scan at check-in. CheckinGuest runs perfectly well without Redflag, and Redflag is not sold on its own.
A record that grows as operators join.
When a property logs an incident, that record surfaces at any other Redflag property the guest turns up at. Not as a list they can browse, only at the moment that guest books or checks in with them.
Redflag is new, so today the record spans the properties you operate. Every operator who joins widens it for everyone already in.
Joining does not hand anyone a searchable directory of guests. A property sees a record only when that guest is actually arriving. No browsing, and no lookups on people who have never stayed with you.
Two checkpoints, two levels of confidence.
The system only speaks at the two moments it changes what your team does.
A booking gives us a name and no document yet. We do not store a guest's email or phone, so the name, hashed, is all there is to match on. That makes it a weak signal: a prompt to pay attention and verify at check-in, never a verdict. Your team might ask for a deposit, assign a different room, or do nothing at all.
The passport is scanned, so the document number is known. An exact match on that is a confirmed record, and everything downstream treats it differently from a booking-time guess. Now the decision is made with certainty, not a hunch.
What a record holds.
Staff log an incident after it happens, in a few seconds, on one form.
Open a flag, see the whole record.
A flag is never the last word. Behind it is the record it came from, and the rights of the guest it names.
- Which property logged it, and when it happened
- The category and the severity
- The factual note
- The evidence, if any is attached
- Whether the record is contested
- A listed guest can ask what is held about them
- They can contest any record
- A contested record still shows, marked as contested
- The property that logged a record can correct or withdraw it
Kept to what is needed, and no further.
Records exist to inform a decision, then they expire. There is exactly one way to reach one outside the access rule, and it is accountable.
Deleted on expiry, not archived, on its own clock that is independent of Foreign Police filing.
When a guest asks what is held about them, an administrator can look the record up to answer that request. It is the only way to reach a record outside the access rule above, and every use of it is audited, so it is always accountable.