Journals and integrity offices increasingly face the operational problem of suspect-paper triage at scale. The detection tools (tortured-phrase scanners, image-duplication detectors, statistical-improbability flags, network-analysis indicators) produce more signals than can be investigated individually. The triage problem is how to escalate signals through orange-flag screening, yellow-flag follow-up, and red-flag investigation without either over-investigating low-signal cases or missing high-signal ones. This post is a practical model for the escalation, drawn from the operational practice of journals and integrity offices that have addressed the problem at scale.
The signal landscape
The detection signals in 2026 fall into several categories. Text-pattern signals: tortured phrases (Cabanac’s nomenclature), suspicious linguistic patterns, AI-generated-text indicators, citation-pattern anomalies. Image signals: duplication of images across papers or within a paper, AI-generated-image indicators, statistical-properties anomalies on Western blots and gels. Statistical signals: Benford’s-law violations, distribution anomalies, p-value clustering, ImpossibleData flags. Network signals: author-citation network anomalies, reviewer-recommendation patterns, institutional-network clustering, submission-pattern bursts. Behavioural signals: rapid resubmission, atypical responsiveness to revisions, refusal to provide raw data, unusual author additions or removals.
Any single signal is a weak indicator. The combination of multiple signals, particularly across categories, is a strong indicator. The CASRAI research integrity domain tracks the signal catalogue.
The orange-flag tier
The orange-flag tier is the first-pass automated screen. A submission that triggers any single signal lands in orange-flag triage. The triage decision is essentially binary: does the signal warrant further attention, or is it explicable by ordinary variation? Most orange-flag cases are explained — a tortured phrase that turns out to be a recognised technical term, a Benford violation that reflects a legitimate constraint on the data — and clear within minutes of human review.
The volume at orange-flag tier is substantial. A major journal processing thousands of submissions per year will produce hundreds to low thousands of orange-flag triggers. The screening workforce is typically the editorial staff with integrity-trained reviewers; the per-case time is minutes if the case is explicable, longer if it is not.
The operational discipline at orange-flag tier is to clear cases quickly and to escalate ambiguous cases promptly. The risk is two-sided: under-escalation misses real cases; over-escalation overwhelms the next tier.
The yellow-flag tier
The yellow-flag tier handles cases that the orange-flag screen could not clear. The work at yellow-flag tier is substantive but not yet full investigation: the editor reads the manuscript in light of the signal, the corresponding author is asked for clarification or for additional information, the suspect feature is checked against external references where possible.
A yellow-flag case typically resolves in one of three ways. Clearance: the additional information satisfies the concern; the manuscript proceeds. Editorial decision: the concern, while not rising to misconduct, makes the manuscript unsuitable for publication; the editor declines on editorial grounds. Escalation to red-flag: the additional information strengthens the concern; the manuscript moves to formal investigation.
The volume at yellow-flag tier is much smaller than orange. A journal that produces hundreds of orange-flag triggers per year might produce dozens of yellow-flag escalations. The per-case time is hours to days of editor and reviewer time.
The red-flag tier
The red-flag tier is formal integrity investigation. The case is referred to the journal’s integrity board or to the publisher’s integrity office; the corresponding author and the institution are formally notified; the investigation follows the COPE framework. Outcomes include retraction, expression of concern, correction, or clearance with documented findings.
The volume at red-flag tier is small but non-trivial. A major journal investigates tens of red-flag cases per year. The per-case time is weeks to months of integrity-office time, with substantial publisher-legal-team engagement in the more serious cases.
The escalation criteria
The transition criteria between tiers are where the operational discipline lives. Three patterns of criteria are useful.
First, multi-signal escalation. A manuscript triggering signals in two or more categories (e.g., tortured phrases and image-duplication) escalates from orange to yellow by default. Single-signal cases get a single-tier review; multi-signal cases get earlier escalation.
Second, author-response escalation. The corresponding author’s response to a yellow-flag query is the strongest single signal in operational practice. A clear, prompt, substantive response that addresses the concern is a strong signal of legitimacy. An evasive, slow, or non-responsive author is a strong signal of escalation-worthiness.
Third, pattern-based escalation. A manuscript that is the third or later submission from a particular author or institutional network that has produced previous escalations gets earlier-stage attention. The pattern-based escalation requires institutional memory; journals that lack this memory under-detect by category.
The cross-publisher coordination
A material limitation of current operations is the cross-publisher information silo. A manuscript that is flagged at journal A and rejected without investigation may be submitted to journal B, which lacks the signal. The author network behind paper mills has long exploited this gap.
COPE’s case-sharing mechanism, the Crossref Similarity Check service, and the publisher-led STM Integrity Hub are addressing this through cross-publisher signal sharing. The 2025 STM Integrity Hub expansion now covers most major publishers; the cross-flagging produces measurable signal improvements for journals that are part of the network. The CASRAI STM Integrity Hub entry tracks the participation and the operational state.
The author-side implications
For honest authors, the implications are real. A submission that triggers an orange or yellow flag is briefly delayed for screening; in nearly all cases the case clears and publication proceeds. The friction is small but non-zero; the alternative (no screening) is much worse for the integrity of the literature that honest authors care about.
The advice for honest authors: respond promptly and substantively to integrity queries; maintain raw data and provenance records that you can produce on request; avoid the practices (suspicious figure-handling, tortured-phrase paraphrasing of others’ work, opaque author-attribution arrangements) that produce orange flags even when the underlying work is sound.
What CASRAI recommends
For journals, three priorities. First, build the tiered triage explicitly into editorial workflow; do not handle integrity cases ad hoc. Second, participate in the cross-publisher information-sharing channels; the network effect is significant. Third, document the case-handling process so that authors understand what triage is doing and why.
For institutions, the parallel priority is to build integrity-investigation capacity that can receive red-flag cases from journals and act on them. The COPE framework is the procedural reference; institutional implementation maturity varies widely.
For the broader research-integrity community, the priority is to continue improving the signal catalogue, to share signal-detection methodologies openly (much of the published work in this area is in Research Integrity and Peer Review, Accountability in Research, and Science and Engineering Ethics), and to maintain the focus on the demand-side incentives that produce the supply.







