ReplyPilot

Guide

Green, yellow, and red risk classification for support automation

Risk classification gives support automation a clear operating boundary. It should reflect the consequence of a wrong action, the need for live customer state, and the sensitivity of the data involved rather than the apparent simplicity of the customer's wording.

Updated July 21, 2026 · 7 min read

Green: stable information

Green messages ask for information that is stable, public, and non-consequential. A response does not change an account, move money, disclose protected data, or require a judgment about safety or policy.

  • Product dimensions or compatibility
  • Published operating hours
  • General setup instructions
  • Documented feature explanations

Yellow: stateful or consequential actions

Yellow messages may benefit from drafting, but the correct answer depends on current order, account, billing, identity, or subscription state. An agent should verify the facts and approve the response.

  • Refund and replacement requests
  • Cancellation or rescheduling
  • Billing and plan changes
  • Identity checks
  • Order edits and delivery exceptions

Red: mandatory human control

Red messages involve high-impact harm or sensitive rights. Block automated sending and route the case to a qualified person. Personal or financial data that remains after a deletion attempt is a privacy-retention issue, even when the request resembles an ordinary billing question.

  • Privacy access or deletion
  • Security incidents and account compromise
  • Fraud and chargebacks
  • Legal threats or regulatory requests
  • Unsafe incidents
  • Unknown authentication or payment-data changes

Use layered controls

Do not rely on one classifier. Combine explicit deterministic rules for known high-risk language with model-based context classification, then apply a final write-back gate. Keep a safety-miss review path so the policy improves when a reviewer finds a wrongly lowered case.