Career Guide · Employer Vetting · Updated July 2026
Red flags after the offer.
The offer is not the finish line. It is the moment a company stops selling you and starts showing you who it actually is. This is how to read it before you sign.
You made it through the screens, the panels, and the reference checks. The offer arrived. And then, quietly, things started to change. The scope of the role drifted from what you discussed. Terms you thought were settled reopened. You asked one ordinary question and got an answer that told you more than the person meant to say. This guide is built from a real interview process that went exactly that way. Names and details are stripped out on purpose, because the pattern matters more than the company. Read it before your next offer. Your leverage is never higher than the day before you say yes.
The offer is not the finish line.
Most job search advice ends at the offer. Get the offer, celebrate, sign. That framing is why so many good people walk into bad jobs with their eyes open. The offer is not the end of the process. It is the start of the only part where you hold the power.
Think about the leverage curve. During interviews, the company holds the cards. It decides who advances and who gets the call. The moment it extends an offer, that flips. Now it wants you. It has spent weeks and real money to get here, told its leadership you are the one, and does not want to reopen the search. For a short window, until you sign and give notice at your current job, you can ask anything and walk away at almost no cost. That window is the most valuable diligence period you will ever get, and most people sleep through it because they are relieved.
Do not sleep through it. Use it to answer one question: is the company you are about to join the same one that sold itself to you? Because sometimes it is not, and the gap only shows up after they think they have you.
Why companies change after you say yes.
It is rarely a con. It is usually pressure meeting honesty at the worst possible time. During interviews, a company is selling. It shows you the roadmap it wishes it had, the culture it aspires to, the plan it hopes to fund. Once you accept, the selling stops and the real constraints come forward. The runway that was almost closed is not. The senior engineer who was almost signed is leaving. The milestone that felt comfortable is now weeks away.
So the role you were hired to build becomes the role of fixing what is already broken. The greenfield rebuild becomes triage on a brittle system. The mission you signed up for becomes whatever keeps the lights on until the next raise. None of that makes the people villains. It makes the situation real. Your job is to see the real situation before you have quit your current one, not after.
The tell is the direction of the change. Good companies over-deliver on the offer to lock you in. They add, they clarify, they reassure. When a company starts subtracting after you accept, when scope shrinks toward damage control and terms move against you, it is showing you that it is under a kind of pressure it did not disclose. That is not a reason to panic. It is a reason to ask a lot of questions, fast.
The red, orange, and green flag system.
You cannot vet on vibes. Relief and hope both distort what you hear. So sort every signal into three buckets, and write them down. On paper, a pattern that a hopeful conversation hides becomes obvious.
A dealbreaker on its own, or part of a clear pattern. Someone dismissing a legal obligation. Scope flipping after you accept. The only person who understands the product walking out as you walk in. One red that holds up after a direct question is often enough. Two is almost always a decline.
Not disqualifying yet, but it needs one more honest conversation before you decide. A vague answer on documentation. A milestone that sounds tight. A team you have not met. Orange is a prompt to dig, not to run. Two oranges that turn evasive when you push become a red.
What good looks like. Plain answers to hard questions. Changes put in writing without you asking twice. Leadership that treats a compliance question as reasonable instead of rude. A team that can name who does what if a key person leaves. Green is not the absence of problems. It is honesty about them.
The rest of this guide is the four reds worth memorizing, the oranges worth chasing, and the greens worth holding out for.
Red flag: the bait and switch.
You spend weeks aligned on a role. You talk through the mission, the stack, the problem you will own. References get called. The offer lands. And then the description of the job quietly rotates, sometimes close to a hundred and eighty degrees from what you discussed the entire time.
In one real case, the whole conversation was about building something new and building it right, replacing a brittle system with a modern one. After the offer, that became a demand to just get the existing mess fixed instead. Same title. Different job. Nobody said the plan had changed. It simply had.
The same move shows up in the terms. Compensation that felt settled reopens. A number gets walked back. A promise made in an interview is not in the letter, and when you point it out, it turns out it was never really on the table. Small clarifications are normal. A significant, unannounced reversal after you accepted is the red flag, because it tells you two things: the version they sold you was not real, and they were willing to let you find out only after they thought you were committed.
What to do. Get the new reality in writing before you respond. Put the change next to what you were told and name the gap out loud, calmly. A company acting in good faith will either honor the original deal or explain the change honestly. A company that shrugs, or insists nothing changed when it plainly did, just showed you how it will handle every disagreement after you are inside.
Red flag: compliance theater.
This is the one that should stop you cold, especially in health, finance, or anywhere regulated data lives. Compliance theater is when a company performs the idea of taking rules seriously while doing none of the work, and reveals it the moment you ask a plain question.
A real example, generalized. During a late conversation, a simple logistics question came up: would the company provide a work computer. The answer was no, the company could not afford to buy machines, so everyone used their personal computers. Fine on its own. So the follow-up was obvious. This is a company handling sensitive personal data. What about compliance for all that regulated data sitting on personal machines, including people working from outside the country. The answer was a version of it is what it is. When the natural next question came up, whether fixing this would be a priority once the next round of funding closed, the subject changed and the discomfort was visible. The exposure of sensitive data was simply not something leadership cared about.
That is the whole red flag in one exchange. Not the missing laptops. The shrug. A leader who treats a direct question about protecting regulated data as an annoyance, rather than as the most reasonable thing a future employee could ask, is telling you exactly how much the obligation weighs on them. Deferring compliance to some future funding milestone is the same tell. Rules that only matter after the money arrives are rules the company does not actually hold.
There is a second layer worth checking. Ask which vendors and tools touch regulated data, including the AI tools used to build and test the product, not just the ones running inside the shipped app. It is common to have a proper agreement in place for the production path and nothing at all for the development and testing path, where engineers are working against real data with tools that were never covered. If the coverage stops at the app boundary while the whole build process runs against live sensitive data, the company has a compliance story, not a compliance practice.
What to do. Ask the compliance question early and plainly, and watch the reaction more than the words. Reasonable, specific answers are green. A shrug, a subject change, or a promise to care later is a red you should trust.
Red flag: the bus factor.
Engineers call it the bus factor. How many people would have to be hit by a bus before a project stops. When the answer is one, and that one person is leaving right as you arrive, you are not being offered an opportunity. You are being handed a rescue with a countdown.
The pattern is specific and it repeats. A contractor or lead architect built the core system and is the only person who truly understands it. That person decides to leave, sometimes at the last possible moment. The remaining team, often distributed and brought on late, was never actually trained to do what the departing person did, so they cannot carry it. And the company has a hard milestone weeks out that it must hit to unlock the next thing, funding, a partnership, a launch. Leadership that does not come from a technical background may not even realize how exposed it is until the knowledge is already gone.
If you accept that job, the rescue becomes yours. You inherit a system you were never allowed to audit, a team that cannot fully operate it, and a deadline set before you arrived. That can be a great opportunity for exactly the right person on exactly the right terms. It is a disaster for anyone who walked in thinking they were joining a functioning team.
What to do.Ask directly. Who wrote the core system, and are they staying. Who else can operate it today. What is documented, and what only lives in one person's head. If the honest answer is that the knowledge walks out with one person and there is a milestone weeks away, you are the plan. Price that in, or pass.
Red flag: claims you cannot verify.
The last red is the quietest. It is not a bad answer. It is being told to trust something you are not allowed to check. The stack is solid, trust us. The compliance is handled, trust us. The codebase is fine, but no, you cannot look before you sign.
You will hear claims that sound reassuring and turn out to be impossible to confirm from the outside. The build is modern and clean, when the people who worked on it describe something brittle and held together with tape. A legal agreement covers the risky path, supposedly, but nobody can show you the scope. The offshore team is fully capable, according to the person who never trained them. Every one of these might be true. The problem is you have no way to know, and the company is asking you to bet a year of your life on faith.
Healthy companies show their work. They will walk you through the architecture, let you skim the repository, describe the compliance posture in specifics, and let you talk to the engineers who will be on either side of you. When a company refuses all of that and asks for trust instead of evidence, the refusal is the evidence.
What to do. Ask to see the thing before you commit to it. A short technical walkthrough. A look at how compliance actually works. A conversation with the team without leadership in the room. You are not being difficult. You are doing the diligence any investor would do before putting in money, and you are putting in something harder to get back than money.
Orange flags: dig before you decide.
Not everything that worries you is a red. Some signals are just prompts to ask one more question. Treat these as orange. Chase them. If they turn evasive under a direct follow-up, they graduate to red. If they resolve with a straight answer, let them go.
- Non-technical leadership in a technical business. Common and survivable, but ask who owns the technical decisions and whether that person is empowered and staying.
- A tight milestone. Startups run on deadlines. Ask what specifically must be true by the date, and what happens if it slips. A clear answer is fine. A milestone nobody can explain is not.
- A legacy system due for a rewrite. Normal. The orange is whether you were hired to rewrite it or to babysit it, and whether the company knows the difference.
- A team you have not met. Ask to meet the people you will work next to, without leadership present. A company that will not arrange it is protecting something.
- Fuzzy documentation answers. If nobody can say what is written down and what is not, assume nothing is written down and price it in.
- Turnover you can see. Check who recently left and, if you can, why. One departure is noise. A pattern of senior people leaving before a milestone is a chorus.
Green flags: what good looks like.
Vetting is not just hunting for reasons to run. It is also confirming what good looks like so you recognize it and say yes with both eyes open. These are the signals that a company is worth joining even when it is hard, because hard and honest is a fine place to work.
- Straight answers to hard questions. You ask something uncomfortable and get a specific, honest reply, even when the honest reply is that they are still figuring it out.
- Changes go in writing without a fight. When something moves, they put the new version on paper before you ask twice.
- Compliance treated as reasonable. A question about data handling is met with detail and maybe a little pride, not defensiveness.
- They show their work. They offer the architecture walkthrough, the repository look, the team conversation, before you have to demand it.
- A real bus factor. More than one person understands the important systems, and they can tell you who does what if someone leaves.
- The offer over-delivers. After you accept, they add clarity and reassurance instead of subtracting scope. Good companies lock in the people they want by being more generous, not less.
The questions to ask before you sign.
Here is the short script. Ask these in the window between the offer and your signature. You are not interrogating anyone. You are doing diligence, and the reaction to being asked is itself part of the answer.
- Can you confirm the scope and priorities of this role in writing, so we are aligned on what I am owning in the first ninety days.
- Has anything changed about the role, the team, or the plan since we first talked. If so, what.
- Who built the core system, and will they still be here in ninety days. Who else can operate it today.
- What is documented, and what currently lives only in one person's head.
- What is the next milestone the company has to hit, when, and what happens if it slips.
- Before I sign, could I get a short walkthrough of the architecture, or a look at the codebase, or a conversation with the engineers I would work with.
- How does the company handle sensitive or regulated data today, in production and during development and testing.
- Which vendors and tools touch that data, and is there a formal agreement in place with each one.
Track the answers the way you would track anything that matters. If you are running your search in Orbyt, drop each answer into the role's notes and tag it red, orange, or green. Patterns are far easier to see across a saved record than inside a single hopeful phone call. When you have a live offer to weigh, the Job Offer Guide covers the money side, and the Eight-Minute Interview covers the red flags that show up earlier in the process.
If the data is regulated: the compliance questions.
If you are considering a company in healthcare, finance, or any field that handles regulated personal data, the stakes of getting this wrong are not only your career. Joining a company that mishandles protected data can put you near real legal and ethical exposure. Ask more, not less.
This is general guidance, not legal advice, and the specifics depend on your jurisdiction and the type of data. But the questions below surface the difference between a company that has a compliance practice and one that has a compliance story.
- Where does regulated data live. On company-managed devices, or on personal computers. Personal machines holding protected data, especially across borders, is a serious question, not a footnote.
- Who has access, and from where. Which team members, which contractors, which countries. Access sprawl is where exposure hides.
- Which vendors touch the data. Every third party that processes protected data usually needs a formal agreement. In health data, that is a Business Associate Agreement, a BAA. Ask if one exists for each vendor.
- What about the AI tools. If engineers use AI assistants to build and test, ask whether those tools are covered for regulated data, and whether they are exposed to real data during development, not just in the shipped product. This is the most commonly missed gap.
- What happens in development and testing. Production is usually the part companies think about. Real exposure often lives in the build and test path, where people work against copies of live data with uncovered tools.
- Is compliance a now problem or a later problem. If the honest answer is that they will handle it after the next raise, the obligation is not real to them yet, and you would be joining before it becomes real.
The reaction to these questions matters as much as the content of the answers. Leadership that meets them with specifics is showing you a practice. Leadership that meets them with a shrug is showing you the risk you would be signing up to carry.
How to walk away clean.
Sometimes the diligence works and you say yes with confidence. Sometimes it surfaces two reds that hold, and the right move is to decline. Declining a bad offer is not a failure of the search. It is the search working exactly as designed. You found the problem while it was still cheap to find.
Walk away clean. Thank them sincerely for the offer and the time. Be honest but gracious about the reason, something like the role has shifted from what we originally discussed, or the fit is not right for me at this stage. You do not need to litigate every red flag on the way out. The founder you decline today may run a different company in three years, and the world is small. Keep the door closed on the job and open on the person.
Then keep moving. One good decline protects a year of your life. Remember the leverage curve: the cost of walking away from a bad offer is a week of searching. The cost of walking into it is a year of your one career, spent rescuing something you were never shown, under a deadline you did not set, for people who told you it is what it is. The offer is not the finish line. It is the last, best moment to make sure the company you are about to join is the one you were promised.
Common questions.
Is it normal for a job to change after you accept the offer?
Small changes are normal: a start date shifts, a title gets adjusted. A large change is a signal. If the scope, the reporting line, the compensation, or the mission moves significantly after you accept, the company is telling you the version it sold you during interviews was not the real one. Treat a big post-offer change as information about how the company behaves under pressure, because that is exactly what it is.
Can an employer change the job description or terms after you accept?
In most of the United States employment is at will, so yes, an employer can change your duties, and unless you have a signed contract the written offer is not an ironclad guarantee of scope. That is why you vet before you sign. Your leverage peaks in the window between the offer and your acceptance. Get any changed term in writing, compare it against what you were sold, and decide before you give notice, not after.
What are the biggest red flags after a job offer?
Scope changing significantly from what you discussed. Compensation or terms renegotiated downward after you accepted. Leadership dismissing a direct question about compliance or data handling. The one person who understands the product leaving as you arrive. A team that cannot function without them. And technical or legal claims you are told to trust but not allowed to verify. Any one deserves a hard second look. Two or more that hold up is usually a decline.
How do I vet a startup before I accept the offer?
Ask to see what you cannot see from the outside. Who wrote the core system, and are they staying. What happens to the roadmap if the key person leaves. Ask for a short architecture walkthrough before you sign. Ask the compliance question directly and watch how leadership reacts, not just what they say. Ask what milestone the company must hit and what happens if it misses. A healthy startup answers plainly. An unhealthy one deflects, and the deflection is your answer.
What should I ask about data security before joining a healthtech company?
Ask where regulated data lives, and on whose devices: company-managed machines or personal computers. Ask which vendors touch protected data and whether a Business Associate Agreement, or BAA, covers each one, including any AI tools used to build and test the product, not just the shipped app. Ask what happens to protected data during development and testing, because that is where exposure hides. If a plain compliance question gets a shrug or a promise to fix it after the next raise, that is a red flag, not a detail.
Should I take the job if the lead engineer is leaving?
Be careful. If the person who built the system is leaving as you arrive, and the remaining team was never trained to do what they did, you are not joining a company, you are inheriting a rescue with a deadline. Ask directly: who else can operate this today, what is documented, and what is the plan if the answer is nobody. If the knowledge walks out with one person and a hard milestone is weeks away, you are being handed the risk, not the opportunity.
Run your search like it matters.
Track every offer, every answer, and every red flag in one place. Orbyt is free to start, no credit card, no time limit.
Start with Orbyt