Finally figured it out. In case of flag it's still a buff. The reason it didn't work was wrong source, it should be Friend. Seems flag in standard UI is some special icon, not a debuff (has no id in tooltip). So summarizing:
Orb of Power - debuff, Cast by: Everyone.
Flags (Alliance, Horde, Netherstorm) - buff, Cast by: Friend.
I think it would be nice to add it to default settings. Self configuring it is a bit unobvious.