Explainable decision intelligence

Decision transparency

How AIM makes recommendations reproducible, explainable, auditable, and reviewable by the people accountable for the outcome.

Freedom AIM eagle and gear mark

AIM is designed to withstand skeptical oversight. Every recommendation can be explained, every score can be traced, and every decision can be reproduced. This page documents how AIM achieves hostile auditor defensibility.

AIM operates upstream of execution. That means the audit-ready record is built at the point the modernization decision is being made — not retrofitted after a platform has already been chosen. The traceability, defensibility, and reproducibility described below are properties of the decision itself, not of the runtime that executes it.


1. How AIM Ranks Options

AIM uses RAO (Ranking and Optimization) to score and rank modernization candidates. Scores are computed deterministically using:

  • Security – Lifecycle status, exposure, data sensitivity
  • Compliance – Regulatory fit (HIPAA, CJIS, PCI, etc.)
  • Cost – Total cost of ownership and budget alignment
  • Complexity – Operational complexity and skill requirements (inverted: lower is better)
  • Lock-in Risk – Vendor dependency and exit difficulty (inverted: lower is better)
  • Maturity – Market adoption and stability

📖 Detailed Methodology: See Scoring Methodology for a complete explanation of each dimension, what high/low scores mean, and how scores are curated for audit defensibility.

The recommendation list assigns one of four tiers from the RAO score:

  • Must Have Score ≥ 80
  • Strong Candidate Score 65–79
  • Consider Score 50–64
  • Avoid Score < 50

The explainability scorecard uses a shorter label for the same score: Recommended at 80 and above, Acceptable from 65 to 79, and Avoid below 65.


2. What AIM Is NOT

Not an ITSM or CMDB

AIM is a decision and sustainment record, not your IT service desk or your configuration database. Pulse Sustainment can read one ServiceNow business application, service, or application and, when ticket sync is connected, queue a change request to Jira or ServiceNow. AIM does not replace those systems and does not edit the configuration database.

Not an Autonomous Decision Maker

AIM provides decision support, not decisions. All outputs are designed to be reviewed, edited, and approved by human architects and stakeholders. Humans remain accountable for all implementation decisions.

Not a Replacement for Expertise

AIM accelerates planning by structuring data and surfacing options. It does not replace subject matter expertise, procurement processes, or vendor negotiations.


3. Vendor Neutrality Statement

Platform Independence

  • No paid placements – AIM does not accept vendor sponsorships, referral fees, or kickbacks
  • Consistent methodology – All candidates are scored using the same RAO dimensions
  • Open competition – Any qualified vendor can bid on work derived from AIM assessments
  • Catalog-backed – Product recommendations come from a curated, version-controlled catalog

When AIM names specific products, these represent a solution baseline for planning and vendor comparison — not vendor preference.


4. Reproducibility & Audit Logs

Every recommendation and report generation is logged with:

FieldDescription
input_hashSHA-384 hash of normalized assessment inputs
output_hashSHA-384 hash of ranked outputs and scores
input_hash_algorithm / output_hash_algorithmAlgorithm that produced each digest. Current seals record SHA-384.
methodology_versionVersion of scoring methodology used
rao_versionVersion of RAO algorithm used
created_byUser who triggered the generation
created_atTimestamp of generation

Quantum-resistant cryptography and hash stability

Input hash: Stable as long as the assessment configuration is unchanged. An auditor can confirm exactly what inputs were used at the time a recommendation was generated.

Output hash: Captures the ranked recommendations, RAO scores, and tier assignments at the moment of generation. Re-running the same assessment at a later date will produce a different output hash if pricing data, labor rates, catalog entries, or compliance flags have been updated since — this is expected and correct behavior. The stored output hash is the auditable record of what was recommended and why at a specific point in time.

Algorithm: AIM-signed operational artifacts across the platform use hybrid NIST FIPS 204 signatures; that posture is published on Compliance and assurance, not as a scoring-methodology claim. Decision seals remain SHA-384. See Decision Provenance for the hash algorithm note.


5. Data Freshness & Updates

AIM uses multiple data sources with defined update cadences:

SourceUpdate CadenceNotes
Cloud Provider APIsMonthlyAWS, Azure, GCP pricing (refreshed 1st of month)
Software/SaaS PricingMonthlyVendor public pricing pages
Hardware MSRPMonthlyDell, HP, Cisco, Palo Alto, etc.
BLS Labor RatesAnnualBureau of Labor Statistics OES data
Technology CatalogAs neededProduct lifecycle, scoring, metadata

6. Uncertainty & Missing Prices

AIM explicitly flags uncertainty rather than hiding it:

  • “Requires Quote” – Products with enterprise custom pricing or population-based licensing
  • Confidence Levels – HIGH/MED/LOW ratings on pricing data based on source type
  • Stale Data Flags – Warnings when data sources exceed expected update cadence
  • Missing Input Warnings – Explicit flags when assessment inputs are incomplete

Honest Uncertainty

AIM prefers to say “This information was not provided” rather than invent data. All estimates are planning-level and should be validated with vendor quotes before procurement.


7. AI Role Statement

How AI Is Used

  • Narrative assistance – AI improves readability of report text
  • Context normalization – AI helps structure free-text inputs into normalized constraints
  • Pattern detection – AI assists in identifying architecture patterns from system descriptions
  • Conversational knowledge access (AIM Eagle) – AI powers the AIM Eagle chat assistant, which answers questions about the platform grounded in verified knowledge content. Eagle operates in a fully separate pipeline from the assessment and scoring engines — it has no ability to read, influence, or modify RAO scores, recommendations, or generated reports. Eagle responses are informational only and are not part of the auditable decision record.

Deterministic Scoring

AI does not change scores. All RAO scores, tier assignments, and rankings are computed using deterministic, rule-based logic that can be reproduced and audited.

AI narrative assistance is clearly disclosed in reports. The underlying scoring methodology is fully transparent and documented.


8. For Auditors

If you are auditing an AIM-generated report or recommendation:

1

Check the Explainability Appendix

Reports include an appendix with methodology version, data freshness, scorecards, and reproducibility hashes.

2

Verify Hashes

Each decision run stores an input hash (stable for unchanged assessments) and an output hash (captures recommendations at that moment). Compare the stored output hash against the report generated at the same time. Output hashes will differ if re-run later as pricing, labor rates, or catalog data has since been updated — this is expected, not an integrity failure.

3

Review Decision Runs

Decision runs are immutable audit records that cannot be modified after creation.

4

Request Data Exports

Structured data exports are available upon request via privileged access.

Learn More About AIM

Explore how AIM works and understand the methodology behind recommendations.

Decision Transparency | Freedom AIM