Platform methodology

How AIM works

A governed path from organizational evidence and constraints to defensible architecture, procurement, delivery, and sustainment decisions.

Freedom AIM eagle and gear mark

AIM (Architectural Insight for Modernization) turns your messy reality — legacy systems, half-documented integrations, political constraints, and budget limits — into a structured modernization plan.

No magic. No vendor kickbacks. Just structured inputs, transparent scoring, and AI that stays inside the lines you define.

The AIM Process

From Assessment to Decision — At a Glance

01

Guided Intake

Structured Questionnaire

Answer targeted questions about your infrastructure, systems, vendors, integrations, and constraints. Scope-conditional questions adapt to your inputs — you are only asked what is relevant.

02

Signal Processing

Context & Normalization

AIM extracts regulatory signals, detects technology domains, and assembles a structured context package. Raw answers never reach AI directly — every decision is scoped to verified, normalized inputs.

03

Scoring & Optimization

RAO Engine

Every modernization path is ranked against your constraints across cost, security, maturity, lock-in risk, complexity, and strategic fit. Your priorities set the boundaries — not defaults.

04

Outputs & lifecycle

Decisions through sustainment

From a single assessment: decision-ready reports and architecture, then Project Pulse delivery, Pulse Sustainment after handoff, and Mission Control observation. Federal procurement artifacts appear only when the assessment has a federal regulatory context.

One assessment. Decision-ready outputs.

White Paper

Technical modernization plan with architecture recommendations and phased roadmap.

Executive Report

Leadership-ready summary with strategy, cost outlook, and prioritized recommendations.

Vendor Brief

Structured summary scoped for implementation partners bidding on the engagement.

RFP Package

Ready-to-issue request for proposal with milestone payment terms and equivalency requirements.

Project Pulse

Delivery heartbeat after the decision — epics, health status, and stakeholder snapshots.

Mission Control

Read-only observation and human review packages. Scout cannot patch, install, or deploy.


AIM in practice

Healthcare modernization walkthrough

Follow St. Agnes Regional Health Network through the same governed workflow described on this page: organizational context, systems, evidence, architecture, decisions, artifacts, delivery governance, and Mission Control readiness.

See healthcare context become a governed modernization decision.Download transcript
AIM assessment workspace with evidence, constraints, and next actions for the fictional St. Agnes Regional Health Network
Assessment workspace · fictional St. Agnes Regional Health Network
AIM recommendation and decision workspace with scored options for the fictional St. Agnes Regional Health Network
Recommendation & decision · fictional St. Agnes Regional Health Network
AIM target architecture workspace for the fictional St. Agnes Regional Health Network
Target architecture · fictional St. Agnes Regional Health Network
AIM Mission Control observation and review workspace for the fictional St. Agnes Regional Health Network
Mission Control · fictional St. Agnes Regional Health Network

1. Start with a Guided Assessment

AIM begins with a structured intake that captures your environment in plain language. You answer questions — AIM normalizes and structures the rest.

Organization & environment

  • City, county, agency, or business
  • On-prem, cloud, or hybrid environment
  • Size and scope of the effort

Systems & components

  • Core systems (ERP, billing, public portals, EHR, mainframes, databases, firewalls, etc.)
  • Critical infrastructure (network, storage, backup, identity)

Applications & vendors

  • COTS products, SaaS platforms, custom apps
  • Known vendor lock-in or proprietary dependencies

Integrations & data flows

  • How data moves between systems
  • Protocols and interfaces (APIs, file transfer, HL7, message buses, etc.)

Constraints & requirements

  • Timelines, budgets, staffing limits
  • Regulatory requirements (HIPAA, CJIS, PCI, FedRAMP, etc.)
  • Uptime, security, data residency, and other technical requirements

Supply-chain policy

  • Supply-chain risk tolerance and workload criticality
  • Minimum supplier transparency and concentration tolerance
  • Disruption limits and mandatory controls such as SBOM, VEX, signing, notification, remediation, and exit planning

Scope-conditional sub-questions automatically appear based on what you select — so you're only ever asked what's relevant to your project.


2. Constraint Normalizer (C-1, C-2, C-3…)

Free-text constraints are converted into normalized constraint records with stable IDs:

  • C-1Timeline
  • C-2Budget
  • C-3Regulatory
  • C-4Technical / SLA
  • C-5Data / Residency
  • C-6Security / Compliance
  • C-7Architecture / Dependency
  • C-8+Other

Each constraint is split into atomic statements, classified by type, and given a stable code. These codes appear in every recommendation and report so decision-makers can see exactly which constraints each recommendation honors.


3. Free-Text Signal Extraction

When you describe your constraints in free text, AIM automatically scans the language for structured signals — deterministically, at zero AI cost — and pre-fills relevant assessment fields without overwriting anything you've already provided.

Cloud providers

Detects Azure, AWS, GCP, Oracle Cloud, on-prem, or hybrid mentions

Regulatory scope

Identifies HIPAA, CJIS, FedRAMP, PCI-DSS, FERPA, SOX, GDPR, and more

Technology domains

Recognizes Identity, Data Platform, Integration, CMS, Cybersecurity, AI/ML, and others

Identity providers

Flags Active Directory, Okta, Entra ID, SAML/SSO, and similar indicators

Project timeline

Extracts month or year durations from natural language

Organization domain

Classifies federal, state/local, healthcare, education, financial, and non-profit contexts

Extracted signals are stored on the assessment and used to skip redundant follow-up questions. You can trigger re-extraction any time from the Smart Follow-Up tab.


4. Structured Context Builder

Behind the scenes, AIM assembles a structured context package — a curated, normalized representation of your situation that AI models are allowed to use. Raw survey answers are never passed directly to AI.

Project Identity & Archetype

Organization type, environment, size, scope. AIM automatically classifies projects across 10 modernization archetypes from assessment signals — no manual selection required.

Current State

Systems, applications, vendors, integrations, data flows, and known risks.

Scored Recommendations

RAO scores for candidate solutions, pre-computed from the catalog, with dimension breakdowns.

Architecture Patterns

Detected patterns (mainframe core, cloud-native, hub-and-spoke, API-driven) and applicable migration paths.

Safety Guardrails

Anti-hallucination boundaries that prevent AI from inventing vendors, regulations, or integrations not in your assessment.

This structured context — not your raw inputs — is what AIM's AI models work within. The package is built deterministically before any AI is invoked.


5. Assessment Confidence & Smart Follow-Up

AIM measures how complete your assessment data is and assigns a confidence tier that appears on every generated report. The more signals you provide, the more precise the recommendations and the stronger the report language.

BaselineScore: 0–44

Core fields provided. Reports include broad assumptions and flag data gaps explicitly.

StandardScore: 45–74

Most key signals present. Recommendations are well-scoped with moderate cost confidence.

High ConfidenceScore: 75–100

Full signal set. RAO scoring and cost modeling are precise. Reports carry maximum authority.

Smart Follow-Up

After you submit an assessment, the Smart Follow-Up tab in your workspace generates a personalized list of up to 12 targeted questions — scoped to exactly what signals are still missing, prioritized by their confidence impact.

  • Questions are ordered by how many confidence points each answer adds
  • Signals auto-detected from your constraints text are pre-filled or skipped
  • Scope-conditional questions only appear for your selected technology domains
  • Answering any question immediately updates your signal score and confidence tier
  • Reports can be regenerated at any time to reflect an improved confidence designation

6. RAO Engine (Ranking and Optimization)

AIM doesn't just “ask a model for ideas.” RAO is a scoring system that ranks modernization paths using your constraints as hard boundaries — not suggestions. It evaluates options across multiple dimensions:

  • Costupfront + operating
  • Maturitystability and real-world adoption
  • Security & compliancefit against your regulatory profile
  • Vendor lock-in riskdifficulty of future exit
  • Operational complexityskills, runbooks, and support needs
  • Supply Chain Assuranceevidence-backed product assurance, applied only when a current score and explicit tolerance exist
  • Strategic fitalignment with constraints C-1, C-2, C-3, etc.

Each recommendation carries a RAO score and a dimension breakdown — so you can explain why a path is preferred, not just what the AI suggested.

Important: AIM outputs are designed to be reviewed, edited, and owned by your architects — not blindly accepted. The goal is a faster, clearer starting point, not a replacement for human judgment.


7. Risk & Integration Insight Engines

AIM analyzes your inputs to surface:

Risk patterns

  • Single-vendor dependence on critical platforms
  • Deprecated or end-of-life technologies
  • Unencrypted or fragile data flows
  • Gaps between requirements and current reality
  • Product-specific vulnerability, supplier-advisory, provenance, evidence, and continuity gaps

Integration hot spots

  • Choke points where many systems depend on a single integration
  • Legacy protocols that will block modernization
  • Candidate areas for API gateways, data hubs, or integration platforms

8. Anti-Hallucination Guardrails

AIM is deliberately strict about what it's allowed to say. The report and recommendation engines are explicitly instructed to:

  • Use only facts present in the structured context
  • Never invent vendors, technologies, integrations, or regulations
  • Recommend named technologies only when supported by your inputs — and flag anything net-new
  • Only mention HIPAA, CJIS, PCI, etc. if detected in your constraints or requirements
  • Tie recommendations back to RAO scores and constraint codes

If the data isn't there, AIM prefers to say:

“This area requires more input before a confident recommendation can be made.”

That's by design. Your assessment confidence tier documents exactly how much data was provided and what was assumed.


9. Intelligence Layers

Beyond the core RAO engine, AIM applies proprietary intelligence layers when their required inputs are available. Deterministic layers enrich outputs without relying on AI guesswork:

  • AI Readiness & Archetype Classification When AI is in scope, AIM scores readiness and classifies the appropriate AI implementation approach.
  • Modernization Focus Classification Automatically infers the primary modernization archetype from assessment signals, adjusting RAO scoring weights downstream.
  • FTE Estimation Engine Produces a staffing range and duration estimate per archetype, broken out by delivery role.
  • Labor Cost Intelligence Computes delivery cost ranges across three models (market hiring, federal staffing, contractor) using authoritative federal rate data.
  • Historical Procurement Benchmarking Compares your project against real public-sector contract award data to surface comparable cost and duration ranges.
  • Sustainment Cost Analysis When enabled, extends the cost picture through long-term operational budgeting, staffing gap analysis, and 3-year TCO projections.
  • Supply Chain Assurance When product identity, current evidence, and organizational tolerance are available, calculates a versioned standing and contributes an evidence-gated seventh RAO dimension.

10. Outputs: What AIM Actually Delivers

From a single assessment, AIM can generate:

1. RAO-Backed Recommendations

  • Ranked list of modernization options with clear tradeoffs
  • Dimension scores and constraint references (e.g., “Addresses C-1, C-3, C-5”)

2. Modernization Brief (PDF)

  • Executive summary, current state, and target architecture
  • Priority recommendations table
  • Risk, compliance, and tradeoff analysis
  • Phased roadmap with quick wins vs. long-term moves
  • Assumptions & Data Basis section — documents your confidence tier, what was provided, and what was estimated

3. Supporting Deliverables

  • Compliance gap analysis against your declared regulatory scope
  • TCO projection (3-year cost model across staffing, licensing, and sustainment)
  • Vendor Brief — a structured summary for prospective implementation partners
  • RFP package with milestone payment terms and equivalency requirements

4. Modernization Strategy

AIM automatically selects a modernization strategy based on your archetype, environment type, vendor lock-in sensitivity, and system constraints:

StrategyBest For
INTEGRATEConnect existing systems with new components while preserving current investments.
REPLACERetire outdated or unsupportable systems and deploy new solutions.
REPLATFORMMove to a new platform with minimal code changes (“lift and reshape”).
LIFT & SHIFTFastest migration path — move with minimal changes.
MODERNIZEUpdate existing systems in place with new technologies and patterns.
RETAINKeep systems as-is — meets current needs with no pressing drivers.
RETIRESunset and decommission. Data migration and archival may be required.
MIXEDMultiple strategies apply across different components.

11. Why AIM Is Different

Pre-Decision Layer

AIM operates upstream of workflow platforms, AI control towers, and execution runtimes. Those tools govern work once a platform has been chosen. AIM helps organizations decide what should be modernized, what should be avoided, what risks exist, and how to defend the decision before the platform commitment is made.

  • Objective by design – AIM is not paid by vendors, marketplaces, or cloud providers.
  • Constraint-driven – C-codes make your priorities explicit and traceable.
  • Transparent – Recommendations and reports show why, not just what.
  • Confidence-aware – Every report documents exactly what was provided and what was estimated.
  • Segment-equal by design – Federal agencies, healthcare systems, state and local government, defense contractors, financial institutions, education, and commercial enterprises are all first-class contexts. The methodology is the same; only the output format adapts to the approval process.

Platform Independence

AIM is vendor-neutral in incentives and implementation. The Freedom Project does not accept vendor partnerships, referral fees, or kickbacks. Any qualified vendor can bid on work derived from AIM assessments.

When AIM names specific products, these represent a solution baseline derived from your assessment — not vendor preference. Vendors may propose alternatives only if they meet all requirements and include an equivalency matrix and impact summary.


12. Teams & Collaboration

AIM supports a multi-stakeholder model with six organization roles (Owner, Admin, Engineer, Program Analyst, Reviewer, Viewer) and a separate guest access system for external participants.

Organization Roles

Owners manage contract visibility, members, and audit logs. Admins manage day-to-day workspace access. Engineers run assessments and technical analysis. Program Analysts generate procurement documents and use the Document Translator. Reviewers approve and flag generated documents. Viewers can read and export existing reports but cannot generate new ones or modify anything.

Guest Collaborators

Assessment owners can invite external stakeholders (architects, vendors, agency partners) to a specific assessment via email OTP — no platform account required, no seat consumed. Guests cannot trigger AI pipelines or generate reports.

Audit Trail

Every collaborator action is logged — who accessed, when, and what changed. Owners and Admins can view an org-wide activity log and a per-assessment access log from the workspace Collaborators panel.

See the full Teams & Access guide →


13. Product Catalog Query

Every assessment workspace includes a Product Catalog Query Widget that lets users investigate the technology catalog directly — without leaving the assessment.

Search & Explain

Search the catalog for any product. If it exists but was not among the top recommendations, request an AI-generated explanation using RAO scores, constraint fit, and competitor rankings. Explanations are cached for consistent repeat access.

Product Requests

If a product doesn't exist in the catalog, submit a request to The Freedom Project team. The form auto-populates your assessment and organization context. You're notified of the outcome.

User-Defined Constraints

Add any product as a user-defined constraint — whether it's existing infrastructure or a client preference outside AIM's evaluated scope. These appear in White Papers, RFPs, Executive Summaries, and Vendor Briefs with a clear user-defined designation.


14. Technology Catalog

AIM recommendations draw from a curated multi-category product catalog— including ERP, Identity & Access, Observability, Data Warehouse, ETL/Integration, and a full AI/ML suite covering Platforms, Generative AI, Data Science, MLOps, NLP, Computer Vision, AI Ethics, and AI Security. AI tools are compliance-filtered against CJIS, FedRAMP, HIPAA, and PCI based on your declared regulatory scope.

Security

Vulnerability posture, certifications, data protection

Compliance

FedRAMP, HIPAA, PCI-DSS, SOC 2 readiness

Cost Efficiency

Total cost of ownership, pricing model transparency

Vendor Lock-in Risk

Portability, migration friction, standards support

Operational Complexity

Skill requirements, maintenance burden, support quality

Market Maturity

Ecosystem stability, community support, longevity

Supply Chain Assurance

Product-specific evidence, confidence, coverage, failed gates, and intended-use tolerance when sufficient current evidence exists

Transparency Guarantee

Product rankings are determined solely by assessment-specific constraints and objective scoring dimensions. AIM does not accept vendor partnerships, referral fees, or placement fees. Products without adequate product-specific assurance evidence remain explicitly unassessed or insufficiently evidenced; they are not treated as low risk.

Learn how Supply Chain Assurance works →

Ready to Get Started?

Create your first assessment and see how AIM works for your organization.

Freedom AIM - Architectural Insight for Modernization