FAQ

Questions that come up most often while teams are evaluating mDecide. Deeper treatment lives on the pages linked from each answer.

What mDecide is

What is mDecide, in one sentence? One platform where AI agents and domain experts work a single high-stakes decision end to end, while leaders see cost, quality, and audit posture across the whole program. See What is mDecide.

Do we need a data platform or a warehouse project first? No. mDecide connects read-only to the systems you already run. There is no migration and no rip-and-replace, and you do not need a data-platform program to finish before you start.

Does it replace our BI tools or our data warehouse? No. Those systems answer questions and store rows. mDecide is the operational layer where a decision is actually made, governed, measured, and remembered — including the human choice and the measured outcome, which BI and warehouses do not capture.

Can we bring agents we have already built? Yes. Agents built in LangChain, LangGraph, Bedrock, AutoGen, or a custom framework plug in through open standards (MCP, A2A). A governance wrapper gives them the same authentication, audit logging, decision capture, and access controls as the agents metricsIQ delivers, so an in-house agent joins the team without being able to bypass the governance contract.

Do we have to build a decision pack from scratch? No. Packs ship pre-configured for specific industry decisions — well intervention, pipeline integrity, manufacturing changeover, batch release, covenant monitoring, customer account intelligence, and scene triage among them — each with the integrations, ontology, and decision structure already wired. See Decision Packs.

Deployment and data

Where does it run? On AWS, as a containerized multi-AZ application, deployed single-tenant: one dedicated environment per customer, with no data comingled across customers. The region is chosen to fit your data-residency needs. See Architecture overview.

Who operates the infrastructure? metricsIQ is the operator of record. Your team does not provision cloud resources, manage backups or disaster recovery, patch containers, manage TLS certificates, configure security groups, manage database instances, or administer the deployment pipeline.

Does our data leave the deployment region? Your data resides in the region selected for your instance, and cross-region replication is not enabled by default. What content reaches the model and embedding APIs, and where that provider processes it, is drawn explicitly per engagement rather than assumed. The full data-handling posture is on Trust and security.

Which models does it use? Agent reasoning is served by Anthropic Claude through Amazon Bedrock. Custom predictive and anomaly-detection models run on Amazon SageMaker alongside the agents, in the same environment your data-science team works in. Open standards and a portable data layer mean the model choice is not a one-way door.

What happens if we decide to leave? Your data, your ontology, your integrations, and your decision history come with you. mDecide is built on open standards (MCP, A2A, OASF) with portable decision records, and a data-retention term for the period after termination is agreed as part of your engagement.

Security and compliance

Are you SOC 2 certified? Not yet, and the honest answer matters more than a comfortable one. The platform’s controls are mapped section-by-section against the SOC 2 Trust Services Criteria — Security, Availability, and Confidentiality — and that evidence is suitable for responding to a vendor security questionnaire today. A SOC 2 Type II audit is on the roadmap; until it completes, the platform is aligned to the criteria rather than third-party-audited against them.

What other frameworks do you map to? NIST SP 800-53 Rev. 5 (Moderate baseline subset), the AWS Foundational Technical Review under the Partner Hosted profile, and the CIS AWS Foundations Benchmark v3.0, which is continuously monitored with findings remediated on a defined cadence. See Trust and security.

Can you map to our internal control catalog or our sector regulations? Yes, on request. Customer-named framework mappings are delivered as an appendix to the security overview and recorded in the engagement statement of work.

Can you sign a BAA? Can the platform handle PHI? Not currently. The platform does not process protected health information under a Business Associate Agreement. The technical controls are consistent with HIPAA Security Rule expectations, but the contractual instrument is not in place today — raise it during scoping if your use case needs it.

What are we responsible for, and what is metricsIQ responsible for? metricsIQ operates the infrastructure, the application, the security tooling, the monitoring, the deployment pipeline, backups and recovery, patching, and incident response. Your side covers what only you can: your end-users protecting their credentials and using MFA where supported, your administrator managing users and role assignments in your own directory, the accuracy and appropriateness of data you put into the platform, authorized use under the services agreement, prompt notification of any suspected security incident, and acknowledgement of the data-flow boundaries for any optional integrations named in your statement of work. The full table is on Trust and security.

Who on the metricsIQ side can see our data? Operator access is controlled and logged separately from application end-user access, and access events are written to an audit trail. The two-layer access model and the audit trail are described on Trust and security.

Getting started

How do we start? Most teams start with mPilot: a fixed-price proof of value on a single anchor decision, running against your real data within weeks. Teams that need to defend a portfolio choice first start with an mPlan assessment. See Adopting mDecide.

How long before we see something real? mPilot is measured in weeks and production readiness in a few months, because the platform being deployed is the same platform already built and tested — the integration scaffolding, decision capture, and governance pattern are product, not project work.

What do you need from us to begin? An anchor decision with a named business owner, read-only access to the systems behind it, your identity provider and two groups, one to three named administrators, and the scope of data products and integrations for the engagement. The full list is on Adopting mDecide.

Can we stop if it does not work out? Yes. A mid-point gate sits between proof of value and production readiness. If value or fit disappoints, you step off there.

Do our people need to be AI specialists? No. The people who own the decision today are the people who work it in mDecide. Role-based training and clear human-in-the-loop checkpoints are part of the engagement, so judgment compounds across your team rather than concentrating in a few specialists.

Support

Who do we contact when something goes wrong? Email mdecidesupport@metricsiq.ai. Requests reach the people who deployed your environment and know your decision packs and your integrations, so there is no first-tier queue to get through before reaching someone with context.

How are issues handled? Requests are logged, triaged by severity, and tracked to resolution, with a named owner and an audit trail for each one. Under mOperate the deployment is also monitored continuously, with alerting on health, cost, and decision quality, so a number of issues are found and resolved before they reach you.

Are service levels published? No. Support terms for your deployment are agreed as part of your engagement rather than described on this site.

Do we get documentation and training? Yes. Documentation for the release your deployment actually runs is available inside the platform once you are live, alongside decision-pack runbooks and role-based training for the people working with the agents. These public pages cover evaluation; the in-product set covers operation.

Commercial

How is mDecide priced? Pricing is discussed in sales conversations. Your metricsIQ contact will walk you through it.

Still have a question?

If something you need to know is not answered here, ask it directly — the fastest path is a conversation with the metricsIQ team, who can speak to your scope rather than to the general case.