Decision LighthouseDecision Lighthouse documentation
Open Decision Lighthouse
For users, analysts, and decision owners

Full User Guide

A complete walkthrough of Decision Lighthouse’s decision assessment, interview, report, prioritization, and implementation features.

Use the sections that match your work. Some reports, history, exports, and administrative actions are role-controlled.

How Decision Lighthouse is organized

The standard Decision Lighthouse workflow is:

1 · Decision Context

Define the organization, decision, persona, objectives, options, and evidence.

2 · Interview

Answer adaptive questions that explore context, risk, options, resources, and readiness.

3 · Report

Review the recommendation, confidence, behavioral findings, risks, metrics, and rationale.

4–5 · Implement and export

Use interventions, control mappings, the Gantt timeline, and permitted exports to move forward.

The sidebar shows the stages. Locked stages become available as prerequisites are completed. Start clears the way into a new assessment; Settings, Help Center, and About are available separately.

Behavioral Profile

A Behavioral Profile supplies reusable organizational context to the interview. It is optional.

  1. Choose Import Profile to load a prior JSON profile, or choose Create Profile to enter information manually.
  2. Review the organization, industry, size, risk tolerance, decision speed, change readiness, and notes.
  3. Choose Use This Profile to include it, Edit Profile to change it, or Clear Profile to remove it from the current workspace.
  4. If you do not have a profile, choose Skip to Decision Setup. Do not invent facts just to fill the profile.
Verify discovered facts. If you use organization discovery, treat the result as public-source context. Review and correct low-confidence or outdated facts before confirming them.

Decision Context

Decision Context is the foundation for the interview and report.

  • Organization: identify the organization being assessed.
  • Role/persona: select the perspective that best matches the person answering. This shapes the interview and recommendations.
  • Objectives: select the outcomes that matter. When a standard objective does not fit, use the custom decision question.
  • Decision: select a pre-built CISO decision or choose a custom decision. Decision Lighthouse includes vendor comparisons, SOC Build vs. Buy vs. Outsource, incident response, identity, cloud, data protection, resilience, and other domains.
  • Options: provide the alternatives that should be evaluated. Vendor-comparison scenarios use a shortlist of 2–6 options.
  • Evidence: add the organizational documents that are relevant to the decision. Only upload documents you are authorized to use.
  • Assessment packs: Decision Lighthouse recommends packs based on the decision. Add more when another area needs to be examined.

Choose Start Interview when the context is complete. Use Edit Setup to revise it later. Use Clear Setup Data or Clear Environment only when you intentionally want to remove the current working assessment from the browser session.

Adaptive Interview

Decision Lighthouse asks one question at a time and uses your answers to choose useful follow-ups. It looks for evidence about risk, resources, options, dependencies, organizational readiness, and constraints.

  1. Read the question and answer from the selected persona’s perspective.
  2. Give specific, decision-relevant details: budget ranges, staffing, service criticality, deadlines, current technology, integrations, regulatory obligations, and known unknowns.
  3. Use Next to save and continue. Use Previous to review earlier answers.
  4. Watch the progress bar and Context, Risk, Options, Resources, and Complete milestones. Do not treat progress as a quality score.
  5. When ready, choose Complete Interview. Export Interview File if you need a JSON copy of the Q&A.
Unknown is a valid answer. If the organization does not know a budget, owner, dependency, or SLA, say so. A visible gap is safer than a confident assumption.

Reading the report

A standard report contains the following sections. Start with the first three, then use the rest to challenge and operationalize the recommendation.

SectionWhat it tells you
Recommendation SummaryThe executive-level result.
Decision Validation LayerRecommendation, confidence, and evidence-backed rationale.
Behavioral Adoption ProfileReadiness and change-management considerations.
Primary Trade-Off NarrativeThe plain-language trade-offs between options.
Framework Drivers (Weighted)The factors that most influenced the decision.
Comparative Option MatrixSide-by-side analysis of available options.
Friction MapExpected resistance and implementation friction.
Behavioral Change LeversActions that improve adoption.
Behavioral Implementation PlanPhased work needed to execute the recommendation.
Success MetricsMeasurable targets, timelines, and measurement methods.
Decisions NeededOpen stakeholder decisions before execution.
Behavioral Risk RegisterRisks, likelihood, impact, and mitigations.
AssumptionsStatements the recommendation depends on.
Behavioral SignalsThemes extracted from interview responses.
BiasesCognitive biases detected in the decision process.
Gaps & ConfidenceEvidence coverage and areas needing more information.
Conclusion / Decision JustificationThe closing synthesis for the decision record.

Confidence describes the strength and breadth of available evidence. It does not replace stakeholder judgment, technical validation, procurement review, or risk acceptance.

Implementation views

  • Interventions: review behavioral interventions connected to adoption risks and decision friction.
  • Control Mapping: inspect how implementation recommendations map to NIST CSF 2.0 and ISO 27001:2022 controls. Export the mapping when permitted.
  • Gantt Chart: use the generated timeline to see phases, tasks, durations, dependencies, and quick/medium/long work. Export an HTML timeline or PNG when available.
  • Tasks: where your deployment exposes task actions, assign, update, and complete implementation work according to your organization’s process.

Vulnerability Management

The vulnerability workflow is separate from the standard decision interview and creates a remediation order from a vulnerability list.

  1. Choose your VM policy. Use an approved policy when one is available. Authorized administrators can save or retire an organization policy.
  2. Extract governance context (optional). Select supported governance documents and choose Extract into context. The extracted context is for analysis.
  3. Enter analysis-only context. Add critical services, sensitive data types, risk tolerance, and remediation SLAs for Critical, High, Medium, and Low findings.
  4. Provide the vulnerability list. Upload CSV, XLSX, JSON, or TXT. Confirm the file is non-empty and contains the fields your team relies on.
  5. Answer the interview. Choose what should influence urgency, how serious delay would be, and how constrained remediation capacity is.
  6. Review and approve. Inspect the ranked findings, key factors, next actions, validation notice, and root-cause intelligence. Download JSON/CSV or choose Approve Prioritization.

Approved decision history contains derived snapshots. Uploaded source bytes and finding descriptions are not retained. Open a history item to capture an outcome such as Remediated, Accepted, Deferred, False Positive, or Risk Accepted, with an optional bounded note. Compare two approved snapshots to see what changed.

Strategic Plan Prioritization

  1. Provide the strategic plan or permitted plan text and review the initiatives Decision Lighthouse extracts.
  2. Answer the adaptive bounded-choice questions one at a time. You do not need to rank initiatives yourself.
  3. Continue until the server-calculated context score reaches 100%, or until the maximum of 10 questions is reached.
  4. Review the ranking labeled Do Now, Do Next, and Do Later. Dependency names are shown for planning; inferred dependencies do not automatically change scores.
  5. Download JSON/CSV. Saving is optional: if you approve a ranking, Decision Lighthouse retains the derived ranking, name, rationale, and approval date—not the source plan or pasted plan text.

Exports, sharing, and privacy

  • Interview File: export Q&A as JSON for your own working record.
  • Assessment HTML: available to the authenticated assessment owner when the assessment is authorized.
  • Report HTML and presentations: generally restricted to organization admins and super admins. Presentations require a completed assessment.
  • Share and comments: use only with stakeholders who are authorized to see the assessment. Follow your organization’s retention and classification policy.
Do not upload secrets. Never put passwords, API keys, private keys, session tokens, or other credentials into an assessment, document, comment, or response.

Common issues

What you seeWhat to do
A stage is lockedComplete the prior stage, or return to Start and resume the current assessment.
AI status is unavailableCheck the Decision Engine Status indicator and ask an administrator to verify the configured AI connection.
The report is still generatingLeave the Report view open or reload later. The platform can recover an in-progress synthesis when the assessment is still authorized.
Export or admin action is unavailableCheck your role. Ask an organization admin to perform the action or grant the appropriate access through your organization’s process.
Uploaded data is rejectedCheck the file type, size, required columns, and whether the file contains any rows. Correct the source and upload again.