Frequently asked questions
Short answers to the questions staff ask most about data, access, validation, cost and support.
For: Everyone · 4 min read
Can I put customer data in a GenAI prompt?
Not unless the GenAI asset is approved for it and you are entitled to the data. Every prompt is screened on the way in: customer names, MyKad numbers, account numbers and similar identifiers are blocked for assets that are not approved for customer data.
Never paste customer data into a public AI tool outside the platform.
Why was my access request returned?
Most returns are for one of three reasons: the purpose was too vague to check ("analysis" is not a purpose), the duration was longer than the purpose needs, or the data asked for was wider than the purpose (customer-level where an aggregate would do).
The reviewer's note says which. Fix it and resubmit the same request.
How long does an access decision take?
Internal assets are granted instantly. Confidential requests are typically decided within 2 working days. Strictly Confidential requests need the data owner's consent and usually take 3 to 5 working days.
How long does validation take?
It depends on the risk tier and on how complete your pack is. As a guide: Tier 3 reproductions take days, Tier 2 independent validation takes 2 to 4 weeks, and Tier 1 challenged validation takes 4 to 8 weeks. Incomplete packs are returned at intake, which is the most common cause of delay.
Who pays for my usage?
The cost centre on the call. Every API call and notebook session is tagged with a cost centre and charged back monthly in MYR. New usage appears as showback for a month before it is charged.
Should I build my own model or reuse one?
Reuse first. Search the catalogue and the use-case pipeline. If something is close, ask the owner whether it can be extended; a new version is cheaper to validate than a new model.
Do I need to request access to my own division's assets?
No. Your division can always call the assets it owns. You still need a service account with the right scopes for an application.
Can I use real customer data in the sandbox?
No. The sandbox runs on synthetic, specimen or masked data, even for assets you are entitled to. Real data is only used in the production environment, in the Malaysia region.
A model gave a result that looks wrong. What do I do?
Do not override the control it supports without following your usual process. Raise an Asset quality ticket with the request_id, the input and why the result looks wrong. The owner and, for validated models, Model Risk Management will see it.
How do I explain a credit decision to a customer?
Credit models return reason codes with every score. Use them in the adverse-outcome letter; the Credit Decision Explainer prompt drafts plain-language wording from them for your review.
What happens when my entitlement expires?
You are reminded 30 days before. If it lapses, calls return 403 and the scope stops working on every service account that carries it. Renew by confirming the purpose still holds.
Do I have to use the SDK to call a model?
No. Every asset has a REST API. The alliance_ai SDK handles authentication, cost-centre tagging, audit headers, retries and entitlement checks for you, so most teams use it.
The model I use is drifting. Should I stop using it?
Not automatically. The drift case says how much performance has moved. The owner tells consuming teams whether to continue, add a manual check, or pause until the retrained version is live.
I am moving to another department. What happens to my access?
Personal entitlements are revoked when your department changes and you request what the new role needs. Service accounts belong to applications, not people, so they keep working; hand ownership over before you move.
Can I use a model from an approved vendor?
Yes, if it is in the catalogue. Vendor models go through the same validation and outsourcing controls, and the licence cost is included in the chargeback rate. To bring in a new vendor model, raise a use case.
Read next
Was this helpful?