Accounts receivable management

The collection floor is changing.
Your system of record hasn't.

The platforms most agencies run today were designed so a human sits in front of an account. Everything since — dialers, letter queues, workflow rules, and now a chatbot bolted to a status code — has been an accessory to that assumption.

Misma ARM starts from the other end. AI agents do the work; your people run the system. That is not a feature list. It is a different data model, a different compliance posture, and a different definition of done.

No demo booking. No gated PDF. The platform's own Help Agent answers concretely — or admits it can't.

What "AI-first" actually has to mean

Any vendor can add a model to a legacy schema and call it AI. The question a seasoned operator should ask is what happens the first time that model is wrong, at 2am, on ten thousand accounts.

A system where agents do the work must be able to answer, for any account at any moment: what happened, who decided it, what were they looking at, what were they permitted to do, and could it have gone otherwise. A status column and a chat log cannot answer that. Everything below exists because those five questions have to have answers.

Status is a column somebody setsDisposition is a calculated function
Compliance is training and hopeCompliance is code in front of every send
Merged consumers, unmergeableClusters that retract cleanly
"Our records show…"Hash-chained, provable in a deposition
Rule change = mass update scriptRule change = a version
Go live and find outNo certified simulation, no live sends

Architecture

The mechanisms, not the adjectives

Every fact is an event

No row is updated in place to represent state. The envelope is bitemporal — when it happened, and when you learned it — because a remittance file on Tuesday describes a payment made Friday, and returned mail surfaces three weeks late.

You can ask what was true on the 14th and what you knew on the 14th, and get two different, correct answers.

Dispositions are calculated

There is no status column anyone can set. Disposition is a pure, versioned function over facts, evaluated as of a moment. Client status codes are views over it — including each client's own dialect.

Status drift becomes structurally impossible. A rules change is a version, not a four-million-row update with a rollback plan.

The gate refuses, and records it

Consent, quiet hours in local time, frequency caps at every applicable jurisdiction, holds, validation windows — evaluated deterministically before every outbound action. Not a model's judgment.

A block is a recorded fact with its reasons. That is a bona fide error defense with evidence attached, not a belief.

Cluster, never merge

Identity records stay pristine as received. A person is a computed cluster over link events, each with its own confidence and provenance.

Low confidence suppresses contact; only high confidence attaches money or disclosures. An unmerge is a retraction, not database surgery.

Documents prove themselves

Artifacts are content-addressed — named by the hash of their own bytes — with the data, template and content versions, delivery, and portal token preserved alongside.

"Prove this is exactly what we sent" is a lookup. A litigation pack is a projection, not a scavenger hunt.

Terms, not template sprawl

Language that varies by state, client, product and status resolves at render time from most specific to general, with the conditional logic where the legal language actually interacts with account facts.

One template, resolved terms. Adding a jurisdiction is content, not a release.

Counterparties are certified

Vendors and clients board as versioned specifications carrying credential references, never values. Certification is a human act over an all-green conformance report.

An uncertified adapter does not run. Mocks learn from real drift, so the sandbox keeps getting more honest.

Go-live is gated

Every agency runs its book in a full simulator first — mock vendors, mock clients, simulated consumers, a controllable clock — and a human certifies the session.

No certified session, no live sends. The gate is in the apply path, not in UI politeness.

The path of one outbound message

Nothing reaches a consumer without passing all of it

event log hash-chained disposition calculated policy gate consent · hours · caps holds · jurisdiction render terms resolved artifact content-addressed blocked · recorded outcome returns as a new fact

The refusal path is not an error path. It is a first-class outcome with reasons, and it is the record you want when someone asks why an account was contacted — or why it wasn't.

Compliance, legal, and medical

The parts that end careers

Unknown is not permission

If a consumer's time zone can't be established, the gate does not assume Eastern and proceed. Missing information narrows what is allowed — every time, without anyone remembering to be careful.

Human in the loop, structurally

Applying configuration, certifying go-live, approving a settlement past a limit, issuing a refund — these require a named human. Not a permission an agent lacks and might be granted by a misconfigured checkbox: the tool does not exist in the agent's surface.

Medical is a regime, not a flag

Models in the path of PHI are only usable under a signed BAA with zero retention, enforced by routing rather than by policy memo. The voice agent holds no direct store access at all — a HIPAA boundary that doubles as prompt-injection containment, because the caller is untrusted input.

Litigation packs, on demand

Full event history with actors and timestamps, every document with proof of contents, every gate decision including refusals, consent with provenance, identity links with confidence, disposition history with the rules version behind each state.

Obligations have clocks

Media requests, validation, disputes, and credit-reporting investigations are tracked as obligations with their own timers and cascading holds — not as flags somebody is supposed to notice.

Tenancy is real isolation

Each agency's data lives in its own database — never co-mingled rows behind a tenant column — and its agents run on that agency's own provider credentials, with their own memory on their own storage. There is no shared key your traffic silently rides on, and no cross-tenant path.

Learn

The questions operators actually ask

Straight answers, mechanism first. These are the questions we hear from people who have run agencies for decades — and every answer below is a structural fact of how the platform is built, not a policy we hope holds.

How do I know my data isn't accessible to other tenants?

Because there is no path, not because there is a rule. Each agency's book lives in its own database — your facts, your documents, your configuration are not rows co-mingled in a shared table with a tenant column; they are physically yours. Inside it, every record still carries its tenant and every read is still scoped in the query itself — defense in depth, not the only defense — and there is no "all tenants" read in the working system.

The isolation goes further than the data. Every tenant holds its own AI provider keys in its own encrypted vault — there is no shared platform key your traffic silently rides on. Your admin agents run in your own dedicated container, with their own memory on their own storage: your System Specialist has never seen another agency's book and has no route to it. And documents live in per-tenant custody, reachable only through your own attachment records. If one tenant's key were ever compromised, it is one tenant's key.

How do you mitigate prompt injection?

By making sure the agents that untrusted people can talk to have nothing to give up. A consumer on a phone call is untrusted input speaking directly into a model — so the phone agent has zero access to the data store. It works inside a bounded envelope the system hands it for that one call. The portal's concierge holds nothing until right-party verification passes. Talk either of them into anything you like; there is nothing behind them to reach.

For every agent, the tools, the loop, and the record belong to code — the model only decides. A model cannot call a tool it wasn't given, widen its own negotiation envelope, or skip the record. And the compliance gate in front of every outbound channel is not a model at all: it is deterministic code, and it cannot be argued with. What a visitor types is treated as data, never as instruction — including on this page: the agent below holds a public knowledge pack and nothing else, and it will tell you so itself.

How do agents in the mesh communicate with each other?

Not by chatting. Hand-offs between agents are structured, recorded work products: the strategist publishes an approved plan; the outreach planner picks from a menu the gate has already screened; the account specialist hands the phone agent a bounded envelope — "you may offer down to this, stop if they mention an attorney"; the background specialists come back with evidence attached to a review request a human answers.

The permanent record is the medium. Each hand-off lands as facts in the event log — who produced it, under which approved version, on what evidence — so "why did the AI do that?" is a query, not a mystery. And because authority originates only in configuration a named human applied, one agent cannot grant another agent power that no human ever clicked.

How can you say the event history is immutable?

Nothing is edited and nothing is deleted — the log is append-only, and each event is hash-chained to what came before, so tampering breaks the chain visibly. Corrections are new events that point at what they correct: a reversed payment shows the payment, the reversal, and the link between them, permanently. Retiring a client or removing a policy is a recorded act, not an erasure.

It works the way the notes on an account have always worked — you never go back and edit what happened last March; you add today's entry. We apply that rule to everything: every letter, every call, every payment, every rule change, every configuration a human approved. That is why "prove what happened" is a replay, not an argument.

What are the benefits of event sourcing?

Replay is the headline: reconstruct exactly what the system knew and believed about any account at any moment in the past — through the rules as they stood that day. Dispute substantiation inside the 60-day clock, a client's "show me everything you did in Q2," a regulator's "why was this account called at 2:14pm" — each is a query, not a project.

Stale status becomes structurally impossible, because nothing stores a status: workability is calculated from the facts every time. Each client's status codes are views over the same facts — no parallel fields drifting out of sync. New kinds of facts don't need new columns, so thirty years of field sprawl never happens. And because configuration changes live in the same log, "what were your contact-frequency rules the day this call was placed" has a provable answer.

What communication channels are supported?

Voice in and out — AI agent or your own collectors, with the AI copilot beside them — SMS, email, printed letters, and the consumer portal, where consumers verify, chat, pay, set up plans and autopay, and view their documents. One notice is one template with per-channel renderings, so the email, the text, and the letter never drift apart; treatments can escalate by engagement — email unopened, text with a secure link, then paper.

Two constants across every channel: everything outbound passes the compliance gate — consent, quiet hours, frequency caps, legal state, checked at send time — and everything sent lands in evidence custody at the moment it happens. The letter in the archive is byte-for-byte the letter that mailed.

Do I need third-party vendors?

Not to start. Carriers, print and mail, payment processing — the platform runs them under its own negotiated accounts by default, so a new agency brings zero vendor contracts to go live. If you have your own relationships and your own rates, bring them: your credentials go into your tenant's vault and your traffic runs on your account instead.

Either way, two rules hold. Every counterparty is certified before it carries live traffic — an uncertified adapter does not run. And vendors are transient sources, never the warehouse: the evidence of every interaction lands in your custody at the moment it happens, so no vendor's retention window ever decides what you can prove.

Have a question that isn't here? That's what the agent below is for — and when it can't answer something, it says so plainly and we go find out.

Ask the platform

The Help Agent — the platform's teacher, and its own best exhibit

This is the same Help Agent that runs inside the product, and its construction is the first thing to notice: it has no tools, no database access, no account data — nothing but a public knowledge pack. Ask it whether it can read your data; it will tell you the honest answer. That is what our AI safety story looks like everywhere: an agent's limits are built, not promised.

Ask it the questions above, or the one you actually care about. It answers concretely — and when something falls outside what it knows, it says so plainly.

Start the conversation

One click to confirm your email, then the agent is open. We verify because the conversation costs us real money to run — and because we read every one and follow up like it matters.

Early adopters

Sign up to be an early adopter

We are bringing on a small number of agencies to run the platform with us before it is generally available. You get the architecture on your own book of business and a direct line to the people building it; we get the scenarios that make it better.

Tell us about your shop and where you stand with AI. A person reads every one of these and replies.