Skip to Content
PurviewPrivacy Act ADM Logger

Privacy Act ADM Logger

TL;DR: This skill produces an automated decision-making log for an agent that makes or substantially contributes to a decision affecting an individual, capturing the input data summary, rationale, model identifier, timestamp, and manual review path.

How does the Privacy Act ADM Logger skill document an agent’s automated decision?

The Privacy Act ADM Logger skill produces a structured log entry for each automated decision an Agentic AI system makes about an individual. It records the input data classes, model version, decision outcome, contributing factors and manual review path, and links the entry to a Microsoft Entra agent identity, so a privacy officer can explain the decision on request.

The log is a good-practice record-keeping aid, not legal advice. The fields and the review timeline are this skill’s own design, not a format prescribed by the Privacy Act.

What does the Privacy Act say about automated decisions?

The OAIC states that APPs 1.7, 1.8 and 1.9, introduced by the Privacy and Other Legislation Amendment Act 2024, commence on 10 December 2026. From then, an APP entity that arranges for a computer program to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests, using that individual’s personal information, must include the information set out in APP 1.8 in its privacy policy. That information covers the kinds of personal information used and the kinds of such decisions made.

The OAIC sources below describe a privacy policy disclosure. They do not, in the material reviewed, prescribe a decision log or its contents. Use this log to help gather that information, and confirm the current legal requirements with the OAIC and your privacy officer.

When should you run this skill?

  • “Generate an automated decision-making log”
  • “Document an agent’s automated decision”
  • “Produce an ADM transparency record”
  • “Log an agent decision affecting an individual”

How this skill works, step by step

  1. Identify the decision event: agent identifier, decision timestamp, affected individual reference
  2. Summarise the input data classes used (not the raw data — class names only)
  3. Record the model or rule set identifier and version
  4. Capture the decision output and its impact category (eligibility, ranking, recommendation, denial)
  5. Record the rationale or top contributing factors at the level the agent can produce
  6. Record the manual review path: how the affected individual requests human review, and the timeline
  7. Produce the log entry below (the agentId field holds the Microsoft Entra agent identity identifier you supply)

Output format

{ "decisionId": "<uuid>", "timestamp": "<ISO 8601>", "agentId": "<entra agent id>", "modelVersion": "<id@version>", "subjectReference": "<pseudonymised id>", "inputClasses": ["..."], "decisionOutcome": "...", "impactCategory": "eligibility | ranking | recommendation | denial", "topFactors": ["..."], "manualReviewPath": "...", "retentionUntil": "<ISO 8601>" }

Followed by a plain-English statement of the decision for the affected individual.

Scope and safety

This skill does NOT:

  • Make or override the agent’s decision
  • Store personal information beyond pseudonymised references
  • Replace your organisation’s own privacy impact assessment

Licensing and permissions

This skill is read-only. It authors a log entry from the decision details you supply and does not query tenant data or change any configuration.

Licences

Capability usedWhat Microsoft Learn documents
Microsoft Entra Agent ID, the source of the agent identity you recordAvailable for all Microsoft Entra customers
Extending Microsoft Entra security features to agentsRequires Microsoft Agent 365
Audit (Standard) search and export in Microsoft PurviewRetains records for 180 days; exports up to 50,000 records per search

Least-privilege roles

  • To search or export Microsoft Purview audit records, the Audit Reader role group (grants View-Only Audit Logs) is enough.
  • Microsoft Learn names the Agent ID Developer and Agent ID Administrator roles for creating blueprints and agent identities. It does not document a role for reading them in the sources cited here, so confirm one before granting access.

Microsoft does not document a Purview feature that retains a JSON log authored by this skill. Store the log in a location your organisation already governs, and apply your own retention rule to the retentionUntil value.

Sources

Reviewed 2026-09-30 against the sources below.


Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Get SKILL.md

Last reviewed 2026-09-30 · Published 2026-06-02

Last updated on