Privacy Act ADM Logger
TL;DR: This skill produces an automated decision-making log for an agent that makes or substantially contributes to a decision affecting an individual, capturing the input data summary, rationale, model identifier, timestamp, and manual review path.
How does the Privacy Act ADM Logger skill document an agent’s automated decision?
The Privacy Act ADM Logger skill produces a structured log entry for each automated decision an Agentic AI system makes about an individual. It records the input data classes, model version, decision outcome, contributing factors and manual review path, and links the entry to a Microsoft Entra agent identity, so a privacy officer can explain the decision on request.
The log is a good-practice record-keeping aid, not legal advice. The fields and the review timeline are this skill’s own design, not a format prescribed by the Privacy Act.
What does the Privacy Act say about automated decisions?
The OAIC states that APPs 1.7, 1.8 and 1.9, introduced by the Privacy and Other Legislation Amendment Act 2024, commence on 10 December 2026. From then, an APP entity that arranges for a computer program to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests, using that individual’s personal information, must include the information set out in APP 1.8 in its privacy policy. That information covers the kinds of personal information used and the kinds of such decisions made.
The OAIC sources below describe a privacy policy disclosure. They do not, in the material reviewed, prescribe a decision log or its contents. Use this log to help gather that information, and confirm the current legal requirements with the OAIC and your privacy officer.
When should you run this skill?
- “Generate an automated decision-making log”
- “Document an agent’s automated decision”
- “Produce an ADM transparency record”
- “Log an agent decision affecting an individual”
How this skill works, step by step
- Identify the decision event: agent identifier, decision timestamp, affected individual reference
- Summarise the input data classes used (not the raw data — class names only)
- Record the model or rule set identifier and version
- Capture the decision output and its impact category (eligibility, ranking, recommendation, denial)
- Record the rationale or top contributing factors at the level the agent can produce
- Record the manual review path: how the affected individual requests human review, and the timeline
- Produce the log entry below (the
agentIdfield holds the Microsoft Entra agent identity identifier you supply)
Output format
{
"decisionId": "<uuid>",
"timestamp": "<ISO 8601>",
"agentId": "<entra agent id>",
"modelVersion": "<id@version>",
"subjectReference": "<pseudonymised id>",
"inputClasses": ["..."],
"decisionOutcome": "...",
"impactCategory": "eligibility | ranking | recommendation | denial",
"topFactors": ["..."],
"manualReviewPath": "...",
"retentionUntil": "<ISO 8601>"
}Followed by a plain-English statement of the decision for the affected individual.
Scope and safety
This skill does NOT:
- Make or override the agent’s decision
- Store personal information beyond pseudonymised references
- Replace your organisation’s own privacy impact assessment
Licensing and permissions
This skill is read-only. It authors a log entry from the decision details you supply and does not query tenant data or change any configuration.
Licences
| Capability used | What Microsoft Learn documents |
|---|---|
| Microsoft Entra Agent ID, the source of the agent identity you record | Available for all Microsoft Entra customers |
| Extending Microsoft Entra security features to agents | Requires Microsoft Agent 365 |
| Audit (Standard) search and export in Microsoft Purview | Retains records for 180 days; exports up to 50,000 records per search |
Least-privilege roles
- To search or export Microsoft Purview audit records, the Audit Reader role group (grants View-Only Audit Logs) is enough.
- Microsoft Learn names the Agent ID Developer and Agent ID Administrator roles for creating blueprints and agent identities. It does not document a role for reading them in the sources cited here, so confirm one before granting access.
Microsoft does not document a Purview feature that retains a JSON log authored by this skill. Store the log in a location your organisation already governs, and apply your own retention rule to the retentionUntil value.
Related skills
- Entra Agent ID Audit: before: lists every agent identity and flags agents with no accountable sponsor
- Agent Audit Trail and Forensics Investigation: after: reconstructs the action timeline for a specific agent or user
- Compliance Manager Control Mapper: after: maps tenant controls to the ISM, Essential Eight, SOCI and the Privacy Act
- Governing AI Agents in Microsoft 365: pillar: govern agents by finding them first, then check tools, data policies and access
- Australian Compliance for Microsoft 365 Copilot and AI: pillar: Australian compliance starts with the tenant you already run
Sources
Reviewed 2026-09-30 against the sources below.
- OAIC APP Guidelines, Chapter 1: APP 1 Open and transparent management of personal information
- OAIC consultation on guidance for transparency in automated decision making
- Microsoft Entra licensing
- Migrate custom app registrations to Agent ID
- Get started with auditing solutions
- Export, configure, and view audit log records
- Learn about auditing solutions in Microsoft Purview
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-09-30 · Published 2026-06-02