AI-Powered Cybersecurity Threat Detection for Government Networks
Safety & Security
What it collects that can identify you
- Login events, email activity, file access records, and cloud workload activity associated with individual Government of Canada employee accounts via the Microsoft 365 tenant.
- Web visits, email interactions, file access patterns, and cloud activity events representing behavioral telemetry of GC employees across enterprise systems.
Also collects operational data, which is anonymized data.
- Run by
- Canada School of Public Service (CSPS)
- Where
- No fixed location
- Kept
- Retained Not specified in the register
- Shared with
- Accountable organization, Vendor
- Your copy
- You cannot see the data it holds about you. What you can do
What it is for
Microsoft Sentinel is a cloud-based security system deployed by the Canada School of Public Service to detect, investigate, and respond to cybersecurity threats across government enterprise systems. It uses machine learning and graph-based analytics to monitor security logs, emails, file access, and cloud activity involving Government of Canada employees. The system processes personal information as part of its security monitoring activities, and affected users are informed that AI is in use.
What it collects and what happens to it
Data taken in
- Login events, email activity, file access records, and cloud workload activity associated with individual Government of Canada employee accounts via the Microsoft 365 tenant.
- Web visits, email interactions, file access patterns, and cloud activity events representing behavioral telemetry of GC employees across enterprise systems.
- Security logs from enterprise systems, Microsoft 365 alerts, and hybrid cloud workload data representing infrastructure and system-level telemetry.
Processing
- Detects anomalies in logins, web visits, emails, file access, and cloud activity using machine learning and graph-based analytics to surface unusual patterns indicative of security threats.
- Classifies security events and assigns threat severity scores using machine learning models trained on enterprise security telemetry, enabling triage and prioritization by security analysts.
What it does
- Uses machine learning and graph-based analytics to detect anomalies in logins, web visits, emails, file access, and cloud activity, producing threat scores and alerts for security analysts to investigate.
- Continuously ingests and parses raw security telemetry — including login events, email metadata, file-access records, and cloud activity logs — turning unstructured event streams into structured detections for downstream analysis.
Outputs
- Threat alerts, anomaly scores, and investigation recommendations surfaced to security analysts, identifying specific accounts, devices, or activities as requiring review or response.
Run by
- The Canada School of Public Service is the federal department responsible for deploying and operating Microsoft Sentinel across its enterprise environment to centralize threat detection and response.
Built by
- Microsoft is the vendor that builds and supplies the Sentinel security intelligence platform, including its machine learning and graph-based analytics capabilities.
Kept for
- Security logs and threat detection records are retained in accordance with Government of Canada records management policies. The specific retention period is not disclosed in the register entry.
- Duration: Not specified in the register
Shared with
- Security alert data, threat intelligence outputs, and investigation records are available to Canada School of Public Service security operations staff and authorized GC security personnel.
- Microsoft, as the cloud platform provider, may have access to telemetry and logs processed within the Microsoft 365 tenant and Azure infrastructure as part of the service delivery agreement.
- Individual GC employees do not have direct access to the threat detection outputs or security logs that the system produces about their own accounts. Security data is available only to authorized security operations staff.
Stored
- Security telemetry, logs, and threat detection outputs are stored within Microsoft's cloud infrastructure via the M365 tenant, operated on behalf of the Canada School of Public Service.
- Duration: Not specified in the register
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerCanada AI and Automated Decision Systems Register — Microsoft Sentinel (2526-CSPS-EFPC-021)Canada School of Public Service, Government of Canada AI Register entry 2526-CSPS-EFPC-021.
- AI registerCanada AI Register — Department field
- AI registerCanada AI Register — Vendor field
- AI registerCanada AI Register — Description field
- AI registerCanada AI Register — Capabilities field
- AI registerCanada AI Register — Capabilities field
- AI registerCanada AI Register — Data sources and Capabilities fields
- AI registerCanada AI Register — Capabilities field
- AI registerCanada AI Register — Data sources field
- AI registerCanada AI Register — Capabilities field
- AI registerCanada AI Register — Capabilities field
- AI registerCanada AI Register — Description and Capabilities fields
- AI registerCanada AI Register — Involves personal information, AI use disclosed fields
- AI registerCanada AI Register — Capabilities and Primary users fields
- AI registerCanada AI Register — AI use disclosed to users field
- AI registerCanada AI Register — Primary users and Capabilities fields
- AI registerCanada AI Register — Primary users field
- AI registerCanada AI Register — Vendor and Data sources fields
- AI registerCanada AI Register — Primary users field
- AI registerCanada AI Register — Data sources field
- AI registerCanada AI Register — Microsoft Sentinel entry
- Register entryPublished by the Helpful Places. Reference 5849f4fe. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseGC employees are informed that AI is in use for security monitoring of their enterprise accounts. The register confirms that AI use is disclosed to users. Contact the Canada School of Public Service privacy office for further information.
- Right to a Human ReviewThreat alerts and anomaly detections are reviewed by human security analysts before any investigative or response action is taken. The system is designed to inform, not replace, human decision-making in security operations.
Risks and safeguards
- Civil liberties harmContinuous behavioural monitoring of GC employee accounts — including emails, web visits, and file access — creates broad workplace surveillance that may chill lawful communications and raise privacy concerns.Safeguard: The register discloses that AI use is communicated to users, and the system is scoped to security threat detection rather than performance management. Oversight is conducted by security professionals rather than automated discipline systems.
- Reputational harmFalse positive threat detections could incorrectly flag a GC employee as a security risk, potentially triggering investigations or disciplinary action based on erroneous AI output.Safeguard: The system surfaces recommendations to human security analysts (human-in-the-loop), who are responsible for investigating and verifying alerts before any consequential action is taken.