Skip to content
This is NOT an official site of the Government of Canada. Click here for the official AI registry.

AI-Powered Cybersecurity Threat Detection for Government Networks

Safety & Security

What it collects that can identify you

Sensitive personal information
Identifiable data
  • Login events, email activity, file access records, and cloud workload activity associated with individual Government of Canada employee accounts via the Microsoft 365 tenant.

Canada AI Register — Data sources and Capabilities fields

About behaviour
Pseudonymous data
  • Web visits, email interactions, file access patterns, and cloud activity events representing behavioral telemetry of GC employees across enterprise systems.

Canada AI Register — Capabilities field

Also collects operational data, which is anonymized data.

Run by
Canada School of Public Service (CSPS)
Where
No fixed location
Kept
Retained Not specified in the register
Shared with
Accountable organization, Vendor
Your copy
You cannot see the data it holds about you. What you can do

What it is for

Microsoft Sentinel is a cloud-based security system deployed by the Canada School of Public Service to detect, investigate, and respond to cybersecurity threats across government enterprise systems. It uses machine learning and graph-based analytics to monitor security logs, emails, file access, and cloud activity involving Government of Canada employees. The system processes personal information as part of its security monitoring activities, and affected users are informed that AI is in use.

What it collects and what happens to it

Data taken in

Sensitive personal information
Identifiable data
  • Login events, email activity, file access records, and cloud workload activity associated with individual Government of Canada employee accounts via the Microsoft 365 tenant.

Canada AI Register — Data sources and Capabilities fields

About behaviour
Pseudonymous data
  • Web visits, email interactions, file access patterns, and cloud activity events representing behavioral telemetry of GC employees across enterprise systems.

Canada AI Register — Capabilities field

Operational data
Anonymized data
  • Security logs from enterprise systems, Microsoft 365 alerts, and hybrid cloud workload data representing infrastructure and system-level telemetry.

Canada AI Register — Data sources field

Processing

Anomaly Detection
  • Detects anomalies in logins, web visits, emails, file access, and cloud activity using machine learning and graph-based analytics to surface unusual patterns indicative of security threats.

Canada AI Register — Capabilities field

Classification & Prediction
  • Classifies security events and assigns threat severity scores using machine learning models trained on enterprise security telemetry, enabling triage and prioritization by security analysts.

Canada AI Register — Capabilities field

What it does

Deciding (Analytical AI)
Human decides
  • Uses machine learning and graph-based analytics to detect anomalies in logins, web visits, emails, file access, and cloud activity, producing threat scores and alerts for security analysts to investigate.

Canada AI Register — Capabilities field

Sensing (Perceptive AI)
Autonomous
  • Continuously ingests and parses raw security telemetry — including login events, email metadata, file-access records, and cloud activity logs — turning unstructured event streams into structured detections for downstream analysis.

Canada AI Register — Capabilities field

Outputs

A recommendation or prediction
Identifiable data
  • Threat alerts, anomaly scores, and investigation recommendations surfaced to security analysts, identifying specific accounts, devices, or activities as requiring review or response.

Canada AI Register — Description and Capabilities fields

Run by

Canada School of Public Service (CSPS)
  • The Canada School of Public Service is the federal department responsible for deploying and operating Microsoft Sentinel across its enterprise environment to centralize threat detection and response.

Canada AI Register — Department field

Built by

Microsoft
  • Microsoft is the vendor that builds and supplies the Sentinel security intelligence platform, including its machine learning and graph-based analytics capabilities.

Canada AI Register — Vendor field

Kept for

Retained Not specified in the register
  • Security logs and threat detection records are retained in accordance with Government of Canada records management policies. The specific retention period is not disclosed in the register entry.
  • Duration: Not specified in the register

Canada AI Register — Microsoft Sentinel entry

Shared with

Available to the accountable organization
  • Security alert data, threat intelligence outputs, and investigation records are available to Canada School of Public Service security operations staff and authorized GC security personnel.

Canada AI Register — Primary users field

Available to vendor
  • Microsoft, as the cloud platform provider, may have access to telemetry and logs processed within the Microsoft 365 tenant and Azure infrastructure as part of the service delivery agreement.

Canada AI Register — Vendor and Data sources fields

Not available to me
  • Individual GC employees do not have direct access to the threat detection outputs or security logs that the system produces about their own accounts. Security data is available only to authorized security operations staff.

Canada AI Register — Primary users field

Stored

Stored on 3rd Party Cloud
  • Security telemetry, logs, and threat detection outputs are stored within Microsoft's cloud infrastructure via the M365 tenant, operated on behalf of the Canada School of Public Service.
  • Duration: Not specified in the register

Canada AI Register — Data sources field

How to read the colours

Can it identify you?

Anonymized data
Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
Pseudonymous data
Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
Identifiable data
The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.

Who completes the loop?

Human decides
This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
Human executes
This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
Autonomous
This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.

Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.

What you can do

Ask about this system

Questions go to the Helpful Places, not the vendor.

Your rights

  • Right to Be Informed of AI UseGC employees are informed that AI is in use for security monitoring of their enterprise accounts. The register confirms that AI use is disclosed to users. Contact the Canada School of Public Service privacy office for further information.
  • Right to a Human ReviewThreat alerts and anomaly detections are reviewed by human security analysts before any investigative or response action is taken. The system is designed to inform, not replace, human decision-making in security operations.

Risks and safeguards

  • Civil liberties harmContinuous behavioural monitoring of GC employee accounts — including emails, web visits, and file access — creates broad workplace surveillance that may chill lawful communications and raise privacy concerns.Safeguard: The register discloses that AI use is communicated to users, and the system is scoped to security threat detection rather than performance management. Oversight is conducted by security professionals rather than automated discipline systems.
  • Reputational harmFalse positive threat detections could incorrectly flag a GC employee as a security risk, potentially triggering investigations or disciplinary action based on erroneous AI output.Safeguard: The system surfaces recommendations to human security analysts (human-in-the-loop), who are responsible for investigating and verifying alerts before any consequential action is taken.