AI Agent Builder for Government Employees
Inform
What it collects that can identify you
- The system involves personal information as part of internal automation use cases, which may include employee or user data processed by the AI agents built on the platform.
Also collects operational data, which is anonymized data.
- Run by
- Canada School of Public Service (CSPS)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Accountable organization, Vendor
What it is for
Copilot Studio is a no-code/low-code platform that allows Government of Canada employees to build custom AI agents and automate internal workflows without extensive programming knowledge. It is used exclusively for internal government operations and is currently in development. The system involves personal information and users are informed when AI is in use.
What it collects and what happens to it
Data taken in
- The system involves personal information as part of internal automation use cases, which may include employee or user data processed by the AI agents built on the platform.
- Internal automation use cases drive the data inputs, including administrative records, operational workflows, and government service data used to configure and train the custom AI agents.
Processing
- Copilot Studio is built on Microsoft's large language model infrastructure, enabling natural language understanding and generation within the custom AI agents created by government employees.
What it does
- The platform enables AI agents to plan and execute multi-step internal workflows autonomously, with government employees setting up the workflows and reviewing outcomes.
- Agents built on the platform may classify, score, or route information as part of automated internal workflows; a government employee reviews and decides on resulting actions.
Outputs
- AI agents built on the platform produce recommendations, automated responses, and workflow outputs for internal government use cases, with human employees retaining decision authority.
- Because the system involves personal information, outputs from AI agents may include data linked to specific government employees or individuals processed by internal workflows.
Run by
- The Canada School of Public Service is the federal government department deploying and operating Copilot Studio for internal Government of Canada employee use.
Built by
- Microsoft is the vendor that builds and licenses the Copilot Studio platform used by the Canada School of Public Service.
Kept for
Not stated by the Helpful Places.
Shared with
- Data produced by AI agents built on Copilot Studio is available to the Canada School of Public Service and the government departments operating agents built on the platform.
- As a Microsoft-provided platform, Microsoft may have access to data processed through the Copilot Studio service in accordance with its enterprise agreement and data processing terms with the Government of Canada.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada Algorithmic Impact Assessment Register — Copilot Studio (2526-CSPS-EFPC-019)Canada School of Public Service, AI Register ID 2526-CSPS-EFPC-019.
- AI registerGovernment of Canada AI Register — Copilot Studio
- AI registerGovernment of Canada AI Register — Copilot Studio
- Register entryPublished by the Helpful Places. Reference 70ceb452. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseGovernment of Canada employees and users are informed when AI is in use, as confirmed by the register entry. Users interacting with AI agents built on the platform are made aware of AI involvement.
- Right to Algorithmic TransparencyThe Government of Canada's AI register entry provides public disclosure of the system's purpose and use. Employees can consult the Canada School of Public Service for information about how agents built on the platform operate.
Risks and safeguards
- Civil liberties harmAI agents built by government employees could be used to automate decisions that affect individuals' access to services or rights without adequate oversight.Safeguard: Use is limited to internal government workflows; users are informed when AI is in use; the system is currently in development allowing for policy controls before production deployment.
- Loss of autonomyEmployees building or using AI agents may over-rely on automated outputs, reducing critical human judgment in workflow decisions.Safeguard: The platform positions itself as a tool for government employees who configure and supervise agents; the no-code builder approach keeps humans accountable for what agents are designed to do.