AI Self-Serve Chatbot Platform for Government Staff
Inform · Research & Development
What it collects that can identify you
- Entra ID integration means the system processes authenticated user identities when employees log in and interact with the chatbot platform. The system handles information up to Protected B, which may include personal information about GC employees.
- User queries, chat history, and interaction patterns within the chatbot interface constitute behavioural input. These are linked to authenticated Entra ID accounts, making them pseudonymous to the system.
Also collects operational data, which is anonymized data.
- Run by
- Global Affairs Canada (GAC)
- Where
- No fixed location
- Kept
- Retained Not specified in the register
- Shared with
- Accountable organization
- Your copy
- You cannot see the data it holds about you. What you can do
What it is for
This platform lets Global Affairs Canada employees create and use AI-powered chatbots to search departmental documents, SharePoint sites, and the internet without writing code. Staff can ask questions and get answers drawn from internal knowledge bases and public web sources. The system handles information up to the Protected B classification level, and employees are informed when they are interacting with AI.
What it collects and what happens to it
Data taken in
- Entra ID integration means the system processes authenticated user identities when employees log in and interact with the chatbot platform. The system handles information up to Protected B, which may include personal information about GC employees.
- The system ingests SharePoint datasets, intranet content, and user-defined knowledge bases — primarily departmental operational documents, policies, and records rather than individual personal records.
- User queries, chat history, and interaction patterns within the chatbot interface constitute behavioural input. These are linked to authenticated Entra ID accounts, making them pseudonymous to the system.
Processing
- The platform provides a wide choice of large language models (LLMs) as the core processing engine, accessed through LangChain and LangGraph orchestration frameworks and Model Context Protocol (MCP).
- SharePoint integration, intranet search, web search, and user knowledge base querying rely on retrieval pipelines — likely retrieval-augmented generation (RAG) — to surface relevant documents in response to employee queries.
What it does
- The system uses semantic search and language understanding to match employee queries to relevant content in SharePoint, the intranet, user knowledge bases, and internet sources. Staff interpret and act on the retrieved information.
- The platform provides access to a wide choice of large language models (LLMs) that generate conversational responses to user queries. Users review and decide whether to act on the generated content.
- Using LangChain, LangGraph, and Model Context Protocol (MCP) orchestration tools, the platform supports multi-step agentic workflows where AI can chain tool calls and actions. Human staff retain oversight and decision authority.
Outputs
- The primary output is AI-generated conversational text responses to employee queries, surfaced in the chat interface. These responses synthesize information from the configured knowledge sources.
- Chatbots may surface recommended documents, suggested next steps, or relevant knowledge base entries in response to staff queries. These are advisory outputs — staff decide whether to act on them.
Run by
- Global Affairs Canada (GAC) is the federal department that deploys and operates this enterprise AI self-serve platform for its staff, enabling chatbot creation and AI-assisted research across departmental systems.
Built by
- The Government of Canada is identified as the developer of this system, supplying the underlying platform infrastructure and AI capabilities deployed by Global Affairs Canada.
Kept for
- The register does not specify a data retention period for chat interactions, knowledge bases, or user activity logs. Retention is likely governed by Government of Canada information management policies and Treasury Board directives, but these are not cited in the register entry.
- Duration: Not specified in the register
Shared with
- This is an internal government platform restricted to GC employees. Members of the public do not have access to the platform or the data it processes.
- GC employees using the platform have access to query outputs and their own interaction history. Platform administrators at Global Affairs Canada have access to usage data and system logs.
Stored
- The platform leverages enterprise AI models and cloud-based tools (including LLM APIs and potentially Microsoft Azure via Entra ID and SharePoint integration), suggesting data is processed and potentially stored on cloud infrastructure. The specific cloud provider and data residency are not stated in the register.
- Duration: Not specified in the register
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada AI Register — Enterprise Self Serve AI (2526-GAC-AMC-016)Global Affairs Canada AI Register entry, accessed 2026-06-10.
- AI registerGovernment of Canada AI Register — Enterprise Self Serve AI
- AI registerGovernment of Canada AI Register — Enterprise Self Serve AI
- Register entryPublished by the Helpful Places. Reference 7fcb8277. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseGC employees are informed when they are interacting with an AI system. The register confirms AI use is disclosed to users of this platform.
- Right to Algorithmic TransparencyInformation about the platform's AI capabilities and data sources is published in the Government of Canada AI Register. GC employees may refer to departmental documentation for further detail on how the system operates.
Risks and safeguards
- Psychological harmLLMs may produce hallucinated or misleading responses that erode staff trust or lead to poor decisions if outputs are accepted uncritically. The system discloses AI use to users, positioning the tool as assistive rather than authoritative. Staff are expected to review and validate AI-generated content before acting on it.
- Civil liberties harmThe system involves personal information and integrates with authenticated identity (Entra ID), creating a risk that employee activity is surveilled or that interaction data is used beyond its stated purpose. Access controls via Entra ID and the restriction to GC employees limit scope. Data classification up to Protected B imposes handling obligations under Treasury Board policy. The register notes AI use is disclosed to users.
- Reputational harmAI-generated responses could misrepresent departmental policy or attribute incorrect positions to the Government of Canada if staff share outputs externally without verification. Mitigations include disclosure of AI use and the expectation that outputs are reviewed before being shared or acted upon.