Where automated decisions hide in your Salesforce org: a practical inventory before 10 December 2026

From 10 December 2026, Australian privacy policies have to explain how personal information is used in automated decisions that could significantly affect people. We covered what the rule says in our earlier guide to the 10 December deadline. This piece is about the part that comes first, and the part most teams underestimate: finding the decisions.

You cannot describe your automated decisions in a privacy policy until you know where they are. In most Salesforce orgs, they are spread across more places than anyone expects.

This is general information, not legal advice. Your privacy and legal advisers should make the final call on what your policy says.

Why an inventory comes first

Salesforce is very good at automating work. Over a few years, most orgs build up a layer of Flows, scores, rules and integrations that quietly shape what happens to customers. Each one made sense when it was built. Few of them were ever written down as "decisions".

The new rules, set out in APPs 1.7 to 1.9, ask your privacy policy to cover three things:

  1. The kinds of personal information used in the operation of computer programs that make or help make these decisions.

  2. The kinds of decisions made solely by the operation of those programs.

  3. The kinds of decisions where a thing that is substantially and directly related to making the decision is done by those programs.

That third category matters. A human signing off at the end does not automatically take a decision out of scope if the program did the substantial work. The OAIC consulted earlier this year on how to judge that, including how much people rely on the output, how easily a human can override it, and whether the output is advisory or decisive.

The rules also point to the kinds of decisions that count as significant, including decisions affecting rights or benefits under a law, rights under a contract or agreement, and access to significant services or support.

So the job is not "list our AI". It is "list every place our systems make or substantially shape a decision about a person, and check which of those could significantly affect them".

Where to look in a Salesforce org

Here is where we find automated decisions most often. Work through each area with the person who knows it best.

1. Flow and approval processes

Flow is where a lot of business logic lives, and a lot of it makes decisions. Look for Flows that set a status, approve or decline something, apply a discount or fee, change a service level, or route a customer down one path rather than another. Older Process Builder and Workflow Rules automation that has been migrated to Flow belongs here too.

Ask: does this Flow decide something about a customer, or pre-fill an outcome that a person usually accepts?

2. Scoring and prediction

Lead and opportunity scoring, prediction models built with Einstein, and any custom scores stored on a record. On their own, scores are often advisory. The question is what happens next. If a score decides who gets a call back, who gets an offer, or who gets escalated, and people almost always follow it, record it.

3. Case routing and eligibility rules

In Service Cloud, look at assignment rules, Omni-Channel routing, entitlements and any eligibility checks. Routing a case to the right team is usually low risk. Deciding who qualifies for a service, a refund or a priority channel may not be.

4. Data 360 segments and calculated insights

Data 360 is where customer data comes together, which is exactly why it matters here. Segments and calculated insights often drive who receives what: an offer, a retention call, a change in terms. Map which segments feed downstream actions, and what personal information each one uses.

5. Agentforce actions

If you have switched on Agentforce, list the actions your agents can take and the topics they handle. Agentforce is powerful, and the teams getting the most from it are the ones who can say exactly what each agent is allowed to decide, and on what data.

6. Integrations and AppExchange apps

Decisions do not always happen inside Salesforce. Check integrations that write back outcomes, such as credit checks, fraud screening or pricing engines, and AppExchange packages that add their own logic. If the outcome lands on a customer record and shapes what happens next, it belongs in the inventory.

What to record for each decision

Keep it simple. A spreadsheet is fine. For each automated decision, capture:

  • What it decides: in plain English, the way you would explain it to a customer.

  • Where it lives: the Flow, rule, model, segment, agent or integration.

  • Personal information used: the fields and data sources it relies on.

  • The human role: none, a sign-off, or a genuine review. Be honest about how often people override it.

  • Who is affected: customers, applicants, members, staff.

  • Could it significantly affect someone? Yes, no, or unsure. Unsure goes to your privacy adviser.

  • Owner: the person accountable for keeping this entry current.

Two columns do most of the work: "personal information used" and "could it significantly affect someone". Together they tell your privacy team what the policy needs to say.

Who should own the list

This is a shared job. Your privacy or legal lead knows what the policy needs to cover. Your Salesforce platform owner knows where the logic lives. Neither can complete the inventory alone.

The most effective first step we have seen is also the simplest: put those two people in a room for an hour and ask them to list every place the org makes or shapes a decision about a customer. The list is usually longer than either of them expects. That is a good thing to find out in October rather than in December.

After that, give the inventory an owner and a review rhythm. New Flows and new agents will keep arriving, and the list is only useful if it stays current.

Then update the policy

With the inventory done, the privacy policy update becomes the easy part. Your advisers can describe the kinds of personal information used and the kinds of decisions made, because you can show them exactly what exists. The OAIC is also preparing guidance on the obligation, so keep an eye out for it. Guidance will help you describe your decisions well. It will not find them for you.

A foundation worth having anyway

An inventory like this pays off well beyond compliance. It shows where your automation is doing real work, where it overlaps, and where it relies on data you are not confident in. It is the same foundation that helps every new Salesforce capability, Agentforce included, land well.

If you would like a hand building the inventory, or a second pair of eyes on what you have found, talk to us. We build so your team can run it, and we will leave you with a list your people can keep up to date themselves.

The carbonx Team

Guiding customers through the implementation and adoption of sustainable tech stacks #sustainablestacks

Previous
Previous

Your Salesforce permission model just became your AI policy

Next
Next

Six signs your Salesforce build has quietly stalled (and what a clean remediation looks like)