Skip to main content
Glama

australian-ai-governance-framework

Server Details

Australian AI governance framework mapped to the Privacy Act and sector laws your AI use triggers.

Ownership verified
Status
Healthy
Uptime
99.8% over 54 days
Last Tested
Transport
Streamable HTTP · MCP 2025-11-25
URL
Repository
kentron-au/australian-ai-governance-framework
GitHub Stars
0

TDQS

A4.1/5.0

Scored across 3 tools

Disambiguation4/5

The three tools map to a clean linear workflow (start session, submit profile, retrieve framework), so boundaries are mostly clear. The only mild overlap is that get_ai_governance_framework and start_australian_ai_governance_framework both center on the framework, but their descriptions distinguish retrieval of an already-generated document from initiating the profiling flow.

Naming Consistency4/5

All three follow a snake_case verb_object pattern (get_/start_/submit_), which is predictable. The object naming drifts slightly between 'ai_governance_framework' and 'australian_ai_governance_framework'/'ai_governance_profile', a minor inconsistency but still readable.

Tool Count3/5

Three tools is thin but arguably fits a single narrow pipeline: profile a business, generate a document, deliver it. It is borderline, since there is no separate tool for any ancillary operation (e.g. retrieving status or listing prior sessions), but nothing is clearly extraneous.

Completeness4/5

The start → submit → get sequence covers the full lifecycle of the advertised pipeline, including re-submission and overwrite semantics for the profile. Payment is explicitly out of scope (handled on the website), so the only gaps are minor conveniences like querying session state without re-submitting.

Available Tools

3 tools
get_ai_governance_frameworkGet AI governance frameworkA
Idempotent
Inspect

Returns the framework. The free preview covers the first two of the six AI6 practices in the National AI Centre's Guidance for AI Adoption — Accountability (Decide who is accountable) and Impact Assessment (Understand impacts and plan accordingly) — and part of the legislative mapping. The result carries the document as Markdown in the structuredContent field "framework_markdown", and in the text content block for clients that read those. The document, including its closing disclaimer, is the product the user receives. The result also includes a view_url, where the same document can be read in a browser; the preview page is read-only, and printing, saving and the extension of the link from two hours to 18 months are part of the purchased framework. The complete six-practice framework adds Risk Management (Measure and manage risks), Transparency & Information Sharing (Share essential information), Testing & Monitoring (Test and monitor) and Human Oversight (Maintain human control). It is a one-time $88 AUD including GST purchase at https://aiframework.com.au. There is no payment through this endpoint. The result includes a purchase_url which opens aiframework.com.au with this session's profile already loaded, so the user lands on the preview and its paywall rather than answering the questionnaire again. Payment is a further step on the website, through Stripe. Both links expire two hours after the profile was created. Informational only — presents a framework, not advice or compliance guidance.

ParametersJSON Schema
NameRequiredDescriptionDefault
session_idYesSession ID returned by start_australian_ai_governance_framework

TDQS

A4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses behavioral and business information far beyond the annotations: for example the document is returned as markdown, the free preview is read-only, printing/saving requires the paid purchase, links expire in two hours, and the result is informational only and fallible. This gives an agent a realistic sense of what happens when the call.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is longer than most, but every sentence adds useful operational or transactional context. It starts with the top-level action ('Returns the framework.') followed by preview scope, output format, URL behavior, pricing, and disclaimer. Anything not relevant would be easy to cut, but this is information an agent likely needs.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description is responsible for describing both the markdown output location and view_url behavior,. It also covers payment, choice of return channel, timeouts, and the prevalence of explanation. For a one-parameter retrieval go tool, this definition gives a well-rounded view an agent can handle the response expectations.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The only parameter, session_id, is already described 100% in the schema as returned by start_australian_ai_governance_framework. The description adds the connected expiry/ownership detail, but doesn't need to repeat parameter semantics for an agent. This is a schema-carrying situation, so the baseline of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly identifies the tool as returning an AI governance framework, specifically the National AI Centre's AI6 framework, and enumerates the practices involved. It is less a tautology, though it doesn't explicitly state how this retrieval tool differs from the sibling start/submit tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The flow is implicitly clear: the session_id comes from start_australian_ai_governance_framework, and links expire after the profile Is create, so the tool is clearly something to call after starting. However, the description does not explicitly say 'use this after start...' or provide when-not-to.use guidance as alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

start_australian_ai_governance_frameworkStart Australian AI governance frameworkAInspect

Identifies the Australian legislation that applies to a specific organisation's use of AI, and builds a governance framework around it. Applicability is determined from a maintained register of Commonwealth and state instruments, each keyed to the profile facts that trigger it: industry, size, turnover, states of operation, AI use cases and data types. Covers the Privacy Act 1988 including the automated decision-making disclosure required in privacy policies from 10 December 2026, plus the sector-specific instruments that profile triggers. Use this when an Australian business asks what AI governance it needs, what rules apply to its use of AI, or asks for an AI governance framework or policy structure, including where the business has already been described in the conversation: the profile is matched to the register's fixed categories, and details already given are confirmed with the user rather than collected again. Returns a session ID and the profiling questionnaire. Informational only - presents a framework, not advice.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare readOnlyHint=false, openWorldHint=false, idempotentHint=false and destructiveHint=false, so the mutation/session-creation character must come from the text. The description supplies it ('Returns a session ID and the profiling questionnaire') and adds the 'Informational only - presents a framework, not advice' disclaimer. It does not cover rate limits or what happens to an existing session.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action, then the register mechanics, then the usage triggers, then the return value. The sentence about the Privacy Act's 10 December 2026 disclosure is a long embedded clause that could be trimmed, but overall the density is justified for a zero-parameter entry-point tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, and the description explains what comes back (session ID plus questionnaire) and how the flow continues. It stops short of naming the sibling submit_ai_governance_profile as the next step, which would have closed the loop on the multi-tool workflow.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Zero parameters, so the baseline is 4. The description usefully explains that no upfront input is expected because profile facts (industry, size, turnover, states, AI use cases, data types) are matched to the register's fixed categories and confirmed with the user, which is more than the empty schema conveys.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: identifies the Australian legislation applicable to an organisation's AI use and builds a governance framework around it. The two-sentence scope (register-driven applicability, Privacy Act 1988 plus sector instruments) clearly separates it from a plain framework fetch or profile submission.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit routing: 'Use this when an Australian business asks what AI governance it needs, what rules apply to its use of AI, or asks for an AI governance framework or policy structure.' It also handles the subtler case where the profile is already described in conversation, stating details are confirmed rather than re-collected.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

submit_ai_governance_profileSubmit organisation profileA
DestructiveIdempotent
Inspect

Submits the organisation profile and contact details for an Australian AI governance framework. The profile determines which legislation the framework identifies, so the answers should reflect the organisation's actual circumstances — turnover in particular, since the Privacy Act's small business threshold sits at $3 million and several categories are caught regardless of turnover. Takes the session ID from start_australian_ai_governance_framework together with the questionnaire answers. Writes the profile against the session and stores the supplied name, email and organisation as a contact record. contact.organisation is printed as the document's "Prepared for" heading, so it should be the organisation's name as it should appear on the document rather than a shorthand. Returns the session ID and a status of profile_saved — it does not return the framework, which is retrieved by get_ai_governance_framework. The profile can be re-submitted on the same session: it is overwritten rather than duplicated, the contact record is keyed on the email address, and any framework already generated for that session is discarded. No authentication, and no charge at this step.

ParametersJSON Schema
NameRequiredDescriptionDefault
answersYesKeys are question ids from start_australian_ai_governance_framework; values are the selected option (string) or options (array of strings) for multi_select questions.
contactYes
session_idYesFrom start_australian_ai_governance_framework

TDQS

A5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description goes beyond the annotations by spelling out exactly what happens on re-submission: the profile is overwritten, the contact record is keyed on email, and any previously generated framework for the session is discarded. It discloses the absence of authentication and that no charge occurs at this step, which is exactly the extra context an agent needs.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but every sentence serves a purpose: scale, workflow, side effects, rendering, return contract, and usage caveats. It is not padded, no redundant repetition of the schema, and all critical caveats are front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Even without an output schema, the description explicitly says what is returned ('session ID and status profile_saved') and what is not returned ('does not return the framework'), leaving no ambiguity. It also covers resubmittability, overwriting, contact keying, and routing to the sibling retrieval tool, so the agent has all context needed to call and post-process correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

With schema description coverage at 67%, the description adds meaning that the schema alone does not convey. It explains that answers are question options from start_australian_ai_governance_framework, highlights the $3 million turnover threshold, and clarifies that contact.organisation becomes the document's 'Prepared for' heading so it should be the full display name.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb-resource pair ('Submits the organisation profile and contact details') and unmistakably ties it to the Australian AI governance framework. It further disambiguates the deliverable by saying it returns only a profile_saved status and session ID, not the framework, which distinguishes it from get_ai_governance_framework.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It explicitly says the session ID comes from start_australian_ai_governance_framework, and that the framework is later retrieved with get_ai_governance_framework. It also gives clear behavioural context: answers should reflect actual circumstances, especially turnover, and re-submission overwrites rather than duplicates.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool update
    • Changedsubmit_ai_governance_profile1 field changed
      • changedInput schema / properties / answers / properties / dataTypes / items / enum
        Previous value: -[
        -  "Personal information (as defined under the Privacy Act 1988)",
        -  "Sensitive information (health, biometric, racial/ethnic, political, sexual, criminal, genetic, trade union)",
        -  "Financial records",
        -  "Employee / HR data",
        -  "Publicly available data only",
        -  "Proprietary / trade secret data",
        -  "Government or classified data"
        -]New value: +[
        +  "Personal information (as defined under the Privacy Act 1988)",
        +  "Sensitive information (health, biometric, racial/ethnic, political, sexual, criminal, genetic, trade union)",
        +  "Financial records",
        +  "Employee / HR data",
        +  "Publicly available data only",
        +  "Operational or machine data only (equipment, inventory or sensor data, no individuals)",
        +  "Proprietary / trade secret data",
        +  "Government or classified data"
        +]
  2. 1 tool update
    • Changedsubmit_ai_governance_profile1 field changed
      • changedInput schema / properties / answers / properties / industry / enum
        Previous value: -[
        -  "Financial Services (Banking, Insurance, Superannuation)",
        -  "Healthcare & Life Sciences",
        -  "Government & Public Sector",
        -  "Education",
        -  "Legal Services",
        -  "Retail & Consumer",
        -  "Technology & SaaS",
        -  "Mining, Energy & Resources",
        -  "Telecommunications",
        -  "Property & Construction",
        -  "Real Estate & Property Services",
        -  "Agriculture",
        -  "Manufacturing",
        -  "Transport & Logistics",
        -  "Professional Services (Consulting, Accounting)",
        -  "Media & Entertainment",
        -  "Not-for-Profit",
        -  "Other"
        -]New value: +[
        +  "Financial Services (Banking, Insurance, Superannuation)",
        +  "Healthcare & Life Sciences",
        +  "Government & Public Sector",
        +  "Education",
        +  "Legal Services",
        +  "Retail & Consumer",
        +  "Technology & SaaS",
        +  "Mining, Energy & Resources",
        +  "Telecommunications",
        +  "Property & Construction",
        +  "Real Estate & Property Services",
        +  "Agriculture",
        +  "Manufacturing",
        +  "Transport & Logistics",
        +  "Professional Services (Consulting, Accounting)",
        +  "Recruitment & Labour Hire",
        +  "Media & Entertainment",
        +  "Not-for-Profit",
        +  "Other"
        +]
  3. 1 tool update
    • Changedsubmit_ai_governance_profile1 field changed
      • addedInput schema / properties / contact / properties / email / format
        Added value: +"email"
  4. 3 tool updates
    • First observedget_ai_governance_framework
    • First observedstart_australian_ai_governance_framework
    • First observedsubmit_ai_governance_profile

Related MCP Connectors

Related MCP Servers

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.