Simple Intelligence
Business Apps · In Development

Simple Bridge
The governance-embedded connector catalog inside SimpleFlow.

For Regulated-vertical buyers (healthcare, financial services, defense, energy) whose procurement teams reject connectors without a documented action-authority inventory, kill-switch, and compliance-profile variant. Sold as part of SimpleFlow; not a standalone SKU.

Every SimpleFlow connector runs through Simple Bridge, which carries a Gifford-aligned action-authority inventory, a documented kill-switch endpoint, and a compliance-profile variant (HIPAA, SOX, FedRAMP, PCI-DSS, ISO 27001). Regulated-vertical customers clear the procurement gate on day one. Microsoft's Premium tier is a licensing bucket, not a compliance grade. Simple Bridge is.

Replaces MuleSoft (regulated variants) Boomi (compliance packs) Ungoverned Zapier connectors
Web Planned Copilot Planned

Procurement rejects connectors that can't answer three questions.

What can this connector actually do? How do we shut it off if it misbehaves? What compliance frame does it map to? Every regulated buyer asks the same three questions, and most connector catalogs (Zapier, Make, off-the-shelf iPaaS) can't answer any of them without a services engagement. That's why regulated verticals still hand-build point-to-point integrations they can't maintain.

Microsoft's Premium tier is a licensing bucket, not a compliance grade.

Getting a Premium connector into Power Platform doesn't make it HIPAA-compliant or FedRAMP-compliant. Those are two different questions the market conflates. Simple Bridge separates them: the Microsoft cert path is one axis (Premium / Standard / Custom), the compliance-profile variant is a second axis that regulated buyers need answered independently.

Simple Bridge is the connector catalog inside SimpleFlow.

Every SimpleFlow customer gets Simple Bridge automatically. Not sold as a separate SKU, not a separate purchase, not a different Marketplace listing. It's the catalog the customer sees when they add a connector step to a workflow, and it's what makes SimpleFlow a real answer to the regulated-iPaaS question rather than another Zapier variant.

From Entra consent to first evidence pack.

1

Pick a connector

From the SimpleFlow workflow designer, the customer picks a connector for their step. Simple Bridge surfaces the connector's action-authority manifest inline before commit: every read, write, action, and escalation is enumerated with named permission scopes and MCP server allowlists.

2

Simple Bridge picks the lane

Based on the customer's compliance-profile setting on their tenant, Simple Bridge routes the connector through the correct Microsoft integration lane: Power Platform Premium (write authority with end-user identity), Copilot Connector (federated MCP, no data movement), or Custom OpenAPI. The four Copilot Studio insertion points that apply are named on the manifest.

3

Kill-switch + downstream notification

Simple Bridge inserts the kill-switch endpoint and the downstream notification template into the customer's workflow. Named invokers on both the publisher side and the customer side are captured. This is the piece the customer's IR playbook actually calls when a connector misbehaves.

4

Evidence pack generated at deploy

When SimpleFlow deploys the workflow into the customer's tenant via Azure Lighthouse, Simple Bridge emits the evidence pack as a deployment artifact: control mappings for the chosen compliance profile, config snapshots, seam definitions, escalation policies, downstream notification templates. Auditor-ready without a services engagement.

What ships in the box.

Three-lane routing

Every connector pre-classified across Microsoft's three official integration paths: Power Platform (Standard / Premium / Custom), Microsoft Copilot connectors (synced Graph-indexed plus federated MCP-based), Custom OpenAPI. The manifest names the recommended lane and the four Copilot Studio insertion points that apply.

Action-authority inventory

Every read, write, action, and escalation the connector exposes is enumerated in a manifest the customer's procurement team attaches to the MSA. Permission scopes are named verbatim, MCP server allowlists are listed. This is the document the customer hands to their auditor.

Kill-switch primitives

Every connector wraps its underlying system with a documented disable endpoint, an SLA for effectiveness, and a named list of authorized invokers on both the publisher side and the customer side. Standard IR playbook can call it directly without a support ticket.

Compliance-profile variants

Each connector ships in a base profile plus regulated variants: HIPAA (patient data, PHI transit controls), SOX (financial record integrity), PCI-DSS (cardholder data segmentation), FedRAMP Moderate (data-residency controls), ISO 27001 (control mapping). The customer picks the variant that matches their obligation.

Customer evidence pack

Every connector deployment produces a downloadable audit bundle: control mappings, config snapshots, seam definitions, escalation policies, and downstream notification templates. Regenerable on demand for annual audit refreshes.

Federated-first for regulated content

Where source data must not leave the source system (HIPAA, PCI, SOX), Simple Bridge defaults to Microsoft's federated Copilot Connector lane (MCP-based, no data movement, permissions enforced by source). Where the workflow requires write authority, Simple Bridge routes through Power Platform Standard or Premium under end-user identity.

Where your data lives, where audit lives, who can sign in.

MCP Registry is the underlying protocol

Simple Bridge is the customer-facing name; MCP Registry is the internal architectural term for the registry protocol Simple Bridge implements, aligned with Anthropic's Model Context Protocol and Microsoft's Copilot connector federation surface. Marketing and buyer conversations use Simple Bridge; engineering specs can reference the MCP Registry layer for precision.

Deployed per-tenant via Azure Lighthouse

Every connector lands inside the customer's own Azure subscription via SimpleFlow's Lighthouse deployment path. Customer data never crosses into SIG's subscription. Only workflow metadata and audit trail flow to the SIG control plane.

Certified through Microsoft Power Platform Connector Certification

Every SimpleFlow connector goes through Microsoft Power Platform Connector Certification, which lands the connector in Azure Logic Apps, Microsoft Power Automate, Microsoft Power Apps, and Microsoft Copilot Studio from one certification pass.

Evidence chain lands in customer Purview

The evidence pack, kill-switch invocation logs, and connector action audit trails write to the customer's own Purview tenant. Auditors read the same surface they already read for agent-call decisions from Simple Council.

Microsoft-first. Cross-vendor where Agent 365 already syncs.

Microsoft data + security

Microsoft Fabric Microsoft Sentinel Microsoft Purview Microsoft Defender XDR Microsoft Entra ID + Agent 365

Microsoft business apps

Dynamics 365 Sales Dynamics 365 Customer Service Dynamics 365 Finance and Operations Dynamics 365 Human Resources Microsoft Fabric semantic models

Cross-vendor SaaS (federated)

Salesforce (Sales / Service / custom objects) ServiceNow (Incident / Change / CMDB / Knowledge) SAP (S/4HANA / SuccessFactors / Ariba) Workday HCM ADP (Workforce Now / Vantage HCM)

Data + collaboration

Snowflake Databricks (Direct Lake, Fabric mirroring) Confluence Zendesk Google Workspace Box Epic FHIR

SIG portfolio

SimpleFlow (parent product) Simple Council (governance plane) Simple Atlas (white-label distribution)

MACC-eligible. Charged through your Azure consumption.

Starter
Base connectors, no compliance variants
Included with SimpleFlow Starter
  • Base-profile connectors only
  • Standard action-authority inventory
  • Kill-switch endpoint
  • Standard downstream notification templates
Enterprise
FedRAMP, PCI-DSS, ISO 27001, custom compliance frames
Included with SimpleFlow Enterprise
  • All five compliance-profile variants
  • FedRAMP Moderate lane
  • Custom compliance-frame authoring
  • Annual audit-refresh evidence-pack regeneration
  • Dedicated connector-request queue
Storage posture
Persistent audit metadata (per SimpleFlow) with federated-first data pass-through where regulated
Certification target
Microsoft Power Platform Connector Certification
Distribution
Azure Marketplace (bundled with SimpleFlow)
Status
In Development

The questions buyers ask in the first call.

Can I buy Simple Bridge without SimpleFlow?

No. Simple Bridge is the connector catalog inside SimpleFlow. Every SimpleFlow customer gets it automatically; it's not sold as a separate SKU or Marketplace listing.

How is this different from Power Platform Premium connectors?

Microsoft's Premium tier is a licensing bucket that gates certain connectors and features. It doesn't make a connector HIPAA-compliant or FedRAMP-compliant. Simple Bridge separates the two axes: Microsoft cert path (Standard / Premium / Custom) is one axis, compliance-profile variant (HIPAA / SOX / FedRAMP / PCI-DSS / ISO 27001) is a second axis.

What is MCP Registry?

MCP Registry is the internal engineering name for the underlying registry protocol Simple Bridge implements. It aligns with Anthropic's Model Context Protocol and Microsoft's Copilot connector federation surface. Buyers and marketing copy use Simple Bridge exclusively; engineering specs can reference MCP Registry.

Which systems ship at launch?

First 10 connectors in the Microsoft cert queue: Microsoft Sentinel, Microsoft Defender XDR, Microsoft Purview, Microsoft Entra ID, Microsoft Fabric, Salesforce, ServiceNow, SAP S/4HANA, Snowflake, Epic FHIR. Broader catalog spans Dynamics 365, Workday, ADP, Databricks, Confluence, Zendesk, Google Workspace, Box.

How does the kill-switch actually work?

Every connector wraps its underlying system with a documented disable endpoint plus an SLA for how fast disable takes effect. The customer's IR playbook holds the named list of authorized invokers on both the publisher (SIG) side and the customer side. Standard incident-response tooling can call it directly; no support ticket required.

Where does the audit trail land?

In the customer's own Purview tenant, alongside the audit trail Simple Council writes for agent-call decisions. Same surface the auditor already reads, no separate audit pipeline to maintain.

What does "federated-first for regulated content" mean?

Where source data must not leave the source system (HIPAA PHI, PCI cardholder data, SOX-scoped financial records), Simple Bridge defaults to Microsoft's federated Copilot Connector lane. The MCP protocol lets the agent query the source without pulling data out, and the source's own permission model enforces access. Where the workflow requires write authority, Simple Bridge routes through Power Platform Standard or Premium under end-user identity.

See Simple Bridge inside SimpleFlow.

A live walk-through of the SimpleFlow workflow designer with Simple Bridge in-loop: pick a connector, watch the action-authority manifest surface, choose a compliance profile, see the evidence pack generated at deploy. Ends with your compliance frame answered against your Purview tenant. No slides.