For Regulated-vertical buyers (healthcare, financial services, defense, energy) whose procurement teams reject connectors without a documented action-authority inventory, kill-switch, and compliance-profile variant. Sold as part of SimpleFlow; not a standalone SKU.
Every SimpleFlow connector runs through Simple Bridge, which carries a Gifford-aligned action-authority inventory, a documented kill-switch endpoint, and a compliance-profile variant (HIPAA, SOX, FedRAMP, PCI-DSS, ISO 27001). Regulated-vertical customers clear the procurement gate on day one. Microsoft's Premium tier is a licensing bucket, not a compliance grade. Simple Bridge is.
What can this connector actually do? How do we shut it off if it misbehaves? What compliance frame does it map to? Every regulated buyer asks the same three questions, and most connector catalogs (Zapier, Make, off-the-shelf iPaaS) can't answer any of them without a services engagement. That's why regulated verticals still hand-build point-to-point integrations they can't maintain.
Getting a Premium connector into Power Platform doesn't make it HIPAA-compliant or FedRAMP-compliant. Those are two different questions the market conflates. Simple Bridge separates them: the Microsoft cert path is one axis (Premium / Standard / Custom), the compliance-profile variant is a second axis that regulated buyers need answered independently.
Every SimpleFlow customer gets Simple Bridge automatically. Not sold as a separate SKU, not a separate purchase, not a different Marketplace listing. It's the catalog the customer sees when they add a connector step to a workflow, and it's what makes SimpleFlow a real answer to the regulated-iPaaS question rather than another Zapier variant.
From the SimpleFlow workflow designer, the customer picks a connector for their step. Simple Bridge surfaces the connector's action-authority manifest inline before commit: every read, write, action, and escalation is enumerated with named permission scopes and MCP server allowlists.
Based on the customer's compliance-profile setting on their tenant, Simple Bridge routes the connector through the correct Microsoft integration lane: Power Platform Premium (write authority with end-user identity), Copilot Connector (federated MCP, no data movement), or Custom OpenAPI. The four Copilot Studio insertion points that apply are named on the manifest.
Simple Bridge inserts the kill-switch endpoint and the downstream notification template into the customer's workflow. Named invokers on both the publisher side and the customer side are captured. This is the piece the customer's IR playbook actually calls when a connector misbehaves.
When SimpleFlow deploys the workflow into the customer's tenant via Azure Lighthouse, Simple Bridge emits the evidence pack as a deployment artifact: control mappings for the chosen compliance profile, config snapshots, seam definitions, escalation policies, downstream notification templates. Auditor-ready without a services engagement.
Every connector pre-classified across Microsoft's three official integration paths: Power Platform (Standard / Premium / Custom), Microsoft Copilot connectors (synced Graph-indexed plus federated MCP-based), Custom OpenAPI. The manifest names the recommended lane and the four Copilot Studio insertion points that apply.
Every read, write, action, and escalation the connector exposes is enumerated in a manifest the customer's procurement team attaches to the MSA. Permission scopes are named verbatim, MCP server allowlists are listed. This is the document the customer hands to their auditor.
Every connector wraps its underlying system with a documented disable endpoint, an SLA for effectiveness, and a named list of authorized invokers on both the publisher side and the customer side. Standard IR playbook can call it directly without a support ticket.
Each connector ships in a base profile plus regulated variants: HIPAA (patient data, PHI transit controls), SOX (financial record integrity), PCI-DSS (cardholder data segmentation), FedRAMP Moderate (data-residency controls), ISO 27001 (control mapping). The customer picks the variant that matches their obligation.
Every connector deployment produces a downloadable audit bundle: control mappings, config snapshots, seam definitions, escalation policies, and downstream notification templates. Regenerable on demand for annual audit refreshes.
Where source data must not leave the source system (HIPAA, PCI, SOX), Simple Bridge defaults to Microsoft's federated Copilot Connector lane (MCP-based, no data movement, permissions enforced by source). Where the workflow requires write authority, Simple Bridge routes through Power Platform Standard or Premium under end-user identity.
Simple Bridge is the customer-facing name; MCP Registry is the internal architectural term for the registry protocol Simple Bridge implements, aligned with Anthropic's Model Context Protocol and Microsoft's Copilot connector federation surface. Marketing and buyer conversations use Simple Bridge; engineering specs can reference the MCP Registry layer for precision.
Every connector lands inside the customer's own Azure subscription via SimpleFlow's Lighthouse deployment path. Customer data never crosses into SIG's subscription. Only workflow metadata and audit trail flow to the SIG control plane.
Every SimpleFlow connector goes through Microsoft Power Platform Connector Certification, which lands the connector in Azure Logic Apps, Microsoft Power Automate, Microsoft Power Apps, and Microsoft Copilot Studio from one certification pass.
The evidence pack, kill-switch invocation logs, and connector action audit trails write to the customer's own Purview tenant. Auditors read the same surface they already read for agent-call decisions from Simple Council.
No. Simple Bridge is the connector catalog inside SimpleFlow. Every SimpleFlow customer gets it automatically; it's not sold as a separate SKU or Marketplace listing.
Microsoft's Premium tier is a licensing bucket that gates certain connectors and features. It doesn't make a connector HIPAA-compliant or FedRAMP-compliant. Simple Bridge separates the two axes: Microsoft cert path (Standard / Premium / Custom) is one axis, compliance-profile variant (HIPAA / SOX / FedRAMP / PCI-DSS / ISO 27001) is a second axis.
MCP Registry is the internal engineering name for the underlying registry protocol Simple Bridge implements. It aligns with Anthropic's Model Context Protocol and Microsoft's Copilot connector federation surface. Buyers and marketing copy use Simple Bridge exclusively; engineering specs can reference MCP Registry.
First 10 connectors in the Microsoft cert queue: Microsoft Sentinel, Microsoft Defender XDR, Microsoft Purview, Microsoft Entra ID, Microsoft Fabric, Salesforce, ServiceNow, SAP S/4HANA, Snowflake, Epic FHIR. Broader catalog spans Dynamics 365, Workday, ADP, Databricks, Confluence, Zendesk, Google Workspace, Box.
Every connector wraps its underlying system with a documented disable endpoint plus an SLA for how fast disable takes effect. The customer's IR playbook holds the named list of authorized invokers on both the publisher (SIG) side and the customer side. Standard incident-response tooling can call it directly; no support ticket required.
In the customer's own Purview tenant, alongside the audit trail Simple Council writes for agent-call decisions. Same surface the auditor already reads, no separate audit pipeline to maintain.
Where source data must not leave the source system (HIPAA PHI, PCI cardholder data, SOX-scoped financial records), Simple Bridge defaults to Microsoft's federated Copilot Connector lane. The MCP protocol lets the agent query the source without pulling data out, and the source's own permission model enforces access. Where the workflow requires write authority, Simple Bridge routes through Power Platform Standard or Premium under end-user identity.
A live walk-through of the SimpleFlow workflow designer with Simple Bridge in-loop: pick a connector, watch the action-authority manifest surface, choose a compliance profile, see the evidence pack generated at deploy. Ends with your compliance frame answered against your Purview tenant. No slides.
We reply inside one business day. No sales qualification gauntlet.
Talk to the teamMicrophone not available? Pick your industry and type a quick note. We reply inside one business day.