For CISOs, Heads of AI Governance, Compliance Officers, and Internal Audit leads at regulated mid-market organizations adopting Microsoft 365 E7 + Agent 365.
Agent 365 unifies the agent registry across Copilot, Bedrock, Vertex, and Foundry. It does not produce the evidence package an auditor reads, the framework control mappings a regulator expects, or the policy-enforcement chain a CISO defends to the board. Simple Council is the compliance and governance plane that sits above Agent 365: continuous evidence, framework-mapped controls, hash-chained audit, and policy enforcement on every agent call.
It reads something like: "How do you govern, audit, and enforce policy on every AI agent operating inside your Microsoft tenant, across every model provider, with evidence your regulator will accept?" It used to be a question your competitors asked your customers. Now your customers are asking it of you.
Agent 365, GA on 2026-05-01, gave you a single surface in the M365 admin center showing every agent across Copilot, AWS Bedrock, Google Vertex AI, and Foundry. It synchronized the agent population, surfaced telemetry, and tied into Defender and Purview. That is enormous progress on the registry problem. It did not produce the evidence package an auditor reads. It did not map agent activity to ISO 42001, EU AI Act, NIST AI RMF, HIPAA, FFIEC, SR 11-7, CMMC L2, FedRAMP, or SOC 2 control families. It did not give your CISO a policy-enforcement chain to defend to the board when an agent moved money, escalated a privilege, or shipped a PHI-tagged record.
Sits above Agent 365 as the compliance and governance layer. Continuous evidence collection bound to your Purview tenant. Framework-mapped controls for every regulated industry your firm operates in. Hash-chained audit ledger that produces a tamper-evident attestation chain. Policy enforcement at the agent-call layer with a four-action enum: block, route, escalate, allow-with-audit. Every decision logged. Every decision defensible.
One Entra-authenticated connection grants Council read access to the Agent 365 registry, agent telemetry from Defender, and audit signals from Purview. No data egress; everything stays in your tenant.
Council ships ten regulated-industry blueprints at GA: ISO 42001, EU AI Act, NIST AI RMF, HIPAA, HITRUST, FFIEC, SR 11-7, FINRA, CMMC L2, FEDRAMP, SOC 2, plus a Generic baseline. You pick the ones your firm files against. Council maps each agent in your registry to the relevant controls automatically.
Council ships default policies per blueprint. You override per agent, per tenant, per risk threshold. The policy decision tree lives in plain language, not in a code editor.
Every agent call is intercepted, evaluated against policy, and dispositioned: block, route to a human, escalate to the agent owner, or allow-with-audit. Every disposition writes a PolicyDecision row, an Evidence row, and an AuditLog row. The Evidence ledger is hash-chained. Your auditor receives an export they can verify cryptographically.
Ten blueprints at GA covering the regulated industries SIG sells into: ISO 42001 (AI management), EU AI Act, NIST AI RMF, HIPAA + HITRUST (healthcare), FFIEC + SR 11-7 + FINRA (financial services), CMMC L2 + FEDRAMP (defense + federal), SOC 2 (cross-industry), plus a Generic baseline. Every blueprint maps to the agent registry automatically; Council shows which agents need which controls.
Council reads agent telemetry from Defender, audit signals from Purview, identity context from Entra, and registry state from Agent 365. It writes evidence records continuously, not on the audit deadline. When the auditor calls, the evidence is already there.
Four-action enum: block stops the call before it executes. Route forwards to a designated reviewer (a human seam). Escalate notifies the agent owner and gates the call until acknowledged. Allow-with-audit lets the call proceed and writes a richer audit trail. Every disposition is a PolicyDecision row with the rule that fired, the agent, the tenant, the user, and the input fingerprint. Disposable in court.
Every Evidence record carries a hash that includes the previous record's hash. Tampering is detectable by recomputing the chain. Your auditor receives an export with the chain verifier; they can confirm no record was inserted, modified, or removed after the fact. The hash chain is the difference between "audit trail" and "tamper-evident attestation."
Council runs on Azure Container Apps in your customer-tenant region. Customer data never lands in Simple Intelligence's subscription. Council's control plane sees agent IDs, policy decisions, and evidence hashes; the underlying agent call payload stays where it was. For zero-data-retention requirements, Council pairs with SimpleForge to enforce on-device inference.
Evidence rows write to your Purview tenant via the documented Purview API surface. Auditors receive a signed export. The chain verifier is open-source so you can verify independently.
Entra ID OIDC throughout. Council enforces RBAC against the same groups your CISO already manages. Multi-tenant per the entity-level ruleset; one Council deployment governs every agent your firm operates regardless of which Microsoft surface registered it.
Simple Intelligence and Simplicity IT both run on the same Council instance you would buy. Every agent we operate is governed by Council. Every blueprint we sell, we exercise against our own production AI footprint first. We are our own first customer.
| Capability | Simple Council | Vanta (AI module) | Drata (AI module) | OneTrust AI Governance | Manual GRC |
|---|---|---|---|---|---|
| Cross-vendor agent registry (via Agent 365) | ✓ | Partial | Partial | Limited | , |
| Continuous evidence to Purview | ✓ | , | , | Partial | , |
| Hash-chained tamper-evident audit | ✓ | , | , | , | , |
| ISO 42001 blueprint | ✓ | Partial | Partial | ✓ | Spreadsheet |
| EU AI Act blueprint | ✓ | Partial | , | ✓ | Spreadsheet |
| HIPAA + HITRUST blueprint | ✓ | ✓ | ✓ | ✓ | Spreadsheet |
| CMMC L2 + FEDRAMP blueprint | ✓ | Partial | , | Partial | Spreadsheet |
| Policy enforcement at the agent-call layer | ✓ | , | , | Partial | , |
| Azure-native deployment | ✓ | , | , | , | , |
| White-label for Solutions Partners (via Atlas) | ✓ | , | , | , | , |
Comparisons reflect publicly available product documentation as of 2026-06-18. Vendors evolve; if a row is out of date, tell us at /contact and we'll update.
Yes if your regulator expects framework-mapped evidence (ISO 42001, HIPAA, FFIEC, etc.) or your CISO needs policy enforcement at the agent-call layer. Agent 365 is the registry. Council is the compliance plane above it.
Agent 365 already syncs those into your Microsoft tenant as registered agents. Council governs them through the same policy engine that governs Copilot Studio agents. One control plane, every model provider.
Into your own Purview tenant. Council does not retain customer evidence in our subscription. The Evidence ledger is hash-chained; your auditor can verify the chain independently.
Starter tier: typically 5 to 10 business days from Entra consent to first auditor-ready evidence pack. Growth tier with 3 blueprints: 3 to 4 weeks. Enterprise with full blueprint coverage: 6 to 12 weeks depending on the agent fleet size.
Certifications are targets, not held attestations today. Council targets MISA membership and Microsoft Security Store listing. Our customers' Council deployments inherit Azure's certifications (FedRAMP High in GCC High, HIPAA-eligible, SOC 2, ISO 27001, ISO 27017, ISO 27018).
Council can be white-labeled via Simple Atlas, our partner platform. Solutions Partners earn 70/30 revenue share on net-new tenants they originate. See /partners/.
Council does not replace your enterprise GRC platform. Council is the AI-agent governance layer specifically. Most customers run Council alongside their existing GRC for everything-not-AI, with Council producing the AI-specific evidence packs the existing GRC cannot.
A live walk-through against a customer-attached Agent 365 tenant, showing the registry sync, the blueprint mapping, a real policy decision firing, and an Evidence ledger export landing in your Purview. No slides.
We reply inside one business day. No sales qualification gauntlet.
Talk to the teamMicrophone not available? Pick your industry and type a quick note. We reply inside one business day.