Simple Intelligence
Security · In Development · Phase 2 shipped
Simple Council

Simple Council
Run Agent 365 the way your regulator expects.

For CISOs, Heads of AI Governance, Compliance Officers, and Internal Audit leads at regulated mid-market organizations adopting Microsoft 365 E7 + Agent 365.

Agent 365 unifies the agent registry across Copilot, Bedrock, Vertex, and Foundry. It does not produce the evidence package an auditor reads, the framework control mappings a regulator expects, or the policy-enforcement chain a CISO defends to the board. Simple Council is the compliance and governance plane that sits above Agent 365: continuous evidence, framework-mapped controls, hash-chained audit, and policy enforcement on every agent call.

Web Planned Copilot Planned Desktop Planned

Your CISO has a new RFP question this quarter.

It reads something like: "How do you govern, audit, and enforce policy on every AI agent operating inside your Microsoft tenant, across every model provider, with evidence your regulator will accept?" It used to be a question your competitors asked your customers. Now your customers are asking it of you.

Microsoft Agent 365 is the registry. It is not the governance plane.

Agent 365, GA on 2026-05-01, gave you a single surface in the M365 admin center showing every agent across Copilot, AWS Bedrock, Google Vertex AI, and Foundry. It synchronized the agent population, surfaced telemetry, and tied into Defender and Purview. That is enormous progress on the registry problem. It did not produce the evidence package an auditor reads. It did not map agent activity to ISO 42001, EU AI Act, NIST AI RMF, HIPAA, FFIEC, SR 11-7, CMMC L2, FedRAMP, or SOC 2 control families. It did not give your CISO a policy-enforcement chain to defend to the board when an agent moved money, escalated a privilege, or shipped a PHI-tagged record.

Simple Council is the plane that does.

Sits above Agent 365 as the compliance and governance layer. Continuous evidence collection bound to your Purview tenant. Framework-mapped controls for every regulated industry your firm operates in. Hash-chained audit ledger that produces a tamper-evident attestation chain. Policy enforcement at the agent-call layer with a four-action enum: block, route, escalate, allow-with-audit. Every decision logged. Every decision defensible.

From Entra consent to first evidence pack.

1

Connect Agent 365

One Entra-authenticated connection grants Council read access to the Agent 365 registry, agent telemetry from Defender, and audit signals from Purview. No data egress; everything stays in your tenant.

2

Pick blueprints

Council ships ten regulated-industry blueprints at GA: ISO 42001, EU AI Act, NIST AI RMF, HIPAA, HITRUST, FFIEC, SR 11-7, FINRA, CMMC L2, FEDRAMP, SOC 2, plus a Generic baseline. You pick the ones your firm files against. Council maps each agent in your registry to the relevant controls automatically.

3

Author policy

Council ships default policies per blueprint. You override per agent, per tenant, per risk threshold. The policy decision tree lives in plain language, not in a code editor.

4

Enforce + evidence

Every agent call is intercepted, evaluated against policy, and dispositioned: block, route to a human, escalate to the agent owner, or allow-with-audit. Every disposition writes a PolicyDecision row, an Evidence row, and an AuditLog row. The Evidence ledger is hash-chained. Your auditor receives an export they can verify cryptographically.

What ships in the box.

Compliance plane above Agent 365

Ten blueprints at GA covering the regulated industries SIG sells into: ISO 42001 (AI management), EU AI Act, NIST AI RMF, HIPAA + HITRUST (healthcare), FFIEC + SR 11-7 + FINRA (financial services), CMMC L2 + FEDRAMP (defense + federal), SOC 2 (cross-industry), plus a Generic baseline. Every blueprint maps to the agent registry automatically; Council shows which agents need which controls.

Continuous evidence collection bound to your Purview tenant

Council reads agent telemetry from Defender, audit signals from Purview, identity context from Entra, and registry state from Agent 365. It writes evidence records continuously, not on the audit deadline. When the auditor calls, the evidence is already there.

Policy enforcement on every agent call

Four-action enum: block stops the call before it executes. Route forwards to a designated reviewer (a human seam). Escalate notifies the agent owner and gates the call until acknowledged. Allow-with-audit lets the call proceed and writes a richer audit trail. Every disposition is a PolicyDecision row with the rule that fired, the agent, the tenant, the user, and the input fingerprint. Disposable in court.

Hash-chained Evidence ledger

Every Evidence record carries a hash that includes the previous record's hash. Tampering is detectable by recomputing the chain. Your auditor receives an export with the chain verifier; they can confirm no record was inserted, modified, or removed after the fact. The hash chain is the difference between "audit trail" and "tamper-evident attestation."

Where your data lives, where audit lives, who can sign in.

Where your data lives

Council runs on Azure Container Apps in your customer-tenant region. Customer data never lands in Simple Intelligence's subscription. Council's control plane sees agent IDs, policy decisions, and evidence hashes; the underlying agent call payload stays where it was. For zero-data-retention requirements, Council pairs with SimpleForge to enforce on-device inference.

Where the audit trail lives

Evidence rows write to your Purview tenant via the documented Purview API surface. Auditors receive a signed export. The chain verifier is open-source so you can verify independently.

Identity model

Entra ID OIDC throughout. Council enforces RBAC against the same groups your CISO already manages. Multi-tenant per the entity-level ruleset; one Council deployment governs every agent your firm operates regardless of which Microsoft surface registered it.

Council on Council

Simple Intelligence and Simplicity IT both run on the same Council instance you would buy. Every agent we operate is governed by Council. Every blueprint we sell, we exercise against our own production AI footprint first. We are our own first customer.

Microsoft-first. Cross-vendor where Agent 365 already syncs.

Microsoft surface

Agent 365 Copilot Studio Microsoft 365 E7 Entra Microsoft Graph Purview Sentinel Defender Intune

Cross-vendor agents Agent 365 already syncs

AWS Bedrock Google Vertex AI Azure AI Foundry OpenAI Anthropic

Partner factory integrations

n8n NVIDIA NeMo

SIG portfolio

Simple Audit (deep evidence collection) Simple Atlas (white-label partner deployment) SimpleForge (ZDR option)

vs the GRC platforms regulated buyers already evaluated.

Capability Simple Council Vanta (AI module) Drata (AI module) OneTrust AI Governance Manual GRC
Cross-vendor agent registry (via Agent 365) Partial Partial Limited ,
Continuous evidence to Purview , , Partial ,
Hash-chained tamper-evident audit , , , ,
ISO 42001 blueprint Partial Partial Spreadsheet
EU AI Act blueprint Partial , Spreadsheet
HIPAA + HITRUST blueprint Spreadsheet
CMMC L2 + FEDRAMP blueprint Partial , Partial Spreadsheet
Policy enforcement at the agent-call layer , , Partial ,
Azure-native deployment , , , ,
White-label for Solutions Partners (via Atlas) , , , ,

Comparisons reflect publicly available product documentation as of 2026-06-18. Vendors evolve; if a row is out of date, tell us at /contact and we'll update.

MACC-eligible. Charged through your Azure consumption.

Starter
First Agent 365 deployment
$60 per agent / month
10 agent minimum, $600/mo floor
  • Up to 25 agents governed
  • Pick 1 blueprint
  • Notify-only enforcement (no block / escalate)
  • 1 year evidence retention
  • Standard support
  • MACC-eligible (Azure Marketplace)
Enterprise
Regulated tenant fleet, white-label option
Talk to us
  • Unlimited agents
  • All 12 blueprints
  • All 4 enforcement actions + custom rules
  • Custom evidence retention
  • Dedicated CSM + custom SLA
  • White-label via Simple Atlas (70/30 partner share)
  • MACC-eligible + GCC High option
Storage posture
Persistent (Postgres + pgvector); evidence chain hash-bound
Certification target
MISA + Microsoft Security Store
Distribution
Azure Marketplace
Status
In Development · Phase 2 shipped

The questions buyers ask in the first call.

We already use Microsoft Agent 365. Do we still need Simple Council?

Yes if your regulator expects framework-mapped evidence (ISO 42001, HIPAA, FFIEC, etc.) or your CISO needs policy enforcement at the agent-call layer. Agent 365 is the registry. Council is the compliance plane above it.

How does Council handle agents from Bedrock or Vertex AI?

Agent 365 already syncs those into your Microsoft tenant as registered agents. Council governs them through the same policy engine that governs Copilot Studio agents. One control plane, every model provider.

Where does the evidence go?

Into your own Purview tenant. Council does not retain customer evidence in our subscription. The Evidence ledger is hash-chained; your auditor can verify the chain independently.

What is the implementation timeline?

Starter tier: typically 5 to 10 business days from Entra consent to first auditor-ready evidence pack. Growth tier with 3 blueprints: 3 to 4 weeks. Enterprise with full blueprint coverage: 6 to 12 weeks depending on the agent fleet size.

Is Council certified?

Certifications are targets, not held attestations today. Council targets MISA membership and Microsoft Security Store listing. Our customers' Council deployments inherit Azure's certifications (FedRAMP High in GCC High, HIPAA-eligible, SOC 2, ISO 27001, ISO 27017, ISO 27018).

How does pricing work for partners?

Council can be white-labeled via Simple Atlas, our partner platform. Solutions Partners earn 70/30 revenue share on net-new tenants they originate. See /partners/.

We have an existing GRC platform (OneTrust, Vanta, Drata, Hyperproof). Does Council replace it?

Council does not replace your enterprise GRC platform. Council is the AI-agent governance layer specifically. Most customers run Council alongside their existing GRC for everything-not-AI, with Council producing the AI-specific evidence packs the existing GRC cannot.

See Council govern your tenant in 30 minutes.

A live walk-through against a customer-attached Agent 365 tenant, showing the registry sync, the blueprint mapping, a real policy decision firing, and an Evidence ledger export landing in your Purview. No slides.