PolicyWatcherPublic evidence laboratory
Enterprise integration surface

One evidence contract. Many enterprise entry points.

PolicyWatcher is API-first. Microsoft, Google and AWS agent packages, workflow connectors and Office experiences sit on the same publication gate and explicit data boundary. Integrations consume evidence records, never scraped portal HTML.

Integration topology

Every path crosses the evidence boundary.

The central contract is the control point. Status labels describe delivery state in words, not color alone.

AvailablePilot readyPlannedCommercial later
Available

Public API v1

Public read and discovery.

/api/v1
Pilot ready

Enterprise API + APIM

Tenant-authenticated system access.

/api/v2
Pilot ready

Power Platform

Composable workflow automation.

6 read actions
Available

Agent Evidence Gateway

One flattened public contract.

3 read operations
PolicyWatcher core
Publication GateOnly reviewed, public evidence passes
Tenant BoundaryVerified Entra identity for v2
Evidence contractOpenAPI 3.0.3
Planned

Teams and M365

Dedicated collaboration experience.

SSO tab + cards
Source ready

Copilot · Vertex AI · Amazon Quick

Tenant-hosted agent packages.

one OpenAPI contract
Source ready

Word task pane

Local clause classification.

derived topics only
Commercial later

Marketplace

Procurement, plans, and lifecycle.

SaaS offer
Choose by job

Start with the outcome, then select the surface.

01Public read and discovery
Public API v1Available
02Portable multi-change evidence
Evidence CollectionsAvailable
03Review-system handoff
Vendor-neutral handoff manifestAvailable
04Change automation polling
Public change event feedAvailable
05Polling continuity rehearsal
Event Feed Continuity LabAvailable
06Receiver signature testing
Webhook Readiness KitAvailable
07Operator-controlled push
Configured Webhook DeliveryPilot ready
08Tenant-authenticated system access
Enterprise API v2Pilot ready
09Workflow automation
Power Platform connectorPilot ready
10Cross-cloud agent evidence
Agent Evidence GatewayAvailable
11Tenant conversation
Copilot, Vertex AI and Amazon Quick packagesSource ready
12Clause evidence review
PolicyWatcher for WordSource ready
13In-workflow collaboration
Teams cards and tabPlanned
14Federated tool access
MCPPlanned
15Procurement and billing
Microsoft MarketplaceCommercial later
Capability catalog

Delivered surfaces stay separate from future architecture.

Each entry names its audience, role, boundary, and concrete route or artifact.

Available

Public, bounded surfaces in the current product.

10

Agent Evidence Gateway

Inspect agent contract
Audience
Microsoft 365 Copilot, Vertex AI Agent Builder and Amazon Quick pilots
Role
Returns deterministic, source-linked public change and Observatory briefs through one OpenAPI 3.0 contract.
Boundary
Anonymous, read-only public evidence only. No confidential prompts, tenant data, raw policy text or model-generated verdicts.
/api/v1/agent/openapi.json

Public API v1

Developer directory
Audience
Developers, researchers, public-interest tools
Role
Anonymous discovery of the integration manifest, curated Observatory registry and portable evidence bundles.
Boundary
Read-only public metadata, publication-aware gates, shared IP rate policy.
/api/v1/manifest | /api/v1/observatory | /api/v1/evidence-collections

Public evidence surfaces

Release feeds
Audience
Browsers, newsroom tools, downstream readers
Role
Human-readable evidence views plus JSON and RSS release feeds.
Boundary
Only already-public records and release metadata. No private retrieval state.
/change/{id} | /press-kit/feed.json

Shareable evidence collections

Open collections
Audience
Researchers, editors, governance reviewers, developers
Role
Selects up to 12 exact public changes and exports deterministic evidence bundles or a vendor-neutral review handoff.
Boundary
Only canonical public evidence leaves the browser. Local title, review states, assignees and due dates are excluded.
/collections | /api/v1/evidence-collections

Collaboration handoff manifest

Build a handoff
Audience
GRC, ticketing and collaboration workflow owners
Role
Provides deterministic work-item titles, acceptance criteria, evidence links and digests for authorized human import.
Boundary
Creates no third-party record, assignment, deadline, notification or delivery confirmation.
/api/v1/evidence-collections?changes={ids}&format=handoff

Public change event feed

Open event feed
Audience
Automation owners, researchers and integration developers
Role
Polls already-published change events through stable event IDs and a forward-only opaque cursor.
Boundary
No subscription, push delivery, recipient data, delivery receipt or signed webhook claim.
/api/v1/change-events?limit=25&lang=en

Event Feed Continuity Lab

Open continuity workbench
Audience
Polling consumer developers and integration reviewers
Role
Inspects bounded event windows, stores a strict browser-local checkpoint and explicitly resumes from its opaque cursor.
Boundary
No hosted consumer, exhaustive-monitoring claim, server-side replay store, delivery receipt or push delivery.
/developers/event-continuity | /schemas/event-continuity-checkpoint/v1

Webhook Readiness Kit

Open verification workbench
Audience
Integration developers and security reviewers
Role
Tests the candidate HMAC-SHA256 receiver contract locally with one editable vector and eight deterministic positive and negative fixtures.
Boundary
No endpoint registration, subscriptions, production secrets, push delivery, retries or delivery confirmation.
/developers/webhook-readiness | /api/v1/webhook-verification-kit | /api/v1/webhook-conformance-suite

Browser extension

Browser extension
Audience
Reviewers working from a provider policy page
Role
Moves a page-level review into the existing PolicyWatcher evidence workflow.
Boundary
The extension does not turn third-party page content into an enterprise API response.
/browser-extension

Embeddable change card

Audience
Publishers and evidence-aware websites
Role
Frames one public change card through a purpose-built embed route.
Boundary
The main portal stays frame-protected. Only the dedicated card route is embeddable.
/embed/change/{id}

Pilot ready

Implemented in source; tenant activation still requires configuration.

08

Enterprise API v2

Inspect OpenAPI
Audience
Enterprise applications, IT and identity administrators
Role
Tenant-bound access to companies, changes, continuity, and governance signals.
Boundary
Verified Entra tenant, delegated scope or app role, private no-store responses.
/api/v2/openapi.json

Azure API Management edge

Audience
Platform engineering and API operations
Role
Gateway policy for token validation, request correlation, and controlled origin access.
Boundary
APIM does not replace origin authorization. The origin verifies the Entra token again.
docs/azure/apim-policy.xml

Power Platform connector

Audience
Power Automate, Power Apps, Logic Apps, Copilot Studio
Role
Six read actions over the same v2 evidence contract, ready for a test tenant pilot.
Boundary
Two Entra applications and environment configuration are required before import.
integrations/power-platform/policywatcher-v2

Microsoft 365 Copilot evidence agent

Audience
Licensed Microsoft 365 Copilot users and tenant administrators
Role
Declarative agent 1.8 and API plugin 2.4 package for cited public evidence dialogue inside the customer tenant.
Boundary
Source package only: not AppSource-published, tenant-enabled or certified. Private access remains on Entra-authenticated API v2.
integrations/microsoft-copilot/policywatcher-evidence-agent

Vertex AI Agent Builder tool

Audience
Google Cloud agent builders and project administrators
Role
OpenAPI tool and tool-first playbook instructions for the same deterministic public evidence contract.
Boundary
Source package only: not deployed into a customer Google Cloud project and no PolicyWatcher dataset is copied by the package.
integrations/google-agent-builder/policywatcher-evidence-tool

Amazon Quick OpenAPI connector

Audience
AWS account owners and Amazon Quick authors
Role
Three-operation OpenAPI connector constrained to one JSON endpoint contract and flattened responses.
Boundary
Source package only: not deployed or shared in an AWS account. Amazon Q Business remains a legacy path for existing customers only.
integrations/amazon-quick/policywatcher-evidence-connector

PolicyWatcher Contract Evidence Review for Word

Preview task pane
Audience
Legal, procurement and GRC reviewers working in Word
Role
Classifies an explicitly selected clause locally and searches public evidence with controlled topic labels only.
Boundary
Selected clause text is not sent or stored. The add-in maps evidence; it does not verify, approve or legally assess a contract.
/office-addin/contract-review | integrations/office-word

Configured webhook delivery

Audience
Integration and security operations teams
Role
Sends eligible public change events to deployment-configured HTTPS destinations through a signed persistent outbox.
Boundary
No public registration, tenant self-service, endpoint challenge, automatic key rotation, guaranteed delivery or SLA.
/admin/webhook-delivery | policy.change.published

Planned

Architected next paths; not delivered or enabled today.

04

Self-service webhook lifecycle

Audience
Tenant administrators and integration owners
Role
Tenant-managed endpoint registration, challenge verification, secret rotation and delivery-health controls.
Boundary
The configured pilot does not establish tenant identity, self-service provisioning or a delivery commitment.
Future tenant delivery control plane

Teams and Microsoft 365

Audience
Legal, GRC, procurement, and business owners
Role
Dedicated SSO tab, Adaptive Cards, and evidence deep links inside collaboration flows.
Boundary
Requires a purpose-built route. The whole portal is not iframe-ready.
Dedicated M365 surface, not portal HTML fetching

Federated MCP connector

Audience
Copilot administrators and knowledge architects
Role
Real-time search and fetch from PolicyWatcher without copying records into an index.
Boundary
Authenticated read tools, tenant controls, and source-of-truth links are required.
search | fetch | query tools

Synchronized Copilot connector

Audience
Organizations requiring Microsoft 365 indexed discovery
Role
Optional external content indexing for tenant search and Copilot grounding.
Boundary
Needs ACLs, delete propagation, retention review, and stale-record controls.
Optional path after governance review

Commercial later

Distribution and lifecycle work after the enterprise foundation.

02

Microsoft Marketplace SaaS

Audience
Enterprise procurement and cloud marketplace buyers
Role
Discovery, commercial plans, purchasing, and access to the PolicyWatcher service.
Boundary
A Marketplace offer distributes the SaaS. It does not embed the portal as the product.
Listing first | transactable offer later

Provisioning and entitlements

Audience
Tenant owners, billing, and customer success
Role
Subscription activation, plan mapping, lifecycle events, and tenant entitlement checks.
Boundary
Requires a production tenant model, support process, audit history, and lifecycle webhooks.
Fulfillment API + subscription lifecycle
Contract choice

Public agent gateway or tenant-bound v2?

The agent gateway supports cited public dialogue across clouds. v2 remains the authenticated foundation for private enterprise workflows.

DimensionPublic API v1Enterprise API v2
AccessPublic internetAllowlisted Entra tenant
AudiencePublic developers and researchersEnterprise apps, users, and automation
Use caseDiscovery and curated registry readsEvidence, continuity, and governance workflows
AuthenticationNone, anonymous read-onlypolicywatcher.read or PolicyWatcher.Read.All
Data boundaryPublic metadata and curated referencesEvidence-gated records with verified tenant context
Contract/api/v1/manifest/api/v2/openapi.json
ReadinessAvailablePilot ready
Private Microsoft tenant pilot

Seven checks for authenticated API v2 workflows.

The pilot uses identifiers and controlled configuration. A client secret belongs in a protected secret store and must never be pasted into a document, issue, chat, or generated artifact.

Open machine-readable contract
  1. 01
    Register the protected API

    Create the PolicyWatcher Enterprise API app, expose policywatcher.read, and define PolicyWatcher.Read.All.

  2. 02
    Register the connector client

    Create a separate Power Platform connector app and grant the delegated API permission.

  3. 03
    Allowlist the test tenant

    Configure the pilot tenant ID and API audiences on the PolicyWatcher origin.

  4. 04
    Choose the API front door

    Use the public HTTPS origin for a controlled smoke test, or the preferred APIM URL.

  5. 05
    Identify the Power Platform environment

    Use the test Environment ID to keep the connector and flows isolated.

  6. 06
    Import and connect

    Generate the source-controlled connector package, import it, and complete interactive consent.

  7. 07
    Prove rejection paths

    Test wrong tenant, wrong audience, missing scope or role, and direct-origin rejection once APIM is enforced.

Security and data boundary

Integrations receive bounded evidence, not the machinery behind it.

API consumers do not fetch PolicyWatcher portal HTML. They receive structured records that have already crossed the same publication controls used by public evidence views.

Provider source
Publication Gate
Bounded record
Never returned to API consumers
  • Raw policy text
  • Raw snapshot text or non-public fingerprints
  • Private retrieval diagnostics
  • Credentials
  • Administrator logs
Next entry point

Use the contract that matches the work.

Inspect the public agent contract, validate a source package in an isolated tenant or cloud project, or use v2 for authenticated enterprise workflows.