Policy packs / Power Automate

Power Automate

Power Platform CoE Toolkit Aligned

Cross-platform governance floor for Power Automate makers.

Roadmap pack. Today this pack applies Flowcerta's cross-platform rules to Power Automate exports. Platform-native detectors are in development and will flow into this pack automatically when they ship.
10rules
3env profiles
advisorydefault mode
critical+blocks at

Why this pack

Microsoft's Power Platform CoE Starter Kit enforces connection-reference governance, DLP policy compliance, and maker auditing. Flowcerta's catalog does not yet have Power Automate-native detectors, so this pack applies our cross-platform credential, PII, and resilience rules to PA flow exports. The rules below run today against any uploaded flow export; the slate of PA-specific detectors will land in a follow-up release and flow into this pack automatically.

Aligned with: Microsoft Power Platform CoE Starter Kit · Power Platform DLP policies

Environment profiles

The pack ships with severity thresholds tuned per environment so the same workflow gets stricter as it promotes toward production.

development
advisoryblocks at critical+

Surface findings without blocking the flow check-in.

default
advisoryblocks at critical+

Catch-all environment. Same posture as development.

production
blockingblocks at high+

Block deploys with credential or PII findings before they reach prod.

Rules included (10)

2 critical7 high1 medium
  • criticalFC-ANY-CRED-001Hardcoded connection string

    PA flows should reference Connections, not embed credentials in actions or expressions.

  • criticalFC-ANY-CRED-002Hardcoded API key or credential variable

    API key values in Compose or Initialize Variable actions leak the moment the flow is exported.

  • highFC-ANY-EXC-001Swallowed exception

    A Configure run after = Failed scope with no Terminate or notify is invisible to ops.

  • highFC-ANY-HTTP-001Missing try/catch around external call

    HTTP actions need Scope-with-Configure-Run-After or the flow turns transient failures into incidents.

  • highFC-ANY-PII-001PII access without audit log

    CoE Toolkit expects every PII-touching flow to log who/when via the audit connector.

  • highFC-ANY-PII-002PII value in log message

    A flow that logs the SSN it just processed is now exporting PII into your log store.

  • highFC-ANY-PII-003PII hardcoded default

    Test PII baked into a Compose default ships to production with the flow.

  • highFC-ANY-RETRY-001Infinite retry without limit

    Power Automate retry policy with no max defeats throttling and racks up consumption.

  • highFC-ANY-RETRY-002Missing retry scope

    External connectors fail transiently. Retry policy belongs on every connector action.

  • mediumFC-ANY-LOG-001Missing log message

    CoE Toolkit auditing depends on flows emitting structured logs. Silent flows skip the audit trail.

Download the Power Platform CoE Toolkit Aligned JSONDrop the file into Settings → Policy Packs → Import JSON inside your Flowcerta org.

We'll email you when we ship platform-native rules for this pack. No spam.