Overview
When an AI tool acts in your organisation, two questions matter: which agent is this, and which person is it acting for? Kroy answers the second with the identity system you already run.
People sign in to Kroy with Microsoft Entra ID. Kroy then links every AI agent they use — Claude, ChatGPT, Copilot or an internal agent — to that person through a delegation. Every request carries both: the agent and the human behind it.
Groups become roles
Kroy can map Entra security groups to Kroy roles. Members of Audit – Managers receive the Kroy role that sees audit clients; members of Partners can approve external communication. Your IT team keeps managing membership where it already does, and Kroy applies it to AI.
People, agents and delegation
Entra ID knows your people. Kroy adds what an identity provider does not usually model: which agents may act for which person, for which tasks, with which Skills and until when. Kroy decides each request against the person, the agent, the delegation, the policy and any approval.
Leavers and changes
When someone leaves and IT disables their Entra account, Kroy treats their access — and every delegation from them to an AI agent — as ended. When someone moves teams, their Kroy role follows their group membership.
Industries
Law firms and financial services firms often need to show who could see what, and when. Tying AI access to managed identities makes that record straightforward to produce.
Security
Kroy holds the app registration credentials. AI clients never receive Entra tokens and cannot sign in as a person. Every sign-in, delegation, request and refusal is recorded against a named identity.