What it means
Businesses already work together through email, portals, shared folders and phone calls. As each business adopts AI agents, a natural next step is for those agents to work with each other’s information directly:
- A client’s AI asks its accountant’s systems which records are outstanding, and uploads them.
- A purchaser’s agent requests a quote from a supplier.
- A solicitor’s AI checks the status of a matter with a client’s in-house team.
- A contractor’s agent retrieves the latest drawings from an architect.
This is sometimes called B2B AI or agent-to-agent collaboration. It is an emerging area, and conventions are still forming.
Why it is harder than it sounds
Inside one organisation, you at least control both ends. Between organisations:
- Neither side should see the other’s internal systems.
- Identity crosses a boundary. You need to know which organisation, which person and which agent is asking.
- Trust is partial. A client should see their own records, not your other clients’.
- Actions have legal weight. A quote, an instruction or an approval sent by an agent may commit a business.
- Data protection applies on both sides. Each organisation remains responsible for the personal data it discloses and receives.
The pattern that works
Rather than connecting agents directly to each other’s systems, each organisation exposes a defined interface:
- A relationship. An explicit link between two organisations, such as “ABC Limited is a client of this practice”.
- A defined portion of information. What the other side may read, such as their own documents, requests and deadlines.
- Defined capabilities. What the other side may do, such as upload a document or respond to a request.
- Identity for the other side. People and agents from the other organisation are identifiable principals.
- Approval where needed. Actions with consequences wait for a person.
- Events. Each side can be told when something relevant changes.
- A record on both sides. Each organisation can see what the other’s agents requested.
Questions to settle before starting
- What exactly will the other organisation’s AI be able to see and do?
- Who in each organisation is accountable for the relationship?
- What happens when the relationship ends?
- Do contracts or terms of business cover AI-initiated actions?
- How will disputes about what an agent did be resolved? A shared record helps.
Where to start
Start with a narrow, low-risk exchange: document requests and uploads, status checks, or deadline notifications. These deliver value without either side exposing much.
How Kroy approaches it
In Kroy, one organisation can share with another through a governed relationship. Guests, including another organisation’s people and agents, are first-class principals. A Channel defines what that audience receives: a projection of the relevant information, selected artifacts, events and Skills they may call. Each side exposes only what it has authorised, and every request is recorded. For most organisations this starts with guest access for clients; direct agent-to-agent collaboration builds on the same foundations.