# Kroy > Give AI somewhere safe to work. The governed interface between your organisation and AI. Kroy is an independent database, state, access, execution and publishing layer through which humans, AI agents, organisations and systems can safely work with organisational information and capabilities. Organisations connect business systems to Kroy once. AI tools (Claude, ChatGPT, Copilot, Codex and others) connect to Kroy. Kroy authenticates the actor, resolves permissions and delegation, restricts context, requires human approval where policy says so, executes authorised actions and records an audit trail. AI never receives the credentials for the underlying systems. Initial market: London, United Kingdom. Machine-readable profile: https://kroydb.com/kroy.json ## Product - [AI Gateway](https://kroydb.com/product/ai-gateway): The Kroy AI Gateway sits between AI tools and business systems. AI requests go to Kroy, which authenticates, checks policy, requires approval where needed, executes the action and records it. - [Artifacts](https://kroydb.com/product/artifacts): Kroy Artifacts store the work AI produces — drafts, reports, analyses — with versions, a Draft-to-Approved status and a record of who or what created each change. - [Connect](https://kroydb.com/product/connect): Kroy Connectors link Microsoft 365, Xero, GitHub, databases and internal systems to Kroy once. Authorised AI then uses them through Kroy, which holds the credentials and enforces permissions. - [Control](https://kroydb.com/product/control): Kroy Control decides every AI request by checking who is asking, which agent is acting, what they are delegated to do, the organisation’s policies, and whether a human must approve. - [KroyDB](https://kroydb.com/product/kroydb): KroyDB is Kroy’s database. It stores clients, projects, decisions and other organisational information as structured, permissioned entities with relationships, so authorised AI and people can query and update them. - [Guest Access](https://kroydb.com/product/guest-access): Kroy Guest Access lets an organisation share a governed projection of its data with clients, advisers or contractors — who can use Kroy directly or through their own Claude or ChatGPT. - [Publish](https://kroydb.com/product/publish): Kroy Publish turns structured Kroy data and approved Artifacts into feeds for websites, client portals, APIs and AI — with drafts, versions, approvals and audit — without being a website builder. - [Skills](https://kroydb.com/product/skills): A Kroy Skill packages a business task — such as preparing a client reminder — with exactly the data, connector actions and approval rules it needs, so AI can do the job without broad access. - [Observe](https://kroydb.com/product/observe): Kroy Observe shows which AI agents are connected, which Skills run, what was approved or denied and which systems AI reaches — an audit and adoption view, not employee surveillance. - [Channels](https://kroydb.com/product/channels): A Kroy Channel combines an audience, a projection of data, artifacts, events and Skills. Organisations run separate Channels for employees, clients, partners, the public and AI agents. - [State](https://kroydb.com/product/state): Kroy State keeps decisions, projects, tasks, artifacts and provenance outside any single AI provider, so work started in Claude can continue in ChatGPT or Codex without re-explaining it. ## Integrations - [ChatGPT](https://kroydb.com/integrations/chatgpt): ChatGPT connects to Kroy as an AI client, for example through MCP-based connectors where the ChatGPT plan supports them. Through Kroy it can read authorised state, use granted Skills and draft work, without receiving system credentials. - [Claude](https://kroydb.com/integrations/claude): Claude connects to Kroy as an AI client, for example through MCP where the Claude product supports it. Through Kroy, Claude can read shared state, use authorised Skills and connector actions, and draft work — without receiving any system credentials. - [Google Workspace](https://kroydb.com/integrations/google-workspace): The Kroy Google Workspace connector gives authorised AI controlled access to Gmail, Google Drive and Calendar. Kroy holds the connection, respects Workspace sharing, and requires approval to send mail or share files externally. - [GitHub](https://kroydb.com/integrations/github): The Kroy GitHub connector gives authorised AI agents controlled access to repositories, issues and pull requests. Kroy holds the GitHub credentials, applies per-agent permissions and requires approval for merges, releases and workflow runs. - [Cloudflare](https://kroydb.com/integrations/cloudflare): The Kroy Cloudflare connector triggers deploy hooks for Cloudflare-hosted sites when Kroy Publish publishes approved content, and can read deployment status. Kroy holds the hook and API token; AI never receives them. - [Microsoft 365](https://kroydb.com/integrations/microsoft-365): The Kroy Microsoft 365 connector gives authorised AI controlled access to Outlook mail and drafts, SharePoint and OneDrive files, with sending and sharing governed by Kroy policy. - [Jira](https://kroydb.com/integrations/jira): The Kroy Jira connector lets authorised AI search, create, comment on and update Jira issues through Kroy, which holds the Atlassian connection, respects project permissions and can require approval for transitions. - [PostgreSQL](https://kroydb.com/integrations/postgresql): The Kroy PostgreSQL connector lets authorised AI run reviewed read queries against your PostgreSQL databases through Kroy, which holds the credentials, limits tables and rows per user, and requires approval for any write. - [Microsoft Copilot](https://kroydb.com/integrations/microsoft-copilot): Microsoft Copilot experiences that support external tools, such as agents built in Copilot Studio with MCP, can connect to Kroy as an AI client. Kroy decides what Copilot can reach for each person and never hands over system credentials. - [Microsoft Entra ID](https://kroydb.com/integrations/microsoft-entra-id): Kroy uses Microsoft Entra ID for sign-in and maps Entra groups to Kroy roles, so every AI request traces to a known person. Disabling a user in Entra removes their Kroy access and that of the agents acting for them. - [QuickBooks](https://kroydb.com/integrations/quickbooks): The Kroy QuickBooks connector lets authorised AI read customers, invoices, bills and reports from QuickBooks Online and prepare estimates, through Kroy — which holds the connection and applies per-user permissions and approval. - [Salesforce](https://kroydb.com/integrations/salesforce): The Kroy Salesforce connector lets authorised AI read accounts, contacts and opportunities, log activity and propose opportunity updates through Kroy, which holds the Salesforce connection and applies permissions and approval. - [Xero](https://kroydb.com/integrations/xero): The Kroy Xero connector lets authorised AI read contacts, invoices, bills and reports, and create drafts, through Kroy — which holds the Xero connection and enforces per-user permissions and approval. ## Case Studies - [Letting AI update your website — with a person approving](https://kroydb.com/case-studies/ai-operated-website-publishing): An example Kroy Publish workflow. Claude identifies public content affected by a new capability, prepares a change set, and — after human approval — Kroy publishes it and triggers a website rebuild, with every step audited. - [Preparing a board pack with AI, and sharing it with the board](https://kroydb.com/case-studies/board-reporting): An example Kroy workflow. Claude builds a draft board pack from Xero, Salesforce and company data, and the finance director approves it. The pack is shared through a board Channel, where non-executive directors can use their own AI. Ledger detail and pre-approval sharing are refused. - [AI-assisted bookkeeping review in Xero](https://kroydb.com/case-studies/bookkeeping-review): An example Kroy workflow. Claude reviews a client’s Xero file for uncategorised, duplicated and suspense items and proposes corrections as a change set. Kroy applies only the corrections a bookkeeper approves, and refuses deletions and bank detail changes outright. - [Onboarding a new client with AI — while the AML review stays internal](https://kroydb.com/case-studies/client-onboarding): An example Kroy onboarding workflow. Claude creates a new client entity, drafts an engagement letter and document request, and prepares an internal AML checklist. Kroy refuses to let the agent complete the AML review, and the client’s workspace never includes it. - [Investigating a client’s question with ChatGPT, Xero and Outlook](https://kroydb.com/case-studies/client-query-investigation): An example Kroy workflow. A client asks why their VAT bill has gone up. ChatGPT, through Kroy, reads only that client’s Xero records and correspondence, explains the change and drafts a reply. Reading another client’s mailbox thread and sending are refused. - [Claude + Xero through Kroy](https://kroydb.com/case-studies/claude-xero): How Claude works with Xero through Kroy. Kroy holds the Xero connection, resolves what each user and agent may see, returns only authorised data to Claude and records every request. - [Claude Code and Codex working from shared state](https://kroydb.com/case-studies/claude-code-codex-shared-state): An example Kroy workflow for development teams. One developer’s Claude Code and another’s Codex share task state, design decisions and progress through Kroy. Both work under GitHub permissions set in Kroy, and merging to main or reading production secrets is refused. - [A client uses their own Claude with the information you share](https://kroydb.com/case-studies/client-workspace-own-ai): An example Kroy guest-access workflow. An accountancy practice shares a client projection with ABC Limited’s director, who connects their own Claude. It can answer what remains outstanding but cannot retrieve the practice’s internal notes. - [Shared project state across a consulting team’s AI tools](https://kroydb.com/case-studies/consulting-project-state): An example Kroy workflow for consultancies. Three consultants use Claude, ChatGPT and Copilot on one engagement. Each reads and updates the same project State in Kroy. Kroy refuses changes to client-agreed decisions without approval, and keeps restricted interview notes from agents not cleared for them. - [A client document room with an expiry date](https://kroydb.com/case-studies/client-document-room): An example Kroy guest-access workflow. A London law firm acting on a share sale shares a document room with the buyer’s advisers. Guests and their own AI can query the documents in the room until it expires. Kroy refuses requests for anything outside it or after the end date. - [A release workflow with deployment approval](https://kroydb.com/case-studies/github-release-workflow): An example Kroy workflow for development teams. Claude gathers merged pull requests, drafts release notes, creates a draft GitHub release and deploys to staging. Deploying to production requires a release manager’s approval in Kroy, and editing workflow files is refused. - [Reviewing a contract against the firm’s playbook with Claude](https://kroydb.com/case-studies/contract-review): An example Kroy workflow for law firms. A solicitor asks Claude to review a supplier agreement against the firm’s playbook. Kroy returns only documents from the solicitor’s matter, Claude saves a review note, and requests to open another matter or email the counterparty are refused. - [Preparing a management accounts pack with Claude and Xero](https://kroydb.com/case-studies/management-accounts-pack): An example Kroy workflow for accountancy practices. Claude builds a draft management accounts pack from Xero through Kroy, writes commentary for review, and cannot share it with the client until a manager approves. Individual salary data is excluded. - [Updating Salesforce after a client meeting with Claude](https://kroydb.com/case-studies/crm-updates-salesforce): An example Kroy workflow. After a client meeting, an account manager asks Claude to update Salesforce. Kroy permits activity logging and tasks, routes a stage change to approval, and refuses deleting records, changing account ownership and exporting contacts. - [Handing over a legal matter between people and their AI](https://kroydb.com/case-studies/matter-handoff): An example Kroy workflow for law firms. An associate going on leave asks Claude for a handover note built from the matter’s state in Kroy. A partner reassigns the matter, and the colleague’s ChatGPT picks up the same state. Early access and self-reassignment are refused. - [Partner approval for AI-prepared work](https://kroydb.com/case-studies/partner-approval-workflow): An example Kroy approval workflow for accountancy practices. A manager’s Claude prepares a set of accounts and requests partner approval. The partner’s Copilot summarises the queue, but Kroy refuses any approval made by an agent or by the person who prepared the work. - [A private ERP Connector with a customer-facing order status Skill](https://kroydb.com/case-studies/private-erp-connector): An example Kroy workflow for systems Kroy did not build. A developer creates a private Connector for an in-house ERP and a Check Order Status Skill. Employees' AI and a customer’s own AI both use it through Kroy. Other customers' orders and price changes are refused. - [A public, machine-readable company profile for AI](https://kroydb.com/case-studies/public-ai-company-profile): An example Kroy Publish workflow. A London accountancy practice publishes a public Channel offering services.read, locations.read, articles.read and consultation.request. A prospect’s AI reads accurate information and books a consultation; requests for anything else are refused. - [Employee self-service from SharePoint with AI](https://kroydb.com/case-studies/sharepoint-knowledge): An example Kroy workflow for employee self-service. Staff ask Copilot or ChatGPT about leave, expenses and IT policies. Kroy returns only SharePoint content the employee may read, and can raise a request to HR. Requests for salary bands or HR case files are refused. - [Preparing a consulting proposal with Claude](https://kroydb.com/case-studies/proposal-preparation): An example Kroy workflow for consultancies. Claude drafts a proposal from past proposals and team profiles through Kroy. Day rates are visible only to partners, so Claude leaves pricing for the partner, and Kroy refuses to send the proposal before approval. - [Reviewing a VAT return with Claude and Xero before submission](https://kroydb.com/case-studies/vat-return-review): An example Kroy workflow for accountancy practices. Claude reads a client’s VAT return and the transactions behind it from Xero through Kroy, flags items worth checking in a review note, and is refused when asked to recode transactions or file the return. - [Chasing year-end records with Claude, Xero and Outlook](https://kroydb.com/case-studies/year-end-records-chase): An example Kroy workflow for accountancy practices. Claude checks client status across Xero and SharePoint through Kroy, lists March year-end clients still owing records and creates Outlook drafts — sending stays with a person. ## Industries - [Financial services](https://kroydb.com/industries/financial-services): Kroy lets financial services firms use Claude, ChatGPT and other AI with CRM, reporting and client data — least-privilege access, named identities, human approval for client-facing and record-changing actions, and a complete audit trail. - [Consulting](https://kroydb.com/industries/consulting): Kroy lets consultancies use Claude, ChatGPT and other AI with client engagement documents, Jira, CRM and firm knowledge — per-engagement access, shared project state across AI tools, controlled client sharing and a full audit trail. - [Accountancy](https://kroydb.com/industries/accountancy): Kroy lets accountancy practices use Claude, ChatGPT and other AI with client data from Xero, SharePoint and Outlook — per-client permissions, payroll boundaries, drafts not sends, and a full audit trail. - [Legal](https://kroydb.com/industries/legal): Kroy lets law firms use Claude, ChatGPT and other AI with matter documents and firm systems — per-matter access, ethical walls, drafts not sends, controlled client sharing and a full audit trail of what AI saw and did. - [Technology](https://kroydb.com/industries/technology): Kroy gives technology companies one governed interface for AI agents — shared state between Claude Code, Codex and others, scoped access to GitHub, Jira and internal databases, approvals for merges and releases, and a full audit trail. ## Learn - [AI and client confidentiality](https://kroydb.com/learn/ai-client-confidentiality): Professional confidentiality duties apply whatever tool is used. Firms can use AI with client information if they choose tools with suitable terms, keep clients strictly separate, limit what AI receives, keep a person responsible for output and keep a record of access. - [B2B AI agent collaboration](https://kroydb.com/learn/b2b-ai-agent-collaboration): B2B AI agent collaboration is one organisation’s AI working with another organisation’s information or agents, for example a client’s AI requesting documents from its accountant. It works when each side exposes only defined information and capabilities through a governed relationship. - [Can AI access a SQL database?](https://kroydb.com/learn/can-ai-access-a-sql-database): Yes. AI tools can query SQL databases through a connector or MCP server. The safe pattern is read-only access through a restricted account, limited to specific tables or views, with queries logged, rather than handing an AI a full database login. - [AI access to confidential data](https://kroydb.com/learn/ai-access-to-confidential-data): AI can safely work with confidential data only if access is enforced outside the AI: classify the data, limit each agent to what the task and person need, keep restricted categories out by default, check provider terms, and record every access. - [Can ChatGPT access SharePoint?](https://kroydb.com/learn/can-chatgpt-access-sharepoint): Yes, ChatGPT can work with SharePoint content through a connector that authenticates to Microsoft 365 on someone’s behalf. The questions that matter are whose permissions it uses, which sites and libraries are in scope, and whether anyone can see what it read. - [Can Claude access Xero?](https://kroydb.com/learn/can-claude-access-xero): Yes — Claude can work with Xero data through a connector, typically using the Model Context Protocol. The important questions are who holds the Xero credentials, what Claude may read or change, and whether a person approves financial actions. - [Can Claude send Outlook emails?](https://kroydb.com/learn/can-claude-send-outlook-emails): Technically, yes. With a connector to Microsoft 365, Claude can draft and even send Outlook email. Most organisations should let AI create drafts freely and require a person to approve anything that actually leaves the building. - [Can AI publish to your website?](https://kroydb.com/learn/can-ai-publish-a-website): Yes. AI can draft content, update pages and trigger deployments if it is connected to your content system and hosting. The safe pattern separates drafting from publishing, and requires a person to approve before anything goes live. - [Can one AI share context with another?](https://kroydb.com/learn/can-one-ai-share-context-with-another): Not natively. Each AI tool keeps its own conversations and memory. To share context between Claude, ChatGPT, Copilot and others, the context has to live somewhere independent that every authorised AI can read from and write to. - [Can clients use their own AI with your data?](https://kroydb.com/learn/can-clients-use-their-own-ai): They can, safely, if you share a defined portion of the information through an access layer that decides what their AI may retrieve. Sending files or opening your workspace to a client’s AI gives up that control; sharing a governed projection keeps it. - [How do I give ChatGPT access to company data?](https://kroydb.com/learn/how-to-give-chatgpt-access-to-company-data): Decide which data ChatGPT needs, connect it through a connector rather than uploads, scope access to each person’s permissions, keep sensitive systems out at first, and make sure every retrieval is recorded. Start with one use case, not the whole business. - [Employees using ChatGPT at work](https://kroydb.com/learn/employees-using-chatgpt-at-work): Employees are likely already using ChatGPT and other AI tools, often with personal accounts. Banning it rarely works. A better response is a clear policy, an approved account, rules for what data may be used, and a governed way to connect AI to company information. - [How do I audit AI actions?](https://kroydb.com/learn/how-to-audit-ai-actions): Record every request an AI makes to your systems at the point where it reaches them: who it acted for, which agent, what resource, what action, which rule decided it and what happened. Chat histories alone are not an audit trail. - [How do I revoke AI access?](https://kroydb.com/learn/how-to-revoke-ai-access): List every place an AI holds access, then revoke at the source: remove app consents and tokens, rotate any shared keys, disable the agent’s identity and check the audit trail. Revocation stops future access; it cannot recall what an AI has already retrieved. - [How do I publish company information for AI?](https://kroydb.com/learn/how-to-publish-company-information-for-ai): Keep your company facts in one structured, approved source; publish them as clear, server-rendered pages with consistent terminology and structured data; add machine-readable feeds or an API where useful; and keep everything current and dated. - [How do I restrict what an AI agent can do?](https://kroydb.com/learn/how-to-restrict-an-ai-agent): Restrict an AI agent on four axes: which data it can see, which actions it can take, whom it acts for, and which actions need a person’s approval. Enforce those limits outside the AI, at the point where it reaches your systems, not in its prompt. - [How do I secure an MCP server?](https://kroydb.com/learn/how-to-secure-an-mcp-server): Authenticate every client, keep upstream credentials on the server, expose narrow tools rather than raw access, validate inputs, treat retrieved content as untrusted, require approval for consequential actions, and log every call. MCP defines the connection, not the security policy. - [How do I use Microsoft Entra ID with AI agents?](https://kroydb.com/learn/how-to-use-entra-with-ai-agents): Use Entra ID to sign people in to AI tools and gateways with single sign-on, control which apps may be consented to, manage who has access through groups, and revoke centrally. Entra establishes identity; you still need rules for what each agent may do on a person’s behalf. - [Managing multiple AI agents](https://kroydb.com/learn/managing-multiple-ai-agents): Once an organisation uses several AI tools and agents, it needs one inventory of what is connected, consistent rules for what each may do, shared context so work is not duplicated, and a single record of what they did. Managing each tool separately does not scale. - [Staff sharing client data with AI](https://kroydb.com/learn/staff-sharing-client-data-with-ai): When staff paste client information into AI tools, the firm can lose control of confidential data. The fix is a clear rule, an approved AI route that respects client boundaries, and a way to give AI the client context it needs without copying files into chats. - [Structured company data for AI](https://kroydb.com/learn/structured-company-data-for-ai): Structured company data holds facts about your organisation (clients, services, projects, decisions, locations) as defined records rather than prose in documents. AI can retrieve, filter and act on records reliably, and access can be controlled field by field. - [What is AI delegation?](https://kroydb.com/learn/what-is-ai-delegation): AI delegation is the explicit record of what a person has authorised an AI agent to do on their behalf: which data, which actions, for how long and with what approvals. It lets an agent act for someone without acquiring everything that person can do. - [What is AI observability?](https://kroydb.com/learn/what-is-ai-observability): AI observability is the ability to see how AI is actually being used across an organisation: which agents are connected, which systems they reach, what they did, what was approved or refused, and where AI adds value or risk. It is about organisational insight, not surveillance. - [What is an AI agent?](https://kroydb.com/learn/what-is-an-ai-agent): An AI agent is an AI system that can take steps towards a goal, choosing and using tools such as search, email or a database, rather than only replying with text. Because agents act, businesses need to decide what each one may see, do and do on whose behalf. - [What is AI agent identity?](https://kroydb.com/learn/what-is-ai-agent-identity): AI agent identity means an agent is recognised as a distinct actor, separate from the person it works for, so systems can tell which agent made a request, apply rules to that agent specifically, record its actions and switch it off without affecting anyone else. - [What is an AI control plane?](https://kroydb.com/learn/what-is-an-ai-control-plane): An AI control plane is the layer where an organisation decides and enforces how AI may use its systems: which agents are connected, what each may see and do, which actions need approval, and what gets recorded. It separates those decisions from the AI tools themselves. - [What is an AI-readable website?](https://kroydb.com/learn/what-is-an-ai-readable-website): An AI-readable website presents its information so that AI systems can find it, understand it and describe it accurately: server-rendered pages, clear definitions, consistent terms, semantic structure, structured data, stable URLs and current, dated content. - [What is human-in-the-loop approval?](https://kroydb.com/learn/what-is-human-in-the-loop-approval): Human-in-the-loop approval means an AI can prepare an action, such as an email, payment or publication, but a named person must approve it before it happens. It keeps accountability with people while letting AI do the preparation. - [What is MCP?](https://kroydb.com/learn/what-is-mcp): MCP, the Model Context Protocol, is an open standard that lets AI applications such as Claude connect to external tools and data through "MCP servers". It standardises how an AI discovers and calls capabilities; it does not by itself decide what the AI should be allowed to do. - [What is context engineering?](https://kroydb.com/learn/what-is-context-engineering): Context engineering is the practice of deciding what information an AI receives for a task, and in what form, so it can do the work well. It covers instructions, retrieved data, tools, memory and history, and treats leaving things out as just as important as putting them in. - [What is organisational AI memory?](https://kroydb.com/learn/what-is-organisational-ai-memory): Organisational AI memory is shared, governed knowledge of an organisation’s current work (decisions, status, facts and artifacts) that any authorised AI can use. Unlike a personal chat memory, it belongs to the organisation, carries provenance and respects permissions. ## Glossary - [AI gateway](https://kroydb.com/glossary/ai-gateway): An AI gateway sits between AI tools and business systems so that access, permissions, approval and audit are handled in one place rather than in every AI integration separately. - [AI agent](https://kroydb.com/glossary/ai-agent): An AI agent uses tools to take actions towards a goal. Because agents act, organisations need to decide what each agent may see, what it may do, whom it acts for and when a person must approve. - [Artifact](https://kroydb.com/glossary/artifact): In Kroy, an artifact is something produced — a report, draft, analysis, article or plan — stored with its status, versions, provenance and permissions, so it outlives the AI conversation that created it. - [Approval](https://kroydb.com/glossary/approval): In Kroy, approval is a checkpoint a policy can require before an action runs, such as sending external email, publishing or changing financial records. Kroy holds the action until the right person decides, and records the decision. - [Channel](https://kroydb.com/glossary/channel): A Kroy Channel is where and to whom information and capabilities are exposed. It combines an audience, a projection, artifacts, events and Skills — for example, an employee, client, partner or public channel. - [Delegation](https://kroydb.com/glossary/delegation): Delegation records who authorised whom to do what. In Kroy, an agent’s authority comes from a delegation that can never exceed the delegator’s own permissions, and can be narrowed, time-limited and withdrawn. - [Audit trail](https://kroydb.com/glossary/audit-trail): An audit trail records every request and its outcome, allowed or denied. In Kroy, every AI request passing through the gateway is recorded in one consistent format, across every AI tool. - [Context engineering](https://kroydb.com/glossary/context-engineering): Context engineering designs what an AI works with. In organisations it is also an access decision: context should be filtered by who is asking and for what, before relevance is considered. - [Connector](https://kroydb.com/glossary/connector): A Kroy Connector links Kroy to an external system such as Xero, Outlook or an internal database, defining authentication, resources, actions, events, health and rate limits. - [Entity](https://kroydb.com/glossary/entity): In KroyDB, an entity is a structured record of something that exists in the organisation — a client, project, product, service or decision — which can be queried, related, permissioned and projected to different audiences. - [Human in the loop](https://kroydb.com/glossary/human-in-the-loop): Human in the loop keeps people responsible for consequential decisions while AI does the preparation. In Kroy it is enforced through approval requirements at the point of action. - [Guest](https://kroydb.com/glossary/guest): In Kroy, guests are first-class principals with their own identity, permissions, expiry and audit trail. A guest receives a projection, not a workspace, and may use Kroy directly or through their own AI. - [Event](https://kroydb.com/glossary/event): An event in Kroy is a meaningful organisational change — artifact.approved, deadline.changed, request.created — that subscribers can react to, instead of repeatedly asking what changed. - [Identity](https://kroydb.com/glossary/identity): Identity establishes who is making a request. Kroy identifies the person and the agent separately on every request, so each can have its own rules, audit records and revocation. - [MCP (Model Context Protocol)](https://kroydb.com/glossary/mcp): MCP standardises how AI clients discover and call capabilities in other systems. It defines the connection, not the permissions — deciding what a given person’s AI may do remains an organisational question. - [Policy](https://kroydb.com/glossary/policy): A policy is a rule Kroy applies to every request — for example, requiring human approval before an agent sends external communication. PolicyHQ helps organisations decide their rules; Kroy puts them into practice. - [Principal](https://kroydb.com/glossary/principal): A principal is anyone or anything that can be given access. Kroy treats people, agents, services and guests as distinct principals, so each has its own identity, permissions and audit record. - [Projection](https://kroydb.com/glossary/projection): In Kroy, a projection is the portion of an entity that a particular audience — a client, a partner, the public, an AI agent — may receive. The same record can have many projections. - [Relationship](https://kroydb.com/glossary/relationship): In Kroy, relationships record how things are connected. They let AI follow links between records, and they help decide access — for example, a client guest sees only entities related to their own company. - [Provenance](https://kroydb.com/glossary/provenance): Provenance tells people and AI why Kroy believes something: its source, author, time and basis. It lets a later reader judge how far to trust a fact, especially one recorded by an AI. - [Skill](https://kroydb.com/glossary/skill): A Kroy Skill describes a business job — such as preparing a client reminder — together with the exact data and actions it needs. Connectors describe technical capability; Skills describe business capability. - [State](https://kroydb.com/glossary/state): In Kroy, state is the current, provenance-tracked record of an organisation’s work — decisions, projects, tasks and artifacts — shared across every authorised AI rather than trapped in one chat. - [Subscription](https://kroydb.com/glossary/subscription): A subscription tells Kroy who wants to know about which events. Subscribers receive only the events their permissions allow, so a client learns about their own requests and nothing else.