Instead of AI → every system
The direct model looks like this: AI → Xero. AI → Outlook. AI → CRM. AI → database. Each connection carries its own credentials and its own idea of what the AI may do.
AI → Kroy → authorised system
With Kroy in between, one request flows through one place:
- Kroy authenticates the person and identifies the agent.
- It determines the delegation and resolves permissions.
- It restricts the context to what this request needs.
- It requires human approval where policy says so.
- It executes the authorised operation with credentials the AI never sees.
- It records the result and updates organisational state.
More than routing
Kroy is not model-routing infrastructure. What makes it different is what sits behind the gateway: organisational state, permissions, Skills, execution, publishing and audit.
How AI connects
AI clients connect to Kroy using open standards such as the Model Context Protocol (MCP), alongside Kroy’s API.