Overview
Claude is an AI client. It does not connect to Kroy the way Xero or GitHub does. Business systems connect to Kroy through Connectors; Claude connects to Kroy to use them.
Once connected, a person can ask Claude “What are the outstanding records for ABC Limited?” Claude calls Kroy. Kroy checks the person, the agent, the delegation between them, the policy and any approval requirement, then runs the authorised request and returns the result. Claude never sees the Xero or Microsoft 365 credentials.
How Claude connects
Kroy exposes an MCP server. Claude products that support remote MCP connectors can add Kroy as a connector; Claude Code can connect to Kroy as an MCP server from the terminal. What is available varies by Claude product and plan, and changes over time — check Anthropic’s current documentation for the product you use.
What Claude can reach
Only what Kroy allows for the person Claude is acting for, narrowed by the Skills in use. A manager’s Claude sees that manager’s clients. A Skill that permits outlook.draft.create lets Claude draft an email; it does not let Claude send one.
One state of work
Work Claude does through Kroy is recorded in Kroy State. If a colleague picks up the task in ChatGPT, or Codex reviews what Claude Code changed, they start from the same record rather than from nothing.
Permissions
Kroy treats Claude as an agent with its own identity, linked to a person by a delegation. An organisation can allow Claude for some Skills and not others, restrict it to particular teams, or require approval for anything it publishes.
Security
Claude holds only a Kroy delegation. Revoking it — or disabling the person in your identity provider — ends Claude’s access to every connected system at once. Every request Claude makes, and every request Kroy refuses, is recorded.