Overview
Many organisations on Microsoft 365 have Copilot, and many of their staff also use Claude or ChatGPT. Each AI tool arrives with its own way of reaching business data. Kroy gives them one governed route.
Microsoft Copilot is an AI client. Business systems connect to Kroy through Connectors; Copilot connects to Kroy to use them, within the limits Kroy sets for each person.
How Copilot connects
Kroy exposes an MCP server. Copilot experiences that can call external tools — for example an agent built in Copilot Studio with an MCP tool — can add Kroy. Microsoft’s Copilot products and their extension options differ and change over time; check Microsoft’s current documentation for the product you use.
Where Kroy fits alongside Microsoft 365
Copilot already works with your Microsoft 365 content according to Microsoft’s own permissions. Kroy adds what sits outside that: Xero, Salesforce, an internal PostgreSQL database, shared Kroy State and Skills that define exactly what an agent may do. It also gives you the same rules for Copilot as for every other AI tool you allow.
Identity
With Microsoft Entra ID connected, the person signing in to Kroy is the same person using Copilot. Entra groups map to Kroy roles, and disabling a user in Entra ends their delegations to every AI agent.
Permissions
Kroy treats each Copilot agent as an agent with its own identity, linked to a person by a delegation. Kroy decides every request against the person, the agent, the delegation, the policy and any approval.
Security
Copilot holds only a Kroy delegation. It never receives the credentials Kroy holds for connected systems. Every request, approval and refusal is recorded.