# Safety and trust

Plain answers to the questions organisations ask before letting AI near their systems. The full Trust Centre is at https://getkroy.com/trust.

## Credentials

Connections to systems such as Xero or Microsoft 365 are held by Kroy and used only by Kroy to carry out requests that have already been allowed. Credentials are never returned to an AI, through the API, or in the Kroy app.

## What an AI receives

The result of each allowed request — the records, documents or confirmations that request was permitted to return. Nothing outside that. What an AI receives is then handled under that AI provider’s own terms, which is why organisations choose which AI tools are approved for which information.

## Can an AI get around Kroy?

Not for systems connected only through Kroy: without credentials, the AI’s only route is through Kroy’s checks. Telling an AI to ignore its rules does not change what Kroy allows, because Kroy makes the decision. Kroy cannot control a separate, direct connection someone sets up outside it.

## Approvals

Some actions should never happen without a person: sending external email, publishing, approving invoices, merging code, deploying. Kroy holds these until an authorised person decides, in Kroy. An AI can ask for approval; it can never give it.

## Guests and their AI

A guest — a client, adviser, auditor — sees only the portion of a record that was shared with them (a projection). If they connect their own AI, that AI is bound by the same projection. Access can expire and can be revoked. Revoking stops future access; it cannot recall what was already seen.

## Record of what happened

Kroy records every request that passes through it — allowed, refused or waiting for approval: the person, the AI, the record or system, the action, the rule that decided it and the result.

## Separation between organisations

Each organisation’s data is kept separate, and every request is decided within one organisation’s rules.

## Refusals

- Giving an AI the passwords, tokens or keys to connected systems.
- Letting an AI see more than the person it acts for can see.
- Letting an AI approve anything. Approvals are made by people, in Kroy, never by an AI on anyone’s behalf.
- Letting someone approve work they prepared themselves, where the organisation requires a second person.
- Returning data outside what was shared — for a guest, anything beyond their projection; for staff, other clients, other matters or restricted material.
- Running actions that sit outside the Skill being used, however the request is worded.
- Changing its rules because an AI was told to. The decision is made by Kroy, not by the AI.
