Your team already uses AI. The question is: whose keys?

Toolshed makes AI adoption safe for organisations of 10–100 people — and for public-sector teams held to even higher standards. Your team works with Claude, Codex, or Cursor on real work data, always within their own roles and permissions, without ever seeing an API key.

https://toolshed.aqqo.io/mcp

78%

of AI users bring their own AI tools to work — 80% at smaller organisations

Microsoft & LinkedIn Work Trend Index

28.65M

keys and secrets leaked publicly on GitHub in 2025, with AI-service leaks up 81%

GitGuardian, State of Secrets Sprawl 2026

±70%

of leaked credentials are still valid years later — nobody revokes them

GitGuardian, State of Secrets Sprawl 2026

The problem

The backdoor you can't see

Employees don't wait for policy. The most resourceful ones connect AI tools to mail, files, and databases themselves — and this is what “I'll just set it up myself” actually looks like.

Keys in plain text

API and MCP keys end up in config files on laptops, in chat history, and in notes apps. Unencrypted, and invisible to IT.

Tied to personal accounts

The key belongs to a person, not to the organisation. Nobody else can see it, rotate it, or revoke it.

More rights than the role

An admin token “because then it works”. The AI tool can suddenly do more than the employee was ever allowed to.

Keeps working after they leave

Offboarding checklists cover accounts, not stray keys. The backdoor stays open indefinitely.

Banning AI doesn't work — usage goes underground and the risk grows. The real question is not whether your team connects AI to your systems, but whether you decide how.

How it works

From one MCP URL to every approved tool

https://toolshed.aqqo.io/mcp

One endpoint for every tool

Employees sign in with their existing work account and reach every approved system through the same MCP URL.

Team MCP access

Choose which integrations this team can use.

S

Sirportly

6 tools

M

MariaDB

3 tools

D

Docs

2 tools

Toolshed checks access

Every request routes through Toolshed, where organisation and team rules decide what each user can reach.

Codex

Use the same approved tools

Claude

Use the same approved tools

Cursor

Use the same approved tools

Works in your favorite AI client

Codex, Claude, Cursor, and other MCP-compatible apps all use the same governed toolset.

Why Toolshed

More for your team, control for your organisation

1

No loose keys

  • Every credential is stored AES-256-GCM encrypted in one vault; tokens are stored hashed
  • Employees never see or manage an API or MCP key themselves
  • One secured endpoint instead of dozens of connections tied to personal accounts

2

Control without friction

  • Roles at organisation and team level: teams decide who gets which integration
  • Offboarding = disable the SSO account, and every AI connection closes with it
  • A usage dashboard shows every tool call — provable for auditors and clients

3

Fits the stack you run

  • Microsoft Entra ID SSO plus native SharePoint, Outlook, Teams, and OneNote integrations
  • Works with any MCP client: Claude, Codex, Cursor — and whatever comes next
  • Aqqo is ISO 27001 certified; built and operated in the Netherlands

Identity & access

Plugs into the identity you already run

AI access should follow your directory — not live next to it in a separate admin.

Available

Microsoft Entra ID

SSO through your existing tenant via OpenID Connect. Your MFA and Conditional Access policies apply automatically to every sign-in.

Coming soon

Entra group mapping

Map team access to the Microsoft Entra security groups your Conditional Access policies already govern — so AI permissions follow your directory. A must-have we hear from government IT.

Coming soon

Google Workspace

Google SSO with Google Groups as the access-group equivalent, for organisations outside the Microsoft stack.

The most tangible proof

Employee leaves? SSO off — all AI access gone.

Every AI connection runs through your identity provider and user-bound tokens. The offboarding step you already have — disabling the account — now closes every AI connection too. One action, nothing left behind.

Without Toolshed

Stray keys on personal accounts survive every offboarding checklist. Nobody knows they exist, so nobody revokes them. An ex-employee's access never expires.

With Toolshed

Disable the SSO account and every AI connection closes instantly — keys stay in the encrypted vault, tokens are user-bound, and the usage dashboard proves it.

Built for organisations that run on sensitive data

AccountingLegal & notaryEngineering & consultingSoftware & IT servicesFinancial servicesMunicipalities & public sectorHealth-adjacent services
See if Toolshed fits your organisation

AI on, backdoor closed.

See in 30 minutes how your team works safely with Claude, Codex, or Cursor on real work data — within the roles and permissions you already manage.

Aqqo is ISO 27001 certified

Book a demo