Software & IT services
Client environments, databases, and ticketing systems like Sirportly.
Developers will connect AI tools anyway. Toolshed channels it: read-only SQL policy, central tokens, telemetry per tool call.
Industries
Toolshed is made for teams that are big enough to hold sensitive client data — and too small for a dedicated security team. And for public-sector organisations, where provable control is not optional. If this sounds like you, we should talk.
10–100 people
enough data and roles to govern, no dedicated security team
Microsoft 365 stack
Entra ID, SharePoint, Outlook, Teams — IT is one person, a small team, or an external MSP. Google Workspace support is on the roadmap.
AI-curious team
employees already use Claude, ChatGPT, or Cursor, with or without permission
Sensitive data
client files, financials, citizen data — and clients or auditors who ask questions about it
Ordered by how sharply it bites. The first three are the beachheads — an MSP is both a customer and a channel into every other one.
Client environments, databases, and ticketing systems like Sirportly.
Developers will connect AI tools anyway. Toolshed channels it: read-only SQL policy, central tokens, telemetry per tool call.
One MSP runs Entra, SharePoint, and Teams for dozens of small clients.
Govern AI access once and resell it across your whole client book — a new managed-service line, and every client's AI made defensible. (Multi-tenant management is on the roadmap.)
Annual accounts, payroll, client files in SharePoint and practice software.
One leaked connection touches dozens of clients at once. Toolshed gives AI access within team permissions, without anyone ever seeing a key.
Case files, correspondence, and deeds in SharePoint and Outlook.
Professional privilege makes stray AI connections indefensible. Everything stays within SSO and each person's role.
Citizen IDs, policies, and income data in mail and client files.
Regulatory pressure demands provable control. The usage dashboard and encrypted credentials are your evidence.
Calculations, drawings, tender documents, and project data across SharePoint and databases.
Project teams get AI on their own project data — teams in Toolshed decide exactly who gets which integration.
Absence and health data in Outlook and SharePoint — occupational health, care administration, staffing.
The most sensitive data type there is, so AI only within tightly managed access.
Public sector
Aqqo already serves government organisations, and the public sector is where unmanaged AI access is least defensible: citizen data, case files, and permits demand provable control.
An employee's shadow AI is the wedge, the IT lead is who has to make it safe, and the director signs on defensibility. So we sell to IT — never around them.
Right now it's either “not allowed” or wiring up API keys and config files yourself — and quietly connecting things that shouldn't be.
Sign in with your work account and use AI on real files, mail, and data — the tools you already like, exactly what your team is allowed to see.
Every self-made AI connection is a credential you don't know about, can't rotate, and can't revoke when someone leaves — and you're held accountable anyway.
One gateway instead of dozens of shadow connections. Register once, assign per team, and offboard through the identity process you already run — every tool call logged.
Your team already uses AI, but you can't see what it's connected to — and under NIS2 the liability is personal.
Say yes to AI with a defensible story for auditors, clients, and insurers: everything behind SSO, roles, and an ISO 27001 certified vendor.
We'd rather tell you now than after a demo. Toolshed is probably not for you if:
On Google Workspace? Support is on the roadmap — get in touch and we'll tell you when it lands.
In one conversation we'll map which AI tools and connections already exist in your organisation — and how to bring them under control without slowing anyone down.
Aqqo is ISO 27001 certified