Industries

Built for organisations that run on trust

Toolshed is made for teams that are big enough to hold sensitive client data — and too small for a dedicated security team. And for public-sector organisations, where provable control is not optional. If this sounds like you, we should talk.

10–100 people

enough data and roles to govern, no dedicated security team

Microsoft 365 stack

Entra ID, SharePoint, Outlook, Teams — IT is one person, a small team, or an external MSP. Google Workspace support is on the roadmap.

AI-curious team

employees already use Claude, ChatGPT, or Cursor, with or without permission

Sensitive data

client files, financials, citizen data — and clients or auditors who ask questions about it

Where this lands first

Ordered by how sharply it bites. The first three are the beachheads — an MSP is both a customer and a channel into every other one.

Software & IT services

Client environments, databases, and ticketing systems like Sirportly.

Developers will connect AI tools anyway. Toolshed channels it: read-only SQL policy, central tokens, telemetry per tool call.

Managed service providers

One MSP runs Entra, SharePoint, and Teams for dozens of small clients.

Govern AI access once and resell it across your whole client book — a new managed-service line, and every client's AI made defensible. (Multi-tenant management is on the roadmap.)

Accounting & administration

Annual accounts, payroll, client files in SharePoint and practice software.

One leaked connection touches dozens of clients at once. Toolshed gives AI access within team permissions, without anyone ever seeing a key.

Legal & notary

Case files, correspondence, and deeds in SharePoint and Outlook.

Professional privilege makes stray AI connections indefensible. Everything stays within SSO and each person's role.

Financial services

Citizen IDs, policies, and income data in mail and client files.

Regulatory pressure demands provable control. The usage dashboard and encrypted credentials are your evidence.

Engineering & consulting

Calculations, drawings, tender documents, and project data across SharePoint and databases.

Project teams get AI on their own project data — teams in Toolshed decide exactly who gets which integration.

Health-adjacent services

Absence and health data in Outlook and SharePoint — occupational health, care administration, staffing.

The most sensitive data type there is, so AI only within tightly managed access.

Public sector

Built to clear the bar municipalities set

Aqqo already serves government organisations, and the public sector is where unmanaged AI access is least defensible: citizen data, case files, and permits demand provable control.

  • Sign-in runs through your Microsoft Entra ID tenant, so your MFA and Conditional Access policies apply automatically
  • Team access mapped to Entra security groups — the groups your Conditional Access already governs — is on the roadmap
  • Every tool call is logged, and access is granted and revoked centrally: evidence that slots into your BIO and ISO 27001 accountability
  • An ISO 27001-certified vendor, built and operated in the Netherlands

Demand starts with the team. The deal is won with IT.

An employee's shadow AI is the wedge, the IT lead is who has to make it safe, and the director signs on defensibility. So we sell to IT — never around them.

Starts the demand

The employee

Right now it's either “not allowed” or wiring up API keys and config files yourself — and quietly connecting things that shouldn't be.

Sign in with your work account and use AI on real files, mail, and data — the tools you already like, exactly what your team is allowed to see.

Primary — has to make it safe

The IT manager or MSP

Every self-made AI connection is a credential you don't know about, can't rotate, and can't revoke when someone leaves — and you're held accountable anyway.

One gateway instead of dozens of shadow connections. Register once, assign per team, and offboard through the identity process you already run — every tool call logged.

Signs the deal

The managing director

Your team already uses AI, but you can't see what it's connected to — and under NIS2 the liability is personal.

Say yes to AI with a defensible story for auditors, clients, and insurers: everything behind SSO, roles, and an ISO 27001 certified vendor.

When Toolshed isn't the right fit

We'd rather tell you now than after a demo. Toolshed is probably not for you if:

  • Fewer than ±10 people — you can manage keys among yourselves
  • An enterprise with its own security team and IAM landscape — different league, different requirements
  • No meaningful internal systems or sensitive data — nothing to unlock, nothing to protect

On Google Workspace? Support is on the roadmap — get in touch and we'll tell you when it lands.

Recognise your organisation?

In one conversation we'll map which AI tools and connections already exist in your organisation — and how to bring them under control without slowing anyone down.

Aqqo is ISO 27001 certified