2Gen: Success with technology
// MCP GATEWAYS

Give AI access to your systems. Not the keys to them.

Custom secured MCP gateways that connect Claude, ChatGPT and your own agents to Microsoft 365 and your business systems, with access controlled at the level you'd actually sign off on.

// THE PROBLEM

Built-in connectors were designed for convenience, not for control.

Every major AI tool now ships connectors for Microsoft 365, Google Workspace and the rest. They take about a minute to switch on and that minute is the whole problem. Nobody scoped what the AI can reach because the connector never asked.

ALL-OR-NOTHING

A built-in connector inherits whatever the person who authorised it can reach. Connect a mailbox and you've connected the whole mailbox.

NO PER-TOOL POLICY

You can't say "read the calendar, never send mail." The connector's operations come as a bundle and it's take it or leave it.

THE WRONG CEILING

When a director connects M365 the AI tool gets director-level reach. Seniority becomes blast radius.

THIN AUDIT TRAIL

What was read, by whom and when sits in the AI vendor's console rather than in your logs, your SIEM or your compliance evidence.

TOKENS YOU DON'T HOLD

Access tokens live with the AI vendor. Revoking means working through their interface on their timeline.

ONE GRANT PER TOOL

Claude, ChatGPT, Copilot and your own agents each need their own connection, each separately authorised and each separately forgotten about.

// HOW IT WORKS

A gateway in the middle, answering to you.

The AI tool connects to your gateway instead of connecting to Microsoft directly. The gateway holds the real credentials, enforces your policy on every request and passes back only what it should. Four dials and all of them yours.

OPERATIONS
Allowlist, not bundle

Only the operations you approve are exposed at all. Everything else simply isn't there to call.

IDENTITY
Scoped per person

The same gateway gives different people different reach, mapped to your existing roles and groups.

DIRECTION
Read and write, separated

Read-only by default. Anything that sends, deletes or modifies sits behind explicit approval.

EVIDENCE
Every call logged

Who asked, which operation ran and what came back. Written to your systems rather than a vendor's dashboard.

The practical difference: with a built-in connector, the question is “do we trust this AI tool with the account we connected it to?” With a gateway, the question becomes “which specific operations do we want available and to which people?” That's a question you can answer, document and change later.

// WHAT YOU GET

The productivity, without the open door.

Your team still gets an AI assistant that knows the business. You get to say precisely what that means.

Your credentials never leave your control

The gateway holds the connection to Microsoft 365 or whichever system you're exposing. The AI tool authenticates to the gateway. It never receives a Graph token and nothing it generates can exfiltrate one. Revocation is a switch you own.

Narrower than the account it runs as

Scope down to specific mailboxes, sites, folders or record types. A gateway built for a support team can read the shared inbox and nothing adjacent to it. That's a restriction the underlying platform permissions alone won't give you.

Filtering before the model sees anything

The gateway decides what actually comes back. Fields can be redacted, records filtered and volumes capped so sensitive data never enters an AI vendor's context in the first place.

One gateway, every AI tool

MCP is an open standard so the same gateway serves Claude, ChatGPT and any agent you build in-house. One place to set policy, one place to audit and one place to switch off.

// WHAT WE CONNECT

Microsoft 365 first. Then whatever else runs your business.

Microsoft 365 / GraphSharePoint & OneDriveExchange & TeamsEntra IDLine-of-business databasesTicketing & CRMInternal APIsFile shares

Most engagements start with Microsoft 365 because that's where the mail, the documents and the calendars are. It's also the connector people switch on without thinking.

From there the same pattern extends to anything with an API: your line-of-business database, your ticketing system, your CRM and your internal tools. If your team would be faster with an AI assistant that can see it, we can expose it safely.

We build the gateway, define the policy with you, wire up logging into your existing monitoring and hand over something you can audit and change without calling us.

Already switched a connector on? Worth a conversation.

Tell us which AI tools your team is using and what they're connected to. We'll tell you what that currently exposes and what a gateway would change.