Connectors & Tools

Connect what you already run. Govern every call it makes.

The systems your team lives in, plus any MCP server your agents should reach, each one connected as the person asking, and checked before the call rather than reported after it.

What it connects to

The systems your work already lives in.

Every connection is governed the same way, whichever family it comes from, and a source your organisation has not approved simply is not there.

22,000+ apps already ship an MCP server. Yours are one governed connection away: ZeroH connects as the person asking, masks before any model, and puts every call on the ledger.

Connected natively today: 7 systems plus the Microsoft estate, 36 governed tools in the box. Not on the list? Ask: we ship new tools every day, and a connector you need is usually days away.

Microsoft 365
Outlook

Triage the unread pile, draft a reply in the thread, never send without your yes.

Live
Microsoft 365
Teams

Where the agents work: ask in a channel, get the answer and its receipt in the same place.

Live
Microsoft 365
SharePoint

A folder becomes a knowledge base; the folder’s own permissions decide who its answers reach.

Live
Microsoft 365
Calendar

Find the free hour, prep the meeting, and know what was decided in the last one.

Live
Microsoft 365
Word

Draft and redline in the document itself, with the sensitive parts masked before any model.

Live
Microsoft 365
PowerPoint

Build the deck from a project’s own context, in your brand kit.

Live
Sales & CRM
Dynamics 365

Read accounts and opportunities, log the activity, keep the record true, field by field.

Live
Sales & CRM
HubSpot

The same governed CRM reads and writes, under each user’s own HubSpot authorisation.

Liveconnects with your own HubSpot OAuth app
Developer
GitHub

Commits, diffs and file reads under your own identity: only the repositories you can already see.

Live
Developer
Jira

Work items read as you: Atlassian’s own per-project visibility is the boundary, not ours.

Live
Knowledge & web
Google Drive

Documents your team keeps in Drive, read under each person’s own Google authorisation.

Live
Knowledge & web
Web search

Research a company or a market with the egress allow-listed and every fetch on the record.

Live
Content
Ghost

Blog and newsletter drafts land in your CMS as drafts, and the family cannot publish by construction.

Live
Bring your own
Any MCP server

ZeroH is the MCP client, connecting as the person asking, so the server’s own permissions still apply, and the result is masked and recorded before any model sees it.

Live
Bring your own
Your own API

Declare an endpoint as a governed tool: same masking, same approvals, same ledger as the built-in ones.

In buildthe console authoring flow is being built out

A folder is a source too, that is how a shelf of documents becomes cited answers. Knowledge & Memory →

Before the call, not after

Anyone can connect a system. This is the part that decides what happens next.

A connection is not consent. Between an agent deciding to use a tool and the tool running, four things are settled, who may use it, what the model may ever see of it, who agreed, and whether a person has to say yes.

1
A tool is granted to an agent, for a job

Not “the AI can use your CRM”. The Sales agent may look up an account because that is the work it was hired to do; the Help Desk agent cannot, because it was not. The grant is the pairing of an agent, a tool and the job it serves.

Live
2
You choose, field by field, what the model may ever see

Connecting a system does not hand it over. Each field carries its own rule, and anything you have not declared is masked rather than guessed, so a schema that grows on the vendor’s side cannot quietly widen what leaves your tenant.

Account nameTokenizedthe model reasons over [ORG-77be03], never “Nordbank”
Billing addressNever sentredacted at the seam, it leaves your tenant for nobody
Deal valueBanded“100k–250k” instead of the figure, when the band is enough to reason
StageIn the clearthe model needs it to be useful, and it identifies no one

The person reading the answer sees the real account name: it is rehydrated on your servers after the model is done. The model never had it.

Livelive for CRM today; the unified per-connector panel is in build
3
Two people have to say yes, and you can take it backLive
4
Reading is one thing. Sending, writing and spending are another.

A read changes nothing: the worst case is that the agent knows something it did not need. An action leaves a mark outside ZeroH: someone receives the mail, the record changes, the money moves. So every tool is tiered low or high, and a high one never runs unattended unless you decided it may.

Approval requiredA person approves it

The job stops and waits as a card with the full context. Nothing is sent, written or spent until someone says yes.

DelegatedThe agent may decide

You pre-approve the routine cases for that agent and that tool. It proceeds alone, and every run is still receipted.

RefusedIt never runs unattended

Some actions are simply refused for that agent, whatever it decides. The refusal is the policy working, not a bug.

And when the case is not one you covered, the agent asks instead of guessing. The escalation goes to a person with the context attached.

Live
Nothing is reachable until you approve it

Saying yes to a new data source should not be an act of faith.

Add the connector, and before you say yes, see exactly what it would reach and which actions it would enable. Approve what you saw; nothing was reachable before that moment.

1
Configure

Add the connection and supply the credential. It lives in your key vault by reference, the token bytes never touch a store, a log, or the ledger.

2
Probe

ZeroH connects and asks the system what is actually there, instead of trusting a description of it.

3
Preview

You see the capability preview before you decide: the tables and records it would reach, and the agent actions it would enable.

4
Approve

You approve what you saw. Nothing was reachable before this moment, and the approval itself lands as a policy-change event.

In buildgoverned source reads through connectors are live; the console configure → probe → preview → approve flow is being built out

Per field, not per system

See exactly what the AI reads from each source.

Right where you connect a source, a panel will list its fields and what the model gets of each: tokenized, masked, or in the clear because reasoning needs it. Anything undeclared is masked, not guessed.

Masked by default

A field you never declared is masked, not guessed, so a schema that grows on the vendor’s side cannot quietly widen what the model sees. Fail closed is the default everywhere in ZeroH.

Plannedper-field structured masking is live for CRM today; the unified per-connector panel is the new piece

One truth, two places to read it

The same rules show cross-cut across every connector in the Policy Center, and changing one is a versioned, audited write.

See the control plane →

Tell us what you run. We will show you the governed version of it.