Connectors›How it works
How connectors work under governance.
A connector is not an integration. It is a scoped credential plus a policy that constrains what an agent may do with it — and the whole point of governing one is that both halves are written down before anyone connects anything.
What a connector actually is
Three things travel together, and a connector is ungoverned if any one of them is missing.
The distinction matters because “we integrate with your ledger” and “an agent on your machine may read your ledger under these constraints” are different claims with different risk. Only the second one can be audited.
Three things true of every connector we certify
The credential is yours, and stays yours
The credential is issued to you and held by Claude on your own device or in your own cloud tenancy. Skoor never holds it, never proxies the connection, and is not a subprocessor you need to disclose to your clients.
The scope is least-privilege and written down
Read-only unless a narrower grant exists. Bound to the specific accounts, sites, folders or company files named in your profile — anything unnamed returns nothing rather than returning everything.
The audit trail is written to a store you control
Your SIEM, your log bucket, your database. We read it to compute your Agent Skoor and keep no copy. If the sink stops accepting writes, that is itself a drift event rather than a silent gap.
What you are actually approving
You are not approving a piece of software. You are approving a set of permissions granted to something that acts on a colleague’s behalf — which is a decision your function already knows how to make. Four questions get you there, and every connector page on this site answers them in the same order.
- What can it reach, and what can it never reach? A permissions list without a refusals list is half an answer. Read the refusals first — they tell you where the boundary actually is.
- Who holds the credential? If a third party holds it, they are a subprocessor and you must disclose them to your own clients. If you hold it, you have nothing to disclose.
- What would an examiner see? Ask which fields are written, and where. “It is logged” is not an answer; a field list is.
- What happens when it changes underneath us? Vendors add scopes. Standards move. Ask what triggers a re-review and inside what window.
A note on what we do not claim. A connector page describes controls. It does not say you are compliant with anything — that is a legal conclusion and it belongs to your counsel. We think being explicit about where our statements stop is part of why they are worth reading.
How a profile is applied
Claude runs on your own desktop and mobile devices, or in your own cloud tenancy. We do not install an agent of ours alongside it and we do not stand between it and anything.
What it changes on the machine
Configuration and policy, not the client. Your staff keep using Claude as they already do — the profile governs what it may reach and records what it did. Anthropic ships the application; we are never a version behind because we do not ship one.
What happens when something moves
A connector approved in March is not still approved in September merely because nobody touched it. Three things move underneath a deployment, and each one re-opens the question.
The vendor changes a scope
A platform adds a permission to an existing grant, or quietly widens what one already covers. The allowlist is checked against what the grant actually confers, not what it conferred at signing.
Your deployment drifts
A folder appears outside the allowlist. An account shows up that is not in the profile. The audit sink stops accepting writes. Each is a drift event with a committed detection window.
The standard itself changes
Guidance is reissued, a regulator adds an obligation, your own clients start asking for something new. The rubric version bumps and everything scored against the old one is re-scored.
What we will not do, on any connector
- Move money. No profile grants an agent payment initiation, and it is not available by request or by exception. Autonomous money movement changes the control environment enough that we decline it rather than attempt to govern it.
- Hold your credentials. Not in escrow, not for convenience, not during onboarding. The moment we hold one, we are a subprocessor and the assessment stops being independent.
- Retain your data. We read your audit trail to compute a score. We do not copy the records the trail describes.
- Push a profile change silently. Versioned, signed, and applied on your approval. A configuration you did not agree to is a supply-chain risk wearing a helpful face.
How to check anything on this site
Every claim here is meant to be checkable, because a score from a party you cannot audit is just an opinion with a number attached.
- The rubric is published per industry and fixed before an engagement begins — you read it before we score you.
- Certifications carry a rubric version and a date, and link to the changelog entry that promoted them.
- Connectors that are not certified say so plainly. Today, that is all of them.
- Refusals are published alongside permissions, because a list that never says no tells you nothing.
Find out what is already connected.
Most firms discover during the assessment that staff have already connected things nobody approved. That is the normal finding, not the embarrassing one.
Book an assessment