# Connor > Connor is the AI control layer for teams. Find out who your AI champions are, package what they built, and distribute it with the controls already in place. Pre-seed stage; the endpoint scanner is macOS today. Contact: james.zhao@runconnor.com Two halves of one layer. Enablement: find the AI your people have already built, package the best of it as governed capabilities, and hand it to everyone who needs it. Compliance: know what went into AI, keep the record that proves it, and find the AI nobody registered. Both run on the same identity, the same policy and the same audit trail, which is why they are one product rather than two. ## Start here - [Home](https://runconnor.com/): Distribute AI to your team, safely. - [Compliance monitoring](https://runconnor.com/compliance): AI monitoring for compliance teams. Every file and chat going into Claude and ChatGPT checked against your watch list, plus the AI nobody registered. - [Leadership](https://runconnor.com/leadership): You are using tokens. Is it driving value? Adoption, cost, risk and shadow AI across every vendor, in one report. ## Platform Three stages, twelve parts. - [Discover](https://runconnor.com/platform/discover): See who's building skills in AI, and surface shadow AI. - Scan: Skills, MCPs and the shadow AI on the machines. An agent on each machine reads what is actually there: skills, MCP servers, prompts and rules. No survey, because the people building the most interesting things are rarely the ones filling in forms. - Connections: Activity from Claude and ChatGPT. Pulls the full activity stream out of Claude Enterprise and ChatGPT Enterprise rather than the summary each console shows, and normalises it into one event model. - Inventory: One list of every skill and MCP. The scan and the connections merge into a single living inventory of every skill, MCP server and capability your organisation has, with an owner and a version against each. - Reporting: The numbers leadership decides on. What is being used, by which teams, at what cost, and by whom. Including the report that answers the only question that matters at board level: is any of this working. - [Distribute](https://runconnor.com/platform/distribute): Package the best of it and put it on the right desks. - Capabilities: Skills, context and tools, packaged. One person's working method, packaged so it behaves the same on somebody else's machine: the instructions, the context they assume, the exact tools they may reach, and the guardrails. - Catalog: Where published work lives. The registry everyone installs from. Browse what has been published, see who owns it and what version you are on, and install in one action. - MCP Gateway: Every tool ready, nothing to set up. Connor is a single MCP server. Somebody assigned a capability has every tool it needs the moment they open it — nothing to install, no accounts to create, no keys to find. They connect once to Connor and everything their role is allowed to reach is already there. - Profiles: Identity, roles and who gets what. Assign to a role rather than to a person. Everybody in it has the capability today, and anyone who joins it next month arrives with it already. - [Govern](https://runconnor.com/platform/govern): Monitor all tool calls and optimise token usage. - Audit log: Every call and every activity, recorded. One record covering two kinds of event: the tool calls made through the gateway, and the activity coming back from the provider APIs. Who, what, when, and the reason attached. - Rules engine: Deterministic rules, with judgement on top. Your own watch list and policies applied to everything, not a sample. Deterministic rules give the same answer every time; a model reads for the sensitivity a rule could not anticipate. - Exceptions: Raised with the reason attached. What the rules engine surfaces becomes a case somebody can act on: the event, the rule it matched, the person, and enough context to decide without going and asking. - Token optimisation: Stop paying for what nobody reads. A tool returns everything the record has and the model reads a fraction of it. Distill trims the response in the path of the call, before it reaches the context window. ## How it is sold Connor is a partnership rather than a licence. A forward-deployed engineer runs the setup, walks the discovery report with you, works with the champions the scan surfaced to package their best work, and pilots it with one team before it widens. Where there is a compliance obligation, a compliance professional comes with them. ## What is true today - The endpoint scan is macOS. It is read-only and collects no secrets. - Claude Enterprise and ChatGPT Enterprise activity are supported. Gemini is in build. - No compliance API from any vendor returns tool-call payloads. Those are recorded by the Connor MCP gateway, which sits in the path of the call. ## Writing - [Most companies can't tell if their AI is actually paying off](https://runconnor.com/blog/ai-roi-gap-why-most-companies-see-no-return): Most companies are not failing to get value from AI. They are failing to find out whether they did. Here is why returns go missing, and what closes the gap. - [How to write an AI Skill your team will actually use](https://runconnor.com/blog/how-to-write-an-ai-skill): Most Skills fail at discovery, not quality. They are never triggered because the description is vague. Here is how to write one that gets picked up and used. - [Why banks have paid $3.5bn in fines over WhatsApp](https://runconnor.com/blog/why-banks-fined-billions-whatsapp): Every firm fined already banned WhatsApp for business. They were not punished for the app. They were punished for being unable to say what was said on it. - [You probably don't need to build an AI agent for that](https://runconnor.com/blog/you-dont-need-to-build-an-agent): The reflex is to commission an agent per workflow. Most of the time the right unit is a Skill plus the tool connections it needs, which nobody has to build. - [Every real AI incident comes down to what you connected it to](https://runconnor.com/blog/ai-gone-wrong-real-company-incidents): Samsung, Apple, Asana, Air Canada, Microsoft 365 Copilot. A tour of what actually happened when AI met company systems without governance — and the pattern underneath. - [What a shadow AI report actually shows you](https://runconnor.com/blog/reading-a-shadow-ai-report): A real Connor scan of an 86-person company found 402 MCP servers and 273 skills. Here is how to read the report — the egress surface, the risk, the sprawl. - [Shadow AI: what it is, and why you should care](https://runconnor.com/blog/shadow-ai-what-it-is-and-why-you-should-care): Shadow AI is the AI your team already uses that you cannot see — models, agents and tool connections wired into live systems, outside any oversight. - [Your team keeps rebuilding the same AI skills](https://runconnor.com/blog/sharing-ai-skills-across-a-team): Most teams lose time, not gain it: the same AI skills get rebuilt on desk after desk and the best ones never spread. Here is why it happens, and the fix. - [The risk isn't the AI. It's the access you bolt on around it.](https://runconnor.com/blog/team-ai-access-security-risks): Giving your team AI access is the easy part. The risk is not the model: every connected tool is an unscoped key, with no record of what it did. - [The hidden token tax in every MCP call](https://runconnor.com/blog/mcp-token-cost): Every MCP tool call returns far more than the model needs, and you pay for all of it. Here is where the token tax comes from and how to cut it. - [What is an AI control plane?](https://runconnor.com/blog/what-is-an-ai-control-plane): An AI control plane is the governed layer between your team and the AI tools they use. Here is what it does, why teams need one, and when to adopt it. ## Elsewhere - [Brand assets](https://runconnor.com/brand): marks, lockups, colour and the rules for using them. Machine-readable index at https://runconnor.com/brand/manifest.json - [Contact](https://runconnor.com/contact): leave an email address and we reply within a day. - [Privacy](https://runconnor.com/privacy) · [Terms](https://runconnor.com/terms)