Skip to content

Nachi Raman

Co-founder and CEO at Elaichi. Entrepreneur driven by the challenge of building businesses from the ground up and scaling them to significant outcomes. Works closely with customers to understand what they actually need, and makes sure the product that reaches them is worth the trust they place in it.

Posts

17 posts

9 min read

Find the MCP servers employees have installed

No admin console lists the MCP servers employees have installed. The order that works: a device sweep, the vendor logs that exist, then a direct ask.

10 min read

Keep BambooHR salary data out of AI assistants

Two layers keep BambooHR salary data away from Claude and ChatGPT: the access level behind the API key, and an allow rule per role in Elaichi.

6 min read

Keep payroll data in HR with Gusto in Claude

Gusto in Claude runs on Gusto's own MCP server. One admin connects it in Elaichi, HR gets a Gusto-only toolbox, and roles decide who reaches which tool.

9 min read

Stop sharing personal API keys with AI tools

Find where people sharing personal API keys with AI tools put them, lean on what the key issuers already catch, then remove the reason to paste one.

6 min read

Connect Elaichi to VS Code and Windsurf

To connect Elaichi to VS Code and Windsurf, add one URL to each editor's MCP config and sign in with OAuth. No personal API keys on any laptop.

7 min read

EU data residency for AI agents, leg by leg

EU data residency for AI agents spans three legs: the app, the control plane and the model. Elaichi's eu region pins the data store and tool calls to the EU.

7 min read

Kong vs Cloudflare MCP gateway, or managed connectors?

Kong vs Cloudflare MCP gateway: both govern MCP servers you build or bring. A managed connector platform ships the SaaS connectors already written.

8 min read

Engineers using ChatGPT at work: block or scope it

For engineers using ChatGPT at work, scope access rather than block it. A block moves the paste to a phone; scoped access removes the reason to paste.

9 min read

Each rep's own Salesforce access, in ChatGPT

Salesforce access in ChatGPT works per rep: each call runs on the rep's own connection, so Salesforce's sharing rules decide which accounts they see.

9 min read

Ironclad contracts in ChatGPT, signing blocked

Legal reads Ironclad contracts in ChatGPT through Elaichi. The connector has no signing or approval tool, and a role rule blocks launching or cancelling.

6 min read

Connect Elaichi to Cursor for a whole team

To connect Elaichi to Cursor, add one URL to mcp.json or share it as a Team MCP server, and each developer signs in with OAuth. No API key.

9 min read

What an AI agent audit log must capture

An AI agent audit log must capture who acted, which client called, which account was reached, what was tried and how it ended. Argument contents stay out.

10 min read

Is Composio secure enough for enterprise use?

The answer to "is Composio secure enough for enterprise use" sits in architecture more than controls: its own pages list SSO, role permissions and call logs.

11 min read

MintMCP alternative when you run no MCP servers

If you run no MCP servers, Elaichi is a MintMCP alternative that writes and hosts its own connectors and serves them through one MCP endpoint.

10 min read

HR can read Rippling in Claude, not run payroll

HR can read Rippling in Claude through Elaichi: workers, teams and departments. The connector has no payroll-run tool, and one rule keeps HR to reads.

12 min read

What is an MCP gateway? The four shapes

What is an MCP gateway: one address between AI clients and their tools that signs people in, applies rules and records calls. It comes in four shapes.

13 min read

Offboarding AI access, contractors included

Offboarding AI access in Elaichi takes effect on the next call. Here is what the removal preflight checks, and the order that works.

Put agents to work on your own systems

14 days on Gold, no credit card. Start with one app and one team.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.