Posts
21 posts
How to approve apps for Claude across a company
There are two places you approve apps for Claude: Anthropic's connector controls, and the restriction rules behind your one MCP endpoint.
Space permissions for Confluence in ChatGPT
ChatGPT ships no Confluence connector, so Confluence in ChatGPT runs over MCP. Here is the route that keeps each person inside their space permissions.
Scope Google Drive in Claude to people or folders
Google Drive in Claude has two honest shapes: each person connects their own Google account, or one dedicated account whose shared folders draw the line.
Govern SharePoint in Claude with delegated OAuth
How to keep SharePoint in Claude inside each person's own site and library permissions, using per-person OAuth and one allow rule per role.
Microsoft Copilot with Salesforce: two paths
Microsoft Copilot with Salesforce indexes your CRM for search. Live reads and writes from Claude, ChatGPT or Cursor take a different path.
n8n AI agents per-user permissions and audit
n8n AI agents per-user permissions come down to whose credential a run holds: what n8n documents, and what Elaichi's MCP endpoint requires.
OpenAI Agents SDK governed access to company apps
What OpenAI Agents SDK governed access to Salesforce and Slack requires: a person's browser OAuth grant, token rotation, and restrictions written server-side.
How to restrict ChatGPT Enterprise connectors
You can restrict ChatGPT Enterprise connectors per app, and per group on Enterprise and Edu. Here is exactly where that grain stops.
Connect company apps to Claude and ChatGPT
To connect company apps to Claude and ChatGPT, connect each account once in Elaichi, share it, and add one URL to both. No MCP server to run.
Connect Elaichi to Claude
To connect Elaichi to Claude, add one URL as a custom connector and sign in with OAuth. On Team and Enterprise, an Owner adds it once for everyone.
Fix OAuth errors when adding an MCP connector
Most OAuth errors when adding an MCP connector come from the URL, the account or a missing checkbox. What each Elaichi error means, and who fixes it.
MCP tools not showing up? Start here
MCP tools not showing in Claude, ChatGPT or Cursor? With Elaichi, connected tools are never listed by design. Check these five things, in order.
Least privilege for AI agents without breakage
Least privilege for AI agents starts from what your pilot actually called: narrow to that recorded set, then confirm the rule landed before you trust it.
Lunar MCPX alternative: count your servers first
With no MCP servers to front, the Lunar MCPX alternative is a hosted server like Elaichi. With several, a gateway like MCPX still fits.
Connect Elaichi to ChatGPT
To connect Elaichi to ChatGPT, a workspace admin adds one MCP endpoint as a custom app and each person signs in with OAuth. No API key, no per-user URL.
How MCP tool search picks one tool from hundreds
MCP tool search in Elaichi scores tools by matching words, then returns nothing unless a tool covers at least half the query, with rare words weighted most.
CASB and AI agents: what each layer can see
CASB and AI agents: a CASB sees who reached which AI service and how much data moved, but not which tool an agent ran or which account it changed.
Designing roles for AI agents: one role each
Design roles for AI agents as one complete job per person: Elaichi gives each member exactly one role and leaves which tools they reach to restrictions.
Proving AI actions in access review evidence
To prove AI actions in access review evidence, record the person and the client behind each call as it happens. SaaS logs name the account, not the client.
Which Notion workspace did ChatGPT write to?
Elaichi's audit trail names the Notion workspace each ChatGPT call reached. Pin the connection or database first, and the other workspace is out of reach.
MCP gateway pricing: per seat vs per call
MCP gateway pricing is metered per call, per task or per seat. Per call is cheaper at low volume; per seat is the bill a company can forecast.
Put agents to work on your own systems
14 days on Gold, no credit card. Start with one app and one team.
- Works with
-
and any other MCP client, or the Elaichi Agent.
- When the trial ends
- Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.