Uday Gajavalli
Uday builds with customers in the driver's seat. He loves jumping on calls, spotting the real pain behind the feature request, and turning that insight into a product that feels obvious in hindsight. He loves tight feedback loops, clean experiences, and systems that quietly do the right thing. From first click to production scale, he's all about making customers feel supported, successful, and genuinely delighted.
Posts
26 posts
AI consultant for small business: what to expect
A good AI consultant for small business learns your work, sets AI up in your own apps, tests it with your team and hands it over in writing.
AI consultant vs AI automation agency: who to hire
AI consultant vs AI automation agency: one gives you a plan, the other builds automations. Forward deployed engineers do both, in your apps.
How to connect AI to CRM without engineers
To connect AI to CRM data safely, give each person's assistant only their own CRM access, start with reads, and keep a log of what it does.
MCP governance: who may do what, in which app
MCP governance decides who connects which app, which tools each role calls, whose account a call uses, what is logged and how access ends.
Why AI pilots fail, and how to get to daily use
Why AI pilots fail: the AI cannot reach your apps, nobody trusts it, or nobody owns it. The fix for each cause, and how to measure daily use.
Vendor MCP servers: why run them through Elaichi
Vendor MCP servers bring the vendor's own tools. Through Elaichi they also get one address, per-person sign-in, tool rules and one audit log.
AI agents with employee permissions, no shared bot
How to run AI agents with employee permissions instead of one shared service account, and the cases where a named service identity is still correct.
Approved AI tools per team, set by role
Approved AI tools per team is two jobs: restrictions bound to a role for enforcement, and templates shared to a team for curation.
ClickUp in ChatGPT for a customer success team
Two decisions put ClickUp in ChatGPT for a customer success team: whose account each call runs on, and which ClickUp tools are restricted.
QuickBooks read-only for a finance team in Claude
QuickBooks has no read-only OAuth scope, so QuickBooks read-only has to be enforced by whatever calls the API. Here is how to do it with one restriction.
Ramp in Claude for finance, minus admin reach
Ramp in Claude for a finance team, without giving every analyst an admin seat: one authorized connection, read-only scopes, restrictions on the finance role.
IT admin controls for MCP connectors, compared
What the IT admin controls for MCP connectors cover in Claude, ChatGPT and Cursor, and the three gaps none of those consoles closes.
Scheduled AI agent tasks, governed in advance
Scheduled AI agent tasks run with nobody present to approve, so the controls that count are set first: role restrictions, frozen arguments, a narrowed grant.
MCP security review checklist: ten questions
An MCP security review checklist: ten questions to ask before approving an MCP server or gateway, what a good answer looks like, and Elaichi's answers.
MCP security risks and how to reduce them
The MCP security risks a company faces, from prompt injection to keys in local configs, with an example and a fix for each, and who owns the fix.
Replace personal MCP servers on employee laptops
Find the MCP servers employees run from each client's config file, then replace personal MCP servers and their tokens with one governed endpoint.
How to roll out Claude and ChatGPT to employees
Roll out Claude and ChatGPT to employees in order: approve apps, connect them once, build team toolboxes, map roles, pilot, onboard and offboard.
Xero in Claude, without letting it edit invoices
Xero in Claude for a finance team: analysts read invoices and reports, no assistant can edit or void an invoice, and one named person drafts supplier bills.
Why blocks match tool names but allows don't
In Elaichi, blocks match tool names or the operation behind them, while allows match the operation only, so a renamed tool can never widen a role's reach.
Lock AI agent tool arguments, like a wire's payee
Lock AI agent tool arguments with frozen parameters: Elaichi removes the field from the model's schema and writes your value over whatever the call sends.
SCIM and AI agents: where provisioning stops
SCIM and AI agents meet at the user account: SCIM creates, updates and deactivates it, but it never decides which tools an agent may call.
The MCP context window problem, and a fix
The MCP context window problem: each listed tool sits in the model's prompt on every turn. Elaichi lists no connected tools; the model searches for them.
Zendesk for support agents, minus bulk deletes
Zendesk for support agents in Claude: let them read and update tickets, block deletes and bulk sends, and give the lead one exception.
Best MCP gateways for company-wide AI access
The best MCP gateways come in four shapes: a hosted catalog, a gateway you run, a per-member server or a control plane. Pick the shape, then the vendor.
Put agents to work on your own systems
14 days on Gold, no credit card. Start with one app and one team.
- Works with
-
and any other MCP client, or the Elaichi Agent.
- When the trial ends
- Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.