Blog · Page 2
Governing AI agents in the apps you already run
How the gateways compare, what to restrict, what the audit log has to capture, and what each team does with it.
Intune in Claude for help desk lookups only
Intune in Claude for a help desk is one allow rule, not six blocks: the msintune connector carries 198 tools and only 69 of them read.
Jamf in Claude on a read-only API role
Jamf in Claude lets a help desk check a Mac's inventory mid-ticket. Build a read-only Jamf API role, then narrow it per person with Elaichi restrictions.
Microsoft Copilot with Salesforce: two paths
Microsoft Copilot with Salesforce indexes your CRM for search. Live reads and writes from Claude, ChatGPT or Cursor take a different path.
n8n AI agents per-user permissions and audit
n8n AI agents per-user permissions come down to whose credential a run holds: what n8n documents, and what Elaichi's MCP endpoint requires.
OpenAI Agents SDK governed access to company apps
What OpenAI Agents SDK governed access to Salesforce and Slack requires: a person's browser OAuth grant, token rotation, and restrictions written server-side.
How to restrict ChatGPT Enterprise connectors
You can restrict ChatGPT Enterprise connectors per app, and per group on Enterprise and Edu. Here is exactly where that grain stops.
Scheduled AI agent tasks, governed in advance
Scheduled AI agent tasks run with nobody present to approve, so the controls that count are set first: role restrictions, frozen arguments, a narrowed grant.
Stop sharing personal API keys with AI tools
Find where people sharing personal API keys with AI tools put them, lean on what the key issuers already catch, then remove the reason to paste one.
MCP for coding agents across an engineering org
MCP for coding agents needs one endpoint, a sign-in per engineer, and rules the agent cannot edit, because nobody reads each call it makes.
Connect company apps to Claude and ChatGPT
To connect company apps to Claude and ChatGPT, connect each account once in Elaichi, share it, and add one URL to both. No MCP server to run.
Connect Elaichi to Claude Code
To connect Elaichi to Claude Code, run one claude mcp add command and sign in with OAuth. The entry holds no secret, so a project .mcp.json is safe to commit.
Connect Elaichi to Codex
To connect Elaichi to Codex, add one URL as a streamable HTTP server and run codex mcp login. No token, no header, and each engineer signs in as themselves.
Connect Elaichi to VS Code and Windsurf
To connect Elaichi to VS Code and Windsurf, add one URL to each editor's MCP config and sign in with OAuth. No personal API keys on any laptop.
Docker MCP Gateway vs a managed MCP platform
Docker MCP Gateway vs a managed MCP platform: Docker runs MCP servers in containers you operate. Elaichi serves connectors behind one sign-in URL.
EU data residency for AI agents, leg by leg
EU data residency for AI agents spans three legs: the app, the control plane and the model. Elaichi's eu region pins the data store and tool calls to the EU.
Human approval for AI agent actions: the layers
Human approval for AI agent actions comes in layers: a prompt for the person asking, then the role rules, frozen values and requests an admin decides.
Kong vs Cloudflare MCP gateway, or managed connectors?
Kong vs Cloudflare MCP gateway: both govern MCP servers you build or bring. A managed connector platform ships the SaaS connectors already written.
MCP security review checklist: ten questions
An MCP security review checklist: ten questions to ask before approving an MCP server or gateway, what a good answer looks like, and Elaichi's answers.
MCP security risks and how to reduce them
The MCP security risks a company faces, from prompt injection to keys in local configs, with an example and a fix for each, and who owns the fix.
Replace personal MCP servers on employee laptops
Find the MCP servers employees run from each client's config file, then replace personal MCP servers and their tokens with one governed endpoint.
How to roll out Claude and ChatGPT to employees
Roll out Claude and ChatGPT to employees in order: approve apps, connect them once, build team toolboxes, map roles, pilot, onboard and offboard.
What is an MCP control plane, and who needs one?
An MCP control plane is one org-wide MCP endpoint that serves the tools, signs each person in and decides access on every call.
Connect Elaichi to Claude
To connect Elaichi to Claude, add one URL as a custom connector and sign in with OAuth. On Team and Enterprise, an Owner adds it once for everyone.
Fix OAuth errors when adding an MCP connector
Most OAuth errors when adding an MCP connector come from the URL, the account or a missing checkbox. What each Elaichi error means, and who fixes it.
Put agents to work on your own systems
14 days on Gold, no credit card. Start with one app and one team.
- Works with
-
and any other MCP client, or the Elaichi Agent.
- When the trial ends
- Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.