Security
Your agent gets exactly the access you have
Every MCP tool call runs inside the permissions you already grant that person. Nobody at either end of a shared connection ever handles a credential.
Compliance
One security review covers every application your people reach through Elaichi, not one review per app.
01 · Credentials
Nobody ever handles a credential
Connecting an application happens in a hosted flow. The credential is encrypted at rest in a dedicated vault, and the API returns it to nobody, not to a person and not to a model.
In once
through a hosted sign-in
Handed back to
- A person in the console
- A model in any client
- A colleague you share with
Share a capability, not a password
A colleague uses your connection for one constrained job. They call the application through it without ever seeing the credential, and they cannot step outside the tools you shared with them.
02 · Access
An agent gets exactly the access of the person it acts for
Every call is checked against the permissions that person holds right now, across 8 predefined roles and any custom role you build. Revoke a share, disconnect an account or remove someone, and the very next request reflects it.
- 38
- permissions to build a role from
- 8
- predefined roles, plus custom roles
- ~1 min
- for a role change to land everywhere
03 · Restrictions
You choose what the agent can even see
Restrictions work on individual tools, not on whole applications. Set them on a role, or on one person, where a person-level rule can only narrow what the role allows.
Where it is checked
- 1 Listing connectors and tools
- 2 Connecting an account
- 3 Saving a toolbox
- 4 Advertising tools to a client
- 5 Running a call
- 6 The outbound request
Audit
Every action is attributed to a person
The append-only log records who, or which agent acting on whose behalf, did what, down to the record changed in the third-party system.
Every tool call lands there with the tool, the connection, the status and the duration. Forward the whole stream to your Datadog, with batched retried delivery and a dead-letter queue.
Audit log
Append only
-
EC 200 312 ms
Emily Carter
Claude
salesforce.update_opportunity
Opportunity 006Ag00000R2xQ1
-
EA 200 288 ms
Elaichi Agent
acting for Jake Morgan
jira.transition_issue
OPS-2841, moved to In Review
-
MB 200 194 ms
Megan Brooks
ChatGPT
slack.post_message
Message in #revenue-ops
-
RH Restricted 9 ms
Ryan Hayes
Cursor
notion.update_page
Refused, restricted for this role
The rest of the review
Short answers to the questions that come next.
- Sign in the way your company already does
- SAML SP and OIDC RP implemented in-house, so no third-party auth vendor sits in the login path. DNS-verified domains, enforced SSO, JIT provisioning, SCIM v2 user and group sync, group-to-role mapping, passkeys, and step-up auth on sensitive actions.
- Cut a client off and it is off
- Session, API and invite tokens are stored as keyed hashes and shown exactly once. MCP access runs on OAuth, so there is no URL or token to lose, and disconnecting a client ends its session immediately. Rate limits apply on both the data plane and the control plane.
- Read from the source, at the moment of the call
- Deals, tickets and pages are fetched from the application when an agent asks for them. You also choose where the data Elaichi does hold lives, across 3 regions: US, EU and APAC.
- Your models, your bill
- Bring your own keys for 4 model providers. Nothing is routed through us for inference, so prompts and results do not become our data, and there is no markup and no lock-in.
- Offboard someone in one action
- Removing a member runs a preflight. Personal connections that shared toolboxes depend on must be transferred or deleted before the removal completes, and unreferenced connections are cleaned up, vault account included.
- Automations will run under the same rules
- Scheduled automations, and dashboards computed from your connected apps, are launching soon. They will be checked against the same roles and restrictions as the person they act for, and land in the same audit log.
Bring your security team. We will go line by line.
Permissions, restrictions, audit, SSO, SCIM and data residency, on the record. Or start a trial and read the audit log yourself.
- Works with
-
and any other MCP client, or the Elaichi Agent.
- When the trial ends
- Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.