How fast does access end when someone leaves?
On their next request. When your identity provider deactivates them, SCIM suspends them in Elaichi and every live grant is revoked in the same transaction. Suspending or removing them by hand has the same effect.
Doesn’t single sign-on already cover AI clients like Claude and ChatGPT?
Single sign-on controls who can sign in to a client. The connections people make inside a client to your apps are set up separately, by each person. With Elaichi, people arrive with a role, and when they leave, every AI client they connected through Elaichi is refused on its next call.
Does SCIM delete the member in Elaichi?
No. A SCIM deactivation or delete suspends the member, which revokes every grant their AI clients hold. Reactivating them restores the membership, and their clients connect again with fresh consent. Removing a member for good is a separate step an admin takes, with the offboarding preflight.
Which identity providers can manage access?
Elaichi supports SAML and OIDC single sign-on and SCIM v2 provisioning, all built in-house with no third-party auth vendor in the sign-in path, so an identity provider that speaks those standards can manage who has access.
Does SCIM put people into teams?
No. A SCIM group mapping grants at most one role and never sets team membership. Invites can preset teams, and people who arrive through SCIM, single sign-on or a verified domain are added to teams afterward.
How long until a role change takes effect?
About two minutes. Roles, restrictions and team membership resolve through a short cache. Suspension, removal and revoked shares take effect on the next request.
How does offboarding keep shared workflows running?
A preflight. Before a member is removed, any of their connections a shared toolbox depends on must be transferred to another member or deleted. A private connection nothing else depends on is deleted rather than handed on.
Do we keep paying for people who have left?
Not once they are suspended. Billable seats are active memberships, so suspended members, along with free roles such as Auditor and Guest, are not counted.
Can we test single sign-on and SCIM before paying?
Yes. Every organization starts with a 14-day Gold trial, no credit card needed, and single sign-on, SCIM and group-to-role mapping are all part of it.