# Team playbooks

> Setting a single team up with governed access, in the order you would actually do it, using the systems that team already runs.

- [Space permissions for Confluence in ChatGPT](https://elaichi.ai/blog/chatgpt-confluence-space-permissions/) — ChatGPT ships no Confluence connector, so Confluence in ChatGPT runs over MCP. Here is the route that keeps each person inside their space permissions.
- [Scope Google Drive in Claude to people or folders](https://elaichi.ai/blog/claude-google-drive-sharing-permissions/) — Google Drive in Claude has two honest shapes: each person connects their own Google account, or one dedicated account whose shared folders draw the line.
- [Govern SharePoint in Claude with delegated OAuth](https://elaichi.ai/blog/claude-sharepoint-permissions/) — How to keep SharePoint in Claude inside each person's own site and library permissions, using per-person OAuth and one allow rule per role.
- [ClickUp in ChatGPT for a customer success team](https://elaichi.ai/blog/customer-success-chatgpt-clickup-tasks/) — Two decisions put ClickUp in ChatGPT for a customer success team: whose account each call runs on, and which ClickUp tools are restricted.
- [QuickBooks read-only for a finance team in Claude](https://elaichi.ai/blog/finance-team-claude-quickbooks-read-only/) — QuickBooks has no read-only OAuth scope, so QuickBooks read-only has to be enforced by whatever calls the API. Here is how to do it with one restriction.
- [Ramp in Claude for finance, minus admin reach](https://elaichi.ai/blog/finance-team-claude-ramp-spend/) — Ramp in Claude for a finance team, without giving every analyst an admin seat: one authorized connection, read-only scopes, restrictions on the finance role.
- [Keep BambooHR salary data out of AI assistants](https://elaichi.ai/blog/hr-team-bamboohr-salary-data/) — Two layers keep BambooHR salary data away from Claude and ChatGPT: the access level behind the API key, and an allow rule per role in Elaichi.
- [Keep payroll data in HR with Gusto in Claude](https://elaichi.ai/blog/hr-team-claude-gusto-payroll/) — Gusto in Claude runs on Gusto's own MCP server. One admin connects it in Elaichi, HR gets a Gusto-only toolbox, and roles decide who reaches which tool.
- [Intune in Claude for help desk lookups only](https://elaichi.ai/blog/it-team-claude-intune-devices/) — Intune in Claude for a help desk is one allow rule, not six blocks: the msintune connector carries 198 tools and only 69 of them read.
- [Jamf in Claude on a read-only API role](https://elaichi.ai/blog/it-team-claude-jamf-devices/) — Jamf in Claude lets a help desk check a Mac's inventory mid-ticket. Build a read-only Jamf API role, then narrow it per person with Elaichi restrictions.
- [Xero in Claude, without letting it edit invoices](https://elaichi.ai/blog/finance-team-claude-xero/) — Xero in Claude for a finance team: analysts read invoices and reports, no assistant can edit or void an invoice, and one named person drafts supplier bills.
- [Should marketing get HubSpot inside ChatGPT?](https://elaichi.ai/blog/marketing-team-chatgpt-hubspot-campaigns/) — Yes: marketing can have HubSpot inside ChatGPT to read contacts and campaigns and draft work, with email sends and deletes restricted and the portal pinned.
- [Each rep's own Salesforce access, in ChatGPT](https://elaichi.ai/blog/sales-team-chatgpt-salesforce-accounts/) — Salesforce access in ChatGPT works per rep: each call runs on the rep's own connection, so Salesforce's sharing rules decide which accounts they see.
- [Ironclad contracts in ChatGPT, signing blocked](https://elaichi.ai/blog/legal-team-chatgpt-ironclad-contracts/) — Legal reads Ironclad contracts in ChatGPT through Elaichi. The connector has no signing or approval tool, and a role rule blocks launching or cancelling.
- [Let IT post to one Slack channel from Claude](https://elaichi.ai/blog/it-team-claude-slack-messaging/) — IT can post to one Slack channel from Claude when Elaichi freezes the channel argument. Channel reads stay open, and opening DMs is restricted for the role.
- [HR can read Rippling in Claude, not run payroll](https://elaichi.ai/blog/hr-team-claude-rippling-employees/) — HR can read Rippling in Claude through Elaichi: workers, teams and departments. The connector has no payroll-run tool, and one rule keeps HR to reads.
- [Zendesk for support agents, minus bulk deletes](https://elaichi.ai/blog/support-team-claude-zendesk-tickets/) — Zendesk for support agents in Claude: let them read and update tickets, block deletes and bulk sends, and give the lead one exception.
- [How to roll out Cursor to an engineering team](https://elaichi.ai/blog/engineering-team-cursor-jira/) — To roll out Cursor to an engineering team, connect Jira and Slack once, block deletes per role, pin the project and channel, then have engineers sign in.
- [Which Notion workspace did ChatGPT write to?](https://elaichi.ai/blog/product-team-chatgpt-notion-workspace/) — Elaichi's audit trail names the Notion workspace each ChatGPT call reached. Pin the connection or database first, and the other workspace is out of reach.
