Skip to content

Blog · Page 4

Governing AI agents in the apps you already run

How the gateways compare, what to restrict, what the audit log has to capture, and what each team does with it.

10 min read

Designing roles for AI agents: one role each

Design roles for AI agents as one complete job per person: Elaichi gives each member exactly one role and leaves which tools they reach to restrictions.

Raajshekhar Rajan

9 min read

AI agents and PHI: four questions for your BAA

AI agents and PHI raise four BAA questions, all about access: minimum necessary, audit controls, workforce clearance and what happens when someone leaves.

Roopendra Talekar

9 min read

Let IT post to one Slack channel from Claude

IT can post to one Slack channel from Claude when Elaichi freezes the channel argument. Channel reads stay open, and opening DMs is restricted for the role.

Roopendra Talekar

9 min read

What an AI agent audit log must capture

An AI agent audit log must capture who acted, which client called, which account was reached, what was tried and how it ended. Argument contents stay out.

Nachi Raman

10 min read

Is Composio secure enough for enterprise use?

The answer to "is Composio secure enough for enterprise use" sits in architecture more than controls: its own pages list SSO, role permissions and call logs.

Nachi Raman

11 min read

MintMCP alternative when you run no MCP servers

If you run no MCP servers, Elaichi is a MintMCP alternative that writes and hosts its own connectors and serves them through one MCP endpoint.

Nachi Raman

10 min read

HR can read Rippling in Claude, not run payroll

HR can read Rippling in Claude through Elaichi: workers, teams and departments. The connector has no payroll-run tool, and one rule keeps HR to reads.

Nachi Raman

8 min read

Restrict one AI tool or the whole app? Six cases

Restrict one AI tool when a role needs part of an app, and block the whole app when it needs none of it. Six cases, and what new tools do to each rule.

Roopendra Talekar

9 min read

Proving AI actions in access review evidence

To prove AI actions in access review evidence, record the person and the client behind each call as it happens. SaaS logs name the account, not the client.

Raajshekhar Rajan

10 min read

Zendesk for support agents, minus bulk deletes

Zendesk for support agents in Claude: let them read and update tickets, block deletes and bulk sends, and give the lead one exception.

Uday Gajavalli

12 min read

What is an MCP gateway? The four shapes

What is an MCP gateway: one address between AI clients and their tools that signs people in, applies rules and records calls. It comes in four shapes.

Nachi Raman

15 min read

Best MCP gateways for company-wide AI access

The best MCP gateways come in four shapes: a hosted catalog, a gateway you run, a per-member server or a control plane. Pick the shape, then the vendor.

Uday Gajavalli

11 min read

Elaichi vs Merge Agent Handler: three forks

Elaichi vs Merge Agent Handler comes down to three forks: one address or many, a grant or a stored secret, and who authors the connectors.

Roopendra Talekar

9 min read

MCP server registry vs first-party connectors

MCP server registry vs first-party connectors comes down to who fixes a broken tool: each server's own author, or one vendor that wrote and serves them.

Roopendra Talekar

13 min read

How to roll out Cursor to an engineering team

To roll out Cursor to an engineering team, connect Jira and Slack once, block deletes per role, pin the project and channel, then have engineers sign in.

Roopendra Talekar

12 min read

OAuth or API keys for AI agents?

Choosing OAuth or API keys for AI agents comes down to revocation: a grant is checked on every call, while a key works until someone rotates it.

Roopendra Talekar

13 min read

Offboarding AI access, contractors included

Offboarding AI access in Elaichi takes effect on the next call. Here is what the removal preflight checks, and the order that works.

Nachi Raman

8 min read

Which Notion workspace did ChatGPT write to?

Elaichi's audit trail names the Notion workspace each ChatGPT call reached. Pin the connection or database first, and the other workspace is out of reach.

Raajshekhar Rajan

8 min read

Shadow AI browser extension log: what it proves

A shadow AI browser extension log proves which AI extensions are installed, where, and which sites they asked to read. It cannot show what anyone pasted.

Uday Gajavalli

7 min read

An API gateway for MCP, or an MCP-native server?

An API gateway for MCP fits when the tools are your own APIs, already behind it. For SaaS accounts your staff sign in to, an MCP-native server fits better.

Uday Gajavalli

13 min read

MCP gateway pricing: per seat vs per call

MCP gateway pricing is metered per call, per task or per seat. Per call is cheaper at low volume; per seat is the bill a company can forecast.

Raajshekhar Rajan

Put agents to work on your own systems

14 days on Gold, no credit card. Start with one app and one team.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.