Compliance
Lumos MCP connector
The Lumos connector brings your apps, users, accounts, groups, roles, and activity logs into Claude, ChatGPT, Cursor, and the Elaichi Agent, so anyone on your team can ask who has access to what and get an answer from Lumos itself.
-
How it connects. Connects with an API key. The credential goes into a vault nobody reads back.
-
One address. https://api.elaichi.ai/mcp, the same for every user.
-
Their own access. An agent never gets more than the person it acts for.
How to connect
How to connect Lumos to Claude, ChatGPT or Cursor
Two steps, about a minute.
In Elaichi
Connect Lumos once
-
Open Connections, choose Add connection, and pick Lumos.
-
Optionally set Share with to give a team access, then press Connect.
-
Paste a Lumos API key. One person generates a token in Lumos and pastes it once. Everyone else works through Share with, and never sees it.
The credential is vaulted. Nobody reads it back, not even the AI.
Add connection
Choose a connector.
In your AI client
Point it at one endpoint
Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.
Connect Lumos to Claude
-
1
Open Customize, then Connectors.
-
2
Press Add.
-
3
Name it, paste the MCP server URL, then Continue.
https://api.elaichi.ai/mcp -
4
Sign in and approve.
On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.
Connect Lumos to ChatGPT
-
1
Open Plugins, then press the + button.
-
2
Name it and paste the endpoint into Server URL.
https://api.elaichi.ai/mcp -
3
Leave Authentication on OAuth, then tick the risk acknowledgement.
-
4
Press Create, then sign in and approve.
Works on the web today. The plugin directory lives at chatgpt.com/plugins.
Connect Lumos to Cursor
-
1
Open
~/.cursor/mcp.json. -
2
Add the endpoint under
mcpServers.https://api.elaichi.ai/mcp -
3
Reload Cursor, then sign in and approve.
~/.cursor/mcp.json
{
"mcpServers": {
"elaichi": {
"url": "https://api.elaichi.ai/mcp"
}
}
}
Set up per machine, so repeat it on each computer you work from.
Connect Lumos to any MCP client
-
1
Add the endpoint as a remote MCP server.
https://api.elaichi.ai/mcp -
2
Sign in and approve.
{
"mcpServers": {
"elaichi": {
"url": "https://api.elaichi.ai/mcp"
}
}
}
The Elaichi Agent already has these tools, with nothing to set up.
Use cases
What teams do with Lumos through Elaichi
Every one of these runs inside the access the person already has, and lands in the same audit log.
-
IT
Answer who has access to what
Ask which accounts a person holds across every app in Lumos, or which people hold accounts in one app, without opening a single admin console.
-
Security
Trace identity events after an alert
Pull the identity events and activity logs around a suspicious sign-in, then ask for the sequence in plain language so the picture is clear before anyone escalates.
-
Compliance
Gather evidence for an access review
List every account and role in a system that is in scope for an audit, group the results by team, and hand the reviewer a ready list instead of a spreadsheet exercise.
-
IT
Add a new app to the Lumos catalog
When the business adopts a tool, create the app in Lumos, put it in the right category, and adjust its settings from the same conversation.
-
People Ops
Confirm a leaver's accounts are closed
On someone's last day, check every account still attached to them in Lumos and flag anything that has not been removed yet.
-
Procurement
See which apps are really in use
Before a renewal, pull the app, its category, and how many accounts exist in it, so the conversation with the vendor starts from real numbers.
Try asking
- “List Lumos apps added in the last 30 days.”
- “Which Lumos users have accounts in the finance apps?”
- “Summarize app settings changed across Lumos this week.”
AI tools
Lumos tools for your AI agents
88 tools are ready to call through Elaichi's MCP endpoint the moment you connect Lumos, governed by the same roles, restrictions, and audit log as everything else in Elaichi.
No tools match your search.
See it in Elaichi
What connecting Lumos gets you
6 screens from the product, each doing one job for your Lumos account.
The agent
Ask about Lumos apps, get real answers.
Question Lumos apps, users and accounts in plain language, answered from live records.
- apps
- app settings
- users
- user accounts
Ask Elaichi to work across your apps.
List Lumos apps added in the last 30 days.
Which Lumos users have accounts in the finance apps?
Summarize app settings changed across Lumos this week.
Also runs in Claude, ChatGPT or Cursor
MCP clients
Claude, ChatGPT and Cursor reach Lumos here.
One org-wide MCP endpoint over OAuth, no SDK and no shared API key.
Copy the endpoint
Tool catalog
88 Lumos tools ready to call.
Apps, app settings, users, user accounts and webhooks, with no custom code.
- List all Lumos apps
- Create a Lumos app
- Get single Lumos app by ID
- Update a Lumos app by ID
Toolboxes
Every team gets its own Lumos toolbox.
Curate one toolbox per team so IT and Compliance see different Lumos tools.
- IT
- Compliance
- Security
- People Ops
Shared connections
Teammates use Lumos without holding credentials.
See who connected each Lumos account and how many teams and members share it.
- IT Core
- Compliance
- Security Ops
- People Ops
Audit log
Every Lumos call is on the record.
When, who, what happened, type and resource, appended for each Lumos request.
- When
- Who
- What happened
- Type
Launching soon
From answering questions to doing the work
A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.
Automations
A schedule runs the whole Lumos review.
Fetch Lumos apps, group them, draft a digest, approve, then post back.
Lumos digest
Run 418 · started 2 minutes ago · on behalf of Emma Laurent
-
✓
Schedule
Every weekday at 08:00
0.2s -
✓
Fetch apps
Lumos
1.4s -
✓
Group by owner
Transform
0.1s -
✓
Draft the digest
Agent step
Ran with 4 tools, returned a structured summary
6.2s -
Approve the digest
Needs approval
Assigned to Michael Brennan
Approve Deny -
Post the digest
Lumos
Queued
Collections and dashboards
Lumos health arrives before anyone asks.
Four metrics, 14 days of records created and a team breakdown, computed on schedule.
Lumos health
Refreshed 4 minutes ago · every 15 minutes · from the apps collection
Apps
1,284 ↓ 12%
App settings
96 ↓ 8%
Needs attention
3 ↑ 2
Updated this week
412 ↑ 9%
Apps created
Last 14 days
By team
Share of activity
IT Core 34%
Compliance 27%
Security Ops 21%
People Ops 18%
Related connectors
More from the catalog
FAQ
Frequently asked questions
How do I connect Lumos to Claude?
First connect Lumos in Elaichi, which asks for a Lumos API key and nothing else, so there is no OAuth application to register and no client ID or secret to generate. Then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp as the endpoint. Claude will ask you to sign in to Elaichi, and from then on your Lumos apps, users, and accounts are available in the conversation.
Does Lumos work with ChatGPT and Cursor as well as Claude?
Yes. Once Lumos is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You connect Lumos once and every client sees it.
What can an AI agent actually do with my Lumos data?
With Lumos connected, an agent can look up a person and list the accounts, groups, and roles they hold, list the apps in your catalog and their categories, and read identity events and activity logs to explain what happened and when. It can also create and update apps and their settings, and upload account lists for systems Lumos does not reach on its own. Because Lumos exposes a lot of capabilities, short concrete asks such as "list Jane's accounts" work better than long paragraphs.
Does connecting Lumos give the AI access to everything in my Lumos workspace?
No. Every call into Lumos runs as the person who signed in, so the agent sees only the apps, users, and accounts that person's Lumos permissions already allow. Elaichi can narrow that further with restrictions, but it can never widen it beyond what Lumos itself grants.
Can I stop an agent from changing things in Lumos?
Yes. Restrictions in Elaichi are set per action, so you can allow reading users, accounts, and activity logs from Lumos while blocking the ability to create or update apps and settings. A blocked action is never shown to Claude, ChatGPT, Cursor, or any other client, so no prompt, however worded, can reach it.
What happens to a Lumos connection when someone leaves?
Offboarding that person in Elaichi ends their access to Lumos through every AI client at once. If they were using a shared Lumos connection, it keeps working for everyone else on the team. If you want the connection gone entirely, disconnecting Lumos once in Elaichi removes it from Claude, ChatGPT, Cursor, and every other client at the same time.
Put Lumos in front of your team
Fourteen days on Gold, no credit card. Connect it once and pick what each team can call.