Can I stop the model from using a specific tool?
Yes. Restrictions work on individual tools, not whole applications. Set an allow or block rule on a role or on one person; a person-level rule can only narrow what the role allows. A restricted tool is left out of what Elaichi advertises, and search shows it only as restricted, with no way to call it.
What does the audit log record for each call?
One append-only entry for every tool call that runs, succeeded or failed: the person, the operation and tool, the account actually reached, the client it came through, how it was approved and the outcome. A call refused before it runs, for example by a restriction, writes no entry. Argument values are not recorded, only the id of the record a call targets.
Can I tell which AI client made a call?
Yes. Each entry records the surface and the named client, such as Claude, ChatGPT or Cursor, alongside the person the call ran for.
Can I give a compliance reviewer access without paying for a seat?
Yes. The Auditor role is read-only and free. A reviewer can see the log and the configuration without a license and without the ability to change anything.
How do restrictions resolve between a role and a person?
Restrictions target a role or a person. A person-level rule can only narrow what the role rule allows, a block always beats an allow, and with no rule the default is open, so you narrow access deliberately with role and person rules.
How long until a new restriction takes effect?
About two minutes. Roles and restrictions resolve through a short cache on every surface. Revoked shares and suspended members take effect on the next request.
Can I send the audit log to my own SIEM?
Forwarding to your own Datadog comes with the Black plan, which is launching soon. On Gold, the audit trail lives in Elaichi, searchable by person, action and time.
Who approves what an AI agent does?
Over MCP, the person approves on Elaichi’s consent screen when they connect a client, choosing whether it may read, change, run tools or delete, and delete is never pre-ticked. Elaichi adds no per-call approval over MCP; a confirmation before a single action is the client’s own prompt, where the client offers one.