Bring people in through the sign-in system your company already uses, with the right role from the start, and close their access in one action when they leave.
Elaichi follows the system your company already uses to manage employee accounts, known as an identity provider.
People join through SAML or OIDC single sign-on, SCIM, a verified domain or a single-use invite, and arrive with the right role. When your identity provider deactivates someone, SCIM suspends them in Elaichi and every live grant is revoked, so their next request is refused. Removing them for good is one action, with a preflight that makes sure anything a teammate depends on is handed over first.
4
ways to join: invite, verified domain, SCIM or single sign-on
Next call
when a suspended or removed member is refused
~2 min
for a role or team change to take effect
$0
for suspended members, who leave the seat count
What changes
Today
How provisioning usually works
Access is often set up by hand, account by account, so a new hire waits while someone connects the tools they need.
On the way out, the obvious systems get switched off first, and the quieter ones are easier to overlook.
Because access was granted piece by piece, accounting for all of it later takes deliberate effort.
With Elaichi
Arrive ready, leave clean
People join through your identity provider with the right role already assigned: map identity provider groups to roles, and set a default role for each verified domain and single sign-on connection.
Invites can preset both a role and a team. People who arrive through SCIM or single sign-on are added to teams afterward.
When your identity provider deactivates someone, SCIM suspends them, every live grant is revoked in the same transaction, and their next request is refused.
Removing someone is one action with a preflight: anything a shared toolbox depends on is transferred or deleted on purpose, and a deleted connection’s stored credential is removed from the vault first.
Who it is for
For the teams that bring people in and see them out
IT admins
You already manage employee accounts and sign-in in one place, and want Elaichi to follow it automatically instead of becoming one more list to keep up to date.
Security teams
When someone leaves, you need to know their AI tools lost access too, in every AI app they had connected.
HR and hiring managers
You want new starters working from their first day, and a leaver’s access closed without raising a ticket for every app.
Real situations
What it looks like in practice
A new engineer, ready at first sign-in
An engineer is added to the Engineering group in the identity provider. SCIM creates them in Elaichi, the group mapping gives them the right role, and they sign in through single sign-on. They connect their own Jira account in minutes, and the restrictions on their role are already in force.
Someone leaves on Friday and is deactivated in the identity provider. SCIM suspends them in Elaichi, so the next call any of their AI clients makes is refused. On Monday an admin removes them; the preflight flags the HubSpot connection the marketing team’s toolbox depends on, and the admin transfers it to the marketing lead instead of deleting it.
An auditor asks what a former employee did through AI before they left. The audit log keeps every call of theirs that ran, by name, and a departed member appears as Former member rather than disappearing from the record.
Setup
How to set it up
Four steps, in the order an admin takes them.
1
Verify your domain
Prove you own your email domain with a DNS TXT record. A verified domain can let new people join on their own, with a default role you choose.
2
Connect single sign-on
Add SAML or OIDC single sign-on, built in-house with no third-party auth vendor in the path, and enforce it so other sign-in methods are refused for your people.
3
Turn on SCIM
Provision users and groups with SCIM v2 and map groups to roles. Each group mapping grants at most one role, and deactivating someone in your identity provider suspends them in Elaichi.
4
Offboard with the preflight
When someone leaves for good, remove them in Elaichi. The preflight lists anything a shared toolbox depends on, and the removal goes through once each item is transferred or deleted.
Compare your options
Three ways to manage who has access
Aspect
By hand
Identity provider alone
Elaichi
Joining
Accounts set up app by app
Sign-in covered; AI access set up separately
Arrive with a role through SSO, SCIM, a domain or an invite
Roles
Granted person by person
Per app, where each app supports it
Mapped from identity provider groups
AI access when someone leaves
Keys tracked down one by one
Sign-in ends; keys and tokens set up for AI tools are handled separately
SCIM suspends them, and every live grant is revoked on the next call
Shared work
Reassigned by hand
Reassigned app by app
The preflight transfers what teammates depend on
Proof it ended
A manual checklist
The sign-in log
Every call that ran, in the audit log, by name
Under the hood
Details that matter
The specifics a careful reviewer checks, answered up front.
SCIM suspends, an admin removes. Deactivating a user in your identity provider suspends them in Elaichi. Reactivating them brings their membership back, and each AI client connects again with fresh consent. Removing a member, with its preflight, is a deliberate step, so a sync mistake never deletes anyone’s work.
Revocation is not cached. Grants are re-read on every call, so suspension and removal take effect on the next request. Roles, restrictions and team membership ride a short cache and land within about two minutes.
Private stays private. A private connection that nothing else depends on is never handed to someone else; it is deleted. If a shared toolbox relied on one, an admin decides whether to transfer or delete it before the removal goes through.
Try it in the trial. Every organization starts with a 14-day Gold trial, no credit card needed, and single sign-on, SCIM and group-to-role mapping are part of it.
On their next request. When your identity provider deactivates them, SCIM suspends them in Elaichi and every live grant is revoked in the same transaction. Suspending or removing them by hand has the same effect.
Does SCIM delete the member in Elaichi?
No. A SCIM deactivation or delete suspends the member, which revokes every grant their AI clients hold. Reactivating them restores the membership, and their clients connect again with fresh consent. Removing a member for good is a separate step an admin takes, with the offboarding preflight.
Which identity providers can manage access?
Elaichi supports SAML and OIDC single sign-on and SCIM v2 provisioning, all built in-house with no third-party auth vendor in the sign-in path, so an identity provider that speaks those standards can manage who has access.
Does SCIM put people into teams?
No. A SCIM group mapping grants at most one role and never sets team membership. Invites can preset teams, and people who arrive through SCIM, single sign-on or a verified domain are added to teams afterward.
How long until a role change takes effect?
About two minutes. Roles, restrictions and team membership resolve through a short cache. Suspension, removal and revoked shares take effect on the next request.
What stops offboarding from breaking a shared workflow?
A preflight. Before a member is removed, any of their connections a shared toolbox depends on must be transferred to another member or deleted. A private connection nothing else depends on is deleted rather than handed on.
Do we keep paying for people who have left?
Not once they are suspended. Billable seats are active memberships, so suspended members, along with free roles such as Auditor and Guest, are not counted.
Can we test single sign-on and SCIM before paying?
Yes. Every organization starts with a 14-day Gold trial, no credit card needed, and single sign-on, SCIM and group-to-role mapping are all part of it.
Wire it to your identity provider
Start a trial, connect single sign-on or SCIM, and watch a suspended account lose access on its next call.
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.
Cookies
Cookie Settings
We use cookies and similar technologies to analyze site traffic, understand where our visitors come from, and improve your browsing experience. Read our Privacy Policy.
Customize
Your preferences
Choose which categories of cookies you allow. You can change this anytime.
Strictly necessaryAlways on
Required for the site to function. Cannot be disabled.
Analytics & marketing
Helps us understand traffic, measure our advertising, and improve the product (Google Tag Manager).