elaichi-governance
Installation
SKILL.md
Governance
Two different questions, answered by two different mechanisms. Keeping them apart solves most confusion here:
- "What may this person do to Elaichi?" → roles, built from permissions. Invite people, create toolboxes, view the audit log.
- "What may this person reach through Elaichi?" → restrictions. Which connectors and tools, enforced everywhere including MCP.
A third layer sits underneath both: sharing grants on individual
connections, toolboxes, templates and connectors. A permission never
substitutes for a grant — connection:manage lets you manage a connection you
hold a grant on, and reaches no connection you do not.
Roles
Eight ship with every organization. Six form a strict chain, each one the previous plus one capability: