Skip to main content
Glama

Costory: Your Finops MCP

create_alert

Create a cost alert that monitors one or more queries and notifies when a condition fires. New alerts are creator-only (you get Admin). To share, call set_object_permissions with resourceKind "costAlert". Accepts the same query config as query (prefer datePreset over hand-computed from/to). scopeId is the same id as list_teams. It is stored on the alert and is not merged into the query filters. Omit it for no scope. The firing rule is a single condition boolean expression over the query names, e.g. a > 1000, rollingSum(a, 7, DAY) > 50000, or (a - timeShift(a, 1, DAY)) / timeShift(a, 1, DAY) > 0.2. Window math (rollingSum/weekToDateSum/monthToDateSum/timeShift) is evaluated daily in BigQuery, so you do NOT pick an evaluation period — instead set dedup to control re-notification frequency (CALENDAR once per WEEK/MONTH, or ROLLING once every N days). The period (datePreset or from/to) defines the preview/look-back window for the underlying queries. Use list_available_destinations for SLACK/TEAMS channel IDs. Optional tagIds: existing IDs from list_tags and/or { name, color? } for new tags; color defaults to #6366F1; missing tags are created. Omit and [] both leave the alert untagged. Returns a URL that you MUST include in your response so the user can view/edit the alert. EXAMPLE: "Alert me on Slack if our production AWS spend exceeds $50k over any 7 days, at most once a week" → { name: "Prod AWS weekly alert", queries: [{ type: "cost", name: "a", metricId: "cost", currency: "USD", filterCel: "cos_provider in ["AWS"] && cos_environment in ["prod"]" }], datePreset: "TRAILING_90_DAYS", condition: "rollingSum(a, 7, DAY) > 50000", dedup: { kind: "CALENDAR", calendarUnit: "WEEK" }, notificationChannel: "SLACK", slackChannelId: "C01ABC" }

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
toNoExplicit window end (inclusive, YYYY-MM-DD). Use with from instead of datePreset.
fromNoExplicit window start (YYYY-MM-DD). Use with to instead of datePreset.
nameYesDisplay name for the alert.
slugNoOrganization slug. Omit to auto-detect from your account (fails if you belong to multiple orgs).
aggByNoTime grain for the series: Hour, Day, Week, Month, or Period (default Month).Month
dedupYesDeduplication config controlling how often a still-firing group notifies. The window is per groupBy value; delivery stays one message listing newly eligible groups. Either CALENDAR (kind: CALENDAR, calendarUnit: WEEK | MONTH) = at most once per current ISO week / calendar month, or ROLLING (kind: ROLLING, windowDays: N) = at most once every N days.
limitNoMax groups/rows per series. Omit to use the default (100). Increase up to 1000 when you need more than 100 breakdown groups.
emailsNoEmail addresses (required if EMAIL)
tagIdsNo`list_tags` id or `{ name, color? }` (created if missing, default #6366F1). Omit and [] leave it untagged.
compareNoAdd a comparison period to show cost evolution side-by-side. Omit `from`/`to` to compare against the preceding period automatically; set `chartType` to choose how it renders.
queriesNoSame series objects as the `query` tool `queries` array (cost / metric / usage / externalMetric / formula / budget). Each requires `type` (never omit) and a `name` (prefer short ids like a/b/c); put human labels in `alias`.
scopeIdNoTeam scope id (list_teams). Stored on the alert, not merged into query filters. Omit for no scope.
conditionYesAlerts v3 firing rule: a single boolean expression over the query names (`name` field of each query). Supports arithmetic (+ - * /), comparisons (> >= < <= == !=), logical and/or/not, parentheses, and these window functions: rollingSum(a, N, UNIT) (trailing sum over the last N units, UNIT ∈ DAY|WEEK|MONTH, inclusive of today), weekToDateSum(a) (Monday-to-date), monthToDateSum(a) (1st-of-month-to-date), and timeShift(a, N, UNIT) (value shifted back N units; may wrap a window function). Examples: `a > 1000`, `rollingSum(a, 7, DAY) > 1000`, `(a - timeShift(a, 1, DAY)) / timeShift(a, 1, DAY) > 0.2`, `a > 10000 or rollingSum(a, 7, DAY) > 50000`.
datePresetNoOfficial date preset (same DatePreset as dashboards/reports, e.g. MTD, LAST_MONTH, TRAILING_30_DAYS). Prefer this over hand-computed from/to when a preset matches. Mutually exclusive with from/to.
slackChannelIdNoSlack target id (required if SLACK): a channel id (C…) to post to a channel, or a Slack user id (U…) to deliver a direct message to that user. Use list_available_destinations to discover both channels and the signed-in user's DM.
teamsChannelIdNoTeams channel ID (required if TEAMS)
notificationChannelYesNotification channel

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedInput schema / properties / scopeId / description
      Previous value: -"Optional saved team scope id (from list_teams). Merges the scope whereClause into cost/usage queries."New value: +"Team scope id (list_teams). Stored on the alert, not merged into query filters. Omit for no scope."
  2. Changed1 schema field changed
    • addedInput schema / properties / tagIds
      Added value: +{
      +  "description": "`list_tags` id or `{ name, color? }` (created if missing, default #6366F1). Omit and [] leave it untagged.",
      +  "items": {
      +    "anyOf": [
      +      {
      +        "description": "Existing tag ID",
      +        "minLength": 1,
      +        "type": "string"
      +      },
      +      {
      +        "additionalProperties": false,
      +        "properties": {
      +          "color": {
      +            "default": "#6366F1",
      +            "description": "Hex color for the new tag (defaults to #6366F1)",
      +            "minLength": 1,
      +            "type": "string"
      +          },
      +          "name": {
      +            "minLength": 1,
      +            "type": "string"
      +          }
      +        },
      +        "required": [
      +          "name"
      +        ],
      +        "type": "object"
      +      }
      +    ]
      +  },
      +  "type": "array"
      +}
  3. Changed1 schema field changed
    • changedInput schema / properties / datePreset / enum
      Previous value: -[
      -  "TRAILING_90_DAYS",
      -  "TRAILING_30_DAYS",
      -  "TRAILING_45_DAYS",
      -  "TRAILING_7_DAYS",
      -  "TRAILING_3_DAYS",
      -  "TRAILING_14_WEEKS",
      -  "MTD",
      -  "QTD",
      -  "YTD",
      -  "CURRENT_MONTH",
      -  "CURRENT_QUARTER",
      -  "CURRENT_YEAR",
      -  "LAST_WEEK",
      -  "LAST_MONTH",
      -  "LAST_6_MONTHS",
      -  "LAST_12_MONTHS",
      -  "LAST_4_YEARS",
      -  "LAST_3_MONTHS",
      -  "LAST_INVOICE_MONTH"
      -]New value: +[
      +  "TRAILING_90_DAYS",
      +  "TRAILING_30_DAYS",
      +  "TRAILING_45_DAYS",
      +  "TRAILING_7_DAYS",
      +  "TRAILING_3_DAYS",
      +  "TRAILING_1_DAYS",
      +  "TRAILING_14_WEEKS",
      +  "MTD",
      +  "QTD",
      +  "YTD",
      +  "CURRENT_MONTH",
      +  "CURRENT_QUARTER",
      +  "CURRENT_YEAR",
      +  "LAST_WEEK",
      +  "LAST_MONTH",
      +  "LAST_6_MONTHS",
      +  "LAST_12_MONTHS",
      +  "LAST_4_YEARS",
      +  "LAST_3_MONTHS",
      +  "LAST_INVOICE_MONTH"
      +]
  4. Changed1 schema field changed
    • changedInput schema / properties / dedup / description
      Previous value: -"Deduplication config controlling how often a still-firing alert notifies. Either CALENDAR (kind: CALENDAR, calendarUnit: WEEK | MONTH) = at most once per current ISO week / calendar month, or ROLLING (kind: ROLLING, windowDays: N) = at most once every N days."New value: +"Deduplication config controlling how often a still-firing group notifies. The window is per groupBy value; delivery stays one message listing newly eligible groups. Either CALENDAR (kind: CALENDAR, calendarUnit: WEEK | MONTH) = at most once per current ISO week / calendar month, or ROLLING (kind: ROLLING, windowDays: N) = at most once every N days."
  5. Changed1 schema field changed
    • changedInput schema / properties / datePreset / enum
      Previous value: -[
      -  "TRAILING_90_DAYS",
      -  "TRAILING_30_DAYS",
      -  "TRAILING_45_DAYS",
      -  "TRAILING_7_DAYS",
      -  "TRAILING_3_DAYS",
      -  "TRAILING_14_WEEKS",
      -  "MTD",
      -  "QTD",
      -  "YTD",
      -  "LAST_WEEK",
      -  "LAST_MONTH",
      -  "LAST_6_MONTHS",
      -  "LAST_12_MONTHS",
      -  "LAST_4_YEARS",
      -  "LAST_3_MONTHS",
      -  "LAST_INVOICE_MONTH"
      -]New value: +[
      +  "TRAILING_90_DAYS",
      +  "TRAILING_30_DAYS",
      +  "TRAILING_45_DAYS",
      +  "TRAILING_7_DAYS",
      +  "TRAILING_3_DAYS",
      +  "TRAILING_14_WEEKS",
      +  "MTD",
      +  "QTD",
      +  "YTD",
      +  "CURRENT_MONTH",
      +  "CURRENT_QUARTER",
      +  "CURRENT_YEAR",
      +  "LAST_WEEK",
      +  "LAST_MONTH",
      +  "LAST_6_MONTHS",
      +  "LAST_12_MONTHS",
      +  "LAST_4_YEARS",
      +  "LAST_3_MONTHS",
      +  "LAST_INVOICE_MONTH"
      +]
  6. First observed

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly=false, destructive=false, and openWorld=false, but the description adds substantial unsurfaced behavior: creator-only ownership with Admin rights, the need to call set_object_permissions to share, scopeId storage semantics, daily BigQuery evaluation of window math, dedup re-notification behavior, and the mandatory return URL. This is rich behavioral context beyond the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is long but front-loads the core purpose and then addresses permissions, query config, scope, condition, dedup, tags, and return value in a logical order. Most sentences earn their place, though some details duplicate the rich schema descriptions and could be trimmed.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (17 nested parameters, 4 required), the lack of an output schema, and the available annotations, the description covers the critical behaviors an agent needs: creator-only access, sharing path, query configuration, firing-rule syntax, deduplication semantics, tag handling, and the required return URL usage. Nothing essential appears missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3. The description nevertheless adds value by giving concrete condition examples, explaining the relationship to the query tool's config, clarifying that scopeId is not merged into filters, and illustrating tagIds creation behavior. It does not describe every parameter beyond the schema, so it does not reach 5.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Starts with a specific verb and resource: 'Create a cost alert that monitors one or more queries and notifies when a condition fires.' This clearly distinguishes it from sibling tools like preview_alert and update_alert.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly routes the agent to set_object_permissions for sharing, list_available_destinations for channel IDs, and list_tags for tag IDs. It also states a preference for datePreset over hand-computed from/to. However, it does not explicitly say when to use create_alert versus preview_alert or update_alert, so it falls short of a full 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources