get_object_permissions
List direct Reader/Editor/Admin grants on a dashboard, report, budget, or cost alert. One tool for all four kinds — pass resourceKind plus the object id from search / get / create. Returns grants (person, team, organization, or organization admins), the caller's effective role, and capabilities (canView / canEdit / canManage). canManage is true only for Admin. Budget alerts use resourceKind "budget" and the parent budget id. Templates have no ordinary grants. Read-only.
EXAMPLES:
• "Who can open the AWS dashboard?" → { resourceKind: "dashboard", resourceId: "clx9aws" }
• "What access do I have on this report?" → { resourceKind: "report", resourceId: "clx9rpt" }
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| slug | No | Organization slug. Omit to auto-detect from your account (fails if you belong to multiple orgs). | |
| resourceId | Yes | Object id from search, get, or create. | |
| resourceKind | Yes | dashboard, report, budget, or costAlert. Budget alerts use the parent budget. |