Skip to main content
Glama

Costory: Your Finops MCP

get_object_permissions

Read-only

List direct Reader/Editor/Admin grants on a dashboard, report, budget, or cost alert. One tool for all four kinds — pass resourceKind plus the object id from search / get / create. Returns grants (person, team, organization, or organization admins), the caller's effective role, and capabilities (canView / canEdit / canManage). canManage is true only for Admin. Budget alerts use resourceKind "budget" and the parent budget id. Templates have no ordinary grants. Read-only. EXAMPLES: • "Who can open the AWS dashboard?" → { resourceKind: "dashboard", resourceId: "clx9aws" } • "What access do I have on this report?" → { resourceKind: "report", resourceId: "clx9rpt" }

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
slugNoOrganization slug. Omit to auto-detect from your account (fails if you belong to multiple orgs).
resourceIdYesObject id from search, get, or create.
resourceKindYesdashboard, report, budget, or costAlert. Budget alerts use the parent budget.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.6/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true and destructiveHint=false, and the description reinforces this with 'Read-only.' It adds meaningful behavioral context beyond annotations: the special case for budget alerts (use parent budget id), the fact that templates have no ordinary grants, and the semantic detail that canManage is true only for Admin. It does not describe pagination or error behavior, but for a read-only listing tool this is a minor gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact and front-loaded: the core purpose appears in the first sentence, followed by return-value summary, special cases, and examples. Every sentence earns its place, and the examples are illustrative without being verbose.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only tool with full schema coverage and safety annotations, the description covers the essential invocation details: resource kinds, id provenance, return contents, and edge cases (budget alerts, templates). It lacks an output schema and does not describe pagination or error conditions, but those are not critical for a permissions-listing tool with this level of guidance.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all three parameters. The description adds value by explaining the relationship between resourceKind and resourceId ('pass resourceKind plus the object id from search / get / create'), clarifying the budget-alert special case, and providing concrete example values. It slightly exceeds the baseline 3 by enriching the enum semantics with usage context.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('List') and resource ('direct Reader/Editor/Admin grants on a dashboard, report, budget, or cost alert'), and explicitly distinguishes itself from the sibling set by covering all four resource kinds in one tool. It also clarifies what it returns (grants, caller's effective role, capabilities), making the tool's purpose unmistakable.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit when-to-use guidance: 'One tool for all four kinds — pass resourceKind plus the object id from search / get / create.' It also provides exclusions ('Templates have no ordinary grants') and two concrete examples mapping natural-language questions to parameter values. This is strong routing guidance relative to siblings like set_object_permissions and get.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources