Skip to main content
Glama

Costory: Your Finops MCP

set_object_permissions

Replace the full grant list on a dashboard, report, budget, or cost alert. One tool for all four kinds — pass resourceKind, the object id, and the complete intended grants array. Omitted principals lose access. Roles are READER, EDITOR, or ADMIN. ORGANIZATION may be Reader or Editor, never Admin. CLERK_ADMIN may use any role and applies only to Clerk organization admins; omit it for No access. Every replacement must retain at least one USER, TEAM, or CLERK_ADMIN Admin grant, so empty grants[] is invalid. Call get_object_permissions first, then send the full list including grants you want to keep. New creates start as creator-only Admin and do not include CLERK_ADMIN. Do not use PRIVATE/PUBLIC or teamId on create/update tools. Resolve people with list_users (userId) and teams with list_teams (teamId) — both list the full organization, not only membership. EXAMPLES: • "Share the AWS dashboard read-only with the whole org" (keep yourself as Admin) → { resourceKind: "dashboard", resourceId: "clx9aws", grants: [{ principalType: "USER", userId: "", role: "ADMIN" }, { principalType: "ORGANIZATION", role: "READER" }] } • "Give the infra team Editor on this budget" (keep yourself as Admin) → { resourceKind: "budget", resourceId: "clx9bud", grants: [{ principalType: "USER", userId: "", role: "ADMIN" }, { principalType: "TEAM", teamId: "team_xyz", role: "EDITOR" }] }

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
slugNoOrganization slug. Omit to auto-detect from your account (fails if you belong to multiple orgs).
grantsYesFull replacement of direct grants. Omitted principals lose access. Every object must retain a USER, TEAM, or CLERK_ADMIN Admin grant. Each principal may appear once.
resourceIdYesObject id from search, get, or create.
resourceKindYesdashboard, report, budget, or costAlert. Budget alerts use the parent budget.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations, it discloses the real side effects and invariants: omitted principals lose access, empty grants[] is invalid because an Admin grant must remain, and ORGANIZATION/CLERK_ADMIN role restrictions. It also explains the default state for newly created objects (creator-only Admin, no CLERK_ADMIN) and warns about PRIVATE/PUBLIC/teamId misuse. This is materially more than annotation hints.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description front-loads the core action and scope, then layers constraints, workflow, and examples in a logical order. It is long, but every sentence carries a distinct rule or procedure, and the two examples make the complex grant array concrete.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a write tool with no output schema, the description covers everything required to invoke it correctly: complete grant semantics, required invariants, prerequisite calls, principal resolution, and example payloads. The only omitted item is the return value, which is not needed for a set-permissions operation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Although the schema already covers the parameters (100%), the description adds meaning the schema does not: 'full replacement', 'omitted principals lose access', role rules per principal type, and exact examples with principalType/userId/teamId/role combinations. It also explains how to resolve principals with list_users/list_teams. This transforms the grant array from a generic array into a guided operation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The first sentence names a specific action ('Replace the full grant list') and a bounded resource set ('dashboard, report, budget, or cost alert'), so the agent immediately knows what the tool does and that it spans four object kinds. It also references get_object_permissions, making the read/write pairing clear without requiring the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives a clear workflow: call get_object_permissions first, then send the full grants list, and resolve principals via list_users/list_teams. It does not, however, contain an explicit 'when not to use' or a direct alternative-tool selection, apart from the prerequisite read tool, so it falls just short of a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources