Skip to main content
Glama

Grant Cloud Access

grant_cloud_access
DestructiveIdempotent

Give a workload credential-free access to AWS, GCP, or Azure resources through a cloud account: ensures the workload has an identity, binds the provider access to it (policyRefs or roleName for AWS, bindings or serviceAccount for GCP, roleAssignments for Azure), and waits until the identity reports it usable. The cloud account must exist already (create_cloud_account and how_to_create_cloud_account, full profile). Replaces this identity's existing provider configuration, so previous access can be revoked for every workload sharing the identity. No key passes through the chat.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
awsNoWith provider aws: policyRefs or roleName, one of the two.
gcpNoWith provider gcp: bindings or serviceAccount, one of the two.
gvcYesGVC slug. If the user named none, list_resources (kind "gvc") and let them choose.
orgNoOrganization slug.
azureNoWith provider azure.
providerYes
workloadYesWorkload that needs the access.
waitSecondsNoSeconds to wait on the server until the identity reports the access usable, 0 to 45. The call returns as soon as it is, or with the latest state when the time runs out. Use this instead of calling again and again.
cloudAccountYesAn existing cloud account of that provider (create_cloud_account, full profile).

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okYes
dataNoThe full result. Read this, not only the summary.
detailsNo
summaryYes
nextStepsNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.3/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare destructiveHint=true and idempotentHint=true, and the description substantiates exactly why: it replaces existing provider configuration so previous access can be revoked for every workload sharing the identity. It also discloses the blocking wait-until-usable behavior and the credential-free guarantee ('no key passes through the chat'), which annotations cannot convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single dense paragraph that front-loads the core action, then prerequisites, then the destructive replacement caveat. Every sentence carries information, though it is lengthy and could be broken into scannable clauses.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 9-parameter tool with nested objects, an output schema, and full annotation coverage, the description covers the critical unknowns: prerequisites, replace semantics, and the wait behavior. It is close to complete; only explicit guidance on choosing among alternative access tools is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 89%, so the schema already documents parameters thoroughly. The description summarizes the provider-specific fields (policyRefs/roleName, bindings/serviceAccount, roleAssignments), which is useful orientation but largely restates the schema rather than adding new meaning. Baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a precise verb (grant) and resource (credential-free cloud access to AWS/GCP/Azure) plus the three-step mechanism (create identity, bind provider access, wait until usable). This clearly distinguishes it from siblings like allow_workload_access and create_cloud_account, which handle different resources.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives a hard prerequisite (the cloud account must already exist, pointing to create_cloud_account and how_to_create_cloud_account) and warns that it replaces this identity's existing provider configuration. It does not explicitly state when NOT to use it versus the alternative access-granting tools, so it stops short of 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.