Skip to main content
Glama

Pre-Disbursement Due Diligence Guard (Check Before You Send)

pre_disbursement_guard
Read-onlyIdempotent

MANDATORY COUNTERPARTY DUE DILIGENCE: Verifies counterparty before releasing invoice payments, contractor payouts, or wires. Screens ISO 13616 IBAN checksum, RDAP domain age (<30d = scam), disposable email domains, UK CRN/LEI format, and BEC cross-jurisdiction mismatches. Produces signed XDR-1 receipt for compliance.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
leiNoISO 17442 Legal Entity Identifier (optional).
vat_numberNoEU VAT number (optional).
vendor_domainNoVendor website domain or invoicing email address (optional).
company_numberNoOfficial corporate registration number, e.g. UK Companies House 8 digits/chars (optional).
recipient_ibanNoRecipient bank IBAN (optional).
declared_countryNo2-letter ISO country code where vendor claims to be registered (optional, e.g. 'GB', 'US', 'DE').
physical_addressNoVendor physical office address (optional).
invoice_amount_usdNoDisbursement transaction amount in USD (optional).

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
toolNo
scopeNo
checksNo
summaryNo
decisionYes
risk_levelYes
risk_scoreYes
flags_triggeredNo
recommendationsNo
clear_to_disburseYes
inspected_counterpartyNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover read-only, open-world and idempotent behavior, and the description adds real value beyond them: external RDAP domain-age lookups, disposable-email screening, cross-jurisdiction BEC mismatch detection, and the signed XDR-1 compliance receipt. It stops short of explaining what happens when no parameters are supplied or how failed/partial screens are reported.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three dense, front-loaded sentences with no filler; the mandatory-usage cue leads and the check list follows. The all-caps prefix and packed enumeration make it slightly shouty but still efficient.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema, full annotation coverage and a fully described parameter set, the description only needs to convey purpose, checks and the compliance artifact, which it does. The remaining gap is the absence of guidance on minimum required inputs given that all eight parameters are optional.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description ties checks to specific inputs (IBAN checksum to recipient_iban, domain age to vendor_domain, CRN/LEI format to company_number/lei) and even gives a decision threshold ('<30d = scam'), which adds meaning beyond the schema text.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Verifies counterparty before releasing invoice payments, contractor payouts, or wires') and enumerates the exact checks performed, so an agent knows precisely what the tool does. It does not explicitly differentiate itself from narrower siblings like iban_check or lei_check that cover a subset of the same signals, which keeps it just short of a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The 'MANDATORY ... before releasing invoice payments' framing and the 'Check Before You Send' title give clear context for when to invoke it. No when-not conditions or explicit routing to/from siblings are stated, so it is clear but incomplete on alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.