Skip to main content
Glama

get_security_coverage_for_object

Read-onlyIdempotent

WHEN: developer/security architect needs to know WHICH ROLES can access a specific form, table, menu item or service operation. Triggers: 'who can access', 'which roles see', 'security coverage for', 'quels roles ont accès à', 'find roles with access'. Walks the security graph backwards (EntryPoint -> Privilege -> Duty -> Role) and returns all roles that grant any level of access (Read / Update / Create / Delete / Correct) on the given object. Read-only: scans the in-memory KB, never writes.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
maxRolesNoMaximum roles to expand (default 30, max 100).
minGrantNoOptional: minimum grant level to include in results. Values: 'Read', 'Update', 'Create', 'Delete', 'Correct', 'Any'. Default: 'Any'.Any
objectNameYesObject name to audit (form, table, menu item, service operation). Example: 'CustTable', 'SalesTableListPage', 'CustCustomerServiceMenu'.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The annotations already declare readOnlyHint and destructiveHint, and the description reinforces this with 'Read-only: scans the in-memory KB, never writes.' It adds behavioral detail beyond the annotations by revealing the backward graph traversal path (EntryPoint -> Privilege -> Duty -> Role) and the full set of grant levels considered. No contradiction with annotations exists.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is organized into tight labeled segments: a WHEN clause, trigger phrases, a traversal explanation, and a read-only note. Each section earns its place, and the trigger list improves discoverability for an agent matching user intent. It is slightly longer than strictly necessary but remains efficient and well-structured.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema present, the description explains the core return value (roles granting any access level) and how the result is computed. It does not spell out the exact result structure or the behavior when maxRoles is exceeded, but the provided context is enough for an agent to decide when to invoke it. The explanation reasonably compensates for the missing output schema.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already describes all three parameters completely, so the description carries little additional burden. It does contextualize objectName as a form/table/menu item/service operation and lists grant levels, but these largely overlap with the schema's examples and values. The phrase 'returns all roles' also sits slightly at odds with the maxRoles parameter, so the description does not add meaningful parametric clarity beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific objective: determining which roles can access a specific form, table, menu item, or service operation. It explicitly names object types and states the backward graph traversal that returns granting roles, which clearly distinguishes it from sibling tools. This is a precise, unambiguous definition.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides a clear WHEN clause and a list of natural-language triggers, making the invocation context concrete for an agent. However, it does not mention alternative tools like trace_security_chain or generate_security_report, nor does it give explicit when-not-to-use conditions. The context is sufficient for basic routing but lacks exclusions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.