Skip to main content
Glama

trace_security_chain

Read-onlyIdempotent

WHEN: security audit -- need the TECHNICAL chain from Role/Duty/Privilege to Entry Points and Table/Form permissions. Also handles BUSINESS-LANGUAGE role explanation when businessLanguage=true. Triggers (technical): 'sécurité de', 'who can access', 'security for', 'role duty privilege', 'droits sur', 'technical security chain', 'trace le rôle', 'what privileges does', 'what duties are assigned', 'which role allows', 'accès au formulaire', 'what roles have access', 'quel rôle donne accès'. Triggers (business language): 'what can a user with role X do', 'explain this role', 'what does this role give access to', 'quel accès donne ce rôle', 'droits du rôle', 'what licence does this role need', 'droits requis pour'. Traverses: Role -> Duties -> Privileges -> Entry Points -> Table/Form Permissions. Set businessLanguage=true for plain-language capability list (no Duty/Privilege IDs). NOT for licence cost inference per entry point -- use trace_role_license_tree for that.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
businessLanguageNoWhen true, explains the role in plain business language (capabilities list) instead of the technical Role->Duty->Privilege chain. Default: false.
securityObjectNameYesSecurity object name, e.g. 'SystemAdministrator', 'VendInvoiceApprovalConfig'

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • addedInput schema / properties / businessLanguage
      Added value: +{
      +  "default": false,
      +  "description": "When true, explains the role in plain business language (capabilities list) instead of the technical Role->Duty->Privilege chain. Default: false.",
      +  "type": "boolean"
      +}
  2. First observed

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The annotations already cover read-only, idempotent, and non-destructive behavior. The description adds the traversal path, the dual-mode behavior controlled by businessLanguage, and the fact that business mode omits Duty/Privilege IDs. It does not describe the exact return format, but the safety profile is well covered by annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-structured and front-loaded with WHEN, but the trigger lists are long and partially redundant with the prose. Still, the structure makes it skimmable and the content is relevant rather than filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a two-parameter read-only tool, the description is largely complete: it gives context, modes, scope, and an explicit alternative. It does not describe the return shape in the technical mode, and there are other security-related siblings (e.g., generate_security_report) that are not explicitly differentiated, but the core guidance is strong.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema already documents both parameters with 100% coverage, including an example for securityObjectName and the default for businessLanguage. The description adds value by explaining what businessLanguage=true changes in the output and when each mode is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool traces the technical security chain from Role/Duty/Privilege to Entry Points and Table/Form permissions, and also explains roles in business language when requested. This is specific and distinguishes it from siblings like trace_role_license_tree.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit WHEN guidance, trigger phrases for both technical and business language modes, and an explicit exclusion: NOT for licence cost inference, with the alternative tool named. An agent can decide between this tool and trace_role_license_tree without guessing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.