Skip to main content
Glama

kevaremesh

Trust Identity Permission Policy Engine AAB3

trust_identity_permission_policy_engine_aab38e57
Read-onlyIdempotent

Evaluates caller-supplied facts against explicit caller-supplied rules and returns blocking violations and warnings. Intended for trust identity permission / trust unknown. Do not use for legal, identity, sanctions, fraud, contractual, or regulatory adjudication. Paid resource; x402 price is $0.002 USD per call at the direct resource URL.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
factsYes
rulesYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover readOnly, openWorld, idempotent, and non-destructive behavior, lowering the burden on the description. The description adds useful context by specifying the output kind (blocking violations and warnings), the caller-supplied facts/rules nature, and the paid x402 price. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is three concise, front-loaded sentences: core action, intended/excluded usage, and cost. Every sentence earns its place and there is no repetition of schema content.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description provides intended use, exclusions, output kind, and cost, which is more than minimal. However, facts is an open object with no description of expected structure or examples, and there is no output schema or rule-to-result mapping, so an agent may still be uncertain how to construct valid input or interpret the response fully.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the prose needed to explain facts and rules. 'Caller-supplied facts against explicit caller-supplied rules' largely restates the required parameter names without explaining the fact object shape, field path semantics, or how rule severity maps to blocking violations versus warnings. The rule schema itself is detailed, but the description adds little meaning beyond it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb and resource: it 'Evaluates caller-supplied facts against explicit caller-supplied rules and returns blocking violations and warnings.' It also narrows the intended domain to 'trust identity permission / trust unknown' and explicitly excludes several other adjudication domains, which distinguishes it from the many sibling policy engines.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit intended use ('Intended for trust identity permission / trust unknown') and explicit exclusions ('Do not use for legal, identity, sanctions, fraud, contractual, or regulatory adjudication'). It does not name a specific sibling alternative to prefer, so it stops just short of full alternative routing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources