sod_matrix
Detect Segregation of Duties conflicts across accounts.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Detect Segregation of Duties conflicts across accounts.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Changes observed during successful MCP inspections.
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure. It does not state whether this is a read-only analysis, what data sources it examines, whether it produces a report, or any side effects. The single phrase 'Detect...conflicts' leaves significant behavioral ambiguity.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single clear sentence with no wasted words. It front-loads the verb and resource immediately, making the intent immediately obvious to an agent.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the lack of annotations, output schema, and parameters, the description is the sole source of context. It is too terse to explain what 'detect' returns (e.g., a list of accounts, a severity report), how the tool operates, or how it relates to sibling tools like access_gap_analysis. This leaves material gaps for an agent trying to decide whether to invoke this tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters, so the input schema is trivially complete. Per the baseline for zero-parameter tools, a score of 4 is appropriate. The description's mention of 'across accounts' adds a small amount of context without needing parameter-level detail.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses the specific verb 'Detect' and identifies the resource as 'Segregation of Duties conflicts across accounts,' clearly stating the tool's core function. However, it does not differentiate this from sibling tools like access_gap_analysis or access_review, which could also reasonably be used for auditing access-related issues.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives. The description simply states what the tool does without outlining appropriate contexts, exclusions, or examples of when a sibling tool would be more suitable.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.