Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
readOnlyHint=true already establishes this as a safe read, so the bar is lower. The description goes beyond the annotation by disclosing the breadth of returned data (groups, memberships, custom attributes), which is meaningful context for a read whose return shape is not defined by an output schema. No auth or rate-limit detail, but the entity scope is well conveyed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.