Skip to main content
Glama
J-MaFf

s2-netbox-mcp

by J-MaFf

get_access_history

Retrieve historical access grant/deny records with optional filters by card number or hot stamp, and enrich results with person names and reader descriptions.

Instructions

Returns historical access (grant/deny) records for optional filters (wraps NBAPI GetAccessHistory). Identifies a person by ENCODEDNUM/HOTSTAMP, not PERSONID — GetAccessHistory has no PERSONID parameter. Set RESOLVENAMES: true to enrich each returned record with the badge-holder's FIRSTNAME/LASTNAME/FULLNAME/NOTES (default false — off); enabling it costs one extra GetPerson call per distinct person found in the result, which is why it is opt-in rather than on by default. RESOLVEDESCRIPTIONS defaults to true — the only default-on optional boolean in this codebase (an inverted, opt-out default, unlike RESOLVENAMES/dryRun-style flags elsewhere): each returned record is enriched with the reader's human-readable READERDESCRIPTION via one GetReaders full-table fetch per call (not per record, since the reader table is small and fixed-size); set RESOLVEDESCRIPTIONS: false to skip it.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
ORDERNoOptional. Sort order for returned records.
HOTSTAMPNoOptional. Restrict results to this hot-stamp number.
AFTERLOGIDNoOptional. Return records strictly after this LOGID.
CARDFORMATNoOptional. Card format of ENCODEDNUM/HOTSTAMP.
ENCODEDNUMNoOptional. Restrict results to this encoded card number.
MAXRECORDSNoOptional. Maximum number of records to return.
STARTLOGIDNoOptional. Begin returning records at this LOGID.
RESOLVENAMESNoOptional (default false). Enrich each returned record with the badge-holder's FIRSTNAME/LASTNAME/FULLNAME/NOTES via one extra GetPerson call per distinct person found in the result.
RESOLVEDESCRIPTIONSNoOptional (default true — on by default; the inverse of this codebase's usual optional-boolean default). Enrich each returned record with the reader's human-readable READERDESCRIPTION via one GetReaders full-table fetch per call (not per record). Set to false to skip it.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed4 schema fields changedv0.3.0
    • removedInput schema / properties / NEWESTDTTM
      Removed value: -{
      -  "description": "Optional. Newest date/time to include.",
      -  "type": "string"
      -}
    • removedInput schema / properties / OLDESTDTTM
      Removed value: -{
      -  "description": "Optional. Oldest date/time to include.",
      -  "type": "string"
      -}
    • addedInput schema / properties / RESOLVEDESCRIPTIONS
      Added value: +{
      +  "description": "Optional (default true — on by default; the inverse of this codebase's usual optional-boolean default). Enrich each returned record with the reader's human-readable READERDESCRIPTION via one GetReaders full-table fetch per call (not per record). Set to false to skip it.",
      +  "type": "boolean"
      +}
    • addedInput schema / properties / RESOLVENAMES
      Added value: +{
      +  "description": "Optional (default false). Enrich each returned record with the badge-holder's FIRSTNAME/LASTNAME/FULLNAME/NOTES via one extra GetPerson call per distinct person found in the result.",
      +  "type": "boolean"
      +}
  2. First observedv0.2.3

TDQS

A3.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are present, so the description carries the burden. It discloses the default-off vs default-on asymmetry for RESOLVENAMES/RESOLVEDESCRIPTIONS, the cost model (per-person GetPerson calls, per-call GetReaders fetch), and the fact that identification is only by ENCODEDNUM/HOTSTAMP. This is exactly the kind of non-obvious behavior an agent needs.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The first sentence is efficient, but the long second half repeats the schema descriptions for RESOLVENAMES and RESOLVEDESCRIPTIONS almost verbatim. Useful rationale remains, but the description could be trimmed to distinguish only what the schema doesn't say.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema, it explains the record shape (grant/deny, enriched fields) and all non-obvious defaults. It doesn't list every possible returned field or describe errors, but for an optional-filter lookup with a fully described schema, the essential context is present.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema already covers all 9 parameters at 100%, including default values and cost notes. The prose adds a few contextual clues (PERSONID absence, codebase-wide inverted default, rationale for opt-in), but much of it duplicates the schema, so it hovers just above the baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource: 'Returns historical access (grant/deny) records' and immediately clarifies the identifying keys (ENCODEDNUM/HOTSTAMP, not PERSONID), which separates it from person-oriented history tools. It could have explicitly named a sibling like get_reader_access_history, so it is not a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It describes what filters exist and how to toggle enrichment, so a caller knows the operational knobs, but it never states when to prefer this tool over get_reader_access_history or get_event_history. The usage is implied by 'historical access (grant/deny) records' rather than explicitly contrasted.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.